Privacy Policy
Last updated: 25 August 2026 · Forest Technologies (פורסט טכנולוגיות מסחר אלקטרוני בע״מ)
1. Who we are
Bookie is software for scheduling a meeting across several Google calendars. It is operated by Forest Technologies (פורסט טכנולוגיות מסחר אלקטרוני בע״מ), a company registered in Israel, company number 516101516, at bookie.forestech.io.
The owner, and the person answerable for privacy, is Netzah Topaz, n@forestech.io. Day to day privacy requests, including review, correction and deletion, go to bookie@forestech.io and are answered within 30 days.
This document describes what we store, what for, for how long, and how to delete it. It is written to be read.
The database's standing under the Privacy Protection Law
Bookie is subject to the Israeli Privacy Protection Law, 5741-1981, as amended by Amendment 13, in force since August 2025. The law raises two questions, and here are the answers:
- Database registration. Amendment 13 directs the registration obligation at public bodies, at businesses trading in data, and at databases whose main occupation is specially sensitive data at scale. Bookie's database holds business contact details of employees, busy and free time ranges from calendars, and billing records of companies. It sits outside those three categories, so the law governs it through its protection, transparency and reporting duties, all of which apply in full.
- Privacy protection officer. The law directs the appointment obligation at public bodies, at data brokers and direct marketing services holding data on 10,000 people or more, at organizations whose core activity is systematic and ongoing monitoring, and at organizations whose main business is processing specially sensitive data at scale. Bookie sits outside those four categories. Responsibility for privacy in the product rests with Netzah Topaz, the owner, whose address appears above.
2. What Bookie does with your calendar
Bookie does two things with Google, and that is the full extent of it:
- It asks when people are free. For calendars whose owners connected them deliberately, Bookie asks Google which time ranges are busy and which are free. What comes back is time ranges.
- It writes the meeting that was booked. When someone picks a time, Bookie creates an event on the participants' primary calendars with the title, time and attendees entered in Bookie.
What Bookie reads from Google is a time range in one of three states: busy, free, and a third state where Google answers that the range is withheld from us, at which point Bookie names the person and asks them to confirm. Event titles, descriptions and attendee lists stay in Google Calendar.
3. The three Google scopes we request
Bookie requests the smallest set of permissions that lets it work. These are the three calendar scopes, exactly as they appear on Google's consent screen:
https://www.googleapis.com/auth/calendar.freebusy
Lets Bookie ask Google when a given calendar is busy and when it is free. The answer is time ranges.
https://www.googleapis.com/auth/calendar.calendarlist.readonly
Lets Bookie see which calendars exist in the account, so it knows which ones to ask about availability. This scope also returns calendar titles. A title is stored to match a calendar to its owner, and it stays inside the system.
https://www.googleapis.com/auth/calendar.events.owned
Grants access to events on calendars the user owns. Bookie uses it to create, update and cancel the meetings Bookie itself created, at your request or at the request of your organization's admin.
These three scopes are the full extent of what Google's consent screen shows. Gmail, Drive and Contacts stay outside that extent.
4. What we store
This is the complete list. A field by field breakdown, including the database table each field lives in, is maintained against the code itself in docs/legal/data-map.md. The purpose beside each field is the only purpose it serves.
| What | Why |
|---|---|
| Your Google subject id, email address, name and profile picture URL | To identify you at sign in. Identity keys on the stable subject id, so changing your address keeps you in the same account |
| Your timezone and your organization's timezone | To show correct times |
| Your company name and its Google Workspace domain | So a second colleague from the same company joins the existing organization |
| Your memberships and role in each organization | Permissions inside the product |
| An encrypted Google refresh token | So Bookie can check availability and book meetings over time from a single sign in. Encrypted with AES-256-GCM, with the key held off the server's disk |
| The ids and titles of the connected calendars | Matching a calendar to its owner. The title stays inside the system and serves that match alone |
| Availability preferences: working days, working hours, buffer between meetings, minimum notice | So the times we offer fit you |
| Scheduling requests: title, duration, date range, and the participant list including the name and email of an external participant | This is what the person scheduling enters |
| Meetings Bookie created: title, start and end time, the Google event and calendar ids, event link, Meet link, the external party's name and email, and a note or location if entered | To display, update and cancel those meetings |
| A hash of every invitation link and booking link, with an expiry date | The link itself stays with whoever received it. A copy of the database holds hashes |
| A hash of a calendar id together with the time range it holds | The mechanism that makes double-booking the same person impossible. The hash keeps the address itself out of the row |
| An audit log: who did what and when, plus a request correlation id | Security, support and fault diagnosis |
| Billing records: subscription state, plan, trial and payment dates, amounts, the VAT rate that applied at issue, SUMIT identifiers and the iCount document number | Accounting and commercial obligation |
Availability ranges live in memory alone. The busy ranges that come back from Google exist in process memory for one calculation, show you the possible times, and vanish when the calculation ends.
5. What stays outside Bookie
- Your calendar's contents. Titles, descriptions, attachments and attendee lists of events created outside Bookie stay in your Google Calendar.
- Availability ranges. They live in process memory for one calculation, as section 4 describes.
- Gmail, Drive and Contacts. They stay outside the scopes we requested. The three scopes in section 3 are the full extent.
- Card details. The card is entered on SUMIT's secure payment page and stays with SUMIT. What Bookie receives back is a transaction id and an outcome.
- Your password. Sign in runs through your Google account, so the protection on your Bookie account is the protection you have configured on Google, including any second factor.
Between two companies that both use Bookie, what crosses is the times that are free for both sides. Each company's event titles, participants and calendar blocks stay with that company.
6. Cookies
One cookie: a signed session cookie that keeps you signed in from page to page. It is the whole of the client-side storage the product uses, and deleting it signs you out.
The typeface is served from our own server too, so loading a Bookie page contacts the Bookie server alone.
7. Subprocessors
| Provider | For | Where |
|---|---|---|
| Sign in and identity, calendar availability and event writes | United States and European Union | |
| Hetzner | Server and database hosting | Germany |
| Amazon Web Services, SES | Outbound email from the product | Ireland |
| SUMIT | Card processing and the hosted payment page | Israel |
| iCount | Invoices and receipts | Israel |
| Cloudflare | DNS. A lookup returns our server's address, and your traffic then reaches that server directly | Global |
Data stays within this list of providers. Transfer to any further party happens with your consent, or where required by law or by an order of a competent authority. The list is updated here before a new provider starts work, and section 14 describes how that is announced.
8. Where the data lives and how it crosses borders
Bookie's database sits on a server in Germany. Outbound mail goes through AWS SES in Ireland. Billing and invoicing are processed in Israel. Google processes availability queries on its infrastructure in the United States and the European Union.
The Privacy Protection (Transfer of Data to Databases Abroad) Regulations, 5761-2001, permit a transfer when one of the conditions in regulation 2 is met, and additionally require a written undertaking from the recipient to protect the data and to keep it from moving further on. Here is how that holds for each provider:
- Germany and Ireland. Hetzner and AWS operate inside the European Union, where the GDPR applies. That is a level of protection equal to what Israeli law requires, which is the first condition in regulation 2. The contract with each of them includes its Data Processing Terms, which are the written undertaking the regulations call for.
- United States. Google runs part of the calendar infrastructure in the United States. The transfer rests on Google's Data Processing Terms, which incorporate the European Union Standard Contractual Clauses and Google's undertaking to secure the data and to move it on only under our instructions. That is the condition in regulation 2 that allows a transfer on the strength of the recipient's contractual undertaking.
- Israel. SUMIT and iCount process billing and invoices in Israel, inside the same legal framework that applies to Bookie.
Israel is recognised by the European Commission as providing an adequate level of protection, a decision granted in 2011 and renewed in January 2024. Data therefore moves between the servers in Germany and the billing systems in Israel inside a single framework of protection.
9. Retention and deletion
Disconnecting a calendar
Disconnecting from inside Bookie, or removing access from your Google account permissions page, deletes the calendar connection and destroys the encrypted refresh token. From that moment Bookie reaches Google again only after a fresh connection you approve.
When a member is removed from an organization
That person's Google connection for that organization is deleted and the encrypted refresh token is destroyed. Meetings already booked stay in their calendar, because those are theirs.
When an organization is deleted
Deleting an organization starts a 30 day clock. At the end of it every piece of organization data is erased: calendar connections and tokens, connected calendars, preferences, invitations and links, scheduling requests and participants, meetings, and audit records. Two rows continue to exist, and this is what they look like afterwards:
- The company row is kept as an anonymous identifier. The name is replaced with a fixed value and the domain is erased, leaving an internal number and two dates. It exists so that billing records and invoices, which Israeli tax law requires to be kept for seven years, stay attached to their source.
- The user row is kept with the Google subject id, the email address and the name. It is the row that audit records and invitations in other Bookie organizations point to, which is why it continues to exist after the organization is gone. Anyone who wants that row erased writes to bookie@forestech.io and we carry out the deletion within 30 days, subject to the accounting records the law requires us to keep.
Other timings
- Invitation links and booking links are live for 14 days, and expire from that moment.
- Audit records are kept for the life of the organization and deleted with it.
- Billing records, payments and invoices are kept for seven years, as Israeli tax law requires.
- Encrypted backups hold deleted data until the backup cycle completes, and at most 30 days.
How to request deletion
You can carry out the deletion from inside the product. The full path is on the data deletion page. If something gets stuck, write to bookie@forestech.io and we will handle it within 30 days.
10. Security
- All traffic is encrypted with HTTPS.
- Google refresh tokens are encrypted in the database with AES-256-GCM. The encryption is bound to the row it sits in, so copying a ciphertext into another row leaves it sealed. The key is served into process memory from the Forest secret store and is held off the server's disk.
- Separation between customers is enforced in the database itself with row level security, underneath the application code. A query that forgets its filter returns zero rows.
- Invitation and booking links are stored as hashes, so a copy of the database holds hashes.
- Sign in runs through Google, so the protection on the account is the protection you have configured in your Google account.
Any certification, audit or cyber insurance we obtain will appear here by name and date. What is written here today is what is running today.
11. Your rights under Israeli law
Bookie is subject to the Israeli Privacy Protection Law, 5741-1981, as amended by Amendment 13. These are your rights and the way to exercise them:
- Review. Under section 13 of the law, any person may review the data held about them. We send the data we hold about you in a readable format, to the address the request came from.
- Correction. Under section 14 of the law, you may ask that data which is inaccurate, misleading or out of date be corrected. Your name, email and timezone are editable directly in the product, and any other field is corrected by us on request.
- Deletion. You can delete a calendar connection, a membership, and the whole organization from inside the product, as described in section 9 and on the data deletion page. Accounting documents are kept for seven years as tax law requires, and section 9 sets out exactly what remains in them.
- Being told. The law requires us to tell you who runs the database, what the data is collected for, and who it is passed to. Sections 1, 4 and 7 answer those three questions, and they are where the answers are kept current.
The way to exercise any of these is one message to bookie@forestech.io. We identify the sender by the email address on the account, and reply within 30 days.
Anyone who wishes to approach the regulator does so through the Privacy Protection Authority at the Ministry of Justice, at gov.il.
12. Visitors from the European Union
Bookie is built for businesses in Israel, the prices are in shekels and the product is in Hebrew. The site is nonetheless reachable from Europe and our servers are in Germany, so here is the position:
- Legal basis. Performance of a contract with you or with your organization, for the data required to run the service, and legitimate interest for security and abuse prevention.
- Your rights. Access, rectification, erasure, restriction of processing, portability and objection. One message to bookie@forestech.io exercises any of them, and the answer arrives within 30 days.
- Who decides what. Toward a business customer, the organization decides who joins it, which calendars are connected and when the data is deleted, and Bookie runs the system according to those decisions. For the account and the billing themselves, the decisions are Bookie's.
- Transfers. Israel is recognised by the European Commission as providing an adequate level of protection, a decision renewed in January 2024. The servers themselves are in Germany, inside the Union.
- Complaints. A resident of the Union may approach the supervisory authority in their country of residence. The list of authorities is published by the European Data Protection Board.
13. Age of use
Bookie is a business tool, and use of it is intended for people aged 18 and over. An account is opened through a workplace Google account, and joining runs through the organization's admin.
14. Changes to this policy
A change to this policy updates the date at the top of the document. A material change, for example an additional Google scope or a new subprocessor, is emailed to account admins before it takes effect.
Google Limited Use disclosure
Bookie's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Contact
Questions about this document, or about your data: bookie@forestech.io
Privacy · Terms · Delete my data · Home