Privacy Policy
Last updated: 14 July 2026
This Privacy Policy explains how Joust (“we”, “us”) collects, uses, and protects personal information when you use withjoust.com, joust.to, and our Service. We are the data controller for the information described here.
1. Information we collect
- Account information — your name, email address, and a securely hashed password.
- Profile information — your handle, headline, timezone, and booking-page settings.
- Booking information — details you and your invitees provide, such as invitee names, email addresses, notes, the times booked, and answers to any custom questions you configure on your booking form.
- Customer records — we build customer profiles from your bookings, including client name, email, and booking history. Paid booking plans can view that history; the Business plan adds editable notes, tags, flags, tasks, segments and campaigns.
- Team information — names, services, schedules, and availability you configure for staff members shown on your booking page.
- Google account data — if you connect Google Calendar, we store your connected Google account email and OAuth access and refresh tokens (encrypted at rest where configured) so we can sync on your behalf. We read calendar event times, titles, and — where present — descriptions and video-meeting links to show your schedule in the dashboard, detect conflicts, and block unavailable times on your public booking page. We create, update, and delete calendar events when you add, reschedule, or cancel bookings or manual blocks, and may add your invitees as attendees and optionally include a Google Meet link. We request only the calendar scopes needed to provide sync.
- Payment information — subscriptions are processed by Stripe. We store customer and subscription identifiers and status, but not your full card details.
- Usage and device data — log data such as IP address, browser type, and pages viewed, collected via cookies and similar technologies.
1a. Google API Services Limited Use
Joust’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google user data for advertising, we do not sell it, and we do not allow humans to read it except where necessary to provide support, comply with the law, or with your explicit permission.
You can disconnect a team member’s Google Calendar at any time from their Team settings. We delete the stored OAuth tokens when you disconnect that calendar, remove the team member, or delete your account. Events already created in Google Calendar may remain until you remove them in Google.
2. Cookies and analytics
We use:
- Essential cookies — required for sign-in, security, and short-lived invitee booking-management sessions. The Service does not work without these.
- Analytics cookies — if you accept them in our cookie banner, we use Google Analytics (measurement ID G-VMS17YHB3Q) to understand how the Service is used, Google Ads conversion measurement to see whether our advertising leads to sign-ups, and Microsoft Clarity to understand how visitors interact with pages (including session recordings and heatmaps). Google collects information such as your IP address (which we ask Google to anonymise), device, and the pages you visit; this is processed in line with Google’s privacy policy. Clarity is operated by Microsoft in line with Microsoft’s privacy statement. You can change your choice at any time via Cookie settings in the site footer, using the Google Analytics opt-out browser add-on, or your browser’s cookie controls.
- Cookie preferences — we store your analytics choice in your browser’s local storage so we remember it on future visits.
3. How we use your information
- to provide and operate the Service, including bookings and calendar sync;
- to send transactional email (verification, password resets, booking confirmations, reminders, and billing notices);
- to process payments and manage subscriptions;
- to secure the Service, prevent abuse, and debug;
- to analyse usage and improve our products;
- to comply with legal obligations.
4. Legal bases (UK/EEA)
Where applicable, we rely on: performance of our contract with you (to provide the Service); your consent (for example, connecting Google, and analytics where consent is required); our legitimate interests (to secure and improve the Service); and compliance with legal obligations.
5. How we share information
We do not sell your personal information. We share it with service providers who process it on our behalf, including:
- Google — calendar sync;
- Stripe — payment processing;
- Resend — sending transactional email;
- Supabase — database hosting;
- Vercel — application hosting;
- Google Analytics & Google Ads — usage analytics and ad conversion measurement;
- Microsoft Clarity — session recordings and interaction analytics;
We may also disclose information to comply with the law or to protect our rights, and in connection with a merger, acquisition, or sale of assets.
If you book through a host’s public booking page, the host is responsible for how they use the information you provide, and we process that booking data on their behalf. Please contact the host directly with questions about their use of your information.
6. Data retention
We keep your information for as long as your account is active. When you delete your account, we delete or anonymise your personal data, except where we must retain certain records (for example, for billing, tax, or legal compliance).
7. Security
We protect your data with encryption in transit, hashed passwords, access controls, and — where enabled — encryption of third-party tokens at rest. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.
8. Your rights
Depending on where you live, you may have the right to access, correct, delete, or export your personal data, to object to or restrict certain processing, and to withdraw consent. You can delete your account and data at any time from your settings, or contact us to exercise other rights. If you are in the UK or EEA, you also have the right to complain to your data-protection authority (in the UK, the ICO).
9. International transfers
Your information may be processed in countries other than your own, including by the providers listed above. Where required, we rely on appropriate safeguards for such transfers.
10. Children
The Service is not directed to children under 16, and we do not knowingly collect their personal data.
11. Changes to this policy
We may update this policy from time to time. We will update the “last updated” date above and, for material changes, take reasonable steps to notify you.
12. Contact
The Service is operated by WithJoust, the data controller for the information described in this policy. For privacy questions or requests, email privacy@withjoust.com.