Legal

Privacy Policy

This policy explains how 3 In 1 Environmental handles information through the Pick a Time booking platform.

Last updated: September 14, 2026

Read the Terms of Service

1. Scope and operator

Pick a Time is operated by 3 In 1 Environmental. This Privacy Policy applies when service providers create or manage accounts and booking pages, when clients schedule or manage appointments, and when anyone communicates with us about the platform.

In this policy, a “provider” is a business or professional using Pick a Time to offer appointments, and a “client” is a person scheduling with a provider. Providers are responsible for their own handling of client information outside Pick a Time.

2. Information collected

We collect information provided to or generated by the platform:

  • Registration and account information: name, business name, email address, password hash, verification and account status, login sessions, and security records.
  • Provider information: professional and business details, contact information, address, website, licenses, time zone, availability, offered services, booking-page text, branding, logo, notification preferences, custom booking questions, and provider policies.
  • Client and appointment information: name, email address, phone number, service or property address, selected service, appointment date and time, time zone, notes, responses to provider questions, appointment status, accepted terms, and provider notes.
  • Files and photos: photos, documents, filenames, file types and sizes, and their association with an appointment when an upload field is offered.
  • Subscription information: plan, billing status, billing-period information, and Stripe customer and subscription identifiers. Pick a Time does not store full payment-card numbers.
  • Technical information: session cookies, request IP addresses used for rate limiting, timestamps, synchronization status, and email delivery metadata such as recipient, subject, provider message ID, attempts, and accepted, delivered, or failed status.

3. How information is used

  • Create, authenticate, secure, and support provider accounts.
  • Publish booking pages and create, display, reschedule, and cancel appointments.
  • Share booking details with the provider selected by the client.
  • Check availability and synchronize appointments when a provider connects Google Calendar.
  • Send account verification, password reset, appointment confirmation, rescheduling, reminder, and provider notification emails.
  • Administer subscriptions, prevent abuse, diagnose failures, enforce platform terms, and comply with legal obligations.

4. Google Calendar and Google OAuth data

Connecting Google Calendar is optional and is not required for email confirmations or reminders. When a provider chooses to connect, Pick a Time requests permission to:

  • read free/busy availability to avoid offering occupied times;
  • read the provider's calendar list so a calendar can be selected;
  • create, update, and delete events generated by Pick a Time; and
  • read the connected Google account email address.

Free/busy checks do not require titles or descriptions from a provider's existing events. Appointment events created by Pick a Time may contain client contact details, service, location, notes, appointment time, and booking reference so the provider can identify and manage the appointment.

Google access and refresh tokens, the selected calendar ID, connected account email, and created Google event IDs are stored server-side. Tokens are used only to provide the requested Calendar features and are not exposed in public booking pages.

Our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Google data is not used for advertising or sold.

5. Email notifications

Pick a Time uses the client email submitted with an appointment and a verified provider notification address to send separate transactional messages. Messages may contain appointment details, client contact information for the provider, and secure management links. Recipients are not exposed to each other through CC.

Resend processes outgoing email and delivery events. An “accepted” status means the email provider accepted a message for delivery; it does not guarantee placement in a recipient's inbox.

6. Payments, database, and file storage

Stripe processes checkout, recurring subscription payments, and billing-portal actions. Payment details entered on Stripe-hosted pages are handled by Stripe under its own privacy policy. Pick a Time stores only the customer, subscription, plan, status, and billing-period details needed to manage access.

Neon hosts the PostgreSQL database used for accounts, provider profiles, appointments, notification jobs, Google connection records, and operational data. Vercel hosts the application and provides private Blob storage for configured uploads. Some media may also be stored in the application database and served through access-controlled routes.

7. Service providers and disclosures

Information may be processed by these platform vendors:

  • Google for optional Calendar integration;
  • Stripe for payment and subscription processing;
  • Neon for database hosting;
  • Vercel for application hosting and file storage;
  • Resend for transactional email; and
  • Upstash QStash to securely trigger processing of due notification jobs.

We may also disclose information when directed by a user, when reasonably necessary to protect the platform or others, in connection with a business transaction, or when required by law. Pick a Time does not sell personal information and does not share it for cross-context behavioral advertising.

8. Cookies and analytics

Pick a Time uses necessary cookies for authentication, session security, navigation during sign-in and onboarding, and protection of the Google OAuth flow. The current application does not use advertising pixels or third-party behavioral analytics.

Google, Stripe, and other vendors may use cookies on their own hosted pages under their respective policies.

9. Protection, retention, and deletion

We use technical and organizational safeguards appropriate to the service, including password hashing, hashed session and verification tokens, secure HTTP-only cookies, authorization checks, input validation, rate limiting, protected worker and webhook endpoints, and restricted file access. No system can guarantee absolute security.

We retain information for as long as reasonably necessary to operate Pick a Time, maintain account and appointment records, resolve disputes, enforce agreements, meet legal obligations, and protect the service. Because these needs vary, this policy does not promise one fixed retention period for every record.

Providers can delete booking pages through available dashboard controls. Clients can cancel an appointment using its secure management link. These actions do not necessarily delete every account, billing, security, backup, or vendor record associated with the user.

To request access, correction, or deletion of account or personal information, contact us using the address below. We may need to verify the requester's identity and may retain information when permitted or required by law.

10. Disconnecting Google Calendar

A provider can disconnect Google Calendar from Dashboard → Integrations. Pick a Time will attempt to revoke the Google authorization and remove the stored Calendar connection and tokens. Disconnecting does not delete appointments or other Pick a Time data, and it does not delete events previously created in Google Calendar.

11. Children and policy changes

Pick a Time is intended for business scheduling and is not directed to children under 13. We may update this policy to reflect changes to the service, vendors, or legal requirements. The revised policy will be posted here with a new “Last updated” date.

12. Contact

Privacy questions and data requests may be sent to SUPPORT_EMAIL (configure this public contact at deployment).

Operator: 3 In 1 Environmental, Pick a Time.