Privacy Policy
What OpenHour collects, why, who we share it with, and the rights you have over it under India's Digital Personal Data Protection Act, 2023.
Last updated: 14 September 2026
Who is responsible for your data
OpenHour is operated by Animesh Roy, a sole proprietor in India. Under the Digital Personal Data Protection Act, 2023 (“DPDP Act”) that makes the proprietor the Data Fiduciary — the person who decides why and how your personal data is processed. You are the Data Principal. Full contact details, including the grievance officer, are at the foot of this page.
In this policy, “expert” means someone who publishes an OpenHour page, and “client” means someone who books a session on one.
What we collect, and why
We collect only what a booking product needs to work. Each item below is tied to the purpose it serves; we do not collect data speculatively or for purposes we have not named here.
- Account details — name, email address and profile picture, received when you sign in with Google. Purpose: to create and identify your account, and to send you service email.
- Your public profile — handle, headline, biography, statistics, highlights, social links and session listings. Purpose: to render the page your clients visit. This content is public by design.
- Google Calendar data — busy/free intervals and the events we create for bookings. Purpose: to compute availability and place the session on your calendar. Described in detail in the next section.
- Booking details — a client’s name, email, timezone and anything written in the booking form. Purpose: to schedule the session and notify both parties.
- Payment information — Razorpay order and payment identifiers, amount, plan and any coupon. Purpose: to take payment and issue refunds. We never see or store card, UPI or netbanking credentials.
- Payout bank details — for experts enabling paid sessions. Purpose: to pay you. Encrypted before storage and never displayed back in full.
- Technical data — a session cookie to keep you signed in, and standard server logs. Purpose: to operate and secure the service.
The basis on which we process it
We process your personal data on the basis of the consent you give when you create an account, connect a calendar, or complete a booking — and for the certain legitimate uses the DPDP Act permits, such as complying with a legal obligation.
Your consent is specific to the purposes named above. You can withdraw it at any time, and withdrawing is as easy as giving it: disconnect a calendar from your dashboard, or delete your account. Withdrawal does not undo processing already carried out, and we may keep what the law requires us to keep.
How we use Google Calendar data
When you connect a calendar, OpenHour requests these Google permissions:
calendar.readonly— to read the times you are already busy, so clients are never offered a slot that clashes with an existing commitment.calendar.events— to create a calendar event when a session is booked, and to update or cancel that event if the session changes.userinfo.email— to identify your account.
We read event timing to compute availability. We do not mine the contents of your calendar, we do not use it to build advertising profiles, we do not sell it, and we do not use it to train machine-learning models. We only write events that correspond to OpenHour bookings.
OpenHour’s use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements.
You can disconnect a calendar at any time from your OpenHour dashboard, and you can revoke OpenHour’s access entirely at myaccount.google.com/permissions. Revoking access stops all future reads and writes immediately.
Why we use your data
- To create and run your account and your public page.
- To show accurate availability and to schedule, reschedule and cancel sessions.
- To take payments, apply coupons, issue refunds, and pay out earnings where applicable.
- To send transactional email — booking confirmations, reminders, cancellations and receipts.
- To keep the service secure, debug faults and prevent abuse.
- To meet tax, accounting and other legal obligations.
We do not sell your personal data, share it with advertisers, use it for behavioural profiling, or use it to train machine-learning models.
Who we share it with
We use a small number of processors, each for one purpose. They act on our instructions and may process data outside India:
- Google — sign-in and Calendar synchronisation.
- Razorpay — payment processing and payouts (India).
- Cloudflare — hosting, storage and content delivery.
- Our email provider — delivery of transactional email.
We may also disclose data where legally required, or to establish or defend a legal claim.
What is public
Your OpenHour page — handle, name, photo, headline, biography, highlights, social links and the sessions you offer — is visible to anyone with the link and may be indexed by search engines. Booking details are not public: a client’s name and email are visible only to the expert they booked with.
How long we keep it
We erase personal data once the purpose it was collected for is served, unless we are required to retain it.
- Account and profile data: while your account exists. Deleting your account erases your page, profile content and calendar tokens.
- Booking records: retained after the session so both sides keep their history.
- Payment records: retained as long as tax and accounting law requires.
- Google Calendar tokens: until you disconnect the calendar or revoke access.
Security, and what happens if it fails
Traffic is encrypted in transit with TLS. Bank account details are encrypted before storage. Access to production data is limited to those who need it to operate the service.
No system is perfectly secure. If a personal data breach occurs we will notify the Data Protection Board of India and every affected Data Principal, as the DPDP Act requires.
Your rights as a Data Principal
The DPDP Act gives you the following rights, and we honour all of them:
- Access — a summary of the personal data we hold about you and how it is processed.
- Correction and erasure — to have inaccurate data corrected, completed, or erased.
- Withdraw consent — at any time, as easily as it was given.
- Grievance redressal — to complain to our grievance officer, named below, before escalating.
- Nomination — to nominate another person to exercise these rights on your behalf in the event of your death or incapacity.
Much of this you can do yourself from your dashboard. For anything else, email hello@openhour.me. We respond within 30 days.
If you are not satisfied with how we handle a grievance, you may complain to the Data Protection Board of India.
Your duties
The DPDP Act also asks Data Principals not to impersonate anyone else, not to suppress material information when providing personal data, and not to raise false or frivolous grievances.
Children
OpenHour is not for anyone under 18. We do not knowingly process the personal data of children, and we do not carry out tracking, behavioural monitoring or targeted advertising directed at children — the DPDP Act prohibits it outright. If you believe a child has given us personal data, contact us and we will erase it.
Changes to this policy
If we change this policy we will update the date at the top of this page, and tell you by email where the change materially affects how we handle your data.
Contact
General questions: hello@openhour.me. Grievances go to the officer named below. See also our Terms of Service and Refunds & Cancellations.
Who operates OpenHour
OpenHour is operated by Animesh Roy, a sole proprietor based in India. There is no company; the proprietor is personally responsible for the service.
301, A block, Sai Rasik ResidencyVittal Rao Nagar, Hi-Tech City, MadhapurImage Hospital LaneHyderabad, Telangana 500081IndiaGrievance officer
Animesh Roy
mail@anir0y.in · +91 70758 81337
Complaints are acknowledged within 48 hours and resolved within 30 days.