Skip to main content

Security and your data

How AddCal protects your account, plus how to export or delete your data and close your account.

T
Written by Tom

This article covers how AddCal keeps your account and data secure, and the controls you have over your own data: signing in securely, single sign-on, exporting or deleting your data, and deleting your account. For the full security overview, see the AddCal Security page.

How AddCal protects your data

A few facts that apply to every account:

  • Encryption in transit and at rest. All traffic is served over HTTPS using TLS 1.2 or higher. Databases, file storage, and backups are encrypted at rest.

  • Card details never reach AddCal. Payments are processed by Stripe, which handles PCI DSS compliance. Card numbers never touch AddCal's systems.

  • Your data is separated per team. One team's calendars, events, and attendee data are never readable by another team.

  • GDPR. AddCal supports data access, export, and deletion requests. You can read our Data Processing Addendum (DPA) and the list of subprocessors online.

Two-factor authentication

You can add two-factor authentication (2FA) to your own login for an extra layer of security. With 2FA on, signing in needs both your password and a one-time code from an authenticator app.

  1. Open your profile settings.

  2. In the two-factor authentication section, enable it and scan the QR code with an authenticator app such as Google Authenticator or 1Password.

  3. Save your recovery codes somewhere safe. They let you sign in if you lose your device.

After 2FA is on, you are asked for a code from your authenticator app each time you log in.

Connect a Google or Microsoft sign-in to your account

If you created your account with an email and password, you can start signing in with a provider instead. AddCal supports Google, GitHub, Microsoft, X, and GitLab.

Click the provider button on the sign-in page. If that provider gives us an email that already has a password account, you see a screen headed You already have an account, explaining that your address is registered with a password rather than that provider. Confirm your password to connect the two:

  1. Enter your AddCal password on that screen. If you have forgotten it, use the Forgot your password? link.

  2. Click Sign in and connect followed by the provider name, for example Sign in and connect Google.

  3. If you have two-factor authentication turned on, enter your code when prompted. This step comes after the password.

The provider is then connected and you land on your profile at the linked accounts section. From that point you can sign in either way, with your password or with the provider button.

If the password is wrong you see That password is incorrect. and can try again, up to five attempts before the request is cancelled and you start over from the provider button. The request also expires after 10 minutes, so if you leave the screen open for a while, begin again.

If your account has no password. Accounts created through a provider have no password to confirm, so this flow does not apply. You are returned to sign-in with the message Your account does not use a password. Sign in with the provider you used originally, then connect from your profile. Sign in the way you normally do, then add the second provider from your profile.

Disconnecting a provider. Open your profile and find the Linked Accounts section. Each connected provider has its own toggle. Turn one off to disconnect it.

Single sign-on (Business plan)

Single sign-on (SSO) lets your team sign in to AddCal through your own identity provider instead of an AddCal password. SSO for customer accounts is available on the Business plan. To set it up for your team, contact AddCal support.

Export your data

Under GDPR, you can request access to and an export of the personal data AddCal holds for your account. This is handled as a request: contact AddCal support or email [email protected] and the team will arrange your export.

Delete your data and your account

You can delete your whole AddCal account yourself from the account deletion page, reached from your settings. Deletion is permanent and cannot be undone.

Cancel any active subscriptions first. If you own a team that is on an active, trialing, or past-due subscription, deletion is blocked until that subscription is cancelled. The page shows a Cancel subscription link so you can do this. See Managing your subscription, payments & invoices.

The confirmation page lists exactly what will be removed, with live counts of your calendars, events, calendar (ICS) subscribers, and smart links.

This breaks calendar feeds for your subscribers. People who subscribed to your calendar feeds have those feeds installed in their Google, Apple, and Outlook calendars. Deleting your account breaks those feeds for them permanently.

To confirm the deletion:

  • If your account has a password, enter your current password.

  • If you sign in with single sign-on (SSO) and have no password, type the word DELETE instead.

What happens to your teams. Teams you solely own are deleted along with all their data. Teams you share with others are not deleted: ownership transfers to another member (the confirmation page names who), so their data is kept.

After deletion you are signed out and returned to the AddCal home page.

If you only want to stop paying rather than delete everything, you can cancel your subscription instead. See Managing your subscription, payments & invoices.

Delete a team

You can delete a whole team from its Team Settings page, in the delete team section. This removes the team and all of its calendars, events, and data. Deletion is permanent and cannot be undone.

Cancel the team's subscription first. If the team has an active subscription, you must cancel it before you can delete the team. In that case the page shows a Cancel subscription link in place of the delete controls. See Managing your subscription, payments & invoices.

To confirm, type the team's exact name and then confirm. The confirm button stays disabled until the name matches.

Deleting a team also breaks the calendar feeds of anyone subscribed to that team's calendars, the same way account deletion does. For managing teams generally, see Team members and collaboration.

Reporting a security issue

If you find a vulnerability or have a security or compliance question, email [email protected]. Please do not run automated scans against live accounts without coordinating with AddCal first.

Did this answer your question?