EagleHQ ("EagleHQ", "we", "us", or "our") operates the website eaglehq.us and the websites, booking tools, and dashboards we build and host for our clients (collectively, the "Services"). This Privacy Policy explains what we collect and how we use it.
Information we collect
- Account information — name, email, phone number, and business details you provide when you request a site, create an account, or contact us.
- Booking and customer data — information submitted through booking forms, support tickets, and customer portals on the sites we host.
- Payment information — processed by our payment provider (Stripe). We do not store full card numbers on our servers.
- Usage data — pages visited, actions taken, device and browser information, and similar analytics collected automatically.
How we use information
- To build, host, operate, and improve the Services.
- To process bookings, subscriptions, invoices, and payments.
- To send transactional messages (confirmations, receipts, and service notices) and, where you have opted in, marketing updates.
- To provide support and respond to your requests.
- To detect, prevent, and address fraud, abuse, and security issues.
Sharing
We do not sell your personal information. We share it only with service providers who help us run the Services (such as hosting, email delivery, and payment processing), when required by law, or as part of a business transfer. Each provider is bound to use the information only to perform services for us.
Data retention
We keep information for as long as your account is active or as needed to provide the Services, comply with our legal obligations, resolve disputes, and enforce our agreements.
Your choices
- You may access, correct, or delete your account information from your dashboard or by contacting us.
- You may opt out of marketing email at any time using the unsubscribe link.
- Depending on where you live, you may have additional rights over your personal data; contact us to exercise them.
Cookies
We and our providers use cookies and similar technologies. See our Cookie Policy for details.
Google user data (Google Calendar integration)
EagleHQ offers an optional Google Calendar integration. It is off until a business owner connects their own Google account, and it can be disconnected at any time. This section explains exactly how EagleHQ accesses and uses Google user data, and applies in addition to — and, for Google data, takes precedence over — the general terms above.
What we access. When you connect Google Calendar, you grant EagleHQ these scopes and nothing more:
- See and edit events on your calendars (calendar.events scope) — used only to create and update the calendar event for a booking on the calendar you select.
- See the list of calendars you can access (calendar.calendarlist.readonly scope) — used only to show your calendars so you can choose which one bookings sync to. We do not read the contents of your existing events.
- Your Google account email address (userinfo.email scope) — used only to display which account is connected.
How we use it. Google Calendar data is used solely to provide the user-facing booking-sync feature described above — writing your bookings into your chosen calendar and letting you pick that calendar. We do not use it for advertising, profiling, credit or lending decisions, or any purpose unrelated to this feature.
How we share it. We do not sell Google user data and do not transfer it to third parties, data brokers, or advertisers. Google data is transmitted only between your browser, Google's APIs, and our hosting and database providers (Vercel and Supabase) acting on our behalf solely to operate the feature.
How we protect it. OAuth tokens are stored server-side in a database table protected by row-level security with no client-readable policies, reachable only with our service-role credentials; refresh tokens never leave our servers. All traffic is encrypted in transit with TLS and data is encrypted at rest by our infrastructure providers.
Retention and deletion. We keep your Google tokens and the calendar selection only while the integration is connected. When you disconnect Google Calendar (from Profile → Integrations), or delete your account, we delete the stored tokens and connection record. You can also revoke EagleHQ's access at any time from your Google Account permissions.
Limited Use. EagleHQ's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google Workspace or Photos API data to develop, improve, or train generalized AI/ML models, and we do not transfer such data to third parties for that purpose.
Contact
Questions about this policy? Email us at hello@eaglehq.us.
Questions? Get in touch.