Privacy Policy
Version 1.4 · Effective date: 2026-09-13
Who we are
Availdar Limited operates the Availdar apps (iOS / Android), website, and related backend services (together, the “Service”). For the Hong Kong Personal Data (Privacy) Ordinance (the “PDPO”), Availdar Limited is the data user of personal data collected through the Service. This statement is written primarily for users in Hong Kong.
Privacy contact: privacy@availdar.com
The official text of this Privacy Policy is English.
Our commitment
Availdar helps people coordinate availability and schedules. We aim to collect only what we need, for clear purposes. If data does not need to leave our systems, it should not.
When you give us information
To create an account you must provide an email address and password. Without them you cannot register.
To finish first-time setup you must provide a display name. Without it you cannot use collaboration features.
Optional: push notifications; remembering your email on this device; a reply email on a problem report; multi-factor authentication; allowing others to find you by account code.
How we use data, and which organisations may receive it, is described below.
You may request access to, or correction of, your personal data by emailing privacy@availdar.com.
What we collect
Account — email, password (handled by our sign-in provider; the app does not store your password), display name, server-assigned account code, optional multi-factor authentication, device identifiers used for a device limit, timezone, and plan level (for feature limits).
Content you create — projects, availability and confirmed times, nicknames, notes, location or call links, calendar-write permissions, notices, private collaborator notes (visible only to you), status labels on a published arrangement, and private calendar overlays that affect only your own calendar and stats.
Notifications — push token, preferences, and in-app notices. Reminders for custom activities stay on the device that created them.
Problem reports you send — category, message, optional reply email, and limited diagnostics (app version, platform, and a coarse screen name). These stay on our servers. They are not sent to Sentry.
Crash diagnostics — if the app errors, Sentry (United States) receives technical crash data. This is on by default. We do not turn on Session Replay or default collection of personal identifiers. Problem-report text is never sent to Sentry.
On this device — sign-in session, preferences, drafts, and local custom activities. If you choose “remember email”, we store the email on the device for autofill. We do not store the password for that feature.
Security and operations — such as IP address, device and app version, timestamps, and short-lived counters used to prevent abuse.
Website — our site is hosted by Squarespace, which may set cookies to operate the site.
If paid plans are enabled — Apple or Google processes the purchase. We may store plan status and limited transaction identifiers. We do not receive your card number.
How we use data
We use personal data to run sign-in and collaboration, send notifications you enable, honour account suspend and deletion, reply when you leave a contact email on a report, keep the Service secure (including device limits and abuse controls), apply plan limits, and — when enabled — send security emails such as multi-factor recovery notices.
We will not use personal data for a purpose unrelated to the above unless you agree or the law allows or requires it. We may use or disclose personal data where the law requires or allows it, including to meet a legal obligation, to establish or defend legal claims, or to address security, fraud, or abuse.
We do not use your personal data for direct marketing, and we do not sell it.
We do not run advertising analytics on your availability. We do not use Session Replay to record calendar screens unless we update this Policy first.
“Write to calendar”
In the app, agreeing that someone may add to your calendar means writing into Availdar calendar data. It does not write into the Apple or Google Calendar apps on your phone. If that changes, we will update this Policy before asking for system calendar permission.
Finding people and share links
Lookup for calendar-write uses account code only, not email or display name. You can turn off “find me by account code” in Account. People you already collaborate with, and anyone you send a share link, can still reach you.
A share link is a key to that project. Anyone with the link may see or join according to the project’s settings. People on a project can see names, nicknames, times, notes, and any location or call link shared on that project. If a host downloads a roster file, that copy is then on their device. Share only with people you trust.
Who helps us run the Service
Supabase — accounts, database, realtime, and backend functions. Primary region: Northeast Asia (Tokyo).
Expo — push delivery when a push token is registered.
Apple / Google — push notifications when you allow them; in-app purchases if paid plans are enabled.
Sentry — crash diagnostics. United States. Session Replay off.
Resend — security emails (for example multi-factor recovery). Only if that feature is turned on.
Squarespace — website hosting.
Some of this happens outside Hong Kong (for example Tokyo for app data, the United States for crash diagnostics). We use these organisations to provide, secure, and diagnose the Service, and we rely on their published terms.
If we add a feature that sends personal data to a new organisation outside our systems, we will update this Policy first.
How long we keep data
You may suspend or delete your account in settings. Deletion has an approximately 30-day cooling period.
After that we remove account-bound app data, including permissions, availability, projects you host, and your availability on other people’s projects. Other people can no longer use a project you hosted. They may still keep past arranged times on their own home calendar and stats until they remove those records.
In-app notices may be removed when older (about 120 days, or about 90 days after you dismiss them).
Problem reports are ordinarily kept up to about 365 days, then deleted or de-identified; they are also removed when the account is deleted.
Backups, logs, and security records (including short-lived abuse counters) may remain for a limited time after deletion (our usual target is no more than about 90 days). We do not promise that every copy worldwide disappears at the same moment.
We may retain information longer where the law requires or allows it, or where we need it to establish or defend legal claims, or to address security, fraud, or abuse.
Uninstalling the app clears data on that device only. It does not delete the cloud account.
Security
We take reasonably practicable steps to protect personal data. The app talks to our servers over HTTPS. Problem reports stay on our servers and are not sent to Sentry. Crash reports are filtered to drop listed sensitive fields. No method of transmission or storage is completely secure.
Your choices
Notification preferences, optional multi-factor authentication, optional report reply email, calendar-write accept or revoke, “find me by account code”, and account suspend or delete. Crash diagnostics stay on by default (no Session Replay). If we later add a real off switch, we will update this Policy first.
Access and correction
Under the PDPO you may request access to personal data we hold about you, and correction of inaccurate personal data. Email privacy@availdar.com. We may need to verify it is you. Where the law allows, we may charge a permitted fee for an access request, and we may refuse or limit a request where the PDPO allows (for example where it is not sufficiently specific, or would disclose another person’s personal data). We aim to respond to a complete request within 40 calendar days.
Children
Availdar is not directed at children. You must be at least 16 to register, and you confirm this when you create an account. We do not independently verify age. If you believe someone under 16 has an account, email privacy@availdar.com.
Changes
Material changes receive a new version and effective date, with notice in the app or on the website.
Contact
Privacy: privacy@availdar.com
Support: support@availdar.com
Availdar Limited