Skip to main content
← Back to home

Last updated: April 20, 2026

Privacy Policy

This Privacy Policy describes how Aggregate Community Groups (“ACG,” “we,” “us,” or “our”) collects, uses, shares, and protects information when you use our website and services at aggregatecommunitygroups.com (the “Services”).

Important note

This policy is designed to be a practical starting point for an early-stage product. Laws vary by region and facts matter. You should have qualified legal counsel review this document for your entity, jurisdictions, data practices, and contractual commitments.

Who we are

For privacy inquiries, contact us at hello@aggregatecommunitygroups.com.

Information we collect

  • Account and profile information you provide (for example: name, email address, business details, profile photos, and content you submit).
  • Authentication information when you sign in (for example: credentials for email/password login, session tokens/cookies, and OAuth-related identifiers when you choose Google sign-in).
  • Google Calendar integration (optional): if you authenticate with Google and grant Calendar access, we process Google OAuth tokens server-side as needed to provide scheduling-related features you initiate (for example, creating or updating calendar events tied to actions you take in ACG).
  • Communications you send through the Services (for example: messages, posts, invitations, feedback).
  • Payment information: payments may be processed by Stripe. We generally receive limited billing metadata (for example: subscription status, customer identifiers) rather than full card numbers.
  • Device and technical data such as IP address, browser type, diagnostic logs, and approximate location derived from IP.
  • Push notifications: if enabled, your browser/device may share a push subscription endpoint so we can deliver notifications you request.

Google user data and Google Calendar

If you choose to sign in with Google or connect Google Calendar, ACG requests the following OAuth scopes: email, profile, and https://www.googleapis.com/auth/calendar.events. We request these scopes only after you explicitly consent on Google’s consent screen, and you may decline or later revoke them at any time.

What Google data we access. From the email and profile scopes we receive your Google account email address, name, and profile picture to create or identify your ACG account. From the calendar.events scope we read, create, update, and delete calendar events on the Google Calendar you authorize, strictly in response to actions you take inside ACG (for example, scheduling a meeting tied to a Project or Opportunity). We do not access calendars or events you have not chosen to share with ACG and we do not scan your broader calendar content for any purpose other than completing the feature you initiated.

How we use Google user data. ACG’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We use Google user data only to provide and improve the user-facing features you requested. We do not use Google user data to serve advertisements, we do not transfer or sell Google user data to third parties, we do not allow humans to read Google user data except (i) with your explicit consent, (ii) when necessary for security purposes such as investigating abuse, (iii) to comply with applicable law, or (iv) in aggregated and de-identified form for internal operations, and we do not use Google user data to train, fine-tune, or develop generalized or non-personalized AI or machine-learning models.

Token storage and security. When you grant Calendar access, Google issues ACG an access token and a refresh token. We store these tokens server-side in a restricted database table (user_google_tokens) hosted by our database provider, Supabase. The table is protected by row-level security, is readable only by ACG’s server-side service role (not by other users and not by client-side code), and tokens are encrypted at rest by the database provider. Tokens are transmitted only over TLS and are used solely to call Google APIs on your behalf to deliver features you initiated.

Retention and deletion of Google data. We retain your Google refresh token for as long as you keep the integration connected. Calendar event data returned by Google is used in-memory to render or complete the action you requested and is not persistently stored on ACG servers beyond short-lived operational caches required to deliver the feature. If you revoke access, disconnect the integration, or delete your ACG account, we delete the corresponding tokens and any cached Calendar data from our systems within 30 days.

How to revoke access. You can disconnect Google from ACG at any time in your ACG settings. You can also revoke ACG’s access directly with Google at https://myaccount.google.com/permissions. Once access is revoked, ACG can no longer read or modify your Google Calendar, and any stored tokens are invalidated and deleted on our next synchronization.

Third parties. Beyond Google (for the integration itself) and Supabase (our database and authentication provider that stores the encrypted tokens), we do not share Google user data with any third party.

How we use information

We use information to:

  • provide, operate, secure, and improve the Services;
  • authenticate users and prevent fraud, abuse, and security incidents;
  • communicate with you about the Services (including service-related notices);
  • provide customer support;
  • enable optional integrations you choose (for example: Google Calendar features where enabled and permitted by your consent configuration);
  • comply with law and enforce our Terms.

Legal bases (EEA/UK users)

If applicable privacy laws require a “legal basis,” we rely on one or more of: performance of a contract, legitimate interests (such as securing the Services), consent where required, and compliance with legal obligations.

How we share information

We may share information with:

  • Service providers who assist us (for example: hosting, database, analytics, email delivery). They are permitted to process information only as instructed.
  • Payment processors such as Stripe to process payments you authorize.
  • Professional advisors where appropriate (for example: lawyers), subject to confidentiality obligations.
  • Authorities if required by law or to protect rights, safety, and security.
  • Google, when you use Google sign-in or Google Calendar features, so Google can authenticate you and return the data you authorized.

We do not sell your personal information as a standalone product.

Retention

We retain information as long as needed to provide the Services, comply with legal obligations, resolve disputes, and enforce agreements. Retention periods depend on the type of information and operational needs. Google OAuth tokens and any cached Google Calendar data are deleted within 30 days of you revoking access, disconnecting the integration, or deleting your ACG account.

Security

We implement reasonable administrative, technical, and organizational safeguards designed to protect information. No method of transmission or storage is 100% secure.

Your choices and rights

Depending on where you live, you may have rights to access, correct, delete, or restrict processing of certain information, or to object to certain processing. To exercise rights, email hello@aggregatecommunitygroups.com. We may need to verify your request.

You can revoke ACG’s access to your Google account at any time by visiting https://myaccount.google.com/permissions; revocation is processed on Google’s side immediately and ACG stops being able to read or modify your Google data as soon as tokens are invalidated.

Children

The Services are not directed to children under 13, and we do not knowingly collect personal information from them.

International transfers

If you access the Services from outside the United States, your information may be processed in the United States and other locations where we or our providers operate.

Changes

We may update this Privacy Policy from time to time. We will post the updated version on this page and update the “Last updated” date above.

Contact

Questions: hello@aggregatecommunitygroups.com