Skip to content
FairlyRemote™
Features Pricing FAQ Trust Try the sample team
Legal

Privacy Policy

Last updated: 25 August 2026 (§6 now lists Slack, Microsoft, Discord, Apple iCloud and the push services, which were already in use; §3.4 discloses the Microsoft and Apple calendar credentials we store; §3.6 corrected: Sentry session replay is disabled, and the audit-log IP exception is stated; §9 export description corrected to match what the product actually provides)

On this page

  1. 1. Who we are
  2. 2. Tier-by-tier summary
  3. 3. What we collect
  4. 4. What we don’t collect
  5. 5. Cookies
  6. 6. Sub-processors
  7. 7. International transfers
  8. 8. Retention
  9. 9. Your rights
  10. 10. Children
  11. 11. Security
  12. 12. Changes
  13. 13. Contact
  14. 14. California (CCPA)
At a glance

The short version: The Free tier keeps your data in the browser. On paid tiers you create an account, and we hold your email, your team configuration, and a server-side history of fairness scores so they survive a device wipe.

Defaults that matter: synced events are review-first: nothing is shown to teammates until you confirm an event, with busy-only pre-selected (a confirmed busy event tells teammates that you’re busy, not what). Calendar sync reads start/end and busy-free for conflict detection. By default we store only the busy time, not the title. A meeting title is stored only if you raise that event to Shared so your board can see it; we do not copy descriptions, attendee lists, or attachments off a synced calendar event. Meetings and proposals you create inside FairlyRemote are different: there we store what you enter, including the invitees you choose and, for external guests, the email address you type so we can send the invitation. You can export or delete your data at any time. We don’t sell it.

1. Who we are

FairlyRemote™ (“we”, “us”, “the Service”) is a meeting-fairness tool for distributed teams, operated by Meourobo Labs Ltd, a company registered in England and Wales under company number 17277317, with its registered office at 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom. Meourobo Labs Ltd is the data controller for the data described below for which we determine the purposes and means (see “The capacity in which we act”). Contact: contact@fairlyremote.com.

The capacity in which we act. We are the data controller for the data we hold for our own purposes: your account and authentication data (§3.1), billing data (§3.5), operational logs and error monitoring (§3.6), and product analytics (§3.7). For team and scheduling data (§3.2), booking-link and booking-board guest data (§3.9), and calendar data we process on a paid team’s behalf (§3.4), the customer organisation (or the team or member that owns the link or board) is the data controller and we act as their data processor under our Data Processing Agreement. Where this policy says “we” in respect of that data, we mean acting as processor on the controller’s documented instructions.

2. Tier-by-tier summary

Different plans collect different data. Use this table to find what applies to you.

TierAccount requiredData on our servers
FreeNoNone: data stays in your browser. Aggregate analytics may apply (see §5).
Team / BusinessYes (email)Account, billing, calendar OAuth tokens (if connected), shared boards, proposal/voting history, member roster, and 365 days of fairness summaries.

3. What we collect and why

3.1 Account data (paid tiers)

What: email address, display name, password hash (or OAuth identifier), tier and billing status, timezone, working-hours preferences.

Why: to authenticate you, route invitations, send transactional email (magic links, billing receipts, invite confirmations, account-deletion confirmations), and apply your subscription entitlements.

Lawful basis (UK/EU GDPR): performance of contract.

3.2 Team and scheduling data (Team tier and above)

What: team membership, roles, board configurations, event metadata (title, time, attendees, visibility setting), proposal/voting records, contribution-alert state.

Why: to provide shared boards, fairness scoring across the team, and meeting proposals.

Lawful basis: performance of contract. The team owner is the data controller for member data they upload; we are the processor.

3.3 Fairness history (paid tiers)

What: aggregated weekly and monthly fairness summaries (accommodation, flexibility, social, and rest scores per member). Team and Business keep 365 days.

Why: so your fairness scores survive clearing browser storage, switching devices, or reinstalling the app, and to power the dashboards and reports listed for your tier.

Lawful basis: performance of contract.

3.4 Calendar integrations (paid tiers, opt-in)

What: OAuth refresh tokens for Google Calendar and Google Tasks, and, if you connect those providers, OAuth tokens for Microsoft 365 / Outlook and an app-specific password for Apple iCloud Calendar. Every one of these is encrypted at rest, and you can disconnect any provider at any time from Settings → Integrations, which deletes the stored credential. Please note an Apple app-specific password is issued by you from your Apple ID account page and can be revoked there at any time; we never receive your main Apple password. We request three Google scopes plus your account email:

  • calendar.readonly: read your free/busy times and event titles, so we can detect conflicts when scoring meeting times.
  • calendar.events: create events on your calendar when you confirm a winning vote, accept a meeting proposal, or are assigned a shift in a rota, and modify or delete events created through FairlyRemote (including removing a shift event if that assignment is withdrawn).
  • tasks.readonly: read your Google Tasks (the task title and due date) so we can show them as to-do blocks on your timeline alongside your events. This is read-only. We never create, modify, or delete your tasks.
  • userinfo.email: identify which Google account is connected.

We do not modify or delete events that FairlyRemote did not create; the server verifies this before every write and refuses the change if the event is not ours. We do not create, modify, or delete any of your Google Tasks, and we do not read event descriptions, attachments, or attendee responses.

Microsoft / Outlook Calendar. If you connect a Microsoft account, we request read-only access to your calendar plus your basic profile:

  • Calendars.Read: read your free/busy times and event titles, so we can detect conflicts when scoring meeting times. We do not write to your Microsoft calendar. Outlook sync is not available yet; these scopes describe the connection as it will work when it ships.
  • User.Read: identify which Microsoft account is connected (your name and email).

Why: to detect meeting conflicts, surface synced events in your review inbox, and let you turn a winning fairness-weighted vote into a real calendar event in one click.

Attendees and invitees. There are two different flows here, and we handle them differently.

Events written to your calendar. When you create or update a meeting through FairlyRemote and add attendees, the attendee email addresses you enter are transmitted to Google Calendar so Google can send the invitation. We do not retain those addresses from the calendar write itself: for that operation they are a pass-through to Google, and only the event’s title, start, end, and your own timezone are written to our database.

Proposals you create in FairlyRemote. When you invite people to vote on a meeting proposal, we do store the invitation, so that we can deliver it, show you who has responded, and stop the same person voting twice. Teammates are stored as a reference to their FairlyRemote account. External guests are stored as the email address you type, because there is no other way to send them the invitation. These records are deleted when you delete the proposal, and are covered by the export and deletion rights in §9. If you are an external guest and want your address removed, email contact@fairlyremote.com.

Storage: tokens are encrypted at rest. Calendar events are processed in your browser whenever possible; aggregate availability snapshots may be cached server-side for sync efficiency. You can disconnect at any time from Settings → Integrations; revocation deletes our token and any cached events.

Lawful basis: consent. You may withdraw consent without affecting the lawfulness of prior processing.

3.5 Billing data

Billing is processed by Stripe. Card details never reach our servers; we hold only the Stripe customer ID, subscription metadata, and invoice records needed for tax and dispute handling. Stripe’s privacy policy: stripe.com/privacy.

3.6 Operational logs and error monitoring

Server requests are logged with timestamp, route, user-agent, and (for authenticated requests) account ID. IP addresses are redacted at the logger boundary (see server/utils/logger.js) and are not retained in our request-summary logs. One exception: security-relevant account events written to our audit log (see §8) may record the originating IP address, which is deleted with the rest of that row after 90 days. Application errors are reported to Sentry with stack traces and the same redacted context; personal data in the data we forward to Sentry from the browser is scrubbed at the client logger boundary (see js/core/logger.js) before it leaves your device. Sentry session replay is disabled: we do not record your screen or your interactions, on error or otherwise (both replay sample rates are set to zero in js/services/error-monitoring-service.js). If we ever enable it we will update this policy first. Logs are retained for 30 days; Sentry events for 90 days.

Lawful basis: legitimate interest (security, fraud prevention, debugging).

3.7 Product analytics

We use Plausible Analytics on both our marketing pages and inside the app. Plausible is cookieless, sets no cookies, performs no cross-site tracking, and collects no personal identifiers. It captures aggregate page views and product-usage events (for example, which features are opened) so we can understand how FairlyRemote is used and improve it.

  • Marketing pages (fairlyremote.com): aggregate page views and click events on CTAs.
  • In-app product (fairlyremote.com/app): aggregate page views and feature-usage events. Plausible events are not tied to your account identity or to any cookie.

In addition to Plausible, the app runs a first-party usage-telemetry service that sends aggregate feature-usage events to our own servers (the same origin as the app, so no third party receives this data). To count distinct installs without identifying you, it stores a random identifier in your browser’s localStorage (the key telemetry_client_id). This identifier is generated locally, is not derived from your account, name, email, or device, and is never combined with your account profile. Before any event leaves your browser we strip personal fields (such as emails, names, and event titles). You can opt out at any time, which stops collection and clears the queued data; the random identifier is removed when you clear in-app data or delete your account.

Lawful basis: legitimate interest (understanding and improving product usage). Plausible collects no personal data and sets no cookies; our first-party telemetry stores a non-identifying random token in local storage strictly for de-duplicated usage counts, which you can opt out of. We do not use Google Analytics, and we do not share analytics data with advertisers.

3.8 Automated processing (GDPR Art. 22)

FairlyRemote uses automated processing to suggest meeting times, weight votes, and route fairness-aware booking links. These outputs are advisory, not decisions. Final scheduling choices are made by your team, and any booking-link routing can be overridden by the team owner. We do not measure individual performance, wellbeing, or productivity, and we do not produce outputs intended for use in employment decisions. You may request human review of any routing decision via your team owner, or by contacting contact@fairlyremote.com.

3.9 Booking-link and booking-board guests

If you book a meeting via a public team booking link (a URL of the form fairlyremote.com/book/<team>), via a personal booking board (a URL of the form fairlyremote.com/board/<name>), or via either of those pages embedded in an <iframe> on the team’s or member’s own website, without holding a FairlyRemote account, we collect:

  • What: the name you submit on the booking form, your timezone, the slot you selected, and (optionally, if you provide it) your email address. We may also log a per-booking guest token so you can manage or cancel the booking later.
  • Why: to confirm the meeting to the team or individual member that owns the link or board, to send you a confirmation if you provide an email, to allow you to cancel or reschedule, and (for team links) to record the booking against the team’s fairness rotation. The team or member that owns the link or board is the data controller for your booking; FairlyRemote acts as their data processor.
  • Lawful basis: the team that owns the booking link relies on performance of the booking arrangement at your request (GDPR Art. 6(1)(b), as a pre-contractual measure), or its legitimate interest in operating its scheduling (Art. 6(1)(f)), to be assessed by the team owner under the law applicable to it. FairlyRemote, as processor for that team, processes your data on the team’s instructions and on the basis of FairlyRemote’s own legitimate interest in providing the Service (Art. 6(1)(f)). FairlyRemote is not a party to your booking and does not itself rely on Art. 6(1)(b) for it.
  • Retention: guest booking records are retained for up to 90 days after the meeting time, then automatically purged or anonymised. Cancelled or no-show records are retained for the same window. If you would like your booking record deleted earlier, contact contact@fairlyremote.com with the booking link and the time slot you booked.
  • Your rights: as a data subject you have the same rights described in §9 (access, rectification, erasure, objection). Submit requests to contact@fairlyremote.com.

4. What we do not collect or do

  • We do not read the body of your calendar events beyond the title; meeting attachments and descriptions are never requested.
  • We do not sell, rent, or share your personal data with advertisers.
  • AI / ML training. FairlyRemote does not use your team data to train its own AI models, and does not voluntarily contribute your data to a sub-processor’s ML training where opt-out is available. We configure our sub-processors to disable AI/ML training features wherever they offer a control (current settings are tracked in our internal sub-processor controls log; see §6 for the list of sub-processors and contact contact@fairlyremote.com for the current configuration). Some sub-processors may use aggregate, de-identified data for service improvement under their own terms. Scope of this commitment. “AI training” here means inclusion of your team data in a dataset used to fit or fine-tune a model. Our developers may use AI-assisted coding tools (for example, GitHub Copilot or Cursor) when writing the FairlyRemote codebase; we do not knowingly upload customer data to those tools, but we cannot guarantee that source code we author is not seen by such tools, and source code may incidentally reference data structures (column names, tier labels) that are not themselves Personal Data.

5. Cookies and similar technologies

What we use, and where:

  • Marketing pages (fairlyremote.com): no FairlyRemote-set cookies, and no third-party cookies. Our analytics provider (Plausible) is cookieless, and we self-host the Inter web font from /fonts/ on our own domain, so there are no calls to Google Fonts on first visit.
  • In-app, essential: session and CSRF cookies for authentication. These cannot be disabled while you are signed in.
  • In-app, preference storage (localStorage): your in-browser configuration, dark mode, and Free-tier team data.
  • In-app, analytics: no cookies. Our third-party analytics (Plausible) is cookieless and sets no cookies. Our first-party usage telemetry stores one non-identifying random token in localStorage (telemetry_client_id) to count distinct installs. It is not a cookie, not tied to your identity, and removable by opting out, clearing in-app data, or deleting your account (see §3.7).

6. Sub-processors and third-party services

ServicePurposeData sharedHosting region
SupabaseDatabase and authentication hostingAll account, team, and fairness dataSee current sub-processor list (link below) for the active project region
Fly.ioApplication hostingAll request traffic and server-side processingMulti-region; primary US
StripePayment processing and subscription billingEmail, billing details, subscription stateUnited States (relies on EU-US DPF / SCCs for EU data)
Google (OAuth + Calendar)Optional calendar syncOAuth tokens; calendar reads as described in §3.4Global; US-headquartered
SentryError monitoring (session replay is disabled: we do not record your screen)Stack traces, anonymous client id, request context (PII scrubbed at the logger boundary)United States (EU region available; current setting documented in our sub-processor list)
ResendTransactional email (welcome, magic link, billing receipts, deletion confirmations)Email address, message bodyUnited States
Plausible AnalyticsMarketing-page and in-app product analytics (cookieless)Aggregate page views and feature-usage events; no personal identifiersEuropean Union
CrispCustomer-support chat and ticketing (only when contacting support)Support-message contents, account email, browser contextEuropean Union
SlackSlack integration (only if you install it)Workspace and user identifiers, plus the contents of messages we post, which can name a meeting, proposal, or group and the person who requested itUnited States
MicrosoftOptional Microsoft 365 / Outlook calendar sync (only if you connect it)OAuth tokens; calendar reads as described in §3.4Global; US-headquartered
DiscordOptional Discord webhook notifications (only if you configure a webhook)The title and body of each notification, which can name a meeting, proposal, or groupUnited States
Apple (iCloud CalDAV)Optional Apple Calendar sync (only if you connect it)Your Apple ID and an app-specific password, both encrypted at rest; calendar reads as described in §3.4Global; US-headquartered
Google Firebase Cloud MessagingDelivering push notifications to the Android app (only if you turn notifications on)Device push token, and the title and body of each notification, which can name a meeting, proposal, or groupGlobal; US-headquartered
Browser push services (Apple, Mozilla, Google)Delivering web push notifications (only if you turn notifications on). Which service is used is decided by your browser, not by usPush endpoint URL for your browser install, and the title and body of each notificationDetermined by your browser vendor

We require each sub-processor to provide adequate data-protection guarantees. A current sub-processor list (with up-to-date hosting regions) and our Data Processing Agreement template are available from contact@fairlyremote.com.

7. International transfers

Several of our sub-processors are based in the United States or operate globally (see the table in §6). Transfers of EU/UK personal data to the United States rely on the EU-US Data Privacy Framework or Standard Contractual Clauses (SCCs); UK data transfers additionally rely on the ICO’s International Data Transfer Addendum (IDTA). On request, we can provide a copy of the current SCCs/IDTA in force with each US-based sub-processor.

8. How long we keep data

  • Account and billing: for the lifetime of your subscription, plus seven years for tax and accounting records.
  • Fairness summaries: 365 days (Team/Business). Data outside the window is automatically purged.
  • Booking-link guest records: up to 90 days after the booked time, then purged or anonymised.
  • Calendar OAuth tokens: until you disconnect or delete your account.
  • Server logs: 30 days. Sentry error events: 90 days under our current Sentry plan; the actual figure depends on the plan in force at the time and is set to be no longer than necessary for security and debugging. Contact contact@fairlyremote.com for the current setting.
  • Audit log: a structured audit-log row is written for account-level events (account creation, account deletion, role change in a team, gift-code redemption, data-subject-rights requests) and is kept for 90 days for fraud and breach investigation, then permanently removed. We log additional event types from time to time as needed to investigate incidents; we do not log read access to your own account data. Contact contact@fairlyremote.com for the current audit-event list.
  • Free-tier data: kept in your browser’s localStorage until you clear it.

After account deletion, residual records may persist briefly in sub-processor systems (e.g., Sentry error events, email-provider suppression lists) until their own retention windows expire. These records do not contain account-level personal data after deletion.

9. Your rights

Under UK and EU GDPR, you have the right to:

  • Access a copy of your personal data.
  • Rectify inaccurate data.
  • Erase your account and associated data (“right to be forgotten”). Use Settings → Account → Delete account, or email contact@fairlyremote.com. Cancellations propagate to Stripe immediately; data is purged within 30 days.
  • Export your data in a machine-readable format. Every signed-in user can export their in-browser configuration as JSON from Settings → Data → Export. Business adds a self-service CSV export of team-level data. Data we hold on our servers (your profiles row, billing metadata, and server-saved fairness history) is not currently covered by the self-service button on any tier: email contact@fairlyremote.com and we will send you a copy within 30 days, on any tier including Free.
  • Object to processing based on legitimate interest.
  • Withdraw consent for analytics or calendar sync at any time.
  • Complain to us directly, or to a supervisory authority. You can complain to us first using the procedure in §9.1 below, and you can also complain to a supervisory authority at any time. UK: the ICO.

9.1 Complaining to us about how we handle your data

If you are unhappy with how we have handled your personal data or a data-rights request, you can make a complaint to us directly. Email contact@fairlyremote.com with “Data complaint” in the subject line, describing what happened and what you would like us to do. We will acknowledge your complaint within 30 days, take appropriate steps to investigate and respond, and inform you of the outcome without undue delay. Making a complaint to us is free, and you do not have to complain to us before going to a supervisory authority. If you are not satisfied with our response, or at any time, you can complain to the UK ICO (or, if you are in the EU/EEA, your local data-protection authority).

10. Children

FairlyRemote is not directed at children under 13 in the United States (per COPPA) or under 16 in the EU and UK (per GDPR). We do not knowingly collect personal data from children below those ages. If you believe a child has provided us data, contact contact@fairlyremote.com and we will delete it.

11. Security

We use TLS in transit, encrypt OAuth tokens at rest, salt and hash passwords (or rely on OAuth providers), and gate access to production systems. No system is perfectly secure; if you discover a vulnerability, please disclose it via the contact in /.well-known/security.txt.

Breach notification. If a personal-data breach affecting your data occurs, we will notify you without undue delay and, where required by GDPR Art. 33 or comparable law, within 72 hours of becoming aware. Notifications go to the email on your account; team owners are notified for breaches affecting team data.

12. Changes to this policy

We will email account holders about material changes at least 30 days before they take effect. Minor edits will be reflected in the “Last updated” date above.

13. Contact

Privacy questions, DSR (data subject request) submissions, or DPA enquiries: contact@fairlyremote.com.

EU representative (GDPR Art. 27). At present we rely on the Art. 27(2)(a) exemption: our processing of EU residents’ personal data is occasional, does not include large-scale processing of special categories or criminal-conviction data under Art. 9 or 10, and is unlikely to result in a risk to the rights and freedoms of natural persons. We will appoint an EU-based representative if and when our EU processing crosses that threshold (for example, becoming regular rather than occasional, or scaling materially) and will update this section in the same commit. In the meantime, EU residents can address all GDPR enquiries to contact@fairlyremote.com and we will respond within statutory timelines. The same approach applies to a UK GDPR Art. 27 representative.

14. Notice for California residents (CCPA / CPRA)

This section supplements the rest of this policy for California residents under the California Consumer Privacy Act, as amended by the California Privacy Rights Act.

Categories of personal information we collect. Identifiers (email, account ID, IP address); commercial information (subscription tier, billing history); internet activity (page views, feature-usage events for paid users with consent); geolocation (timezone, coarse, city-level only). We do not collect biometric, health, or precise-geolocation data, and we do not knowingly process “sensitive personal information” as defined by the CPRA.

Sources. Directly from you when you create an account or use the Service; from your browser via cookies and analytics described in §5 and §3.7; from sub-processors listed in §6.

Purposes. The purposes set out in §3 of this policy: authentication, providing the Service, billing, security, and (with consent) analytics.

Sale and sharing. We do not “sell” or “share” personal information as those terms are defined in the CPRA, including for cross-context behavioural advertising. We have not done so in the preceding 12 months.

Sensitive personal information. We do not use sensitive personal information for any purpose other than as expressly permitted under CPRA §7027(m). The right to limit use of sensitive personal information therefore does not currently apply, but you may still exercise it by contacting contact@fairlyremote.com.

Your rights. California residents have the right to know, correct, delete, and portability of personal information; the right to opt out of sale/sharing (not applicable as above); the right to non-discrimination for exercising these rights; and the right to limit use of sensitive PI (also not currently applicable). Submit a request via contact@fairlyremote.com; we verify identity by confirming control of the account email.

Authorised agents. You may designate an authorised agent to make a request on your behalf; we will require written authorisation and may verify your identity directly.

Retention. See §8.

FairlyRemote™

Pick meeting times that are fair to every timezone.

Try the sample team →

Product

  • Features
  • How it works
  • Pricing
  • Changelog

Resources

  • Blog
  • FAQ
  • Trust

Company

  • About
  • Contact

Legal

  • Privacy
  • Terms
  • Security
  • Sub-processors

© 2026 FairlyRemote™. Built for distributed teams everywhere.

FairlyRemote™ is a service of Meourobo Labs Ltd, a company registered in England and Wales (company no. 17277317). Registered office: 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom. Contact: contact@fairlyremote.com.

FairlyRemote™ and the FairlyRemote logo are trademarks of Meourobo Labs Ltd.