1. Application and business identity
This Privacy Policy applies to the TR Booking appointment booking application, available at booking.3in1environmental.com. TR Booking is owned and operated by 3 In 1 Environmental, the data controller responsible for the information described below.
- Application name: TR Booking
- Operator: 3 In 1 Environmental
- Effective date: September 14, 2026
- Last updated: September 17, 2026
- Privacy contact: 3in1environmental@gmail.com
TR Booking is a scheduling tool. A “service provider” is a business or professional who publishes a booking page, and a “client” is a person who schedules an appointment with that provider. Service providers remain responsible for how they handle client information outside TR Booking.
2. Information we collect directly
We collect only the information needed to operate booking pages, schedule appointments, notify the people involved, and manage subscriptions.
- Account information: the first and last name and email address used to register, a hashed password, email-verification status, session records, and security events such as sign-in attempts and rate-limiting data.
- Business and service-provider profile: business name, contact email and phone number, business address, website, license or credential details the provider chooses to publish, time zone, working hours and blocked dates, services and prices, appointment durations, booking-page text and branding, uploaded logo, custom booking questions, provider policies, and the notification email address where new-appointment alerts are sent.
- Client contact information: the name, email address, phone number, and service or property address a client submits when booking an appointment.
- Appointment information:the selected service, appointment date and time, time zone, duration, location or meeting details, notes, answers to the provider's custom questions, accepted provider terms, booking reference, and appointment status including rescheduling and cancellation history.
- Uploaded content: when a provider enables a file or photo field, we store the uploaded photos or documents together with their filename, file type, size, and the appointment they belong to. Uploads are stored in private, access-controlled storage and are not published on public booking pages.
- Payment and subscription records: the plan, subscription status, billing period, and the Stripe customer and subscription identifiers linked to a provider account. Card numbers and payment credentials are entered on Stripe-hosted pages and are processed by Stripe. TR Booking never receives or stores full payment-card details.
- Technical and delivery information: session cookies, request IP addresses used for abuse prevention and rate limiting, timestamps, calendar synchronization status, and email delivery metadata such as recipient type, message identifiers, attempt counts, and accepted, delivered, bounced, or failed status.
TR Booking is intended for business scheduling and is not directed to children under 13. We do not knowingly collect personal information from children.
3. Google Calendar information we access
Connecting Google Calendar is optional. TR Booking works without it, and email confirmations and reminders do not depend on it. A provider connects Google Calendar from Dashboard → Integrations, and Google asks the provider to approve the access listed below before anything is shared with us.
After the provider authorizes the connection, TR Booking may:
- View the list of calendars the user subscribes to, so the provider can choose which calendar TR Booking should use for bookings. This access is read-only.
- View availability (free/busy) information for the selected calendars. Free/busy queries return only whether a block of time is busy; they do not return the titles, descriptions, guests, or locations of the provider's existing events.
- Create, view, update, and remove Calendar events related to TR Booking appointments. We create events for appointments booked through TR Bookingand update or remove those events when the appointment changes. An appointment event may include the client's name and contact details, the service, location, notes, appointment time, and booking reference so the provider can identify and manage the appointment.
- Receive the Google account identity needed to maintain the connection, specifically the email address of the connected Google account. We display it so the provider can confirm which account is connected, and we store the selected calendar identifier and the identifiers of events we created.
We do not request access to Gmail, Google Drive, Google Contacts, or any other Google product, and we do not read Calendar events that TR Booking did not create, beyond the free/busy availability described above.
4. How we use Google information
Information received from Google Calendar is used only to deliver the scheduling features the provider asked for:
- check the provider's availability so that busy times are not offered to clients and double-booking is prevented;
- add confirmed appointments to the calendar the provider selected;
- update or remove the corresponding Calendar event when an appointment is rescheduled, changed, or canceled;
- keep booking information synchronized between TR Booking and the connected calendar, and show accurate connection and synchronization status in the dashboard; and
- maintain the authorized connection, including refreshing access so the provider does not have to reconnect for every appointment.
We do not use Google Calendar information to build advertising or marketing profiles, to train generalized artificial-intelligence or machine-learning models, or for any purpose unrelated to the scheduling features above.
5. Sharing of Google user data
We do not sell Google user data, and we do not use it for advertising or for cross-context behavioral advertising of any kind. We do not transfer Google user data to data brokers, information resellers, or advertising networks.
Google user data is shared only in these limited circumstances:
- With the provider who authorized the connection, within their own TR Booking dashboard and their own Google Calendar.
- With infrastructure and service providers strictly as needed to operate the application — for example our application host and our database host, which store the connection record. These vendors act on our instructions, are bound by contractual confidentiality and security obligations, and are not permitted to use the data for their own purposes.
- When required by law or to protect the service, such as responding to a valid legal request or addressing fraud, security, or abuse.
Any human access to Google user data is limited to the narrow cases permitted by Google's policy: an explicit request from the provider for support, a specific security investigation, a legal requirement, or aggregated and anonymized data used for internal operations.
6. Google API Services User Data Policy
TR Booking's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
You can read the full policy at https://developers.google.com/terms/api-services-user-data-policy.
7. Storage and protection of information
Google access tokens and refresh tokens are held only on our servers. They are never sent to browsers, never included in public booking pages, never written to application logs, and are encrypted at rest using authenticated AES-256-GCM encryption with a key that is stored separately from the database and is available only to the server application.
Application data, including accounts, provider profiles, appointments, notification records, and Google connection records, is stored in a managed PostgreSQL database hosted by Neon, with encryption in transit. The application itself is hosted by Vercel, and uploaded files are kept in private, access-controlled storage.
We apply security practices appropriate to the service, including password hashing, hashed session and verification tokens, secure HTTP-only cookies, HTTPS for all traffic, server-side authorization checks on provider data, input validation, rate limiting, authenticated background-worker and webhook endpoints, and restricted access to production systems. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.
This policy intentionally does not disclose credentials, keys, configuration values, or other operational secrets.
8. Retention and deletion
- Account information is retained while the account is active and afterwards only as long as reasonably needed for legal, tax, accounting, security, and dispute-resolution purposes.
- Appointment and booking records are retained so providers and clients keep an accurate service history, and are deleted on request or when the associated account is deleted.
- Google Calendar connection data — the access token, refresh token, selected calendar identifier, and connected account email — is retained only while the connection is active. It is deleted as soon as the provider disconnects Google Calendar or the account is deleted.
- Email delivery records and security logs are retained for a limited operational period to troubleshoot delivery problems and investigate abuse.
What is deleted when you disconnect Google Calendar: disconnecting removes the stored access token, refresh token, selected calendar identifier, and connected Google account email from our database, and we ask Google to revoke the authorization. Disconnecting does not delete Calendar events that were already created in your Google Calendar, and it does not delete your TR Booking account or appointment records. You can delete individual Calendar events directly in Google Calendar.
Requesting account and personal-data deletion: providers can delete their booking pages and disconnect Google Calendar from the dashboard at any time, and clients can cancel an appointment using the secure management link in their confirmation email. To delete an entire account and the associated personal data, send a deletion request from the email address on the account to 3in1environmental@gmail.com, with the subject line “Data deletion request.” We will confirm the request, may need to verify your identity, and will complete verified deletions within 30 days, except for records we are required or permitted to keep by law. Residual copies may persist in encrypted backups for a limited period before being overwritten.
9. Revoking access to Google Calendar
You can end the Google Calendar connection in two ways:
- Disconnect inside TR Booking: sign in and open Dashboard → Integrations, then select “Disconnect” on the Google Calendar card. TR Booking deletes the stored tokens and connection record and asks Google to revoke the authorization.
- Revoke access through Google: visit https://myaccount.google.com/connections, select TR Booking, and remove its access. Once access is revoked, TR Booking can no longer read availability or manage Calendar events, and the provider must reconnect to resume calendar synchronization.
10. Email notifications
TR Booking sends transactional email that is necessary to operate the service. Each recipient receives a separate message, so client and provider addresses are never exposed to each other through CC.
- Booking confirmations are sent to the client at the email address submitted with the appointment, and include the provider and service, the date and time with its time zone, location details where applicable, the booking reference, and secure links to view, reschedule, or cancel.
- Service-provider notifications are sent to the provider's saved notification address, or to their verified account email when no separate address is configured, and include the client's name and the contact details needed to prepare for the appointment.
- Appointment reminders are sent to both the client and the provider approximately one hour before the appointment starts. Reminders are canceled automatically when an appointment is canceled, and rescheduled when the appointment time changes.
- Account email such as address verification and password reset messages.
Resend delivers these messages on our behalf and reports delivery events such as accepted, delivered, bounced, or failed, which we store as delivery metadata. Because these messages are required to operate a booking, they are not marketing email; we do not send promotional campaigns to clients who book through a provider's page.
11. Third-party services
We rely on the following providers to operate TR Booking. Each processes only the information needed for its function and under its own privacy terms. Their inclusion here does not imply that they sponsor, endorse, certify, or are affiliated with TR Booking or 3 In 1 Environmental.
- Google — optional Google Calendar integration and the OAuth sign-in used to authorize it, as described in sections 3 through 6 and 9.
- Stripe — subscription checkout, recurring billing, and the billing portal. Stripe receives and processes payment-card details directly; we receive only subscription status and identifiers.
- Resend — delivery of transactional email and the associated delivery events.
- Vercel — application hosting, content delivery, and private storage for uploaded files.
- Neon — managed PostgreSQL hosting for application data.
- Upstash QStash — an authenticated scheduler that triggers processing of due notification jobs such as reminders.
We use cookies that are necessary for the service: authentication and session cookies, cookies that protect sign-in and the Google authorization flow against cross-site request forgery, and navigation state during onboarding. TR Booking does not use advertising pixels or third-party behavioral analytics, and does not sell personal information or share it for cross-context behavioral advertising.
12. Your rights, changes, and contact
Depending on where you live, you may have the right to access, correct, export, restrict, or delete your personal information, to object to certain processing, to withdraw consent — including by disconnecting Google Calendar — and to be free from discrimination for exercising these rights. Providers can review and update most of their information directly in the dashboard; for anything else, contact us using the address below. We may need to verify your identity before acting, and we respond within the time required by applicable law.
If a client asks us to change or delete information that belongs to a service provider's appointment records, we will direct the request to that provider where appropriate, since the provider controls its own client records.
We may update this policy when the service, our vendors, or legal requirements change. The revised policy will be posted on this page with a new “Last updated” date, and material changes affecting Google user data will be reflected here before the change takes effect. Continued use of TR Booking after an update means you accept the revised policy.
Contact: privacy questions, access requests, and deletion requests may be sent to 3in1environmental@gmail.com.
Operator: 3 In 1 Environmental, which owns and operates TR Booking at booking.3in1environmental.com.
