Privacy Policy

    1. Information We Collect

    We collect information you provide directly to us, including when you create an account, use our services, communicate with us, or participate in surveys. This may include your name, email address, phone number, business information, and payment details.

    We also automatically collect certain technical information when you visit our website, for security and analytics purposes. This includes your IP address, browser and device type (user agent), the pages you visit, referring URLs, and an approximate location (country/region/city) derived from your IP address. We use this information to understand site traffic, distinguish real visitors from automated bots and crawlers, protect the service against abuse, and improve our product.

    2. How We Use Your Information

    We use the information we collect to:

    • Provide, maintain, and improve our services
    • Process transactions and send related information
    • Send technical notices, updates, and support messages
    • Respond to your comments and questions
    • Monitor and analyze trends, usage, and activities
    • Detect, prevent, and address technical issues and fraudulent activity

    3. Google User Data

    HustleHub's integration with Google Calendar requests only the minimum scopes necessary to perform scheduling functions.

    When you connect a Google Calendar account, HustleHub requests these scopes:

    • calendar.freebusy — read the busy/free blocks on your primary Google Calendar so already-committed times are hidden on your booking page. This scope returns start and end times only. It does not expose event titles, descriptions, guests, locations, or any other event content, and HustleHub does not read your other calendars.
    • calendar.events — create, update, and cancel the calendar event for a booking on your primary calendar, including generating a Google Meet link and inviting the client.
    • openid, userinfo.email, userinfo.profile — standard sign-in, and to show you which Google account is connected.

    Busy/free times retrieved from Google are used transiently to compute available booking slots and are not stored. What HustleHub retains is your OAuth tokens, the email address of the connected Google account, and the identifiers of the calendar events HustleHub itself created for your bookings.

    Disconnecting. Disconnecting Google Calendar in Settings → Services & Hours revokes HustleHub's access with Google and deletes the stored tokens. Deleting your HustleHub account does the same. You can also revoke access at any time from your Google Account under "Security → Third-party access."

    4. Google User Data, AI, and Model Training

    HustleHub uses a third-party AI provider (Anthropic's Claude API) at runtime for its in-app support chatbot and for marketing and content-generation features. These features are entirely separate from the Google Calendar integration.

    Data obtained through Google Calendar OAuth scopes is never transmitted to Anthropic or to any other AI or machine-learning provider. It is not included in AI prompts, chatbot conversations, embeddings, vector databases, or telemetry sent to AI providers, and it is never used to develop, improve, train, fine-tune, or evaluate any generalized artificial-intelligence or machine-learning model — HustleHub's or anyone else's. Google Calendar access is used solely for booking availability and calendar synchronization by deterministic scheduling logic.

    We do not sell Google user data, and we do not use it for advertising.

    5. Information Sharing

    We do not share your personal information with third parties except as described in this Privacy Policy. We may share information in the following circumstances:

    • With your consent or at your direction
    • With service providers who perform services on our behalf
    • To comply with laws or respond to lawful requests
    • To protect the rights and safety of HustleHub and others

    6. Our Security Commitments

    We implement industry-leading security measures to protect your data:

    • Encryption: Data is encrypted in transit with TLS and encrypted at rest (AES-256) by our hosting infrastructure
    • Password Security: Passwords are hashed using bcrypt. We check new passwords against databases of over 10,000 compromised passwords
    • Breach Detection: Real-time monitoring prevents the use of passwords found in known data breaches
    • Rate Limiting: Automatic protection against brute force login attempts and credential stuffing attacks
    • Real-time Threat Monitoring: 24/7 security monitoring with automated alerts for suspicious activity patterns
    • PCI-DSS Compliance: All payment processing handled through Stripe's PCI-DSS Level 1 certified infrastructure
    • No Card Storage: We never store credit card numbers - only tokenized payment references
    • Secure OAuth: Third-party integrations (Google Calendar, etc.) use OAuth 2.0. Tokens are held in our database with infrastructure-level encryption at rest, are accessible only to our server-side functions, and are never shared with other users or third parties

    7. Payment Data

    We use Stripe to process payments. HustleHub does not store full credit card numbers. Stripe may process payment information in accordance with its own security standards and privacy policies.

    HustleHub may store tokenized payment references (such as a payment method identifier) for billing and account management purposes.

    8. Data Security

    We take reasonable measures to help protect your personal information from loss, theft, misuse, unauthorized access, disclosure, alteration, and destruction. However, no internet transmission is ever fully secure or error-free.

    9. Google User Data Security

    All communication with Google APIs uses OAuth 2.0 and HTTPS encryption. Tokens are stored securely and are never shared with other users or third parties. Users can revoke HustleHub's access at any time through their Google Account settings under "Security → Third-party access."

    10. Data Retention

    We store the information we collect for as long as is necessary for the purpose(s) for which we originally collected it. We may retain certain information for legitimate business purposes or as required by law.

    Analytics IP addresses are treated as personal data and retained in raw form for no more than 90 days, after which they are automatically anonymized (irreversibly hashed) while aggregate, non-identifying analytics are retained. You may request deletion of your personal information as described in “Your Rights.”

    11. Your Rights

    You may update, correct, or delete your account information at any time by logging into your account. You may also contact us to request access to, correct, or delete any personal information that you have provided to us.

    12. Cookies and Tracking Technologies

    We use cookies and similar tracking technologies to track activity on our Service and hold certain information. You can instruct your browser to refuse all cookies or to indicate when a cookie is being sent.

    13. Changes to This Policy

    We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last updated" date.

    14. Contact Us

    If you have any questions about this Privacy Policy, please contact us through our support channels.

    HustleHub's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

    Last updated: 9/11/2026