Privacy

Privacy policy

This section explains the information acquired by Tokiawase, the data handled in Google Calendar / Microsoft Teams / Zoom / Webex integration, purpose of use, storage period, and how to contact us.

Last updated: July 24, 2026

Operator


Business operatorClassAct, Inc.
Address7F SH Building, 2-9-9 Shinkawa, Chuo-ku, Tokyo 104-0033
Contact informationtokiawase@classact.co.jp

Information we collect


  • We collect your name, email address, tenant, authentication status, etc. for account registration, login, identity verification, and notifications.
  • When you log in with Google or connect Google Calendar, we collect your Google account identifier, email address, and the OAuth scopes you granted.
  • To keep the Google Calendar integration working, we encrypt and store the access token, refresh token, and expiry. We never display client secrets or tokens on screen, in logs, or in issues.
  • To let you choose calendars in a connected Google account, we retrieve each calendar's name, identifier, primary flag, and the write capability determined from ownership and access permissions. You can select multiple calendars for availability and one calendar for confirmed events. We do not retrieve event contents, attendees, or attachments through this list.
  • To calculate candidate dates, we retrieve busy time blocks with the Google Calendar FreeBusy API only for calendars you select for availability. We use only the period and calendar ID needed to determine free time.
  • Only when the Google Calendar FreeBusy API cannot read a public calendar you selected for availability, such as a holiday calendar, we retrieve public event start/end times, all-day status, cancellation status, and transparency. We do not store or display event titles, descriptions, attendees, or attachments.
  • For reservation confirmation, Google Meet URL issuance, and host preview, we may handle event title, start/end time, participant email address, created event ID, event URL, etc.
  • When you connect a meeting integration such as Microsoft Teams, Zoom, or Webex, we collect the identifier and email address of the external service account you consented to, and the OAuth scopes you granted.
  • To issue meeting URLs, we encrypt and store the OAuth access token, refresh token, and expiry for Microsoft Teams, Zoom, and Webex. We never display client secrets or tokens on screen, in logs, or in issues.
  • To issue a meeting URL through your explicit action, we handle only the minimum information needed to create the meeting: event title, start and end times, time zone, the created meeting ID, and the join URL.
  • For security, auditing, and failure investigation purposes, we may obtain IP addresses, user agents, operation dates and times, request IDs, audit logs, and error logs.

Purpose of use


  • For Tokiawase registration, login, session management, MFA, identity verification, and account protection.
  • To compare the schedules of participants and hosts so we can offer candidate dates, 1:1 booking slots, and team availability suggestions.
  • To create confirmed events in Google Calendar and, if necessary, issue a Google Meet URL based on your explicit actions.
  • To create a meeting in the Microsoft Teams, Zoom, or Webex account you selected, and to save and display the join URL on the Tokiawase event.
  • To prevent unauthorized use, manage privileges, audit logs, investigate failures, and maintain service quality.
  • To respond to inquiries, send important announcements, and notify you of changes to the terms of use and our policies.

Handling of Google user data


  • Tokiawase's use of information obtained from Google APIs and transfer to other applications is subject to the Google API Services User Data Policy (including Limited Use requirements).
  • Information obtained from the Google API is used only to provide Google Calendar integration features enabled by the user, such as scheduling, checking availability, creating schedules, and issuing Google Meet URLs.
  • If you disconnect the integration, we invalidate and delete the stored tokens, and Tokiawase no longer accesses that Google Calendar.
  • We do not use Google user data for advertising, for sale to third parties, or for profiling unrelated to the user.
  • Google user data may only be viewed by a person at the explicit request of a user, when necessary to investigate failures or abuse, comply with regulations, or for aggregated, non-personally identifiable internal operations.
  • We do not use Google user data to develop, improve, or train AI/machine learning models unrelated to Tokiawase's user-facing features.

Handling of meeting integration data


  • Microsoft Teams, Zoom, and Webex integrations require only the OAuth scope necessary to verify the connection account and issue the user-selected meeting URL.
  • OAuth tokens for Microsoft Teams, Zoom, and Webex are encrypted and stored and are not displayed on screens, logs, issues, PRs, or documents.
  • We call the meeting creation API only for confirmed events, or when you explicitly choose to issue a meeting URL.
  • Tokiawase does not capture or store Microsoft Teams, Zoom, or Webex recordings, transcriptions, chat history, participant behavior analysis, or organization management data.
  • If you disconnect the integration, we invalidate and delete the stored tokens, and Tokiawase no longer accesses that meeting provider.

Managing and deleting your data


  • Google Calendar, Microsoft Calendar, and iCloud integrations can be disconnected in Tokiawase settings, which invalidates and removes stored tokens. Delete connection data also lets you permanently remove stored external account identifiers, scopes, and connection metadata through self-service.
  • You can also revoke Tokiawase access from the "Third-party apps and services" screen on your Google account.
  • Calendar connection data can be deleted directly from integration settings. For Tokiawase account data or data outside the self-service flow, contact tokiawase@classact.co.jp.
  • If we receive a request for account deletion or suspension of use, we will delete or anonymize the subject data within a reasonable period of time, except to the extent necessary for laws and regulations, audits, and measures to prevent unauthorized use.

Third-party services and subcontractors


Google APIWe communicate with Google's APIs, based on your consent, for Google Sign-In, the Google Calendar API, and issuing Google Meet URLs.
Microsoft GraphWe communicate with the Microsoft Graph API, based on your consent, to issue Microsoft Teams meeting URLs and verify the connected account.
Zoom APIWe communicate with the Zoom API, based on your consent, to issue Zoom meeting URLs and verify the connected account.
Cisco Webex APIWe communicate with the Cisco Webex API, based on your consent, to issue Webex meeting URLs and verify the connected account.
Google AnalyticsWe use Google Analytics to improve the public site. No Google tag or measurement request starts before your explicit consent. Measurement is limited to the fixed canonical path, language, page type, and fixed CTA identifiers for allowlisted public pages. Query strings, fragments, referrers, titles, personally identifying information, schedules, identifiers, and tokens are not sent. Authentication, administration, quick scheduling, booking, verification, invitation, and reset pages are never measured, regardless of consent. You can withdraw consent at any time from Cookie settings in the landing, blog, and legal footers; withdrawal removes Google Analytics cookies and storage.
Infrastructure and operations subcontractorsIn order to provide services, maintain, monitor, and provide security, we may use infrastructure operating environments and subcontractors to the extent necessary.

Retention period and deletion


  • We store OAuth tokens for as long as the integration needs them, and delete them when you disconnect the integration, close your account, or request deletion, except where retention is required by law or for audit.
  • We retain audit logs, security logs, and incident investigation logs for as long as needed to prevent unauthorized use, maintain internal controls, and comply with laws and regulations.
  • Requests for disclosure, correction, suspension of use, or deletion of personal data will be responded to within a reasonable period of time after identity verification.

Contact


  • We accept inquiries about personal information or Google Calendar integration data, deletion requests, and questions about disconnecting an integration.
  • Contact: tokiawase@classact.co.jp
Privacy policy | Tokiawase