Privacy policy

Effective September 12, 2026. wardtime.org (“WardTime”, “we”) is an appointment-scheduling service for congregations. This policy explains what we collect, why, and how we handle data from Google. It is written to be read, not just agreed to.

The short version

  • We collect the minimum needed to book an appointment: a name, an optional email, and an optional note about who is coming.
  • We never store anything about what is discussed in an appointment. WardTime handles logistics only.
  • Google Calendar access is used for two things: hiding times the bishop is already busy, and adding bookings to the calendar the ward chooses.
  • We do not sell data, show ads, or share personal data with anyone except the service providers listed below.
  • Appointments are deleted automatically after 12 months. A ward can delete everything at any time.

Who WardTime is for

A ward (a local congregation) signs up and gets a public booking page. Members of that ward use the page to pick an appointment time. Ward leaders use a signed-in admin area to manage appointments. WardTime is operated by an individual and is not affiliated with The Church of Jesus Christ of Latter-day Saints.

What we collect

From members booking an appointment: the name you enter, your email address if you choose to give one, an optional note such as “the Jensen family”, the time you booked, and status timestamps on the day (arrived, started, finished). A random link lets you cancel or reschedule without an account.

From ward admins and clerks: your name and email from your Google or email sign-in, the ward and stake names, the ward’s timezone, a reply-to email, a location note, and optionally the bishop’s name for the printed flyer. Clerks may add short logistics notes to an appointment (for example, “must leave by 3:30”). The admin interface labels these as logistics only.

Automatically: standard server logs (IP address, browser type, timestamps) kept briefly by our hosting providers for security and debugging. We do not use analytics trackers or advertising cookies.

Google user data

If a ward admin connects a Google Calendar, WardTime requests these Google OAuth scopes and uses them only as described:

  • See your calendars and their free/busy information (calendar.readonly): to list the account’s calendars so the admin can choose one, and to read free/busy times only from that calendar so members are not offered times the bishop is already busy. Event titles, descriptions, and attendees are never read, stored, or displayed.
  • View and edit events on your calendars (calendar.events): to create an event on the chosen calendar when an appointment is booked, update it if the appointment moves, and delete it if the appointment is cancelled. We only touch events that WardTime created, which are tagged with a private property so they can be identified.
  • Your email address (userinfo.email): shown in the ward’s settings so admins can see which Google account is connected.

Storage. The Google refresh token is encrypted at rest with AES-256-GCM using a key that is not stored alongside the data. Free/busy results are cached for at most a few minutes and then discarded. We keep the ID of each calendar event we created so we can update or remove it.

Sharing. Google user data is never sold, never used for advertising, never used to train machine learning models, and never transferred to third parties except to our infrastructure providers listed below, solely to operate the service, or when required by law.

Revoking access. A ward admin can click Disconnect on the Calendar page, which deletes the stored token and cached data immediately. Access can also be revoked from your Google account permissions page. Events already on the calendar stay there; they belong to the calendar.

Limited Use disclosure. WardTime’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

How we use data

  • To show open appointment times and record bookings.
  • To send a confirmation, a reminder the day before, and notices if an appointment is cancelled, moved, or running behind. Emails are sent only to the address the member provided, and only if one was provided.
  • To show ward leaders who is booked, who has arrived, and who is next on the day.
  • To add bookings to the ward’s Google Calendar, if connected.
  • To keep the service secure and fix problems.

Who can see what

  • Members booking on the public page see only the open times. Other members’ names are never shown publicly.
  • Ward admins and clerks see appointments for their own ward only. Each ward is a separate organization; there is no cross-ward access.
  • A ward can create a “device link” for a shared tablet so the front desk and bishop screens work without a login. Anyone with that link can see that day’s names, so admins are told not to share it, and it can be revoked at any time.

Service providers

We use these providers to run WardTime. Each receives only what it needs to do its job.

  • Convex (database and backend), United States.
  • Vercel (web hosting), United States.
  • Clerk (sign-in and organization membership for ward admins), United States.
  • Mailgun (transactional email), United States.
  • Google (Calendar API and sign-in), under your own Google account and settings.

Retention and deletion

  • Appointments are deleted automatically 12 months after their date. A ward can shorten this in Settings.
  • Members can cancel an appointment from their manage link. Cancelled appointments are kept until the retention period ends so the ward’s records stay consistent, then deleted.
  • A ward admin can delete the entire ward, which removes all of its appointments, notes, email logs, and calendar connection immediately.
  • Google tokens are deleted when a calendar is disconnected or a ward is deleted.
  • To have data about you removed sooner, email help@wardtime.org and we will handle it within 30 days.

Cookies

The admin area uses a session cookie from Clerk to keep ward admins signed in. Public booking pages set no cookies. We do not use advertising or cross-site tracking cookies.

Security

All traffic is encrypted in transit. Google tokens are encrypted at rest. Manage links and device links are long random tokens that stop working when they expire or are revoked. Access to production systems is limited to the operator of the service.

Children

WardTime is intended for use by adults on behalf of their households and is not directed at children under 13. A ward may offer youth appointment types; those are booked by a parent or the youth’s leaders, and we collect nothing beyond a name and optional email for them.

Changes

If this policy changes in a way that matters, we will update the effective date above and, for ward admins, note the change in the admin area.

Contact

Questions or requests: help@wardtime.org, or use the help page.