Privacy policy
Last updated: 2026-06-16
This privacy policy explains how Snowdrop AB (“Snowdrop”, “we”, “us”) collects, uses and protects personal data when clients book meetings through Snowdrop Connect at connect.snowdrop.se, and when Snowdrop consultants connect Google Calendar to the service.
Snowdrop Connect is a booking service that allows clients to schedule meetings with Snowdrop consultants. The service uses consultant calendar information to show available booking times and to create, update or cancel booking events in the consultant’s calendar.
Data controller
Snowdrop AB
Vegagatan 14
113 29 Stockholm
Sweden
Email: privacy@snowdrop.se
Snowdrop AB is the data controller for the personal data processed in Snowdrop Connect.
Who this policy applies to
This policy applies to:
- clients who use Snowdrop Connect to book a meeting with a Snowdrop consultant;
- Snowdrop consultants who use Snowdrop Connect and choose to connect Google Calendar;
- visitors to the Snowdrop Connect website.
Clients do not connect their own Google account to Snowdrop Connect. The Google accounts connected to the service belong to Snowdrop consultants.
About Snowdrop Connect
Snowdrop Connect helps clients book meetings with Snowdrop consultants.
The service allows a client to select a consultant, choose an available time, enter booking details and confirm a booking. When a booking is confirmed, Snowdrop Connect creates a calendar event for the consultant.
Snowdrop consultants may connect one or more Google accounts to Snowdrop Connect so that the service can calculate available booking times and, for the consultant’s primary Google account, create, update or cancel booking events in the consultant’s calendar.
Personal data we collect from clients
When you book a meeting through Snowdrop Connect, we may collect and process:
- your name;
- your email address;
- the service or meeting type you selected;
- the selected consultant;
- the selected date and time;
- any message, note or other information you choose to provide in the booking form;
- technical information needed to operate, maintain and secure the service, such as logs and request metadata.
We use this data to:
- create and administer your booking;
- send booking confirmations and other booking-related messages;
- allow the consultant to prepare for and attend the meeting;
- handle rescheduling, cancellation and support requests;
- operate, maintain and secure the service.
Google user data and calendar integration
Snowdrop consultants may choose to connect one or more Google accounts to Snowdrop Connect. This allows Snowdrop Connect to show available booking times and, for the consultant’s primary Google account, create, update and delete booking events in the consultant’s own calendar.
Clients who book through Snowdrop Connect do not connect their own Google account. The Google accounts connected to the service belong to Snowdrop consultants.
Primary Google account
A consultant’s primary Google account is used both for availability checks and for managing booking events.
For the primary Google account, Snowdrop Connect may access or process:
- the consultant’s Google account email address, used to identify the connected account;
- OAuth access tokens and refresh tokens, used to maintain the calendar connection after the consultant has authorized it;
- the list of calendars the consultant is subscribed to, including calendar identifiers and calendar names, so the consultant can choose which calendar should be used for bookings and availability checks;
- free/busy information from selected calendars, used to calculate available booking times and avoid double bookings;
- booking events created, updated or deleted by Snowdrop Connect on calendars owned by the consultant.
Snowdrop Connect uses free/busy information to calculate availability. This means Snowdrop Connect does not need to read unrelated calendar event details, such as titles, descriptions, attendees or locations, in order to determine whether the consultant is busy.
For the primary Google account, Snowdrop Connect may create, update and delete booking events in calendars owned by the consultant. These booking events may contain client booking information, such as the client’s name, email address, selected service, booking time and any message or note provided by the client.
Additional Google accounts
A consultant may optionally connect additional Google accounts for availability checks only. This can be useful when a consultant has more than one calendar account and wants Snowdrop Connect to avoid bookings that conflict with busy time in another account.
For additional Google accounts, Snowdrop Connect may access or process:
- the Google account email address, used to identify the connected account;
- OAuth access tokens and refresh tokens, used to maintain the calendar connection after authorization;
- the list of calendars the account is subscribed to, including calendar identifiers and calendar names, so the consultant can choose which calendars should be checked for busy time;
- free/busy information from selected calendars, used only to calculate availability and avoid double bookings.
Snowdrop Connect does not create, update or delete calendar events in additional Google accounts.
Google OAuth scopes
Snowdrop Connect requests only the Google OAuth scopes needed for the booking functionality.
For a consultant’s primary Google account, Snowdrop Connect may request:
openidandemail— to identify the connected Google account;https://www.googleapis.com/auth/calendar.freebusy— to check busy intervals and calculate availability;https://www.googleapis.com/auth/calendar.calendarlist.readonly— to show the consultant’s list of calendars so they can choose which calendars Snowdrop Connect should use;https://www.googleapis.com/auth/calendar.events.owned— to create, update and delete booking events on calendars owned by the consultant.
For additional Google accounts used only for busy-time checks, Snowdrop Connect may request:
openidandemail— to identify the connected Google account;https://www.googleapis.com/auth/calendar.freebusy— to check busy intervals and calculate availability;https://www.googleapis.com/auth/calendar.calendarlist.readonly— to show the consultant’s list of calendars so they can choose which calendars Snowdrop Connect should check for busy time.
How we use Google user data
We use Google user data only to provide the booking functionality in Snowdrop Connect.
Specifically, we use Google user data to:
- identify connected Google accounts;
- let the consultant choose which calendars should be used for bookings and availability checks;
- calculate available booking times;
- avoid double bookings;
- create calendar events for confirmed bookings in the consultant’s selected own calendar;
- update calendar events when bookings are changed;
- delete or cancel calendar events when bookings are cancelled;
- troubleshoot the calendar integration when requested by the consultant or when necessary to maintain the service.
We do not use Google user data for advertising, retargeting, personalized advertising, data brokerage, information resale, creditworthiness decisions, lending purposes or any unrelated purpose.
We do not use Google user data to train artificial intelligence or machine-learning models.
Storage of Google user data
Snowdrop Connect stores the OAuth tokens needed to maintain the consultant’s Google Calendar connection. These tokens are stored server-side and are not visible to clients.
Snowdrop Connect also stores calendar connection settings, such as connected account email addresses, selected calendar identifiers and selected calendar names.
Booking records are stored in our database so that we can administer bookings and keep booking events synchronized with the consultant’s calendar.
Free/busy information from Google Calendar is used to calculate available booking times. Snowdrop Connect does not store unrelated calendar event details from consultants’ calendars for availability checks.
Human access to Google user data
Humans do not access Google user data except when:
- the consultant asks us to help troubleshoot the calendar integration;
- access is necessary for security purposes, such as investigating abuse or a technical incident;
- access is necessary to comply with applicable law.
Access is limited to what is necessary for the relevant purpose.
Sharing and transfer of Google user data
We do not sell Google user data.
We do not transfer, sell or share Google user data with advertising platforms, data brokers or information resellers.
We do not transfer, sell or use Google user data for serving ads, retargeting, personalized or interest-based advertising, creditworthiness decisions or lending purposes.
Google user data is processed only by Snowdrop Connect and by service providers that are necessary to operate the application, such as hosting, database, authentication, logging and application platform providers. These providers process data only to operate, maintain and secure Snowdrop Connect.
Snowdrop Connect’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Other service providers
We use service providers to operate Snowdrop Connect. These may include providers for hosting, database, authentication, application platform services, email delivery, logging and technical operations.
These service providers may process personal data only for the purposes described in this policy and only as needed to provide services to us.
We do not sell personal data.
Legal basis for processing
We process client booking data because it is necessary to provide the booking service requested by the client and to administer the meeting.
We process consultant Google Calendar data based on the consultant’s authorization and our legitimate interest in providing a working booking service for Snowdrop consultants and their clients.
We may process limited technical and security data based on our legitimate interest in operating, maintaining and protecting the service.
Where required by law, we process data to comply with legal obligations.
Storage location and security
Data is stored in the EU region where supported by our service providers.
We use technical and organizational measures designed to protect personal data against unauthorized access, loss, misuse or alteration.
These measures include:
- HTTPS for data transport;
- server-side storage of OAuth tokens;
- access controls;
- database row-level security;
- restricted access to production systems;
- security practices intended to limit access to people and systems that need it to operate, maintain or secure the service.
No method of transmission or storage is completely secure, but we take reasonable steps to protect the data processed by Snowdrop Connect.
Retention
Booking data is kept for as long as needed to administer the booking service, handle support requests and maintain appropriate business records, unless a longer retention period is required by law.
Google OAuth tokens are kept until the consultant disconnects the Google account from Snowdrop Connect, revokes access through the Google account, or the connection is otherwise removed.
When a consultant disconnects Google Calendar, Snowdrop Connect stops using the Google Calendar connection and deletes or disables the stored tokens needed for continued access.
Technical logs are kept only for as long as needed to operate, troubleshoot and secure the service.
We delete personal data on request where required by applicable law.
Revoking Google access
A consultant can disconnect a Google account from Snowdrop Connect in the consultant dashboard.
A consultant can also revoke Snowdrop Connect’s access directly in their Google account permissions.
After access has been revoked, Snowdrop Connect can no longer access that Google account unless the consultant connects it again.
Your rights under GDPR
If your personal data is processed by Snowdrop Connect, you have rights under the General Data Protection Regulation, including the right to:
- request access to your personal data;
- request correction of inaccurate data;
- request deletion of your data;
- request restriction of processing;
- object to processing;
- request data portability where applicable;
- lodge a complaint with the Swedish Authority for Privacy Protection, IMY.
To exercise your rights, contact us at privacy@snowdrop.se.
Children
Snowdrop Connect is not directed at children under 16. We do not knowingly collect personal data from children under 16.
Changes to this policy
We may update this policy from time to time. Changes are published on this page together with a new “Last updated” date.
If we materially change how Snowdrop Connect uses Google user data, we will update this policy and notify affected users where required before using Google user data in a new way.
Contact
Snowdrop AB
Vegagatan 14
113 29 Stockholm
Sweden
Email: privacy@snowdrop.se