Legal
Privacy Policy
Effective August 30, 2026
Overview
Community Calendar is a public community-events service operated from Salina, Kansas. This Privacy Policy explains what information the service collects or processes, why it is used, when it may be public, when it may be shared with service providers, how long it may be retained, and how you may request access, correction, or deletion.
We try to collect only information needed to operate the calendar, authenticate accounts, protect the service, moderate event submissions, and provide features you choose to use. We do not sell personal information. We do not use personal information for targeted advertising, and the application does not include third-party advertising or analytics trackers.
Information we collect
Account information
If you create an account, we may store your display name, email address, account role/status, account creation and update dates, and last-login date. Local-password accounts store a password hash rather than the password itself. Local two-factor authentication stores an encrypted authenticator secret and enrollment status.
Social and provider login information
If you choose Google, Microsoft, or Facebook login, the provider may send us a stable provider account identifier, name, and email address when available. Community Calendar stores the provider name, provider account identifier, and provider email needed to recognize that login in the future.
For Facebook Login specifically, Community Calendar requests only public_profile and email. The application uses the returned Facebook account ID, name, and email address, when Facebook supplies one, to create or recognize your Community Calendar account.
Event information you submit
If you create or import an event, we may store the event title, short and full descriptions, dates and times, time zone, location name and address, Google Place identifier, coordinates, public phone/email/Facebook contact values, event artwork, publication/moderation status, recurrence information, and source-provider references used to identify an imported event.
Published event information is public. Do not put private information in an event title, description, artwork, location, or public contact field unless you intend that information to be visible to anyone who visits the site.
Saved events and account activity
If you save events, we store the relationship between your account and those events. The service also keeps security, moderation, and audit records such as account actions, event moderation actions, API-key activity, and record timestamps.
Calendar imports
If you explicitly choose to import from Google Calendar or Microsoft Outlook, Community Calendar requests read-only access needed to let you select and import an event. Provider authorization is requested only when you initiate that feature. Imported events become local drafts. The application is designed not to maintain a continuing background calendar synchronization relationship or persist provider refresh tokens for those one-time imports.
Technical information
The service uses an essential session cookie to keep you signed in, protect account state, and support security controls. IP addresses and request information may be temporarily processed for rate limiting, security, troubleshooting, and normal web-server or reverse-proxy operation. Depending on infrastructure configuration, server logs may contain request time, IP address, browser/user-agent information, requested URL, response status, and error details.
How we use information
- Provide and maintain Community Calendar.
- Create, authenticate, secure, and administer user accounts.
- Publish, display, save, import, edit, moderate, and manage community events.
- Prevent spam, fraud, abuse, unauthorized access, and excessive automated requests.
- Troubleshoot errors, maintain security, and improve reliability.
- Keep audit and moderation history needed to protect the integrity of the service.
- Comply with applicable law, lawful process, and enforceable legal requests.
- Protect the rights, safety, and property of users, the service, and others.
When information is public
The public calendar is designed to publish community-event information. Published event titles, descriptions, dates, times, locations, artwork, and event-level contact information may be visible without an account and may be indexed, copied, cached, linked to, or archived by third parties.
Your Community Calendar account email and linked-login identity are not automatically published merely because you created an event. Only information intentionally entered into public event fields is intended to appear publicly.
Third-party services
Features you choose may communicate with third-party providers. These providers process information under their own terms and privacy policies.
- Meta/Facebook for Facebook Login.
- Google for Google Login, Google Calendar import, Google Places location search, and Google Maps.
- Microsoft for Microsoft Login and Outlook Calendar import.
- GitHub for administrator-controlled application update checks and source updates; this function is administrative and is not used for ordinary visitor tracking.
When a Google Map is displayed, your browser may connect directly to Google and transmit technical information such as your IP address and browser information to Google. Similar direct communication occurs when you choose an external login or calendar provider.
Cookies and tracking
Community Calendar uses essential session technology required for login, security, and site operation. The application does not currently use advertising cookies, behavioral-advertising trackers, or third-party analytics trackers. If those practices materially change, this policy should be updated before the new collection begins.
Data security
We use reasonable administrative and technical safeguards appropriate to the information handled by the service. Examples include hashed passwords, encrypted authentication secrets where applicable, server-side authorization checks, CSRF protections, rate limiting, restricted administrative functions, and database-backed access controls.
No internet service can guarantee absolute security. If we determine that a security incident requires notice under applicable law, we will investigate and provide required notices in accordance with applicable legal requirements.
Data retention
We retain information for as long as reasonably necessary for the purposes described in this policy, including operation of the service, event history, moderation, security, dispute resolution, legal obligations, and protection against abuse. Retention periods differ by record type.
- Active account information is generally kept while the account exists.
- Session records expire and are removed as part of normal session management.
- Saved-event relationships are removed when the account is deleted.
- Linked provider identities and local authentication/MFA material are removed when the account is deleted.
- Published events, event ownership references, moderation actions, and audit records may be retained after account deletion so the service can preserve event history, moderation integrity, security records, and legal/accountability records.
- When an account is deleted, the retained user record is anonymized where practical rather than keeping the former display name, email, password, or linked-provider identity.
Your privacy choices and requests
You may ask us to provide information about personal data associated with your account, correct inaccurate account information, delete your account, remove linked-provider identity information, or address public event information that contains your personal information. We may need to verify your identity before acting on a request.
We intend to honor reasonable access, correction, and deletion requests even when a specific state privacy statute does not require the request, subject to exceptions needed for security, fraud prevention, legal obligations, public event history, moderation records, exercise or defense of legal claims, and other legitimate recordkeeping needs.
To make a request, use the protected contact address: . The address is revealed only after activation to reduce passive address harvesting. Account-deletion details are also available on the Data Deletion page.
Children
Community Calendar is a general-audience service and is not directed to children under 13. Do not create an account if you are under 13. We do not knowingly collect personal information from a child under 13 without legally required parental authorization. If we learn that an account belongs to a child under 13 and the collection is not lawfully authorized, we will take reasonable steps to remove the child's personal information and close or restrict the account.
Legal and regulatory protections
Community Calendar is operated in Kansas. We maintain this policy and our information practices with the intent to comply with applicable federal and state privacy, consumer-protection, data-security, and breach-notification requirements. Applicable rights and obligations can vary based on your location, the type of information involved, and the size or nature of the service.
If a law applicable to you provides rights that are broader than this policy, those legal rights are not limited by this policy.
Changes to this policy
We may update this policy when the service, law, or third-party integrations change. Material changes should be posted here with a new effective date before or when they take effect. We will not use previously collected personal information for a materially different purpose without providing notice or obtaining consent when applicable law requires it.
Contact
Questions or privacy requests may be sent using this protected contact address: .