Privacy Policy

Last updated: July 18, 2026

What Riverli is

Riverli is a scheduling platform. We help you schedule meetings with multiple co-hosts and guests without requiring them to create an account. This policy explains what data we collect, why we collect it, and how we protect it.

What we collect

When you sign in as a host, we collect your name, email address, and calendar access tokens from Google or Microsoft. We use these solely to read your calendar availability and create meeting events on your behalf. When a co-host connects their calendar via an invite link, we collect their name, email, and calendar access tokens — same scope, same purpose. When a guest books a meeting, we collect their name and email address to send a confirmation and create a calendar invite. We also store the selected time and any notes they provide. We collect your detected timezone to format times correctly in emails and on the booking page.

What we do not collect

We never read the content of your calendar events — only whether a time slot is free or busy. We do not sell or rent your personal data to any third party.

Advertising and analytics

We run Google Ads to help people find Riverli. When you arrive at our site by clicking one of our ads, Google's advertising tag is loaded (only after you accept cookies — see "Cookies" below) so we can measure whether our ads are effective. If you sign up for an account after clicking one of our ads, we use Google's "enhanced conversions" feature, which shares a cryptographically hashed (not plain-text) version of your email address with Google. This lets Google match your signup back to the ad you clicked, even if some time passed in between. Google processes this data under its own advertising and privacy policies. We do not share your calendar data, booking details, or any other information with Google for this purpose — only the fact that an ad-driven visit resulted in a signup.

Cookies

When you first visit Riverli, you'll see a banner asking whether to accept or decline cookies used for advertising measurement. If you accept, Google's advertising tag loads and may set cookies used to measure ad performance, as described above. If you decline, that tag never loads and no advertising cookies are set. Riverli's core functionality — signing in, booking, and managing events — works identically either way; declining does not limit anything you can do on Riverli. Your choice is remembered in your browser's local storage so you won't be asked again on future visits, unless you clear your browser data.

Calendar access

Riverli requests calendar access to check availability and create booking events. For hosts and co-hosts, this access persists so we can check availability for future bookings. For guests who optionally connect their calendar on the booking page, access is one-time and transient — we fetch busy times for that session only and never store a guest's calendar tokens.

How we store your data

Your data is stored in a PostgreSQL database hosted by Supabase in the United States. All data is encrypted in transit using TLS and encrypted at rest, including calendar access tokens. Access to production data is limited to the systems and processes required to operate Riverli — we do not manually access your calendar tokens outside of what the application needs to check availability and manage bookings. We retain booking data for as long as your account is active. See "Your rights" below to request deletion at any time.

Emails we send

We send transactional emails only — booking confirmations, reschedule notices, cancellation notices, and meeting reminders. We do not send marketing emails without your explicit consent. All emails come from bookings@updates.riverli.io.

Third-party services

Riverli uses the following third-party services to operate, and each receives only the data it needs to perform its function: Google Calendar API and Microsoft Graph API — receive your calendar access tokens to check availability and create, update, or delete meeting events on your behalf. Resend — receives attendee names, email addresses, and meeting details to send transactional emails (confirmations, reschedules, cancellations, reminders). Stripe — receives billing information (name, email, payment details) to process subscription payments. Stripe never receives your calendar data. Supabase — stores all application data (accounts, event types, bookings) in an encrypted database. Vercel — hosts the application and processes requests; it does not have standing access to stored data. Google Ads — receives ad click and conversion data as described in "Advertising and analytics" above, only if you accept cookies. We do not sell or rent your personal data to any third party. Each provider is bound by its own privacy policy and only processes data as needed to deliver the service or, for Google Ads, to measure advertising performance as described above.

Your rights

You can request access to, correction of, or deletion of your personal data at any time. For formal data rights requests — access, correction, deletion, or GDPR/UK GDPR requests — email legal@riverli.io; we will respond within 30 days. For general questions or support, reach us at hello@riverli.io. If you are in the EU or UK, you have additional rights under GDPR and UK GDPR respectively.

Changes to this policy

We may update this policy from time to time. When we do, we will update the date at the top of this page. Continued use of Riverli after changes constitutes acceptance of the updated policy.

Contact

Questions about this policy? Email us at legal@riverli.io. We're a small team and we respond personally.

Riverli© 2026 Riverli
Got a thought?
A real person reads every one of these.
Leave it if you'd like a reply — totally optional.
No account needed.