Effective August 29, 2026
Privacy Policy
This policy explains how Gibbor Technologies handles information through Gibbor Calls, including authorized access to Google Calendar.
1. Controller and scope
Gibbor Technologies operates Gibbor Calls. This policy applies to application users, organizations managing calls, and people whose information is added to the CRM. For privacy questions or requests, email hello@gibbortechnologies.com.
2. Information we process
Depending on each organization’s use and configuration, we process:
- Account, organization, role, session, and audit-log data.
- Contact and call data received from Retell, such as phone numbers, duration, transcript, summary, analysis, and recording links.
- Appointment data, such as name, email, phone number, time, time zone, and booking status.
- Technical and security data needed to authenticate requests, prevent abuse, and diagnose errors.
3. Google Calendar data
Gibbor Calls requests the calendar.events and calendar.events.freebusy permissions. With the user’s explicit authorization, the application can:
- Check busy time intervals to determine availability.
- Create and retrieve appointments generated through the call workflow.
- Add the time, title, and attendee information provided for the booking to those appointments.
We store the calendar identifier, identifiers for created events, and an encrypted refresh token used to maintain the connection. We do not use Google Calendar data for advertising, commercial profiling, credit evaluation, or training generalized artificial-intelligence models.
4. How we use information
We use information to provide and secure the service: authenticate users, organize calls and contacts, check availability, create requested appointments, show operational results, provide support, maintain audit records, and comply with applicable legal obligations.
5. Service providers and disclosure
We may process information through providers supporting necessary service functions, such as hosting, databases, voice telephony, monitoring, and Google Calendar. They receive only the information needed to perform their function. We do not sell personal or Google data, and we do not transfer it to advertising networks, data brokers, or information resellers. We may also disclose information when necessary for security, legal compliance, or a permitted corporate transaction, subject to required protections and consent.
6. Security
We use encryption in transit, organization-level access controls, protected sessions, auditing, and cryptographic verification for integrations. Google refresh tokens are encrypted before storage. No system eliminates all risk, so we also limit operational access to personnel who need it for support, security, or compliance.
7. Retention, disconnection, and deletion
We retain information while the account or business relationship remains active and for the period needed to operate the service, resolve disputes, maintain security, and comply with law. An OWNER or ADMIN can disconnect Google Calendar from Settings; this deletes the stored refresh token from Gibbor Calls and stops future access. Events already created remain in Google Calendar until their owner deletes them. You may request access, correction, or deletion by emailing us.
8. Google API Services User Data Policy
Our use and transfer of information received from Google APIs complies with the Google API Services User Data Policy, including its Limited Use requirements.
9. Changes and contact
We will update this policy when our handling of information changes materially and request new consent when required. Contact: hello@gibbortechnologies.com.