Draft, last updated 4 October 2026
Privacy Policy
Who we are
My Meeting Pass is operated by Coldabry LLC, 1209 Mountain Road Pl NE #4337, Albuquerque, NM 87110, USA. Contact for anything privacy related: rk@coldabry.com.
We deal with two groups of people, and our role is different for each:
- Agencies and other businesses that create an account ("agencies"). For their account data we are the controller.
- Attendees who book a call with an agency and receive a meeting page and pass. For attendee data we are a processor acting for the agency, which is the controller. Questions about why an agency has your booking should go to that agency first; we will help them answer.
Data we process
For agencies (account data)
- Name, work email and a hashed password.
- Company name, logo, pass colour, time zone, optional contact email and website.
- If the agency uses its own Apple certificate: the certificate and private key, stored encrypted (AES-256-GCM).
- Usage records such as sign-in sessions, IP address and browser of a session, and which features were used.
For attendees (booking data, on behalf of the agency)
- Name and email address, as sent by the agency's booking tool (for example cal.com or Calendly).
- Meeting title, start and end time, time zone and the join link.
- Optional reschedule link from the booking tool.
- Whether the meeting page was opened, and whether the pass was added to Apple Wallet, Google Wallet or a calendar.
- Apple Wallet: a device library identifier and a push token that Apple Wallet sends us when the pass is added, so we can tell the device when the pass changes.
- Google Wallet: the id of the Google Wallet pass object we create for the booking.
- The outcome the agency marks after the call (attended or no-show), if it uses that feature.
For everyone
- IP address, briefly, to limit abuse of the demo and sign-in (rate limiting). It is held in memory and not stored with bookings.
- Standard server logs for security and troubleshooting.
The attendee's email address is never shown on the pass and never put in a link. Meeting page links use random tokens. When a booking tool adds a name or email to our redirect address, we drop it right away.
Shown on the lock screen
Apple Wallet and Google Wallet can show pass content on the lock screen and in notifications, for example near the start time or when the time changes. That content is the host name, the meeting title, the time and the status line. Anyone who can see the phone may see it. Attendees can remove the pass at any time, which also deletes the Apple device registration on our side.
Why we use the data, and on what legal basis
| Purpose | Data | Legal basis (GDPR) |
|---|---|---|
| Running the agency account, sign-in, password reset | Account data | Contract (Art. 6(1)(b)) |
| Creating meeting pages and passes, updating them on reschedule or cancel, sending the reminder status | Booking data, push tokens, Google object ids | We process this for the agency under our Data Processing Agreement. The agency needs its own basis, usually the contract with the attendee or legitimate interest. |
| Optional "your meeting pass" email, only if the agency turns it on | Attendee name and email | On behalf of the agency, as above |
| Security, abuse prevention, rate limiting | IP address, logs | Legitimate interest in keeping the service safe (Art. 6(1)(f)) |
| Product statistics in aggregate (for example how many passes were added) | Usage counts | Legitimate interest in improving the service (Art. 6(1)(f)) |
| Keeping records we must keep by law | Account and billing records | Legal obligation (Art. 6(1)(c)) |
We do not sell data, we do not use attendee data for advertising, and passes never carry marketing messages.
Sub-processors
We use these providers to run the service. Each is bound by a data processing agreement.
| Sub-processor | What it does for us | Where | Transfer safeguard |
|---|---|---|---|
| Contabo GmbH | Hosting of the application, database and backups | European Union (Germany) | None, data stays in the EU |
| Apple Inc. (Apple Push Notification service) | Telling Apple Wallet that a pass changed, using the device push token | USA | EU-US Data Privacy Framework, Standard Contractual Clauses |
| Google LLC (Google Wallet API) | Creating and updating Google Wallet passes and their notifications | USA and other Google locations | EU-US Data Privacy Framework, Standard Contractual Clauses |
| Sendinblue SAS (Brevo) | Sending account emails and, if the agency turns it on, the meeting pass email | European Union (France) | None for storage; Brevo's own sub-processors are covered by its DPA |
How long we keep data
- Demo pages made without an account: deleted after 24 hours.
- Apple device registrations and push tokens: deleted as soon as the pass is removed from the device, or when Apple tells us the token is no longer valid.
- Bookings, meeting pages and pass data: kept until the agency deletes them or closes its account. After an account is closed we delete its data within 30 days, except backups, which roll over within a further 30 days.
- Account data: for as long as the account exists, then as above.
- Server logs: up to 30 days.
International transfers
Our servers are in the European Union. Coldabry LLC is a US company, and Apple and Google process pass updates in the USA. Where data leaves the EU or EEA, we rely on the EU-US Data Privacy Framework where the recipient is certified, and on the European Commission's Standard Contractual Clauses otherwise.
Your rights
Under the GDPR and similar laws you can ask for access to your data, a copy in a portable format, correction, deletion, restriction, or object to processing based on legitimate interest. You can also complain to your local data protection authority.
- Agencies: write to rk@coldabry.com. Most settings and bookings can also be changed or deleted in the dashboard.
- Attendees: contact the agency you booked with, because it decides about your booking. You can also write to us and we will pass your request to the agency and help it answer. Removing the pass from your wallet stops all updates to your device straight away.
Security
Traffic is encrypted with TLS. Uploaded certificates and keys are encrypted at rest. Webhooks from booking tools must carry a valid signature or secret. Access to production systems is limited to the people who run the service.
Children
The service is for businesses and is not directed at children.
Changes
This is a draft. When we change it, we update the date at the top, and we tell agencies by email before changes that affect them take effect.
Contact
Coldabry LLC, 1209 Mountain Road Pl NE #4337, Albuquerque, NM 87110, USA. Email: rk@coldabry.com.