DaySlate

Privacy Policy

Last updated 26 July 2026

DaySlate is software for local service businesses, operated by Merged Media in Ontario, Canada. This policy explains what it collects, what it does with that information, and how to get rid of it. Questions go to ai@merged.ca.

Two parties matter throughout. The operator is the business paying for DaySlate — the plumber, the shop, the clinic. Their customersare the people who contact that business. DaySlate holds information about both, and the operator decides what happens to their customers’ information.

Google user data

DaySlate can connect to an operator’s Google Calendar so that jobs booked in DaySlate and events in that calendar stay in agreement. Connecting is optional. The product works without it, and it can be disconnected at any time.

What we request, and why

When an operator connects a Google account, we request access to that account’s calendars so that DaySlate can create, read, update and remove the calendar events that correspond to DaySlate bookings. A narrower, read-only scope is not sufficient: the point of the feature is that a booking made or moved in DaySlate appears and moves in the calendar the operator actually carries around.

What we do with it

  • Create a calendar event when a job is booked, and update or remove it when the job is rescheduled or cancelled.
  • Read existing events on the connected calendar to avoid offering a time the operator is not free.
  • Store the identifier of each event we create, so a later change updates the right event rather than making a duplicate.

What we do not do with it

  • We do not use Google user data for advertising, and we do not send it to any ad platform.
  • We do not sell it, rent it, or share it with anyone for their own purposes.
  • We do not use it to train machine learning models.
  • We do not read calendars belonging to anyone other than the connecting operator.

Limited use

DaySlate’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.

Storage, retention and removal

Access tokens are held encrypted and used only to make the calls described above. Event identifiers are stored alongside the booking they belong to. An operator can disconnect Google at any time from their settings, which revokes our access and deletes the stored tokens; access can also be revoked directly at myaccount.google.com/permissions. Calendar data we no longer need is deleted within 30 days of disconnection or account closure. Events already written to the operator’s calendar remain theirs and are not removed by disconnecting.

Information DaySlate collects otherwise

  • Operator accounts. Name, email address and which workspace the account belongs to. Sign-in is by emailed link; we do not store passwords.
  • Customer records. Whatever the operator records or captures about the people who contact them — typically name, phone number, email address, service address and what they asked for.
  • Advertising identifiers. When someone reaches an operator through an advertisement and submits a form, we record the click identifier the platform attached to that visit, along with campaign parameters and the page they landed on. This is what allows the operator to know which advertising produced real work.
  • Messages and bookings. Text messages sent and received through DaySlate, and the jobs, prices and notes attached to them.

Sharing with advertising platforms

This is the part worth reading twice, because it is what DaySlate is for. When an operator marks a job as booked or won, DaySlate reports that event to the advertising platform that produced the lead — Google Ads or Meta — together with the job’s value and the identifiers needed to match it to the original click. Where an email address or phone number is used for matching, it is hashed before it leaves us; we do not send the plain values.

This reporting is off by default. An operator turns it on per platform and chooses which events are reported. It uses information the operator collected from their own customers, and it never uses Google Calendar data.

Who else processes this information

We use a small number of providers to run the service: Supabase (database and authentication), Vercel (hosting), and Telnyx (text messaging). Each processes information only to provide their part of the service. Where reporting is enabled, Google and Meta receive the conversion information described above.

Text messaging

DaySlate sends messages on the operator’s behalf, from the operator’s own number. Anyone can stop them by replying STOP; that opt-out is recorded against the person, applies across the whole business, and cannot be undone by the operator. Operators are responsible for having a lawful basis to contact the people they message, including under Canada’s anti-spam legislation.

Your rights

Canadian privacy law gives people the right to know what an organisation holds about them, to have it corrected, and in most cases to have it deleted. If you are a customer of a business using DaySlate, that business controls your information — contact them first. If you cannot reach them, or you are an operator, write to ai@merged.ca and we will respond within 30 days.

Security

Information is encrypted in transit and at rest. Each workspace’s data is isolated at the database level, so one business cannot read another’s, and that isolation is enforced by the database itself rather than by application code.

Children

DaySlate is a tool for businesses and is not directed at children.

Changes

If this policy changes in a way that affects how Google user data is handled, we will say so here and notify operators before the change takes effect.

See also the terms of service.