iC iCal Merge
  • Home
  • Features
  • Guides
  • Pricing
  • About
Get started

Privacy Policy

Last updated: July 12, 2026

This Privacy Policy explains how Mark Davenport, d/b/a iCal Merge (“we”, “us”, “our”), the operator of iCal Merge (the “Service”, available at icalmerge.com), collects, uses, and protects your information. We are based in the United States and serve users worldwide.

Plain-language summary (not a substitute for the full text): We store the account info needed to log you in, the calendars you create, and the feed URLs you add. We fetch those feeds on your behalf and combine them into a single calendar feed. We do not sell your data. Merged calendar feeds are served at public URLs — anyone who has the URL can read that calendar.

1. Who is responsible for your data

The data controller is Mark Davenport, d/b/a iCal Merge, located in Kansas, United States. Contact: [email protected].

2. Information we collect

Account information. Authentication is handled by our identity provider, Auth0 (Okta). When you sign in we receive and store a unique user identifier and your email address. We do not store your password.

Calendar configuration you provide. For each calendar you create we store: the calendar name/title, a generated calendar identifier, the source feed URLs you add, and the display name you give each source.

Content fetched on your behalf. To produce a merged feed, we request the contents of the source URLs you configure and combine their events. We may cache the merged result for a limited period to improve reliability and performance. We do not use the contents of your calendar events for any purpose other than producing your merged feed. If you enable double-booking alerts for a calendar, we additionally compare the start/end times of events across that calendar's sources to detect overlaps, and email you a summary of any we find.

Usage and access data. We record limited access metadata for each merged feed (for example, an access count and last-access timestamp) and standard server logs (IP address, user agent, timestamps) for security and operations.

Product analytics. We collect first-party usage analytics to understand how the Service is used and to improve it: which pages are visited on our site, and product actions in your account (for example, creating a calendar, adding a source, or reaching a plan limit). This is done without cookies or browser storage — an anonymous visitor is not recognized across visits. If you sign in, analytics events are associated with your account identifier. We process this data in PostHog (a US analytics provider) via our own domain; we do not track you across other websites, and this data is never sold or used for advertising.

Payment information. Payments are processed by our Merchant of Record, Paddle, who acts as the seller of record. We do not receive or store your full payment card details. We receive subscription status (e.g., active, cancelled, past due) and limited billing metadata needed to provision your plan.

3. How we use your information

  • To operate the Service: authenticate you, store your calendars, fetch sources, and serve merged feeds.
  • To provision and manage your subscription and plan limits.
  • To maintain security, prevent abuse, and debug problems.
  • To communicate with you about the Service (service notices; double-booking alert emails for calendars where you turn them on; and, only if you opt in, product updates).

We rely on the following legal bases (for users in the EEA/UK under GDPR): performance of a contract (operating the Service you signed up for), legitimate interests (security, abuse prevention, service improvement), and consent (optional marketing communications).

4. Public nature of merged feeds

A merged calendar feed is served at a URL with the calendar's identifier so that calendar applications can subscribe to it without authenticating. Anyone who knows or obtains that URL can read the contents of that merged feed. Treat the feed URL as a secret. Do not include sensitive information in calendars you intend to keep private. We are not responsible for access by anyone who obtains a feed URL.

5. Third-party feeds

You are responsible for ensuring you have the right to access and redistribute the source feeds you add. We fetch those feeds as your agent. We are not the author of, and do not control, the content of third-party feeds.

6. Sharing and disclosure

We do not sell your personal information. We share data only with service providers who help us run the Service, under contract:

  • Auth0 (Okta) — authentication and login.
  • Paddle — payment processing and tax (Merchant of Record).
  • Cloudflare — DNS, network proxy/CDN, encrypted off-site backup storage (R2), and inbound email routing for our support address.
  • Resend — outbound email delivery (e.g., alert and service emails).
  • PostHog — first-party, cookieless product analytics (see “Product analytics” above).

The Service itself runs on infrastructure we operate directly (it is not hosted by a third-party application host). We may also disclose information if required by law, to protect our rights, or in connection with a merger or acquisition.

7. Cookies and local storage

We use only the storage strictly necessary to run the Service. Our login provider (Auth0) stores authentication tokens in your browser's local storage so you stay signed in, and we store your light/dark theme preference locally. Our product analytics is deliberately cookieless: it sets no cookies and writes nothing to your browser's storage, so an anonymous visitor cannot be recognized across visits. We do not use advertising cookies, and we do not track you across other websites — so there is no behavioral-advertising activity to opt out of.

8. Data retention

We retain your account and calendar configuration for as long as your account is active. When you delete a calendar, its sources are deleted with it. When you delete your account, we delete your calendars and configuration and remove your personal data within 30 days, except where we must retain limited records for legal, tax, or security reasons. Cached feed content expires automatically.

9. Your rights

Depending on your location (including under GDPR and the CCPA/CPRA), you may have the right to access, correct, export, or delete your personal data, and to object to or restrict certain processing. To exercise these rights, contact [email protected]. You can delete your calendars at any time from your account, and request full account deletion by emailing [email protected]. EEA/UK users may lodge a complaint with their local data protection authority.

California residents (CCPA/CPRA). We do not sell your personal information and do not share it for cross-context behavioral advertising. You have the right to know what personal information we collect, to request its deletion or correction, and not to be discriminated against for exercising these rights. To make a request, contact [email protected].

10. International transfers

We are based in the United States and our providers may process data in the U.S. and elsewhere. Where required, we rely on appropriate safeguards (such as Standard Contractual Clauses) for transfers out of the EEA/UK.

11. Security

We use reasonable technical and organizational measures (encrypted transport, access controls, managed authentication) to protect your data. No method of transmission or storage is completely secure.

12. Children

The Service is not directed to children under 16, and we do not knowingly collect their personal data.

13. Changes

We may update this policy. Material changes will be posted here with a new “Last updated” date and, where appropriate, notified to you.

14. Contact

Mark Davenport, d/b/a iCal Merge — [email protected]


See also our Terms of Service.

iCiCal Merge

Merge multiple calendar feeds into one free, auto-updating link you can share and subscribe to anywhere.

HomeFeaturesGuidesICS viewerCreate ICS filePricingAboutContactPrivacyTerms

© iCal Merge