PRIVACY POLICY
Last updated September 3, 2026

Meeting Room 365, LLC ("Company", "we", "us", "our") describes here how and why we collect, store, use, and share ("process") your information when you use our services ("Services"), such as when you:
Questions? Email [email protected].

SUMMARY OF KEY POINTS
What personal information do we process? For the website and your account: names, email addresses, and billing details. For our applications: your work account identity and the workplace data your organization has authorized us to access. Details in What information do we collect.
Do we process sensitive personal information? No.
Do we receive information from third parties? When you sign in to one of our applications with a Microsoft or Google work account, we receive the information you authorize at sign-in. Otherwise, no.
Do we store your calendar? We do not copy your mailbox or keep a history of your calendar. Room displays send the current and next meeting's subject and organizer so administrators can see what a display is showing; administrators can redact or disable that. Nothing else in our applications sends calendar contents to us.
Do we sell your information? No. We do not sell or share personal information with advertisers or data brokers, and we do not use your data to train machine-learning models.
How do we keep it safe? Encryption in transit, organizational and technical controls, and EU-hosted storage. See How do we keep your information safe.
How do you exercise your rights? Email [email protected]. See What are your privacy rights.


TABLE OF CONTENTS
1. WHAT INFORMATION DO WE COLLECT?
2. HOW DO WE PROCESS YOUR INFORMATION?
3. WHAT LEGAL BASES DO WE RELY ON?
4. WHEN AND WITH WHOM DO WE SHARE YOUR INFORMATION?
5. DO WE USE COOKIES AND OTHER TRACKING TECHNOLOGIES?
6. HOW LONG DO WE KEEP YOUR INFORMATION?
7. HOW DO WE KEEP YOUR INFORMATION SAFE?
8. DO WE COLLECT INFORMATION FROM MINORS?
9. WHAT ARE YOUR PRIVACY RIGHTS?
10. CONTROLS FOR DO-NOT-TRACK FEATURES
11. DO CALIFORNIA RESIDENTS HAVE SPECIFIC PRIVACY RIGHTS?
12. DO WE MAKE UPDATES TO THIS NOTICE?
13. HOW CAN YOU CONTACT US?
14. HOW CAN YOU REVIEW, UPDATE, OR DELETE YOUR DATA?

1. WHAT INFORMATION DO WE COLLECT?

Personal information you provide to us
We collect personal information you voluntarily provide when you register, express interest in our products, participate in activities on the Services, or contact us. Depending on how you interact with us, this may include:
Sensitive information. We do not process sensitive information.
Passwords. Most customers authenticate through Microsoft or Google single sign-on, and we never receive or store a password. For password-based Exchange Web Services deployments, authentication is handled by Google Firebase; we do not store those passwords ourselves.
Payment data. If you make a purchase from us, we collect the data necessary to process it. All payment data is stored by Stripe — see https://stripe.com/privacy. Subscriptions bought through the App Store or Google Play are processed by Apple or Google under their own terms; we receive confirmation of an active subscription, not your payment details.

Information collected automatically
When you visit the website we automatically collect technical information that does not reveal your identity: IP address, browser and device characteristics, operating system, language preferences, referring URLs, country, and log and usage data. We use it to keep the Services secure and operational, and for internal analytics.
We use cookies only where necessary for authentication and session management. We do not use third-party tracking or advertising cookies.

Information collected by our applications
Our applications are used with a work account issued by your employer. You sign in directly with Microsoft or Google, and we never see or store your password.
Across all our applications:
Google in real time and rendered on the device. We keep no history of your calendar, and event bodies, attachments, and attendee lists are never sent to us. The one exception is described under room displays below.
portal.
What each application accesses, and the much smaller set it sends to us, is below.

Meeting Room 365 Desk Booking (iOS, Android)
With the permissions you approve at sign-in, the application accesses the following through Microsoft Graph, on your device:
Most of this stays on your device. What the application sends to our servers is limited to your work-location schedule: your name, work email address, Microsoft account identifier, and, for each day, a date range, a location label (such as "Office", "Remote", "Out of office", or a building name), and the desk you checked in to, if any. We use this to show colleagues in your organization where you are working.
Sharing your work location is optional. Turn it off under Settings in the application and we stop receiving your schedule. Your schedule is visible only to people signed in to the same organization as you, and is never made public.
The application does not access your device's location, camera, microphone, photos, or contacts, and contains no advertising, analytics, or tracking software.

Meeting Room 365 Display and Meeting Room 365 Classic (iOS, Android)
Room displays are tablets mounted outside meeting rooms, set up by your IT administrator and signed in with your organization's Microsoft 365 or Google Workspace account. This covers both the current Display application and the older Classic application it replaces. They are shared devices in shared spaces, not personal ones.
A display sends the following to us, so your administrators can manage the estate from the management portal:
If someone uses Report an Issue on a display, we receive the description they write and, if they provide it, their name.
Administrator controls. Each of these can be turned off per display from the management portal: analytics, meeting-subject redaction (which replaces subjects and organizers with "Redacted" before anything is sent), device status, device state, location, and screenshots. They are administrator settings, not end-user settings, and they are off by default — meaning the data above is sent unless your administrator changes it.
The camera is used only for an optional augmented-reality preview that shows how a display would look on a wall during setup. Camera frames are never uploaded or stored, and screenshot capture is suspended while the preview is open.

Meeting Room 365 Visitors (iOS, Android)
Visitors is a sign-in kiosk, usually an iPad at a reception desk. It is set up by the organization whose office you are visiting, and it is the one application of ours that collects information about people who are not our customers.
If you are signing in as a visitor. The organization you are visiting decides what its kiosk asks you for and how long it keeps your information. We provide the software and store the records on their behalf; they decide what is collected and why. Questions about your visit record are best directed to the organization whose reception desk you used, and we will help them answer you.
Depending on how that organization has configured its kiosk, signing in may collect:
Not all of this is collected everywhere. A minimally configured kiosk asks only for a name and a host. Photographs, signatures, and agreements are each optional and are switched on per organization.
We use this information only to record the visit, notify your host that you have arrived, print your badge, and give the organization a record of who was on site — which is often how they meet fire-safety and evacuation obligations. We do not use visitor photographs for facial recognition, and the application performs no biometric matching of any kind. We do not use visitor information for marketing, and we never sell it.
Visit records are held on the kiosk and synced to our servers so the organization can see them in its management portal. The kiosk deletes its local copy after a retention window the organization sets, 90 days by default; an administrator can shorten it, or set it to keep records indefinitely.
Host and administrator information. To let a visitor pick who they are visiting, the kiosk searches the organization's own staff directory through Microsoft or Google, with the organization's permission. The administrator who sets up the kiosk signs in with their work account, and we receive their email address.
Subscriptions. Visitors can be subscribed to through the App Store or Google Play. Those purchases are processed by Apple or Google, not by us; we receive confirmation that a subscription is active, not your payment details.

2. HOW DO WE PROCESS YOUR INFORMATION?
We process your information to:

3. WHAT LEGAL BASES DO WE RELY ON?
We process personal information only where we have a valid legal reason.
If you are in the EU or UK, we rely on: consent, which you may withdraw at any time; performance of a contract; legitimate interests (analyzing use of the Services to improve them, diagnosing problems, preventing fraud, and informing users about our products); legal obligations; and vital interests.
If you are in Canada, we process your information with your express consent, or with implied consent where permitted. In limited cases the law permits processing without consent — for investigations and fraud prevention, for business transactions meeting certain conditions, to comply with a subpoena or court order, or where the information is publicly available and specified by the regulations.
Where we act for an organization. When you use our applications with a work account, your employer determines why the workplace data is processed. The same is true of a visitor record: the organization operating the kiosk decides what its form asks and how long records are kept. In both cases that organization is the controller and we are the processor, acting on its documented instructions. Requests about that data may need to go to them; we will tell you when that is the case, and we will help them respond.
Where an organization collects a photograph, a signature, or an agreement from a visitor, it is that organization's responsibility to have a lawful basis for doing so and to tell visitors why — the kiosk shows the notice they configure.

4. WHEN AND WITH WHOM DO WE SHARE YOUR INFORMATION?
We share personal information with third-party vendors and service providers who perform work on our behalf and need access to do it. We have contracts in place requiring them to protect it, to use it only as we instruct, and to retain it only as long as we specify. The categories are:
We may also share information in connection with a business transfer — a merger, acquisition, financing, or sale of assets — and where required to comply with law or to protect our rights.
We do not share personal information with advertisers, data brokers, retargeting platforms, or third-party analytics providers.
We do not share your data between customer organizations. Information from your organization is visible only to people signed in to that organization.

5. DO WE USE COOKIES AND OTHER TRACKING TECHNOLOGIES?
We set only the cookies necessary for authentication and session management. We do not use third-party tracking or advertising cookies, tracking pixels in the emails we send, or device fingerprinting.
Most browsers accept cookies by default; you can set yours to reject or remove them, though this may affect some features.

6. HOW LONG DO WE KEEP YOUR INFORMATION?
We keep personal information only as long as necessary for the purposes in this notice, unless a longer period is required or permitted by law. Other than visitor records, which are governed by the period described below, no purpose in this notice requires keeping personal information longer than twelve (12) months past the termination of your account.
Work-location information collected through Desk Booking is retained for 180 days, and is deleted sooner if you or your organization requests it, or when your organization's account ends.
Visitor records are retained for a period chosen by the organization operating the kiosk. On our servers the default is 2 years, and an organization may set a longer or shorter period up to a maximum of 7 years, which we enforce. The kiosk itself keeps a local copy for a shorter window — 90 days by default — and deletes it on that schedule regardless. An organization may delete any record at any time.
Organizations often keep visitor logs longer than they keep other records, because site-access history is used for fire-safety, insurance, and security-incident purposes. The period that applies to your visit is set by the organization whose reception desk you used, and they can tell you what it is.
We keep no history of your calendar. The current-meeting information sent by room displays reflects present state and is replaced as it changes. Display screenshots are kept for up to 7 days, so an administrator can confirm a display is working, and are then deleted.
When we no longer have a legitimate business need to process your information, we delete or anonymize it. Where that isn't immediately possible — because it sits in a backup archive — we isolate it from further processing until deletion is.

7. HOW DO WE KEEP YOUR INFORMATION SAFE?
All traffic to and from our Services is encrypted in transit over HTTPS. Credentials on mobile devices are stored in the operating system's secure keystore (the iOS Keychain, the Android Keystore). Access to data on our servers is authenticated with your identity token on every request.
Where your data lives. All of our databases, backups, and object storage are located in the European Union. Our web and API servers run from an EU primary region with secondary regions in the United States and Asia to serve requests closer to you, so request traffic may be processed outside the EU even though stored data is not.
No electronic transmission or storage technology can be guaranteed to be 100% secure. Although we work to protect your personal information, transmission to and from the Services is at your own risk, and you should access them only in a secure environment.

8. DO WE COLLECT INFORMATION FROM MINORS?
We do not knowingly collect data from or market to children under 18, and our Services are not directed at them. Our applications are workplace tools used by employees and by visitors to a workplace.
If a visitor kiosk is used to sign in a person under 18 — a family member visiting an office, for example — that record is created by, and belongs to, the organization operating the kiosk, and is subject to the retention period it sets. We do not create accounts for visitors and do not contact them.
If we learn we have collected personal information from a person under 18 other than as described above, we will delete it. Contact [email protected].

9. WHAT ARE YOUR PRIVACY RIGHTS?
In some regions — including the EEA, UK, and Canada — you have rights to request access to and a copy of your personal information, to request correction or erasure, to restrict processing, to data portability, and in certain circumstances to object to processing. Email [email protected] to make a request; we will act on it in accordance with applicable law.
If you are in the EEA or UK and believe we are processing your information unlawfully, you may complain to your local supervisory authority (https://ec.europa.eu/justice/data-protection/bodies/authorities/index_en.htm). In Switzerland, the authority's details are at https://www.edoeb.admin.ch/edoeb/en/home.html.
Withdrawing consent. Where we rely on consent, you may withdraw it at any time. This does not affect the lawfulness of processing before withdrawal, or processing carried out on another lawful basis.
Opting out of marketing. Unsubscribe from any marketing email, or contact us. We may still send service-related messages necessary to administer your account.
Your account. You may review or change your information in your account settings, or ask us to terminate your account. On termination we deactivate or delete your account and information from our active databases, though we may retain some records to prevent fraud, troubleshoot, assist investigations, enforce our terms, or comply with law.
In our applications. Signing out clears your credentials and cached data from your device; deleting the application removes them. To delete the information held on our servers, see section 14.

10. CONTROLS FOR DO-NOT-TRACK FEATURES
Most browsers and some mobile operating systems offer a Do-Not-Track ("DNT") setting. No uniform standard for recognizing DNT signals has been finalized, so we do not currently respond to them. We do not track you across third-party websites or applications in any case. If a standard is adopted that we must follow, we will update this notice.

11. DO CALIFORNIA RESIDENTS HAVE SPECIFIC PRIVACY RIGHTS?
Yes. California Civil Code Section 1798.83 ("Shine The Light") lets California residents request, once a year and free of charge, information about the categories of personal information we disclosed to third parties for direct marketing purposes in the preceding calendar year, and the names and addresses of those third parties. We do not disclose personal information to third parties for direct marketing purposes. Submit any such request in writing using the contact details below.
If you are under 18, reside in California, and have a registered account, you may request removal of data you have publicly posted on the Services. Contact us with the email address on your account and a statement that you reside in California. We will remove it from public display, though it may persist in backups.

12. DO WE MAKE UPDATES TO THIS NOTICE?
Yes. The updated version is indicated by a revised date and is effective as soon as it is accessible. If we make material changes we will notify you, either by prominently posting a notice or by contacting you directly.

13. HOW CAN YOU CONTACT US?
Email [email protected], or write to:
Meeting Room 365, LLC 440 N Barranca Ave #3659 Covina, CA 91723 United States

14. HOW CAN YOU REVIEW, UPDATE, OR DELETE YOUR DATA?
To review, update, or delete the personal information we hold about you, email [email protected] from the address on your account.
Information from our applications. Signing out clears your credentials and cached data from your device, and deleting the application removes them entirely. To delete the work-location information held on our servers, email [email protected] from your work email address. Your organization's administrator may also request deletion for the entire organization.
Our applications do not create accounts. Your account belongs to your employer's Microsoft 365 or Google Workspace organization, and only they can delete it.