Legal
Privacy Policy
Last updated: June 28, 2026
This Privacy Policy explains how D-1 Meetings (the “Service”) collects, uses, shares, and protects information. D-1 Meetings is a Google Workspace add-on and web application for scheduling external meetings — you propose times, invitees vote, and the meeting is placed on your calendar.
The Service is operated by D-1 Digital Solutions Pte. Ltd. (“D-1”, “we”, “us”), a company incorporated in Singapore. You can reach us at hello@d-1.one.
This policy covers the D-1 Meetings add-on and feature specifically. If we offer other D-1 products, a separate notice may apply to them.
Information we collect
We collect only what we need to provide scheduling. The categories are:
Account and identity (Google sign-in)
When you connect your Google account we receive your email address, your Google account identifier, your name, profile picture, and your Workspace domain. This uses the openid, userinfo.email, and userinfo.profile scopes. We use it to create and identify your account and to show who organized a meeting.
Calendar data
To suggest times we read your free/busy availability (calendar.freebusy) and your calendar’s time zone (calendar.settings.readonly). To hold and book meetings we create, update, and delete calendar events on your behalf — tentative holds for proposed times and the final event once a time is chosen (calendar.events). We do not read the contents of your other calendar events beyond free/busy and the events we create for you.
Gmail context
When you open the add-on from an email, we read only the metadata of that message — its subject and the recipients — and the draft you are composing, so we can pre-fill invitees and context (gmail.addons.current.message.metadata and the compose action scope). We do not read the body of your emails, and we have no permission to send email from your Gmail account.
Directory lookups
When you search to add participants, we query your organization’s Google Workspace directory (directory.readonly) and show matching people so you can pick them. These results are used to populate the picker and are not stored beyond the participants you actually add.
Meeting and scheduling data you create
- Poll details: titles, descriptions, locations, invite messages, and candidate time slots.
- Participants: the email addresses and display names of people you invite.
- Votes and responses: each participant’s availability choices (yes / no / maybe).
- Voter verification: for invitees who verify by email, a one-time passcode tied to their email address. The passcode itself is stored only as a secure hash, never in plain text.
Google authorization tokens
To act on your behalf, we store the OAuth access and refresh tokens Google issues when you connect. These tokens are encrypted at rest.
Technical and operational data
We keep limited server logs and error reports to operate the Service securely and reliably. We do not use advertising or cross-site tracking technologies.
How we use information
- To provide scheduling: suggest times, create holds, and book the final meeting.
- To invite participants and send meeting-related notifications and confirmations.
- To verify the identity of invitees who vote by email.
- To secure the Service, prevent abuse, and meet legal obligations.
- To provide support when you contact us.
Google API Services Limited Use
D-1 Meetings’ use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. We use Google user data only to provide and improve the scheduling features described in this policy. Specifically, we do not sell Google user data, do not use it for advertising, and do not allow humans to read it except: (a) with your explicit consent; (b) where necessary for security, to investigate abuse, or to comply with applicable law; or (c) where the data has been aggregated and anonymized.
How we share information
We do not sell your personal information. We share it only as follows:
- With Google, to read your free/busy times and to create the calendar events you ask us to create.
- With meeting participants, who see the poll details, proposed times, and the organizer’s name, and whose responses are visible to the organizer.
- With service providers that process data on our behalf under contract: our hosting provider DigitalOcean (data centers in Singapore) and our email delivery provider MailerSend, which sends meeting invitations and notifications on our behalf.
- When required by law, or to protect the rights, safety, and security of D-1, our users, or the public.
- In a business transfer, such as a merger or acquisition, subject to this policy.
Where your data is stored
The Service is hosted on infrastructure located in Singapore. If you access the Service from the European Economic Area, the United Kingdom, or elsewhere, your information will be transferred to and processed in Singapore. Some of our service providers — including our email delivery provider — may process limited data in other countries, such as the United States. Where required, we rely on appropriate transfer safeguards such as the European Commission’s Standard Contractual Clauses.
Data retention and deletion
We keep your information while your account is active and while your polls are in use. You are in control of removing it:
- Disconnect Google at any time from your Meetings settings. Disconnecting immediately revokes our access at Google and deletes the stored connection, including the OAuth tokens. Your existing polls are kept so you can reconnect — use the deletion request below to remove them.
- Delete your Meetings data at any time, from the app or by emailing hello@d-1.one. We remove your connection and tokens immediately and erase your associated Meetings data — polls, participants, votes, and related records — within 30 days.
If you uninstall the add-on or stop using the Service, the connection and its associated Meetings data are purged automatically after a period of inactivity. We may retain limited records where required for legal, accounting, or security purposes.
How we protect information
We encrypt Google authorization tokens at rest and transmit data over encrypted connections (TLS). One-time voter passcodes are stored only as hashes. We restrict internal access to personal data to what is needed to operate and support the Service.
Your rights (EEA and UK — GDPR)
If you are in the European Economic Area or the United Kingdom, you have the right to access, correct, delete, restrict, or object to our processing of your personal data, and the right to data portability. Where we rely on consent, you may withdraw it at any time.
Our legal bases for processing are: your consent (for connecting your Google account); performance of a contract (to provide the scheduling you request); and our legitimate interests (to secure and improve the Service). You may lodge a complaint with your local supervisory authority. To exercise any right, email hello@d-1.one.
Your rights (California — CCPA/CPRA)
We do not sell or share your personal information as those terms are defined under California law, and we have not done so in the preceding 12 months. California residents have the right to know what personal information we collect, to request its deletion or correction, and to not be discriminated against for exercising these rights. To make a request, email hello@d-1.one.
Your rights (Singapore — PDPA)
We handle personal data in accordance with Singapore’s Personal Data Protection Act. You may request access to, or correction of, the personal data we hold about you, and you may withdraw consent for our processing. Contact our data protection representative at hello@d-1.one.
Children
The Service is intended for business use and is not directed to children under 16. We do not knowingly collect personal data from children.
Cookies
The web application uses only essential, secure session cookies to keep you signed in. We do not use advertising or cross-site tracking cookies.
Changes to this policy
We may update this policy from time to time. We will revise the “Last updated” date above and, for material changes, provide a more prominent notice.
Contact us
D-1 Digital Solutions Pte. Ltd., Singapore — hello@d-1.one.