PRODUCT GUIDE

Meetin.gs security and privacy overview

Learn how calendar data, access, sessions, and integrations are protected.

Short answer: Learn how calendar data, access, sessions, and integrations are protected. Begin with “Classify the calendar, participant, and free-text data in the workflow.” and verify the result through the public participant path.

Before you change the setup

Identify the exact organizer, event type, public link, and time zone involved before editing anything. Save the current behavior or take a screenshot so the test has a reliable before-and-after comparison.

How to complete this task

  1. Classify the calendar, participant, and free-text data in the workflow.Start with the intended outcome and the record that controls it.
  2. Restrict access and integration permissions to the minimum required.Review every related setting before saving so one rule does not mask another.
  3. Set secure session, transport, backup, logging, and retention controls.Keep private data and guest-facing information clearly separated.
  4. Practice reporting and responding to a scheduling-data incident.Complete the same path an external participant will use.

Verify the participant result

Run one successful case and one edge case. Confirm the public title, local time, available choices, duration, location, confirmation, calendar file, and private management path as applicable. Then check the organizer view and any email delivery record. A saved setting is not proof that the scheduling lifecycle worked.

Troubleshoot Meetin.gs security and privacy

These are the failures reported most often for this specific task, with the cause that explains each one.

What participant data does a booking hold?

Name, email address, chosen time, and any answers you requested. Free-text answers are the highest-risk field, so ask for them only when necessary.

Who can see a private booking page?

Anyone with the URL. These links are unguessable and unindexed, but they are not access-controlled — treat them as shareable secrets.

How should a scheduling incident be handled?

Decide in advance who is notified, who revokes integration access, and how affected participants are told. Practise it before you need it.

Related Meetin.gs help

Return to the Meetin.gs Help Center for the adjacent configuration guide, or send the exact event code and expected result when the documented checks do not explain the behavior.

Meetin.gs security and privacy overview acceptance checklist

Use the following evidence map while completing this specific task. It ties each action to an observable result so another person can repeat the setup or diagnose it without guessing.

1. Classify the calendar, participant, and free-text data in the workflow.

Write down the intended result, the organizer or account that owns it, and the exact event type or public link in scope. This prevents a correct change from being applied to the wrong record.

2. Restrict access and integration permissions to the minimum required.

Inspect the related rules and dependencies before saving. Record the previous value and the new value, including the time zone, provider account, or team owner when one controls the outcome.

3. Set secure session, transport, backup, logging, and retention controls.

Review what an invitee can see and what remains private. Keep only the context needed to complete the meeting task, and make the fallback understandable when information is missing.

4. Practice reporting and responding to a scheduling-data incident.

Complete this step from a signed-out participant session. Preserve the resulting URL or event code, displayed state, message, calendar output, and any provider response needed to prove the task worked.

Evidence typeWhat to record
Controlling inputThe account, event type, setting, public link, and time zone used in the test.
Participant resultThe exact choices, context, confirmation, or error visible while signed out.
Lifecycle resultWhat changes after confirmation, finalization, cancellation, reschedule, or retry.
Failure boundaryThe missing permission, unavailable dependency, invalid input, or conflicting rule that prevents success.
OwnerThe person responsible for correcting the setting, provider connection, content, or customer communication.
RELATED CAPABILITY

Administration and governance

Manage users, groups, roles, event standards, domain policy, integrations, and activity from one place. This page explains administration and governance requirements. Confirm production availability before depending on this capability.

Review scope

Meetin.gs security and privacy overview: frequently asked questions

Short answers to the questions organizers ask most about Meetin.gs security and privacy.

Is a booking page private?

It is unindexed and its URL is unguessable, but anyone holding the link can open it. Treat these links as shareable secrets rather than access-controlled pages.

What participant data does a meeting hold?

Name, email address, chosen time, and any answers you requested. Free-text answers carry the most risk, so ask for them only when they change your preparation.

How is scheduling data protected in transit?

Traffic is served over HTTPS with strict transport security, a content security policy, and same-origin framing controls. Session cookies are HTTP-only and marked secure in production.

What should an incident plan cover?

Who is notified, who revokes integration access, how affected participants are told, and what evidence is preserved. Decide it before you need it.