mcdesk

Privacy Policy

Last updated: 2026-09-04

Who we are

mcdesk (mcdesk.id) is an operational tool for professional Masters of Ceremonies. Questions about this policy: hello@mcdesk.id.

Account data

When you create an account we store your email address and a hashed password (never plaintext). Optional profile fields include stage name, phone, and bank payout details used on invoices you generate.

Google Sign-In

If you sign in or link Google, we request scopes openid, email, and profile. Identity records are stored on user_identities and used only to authenticate or link your account.

Google Calendar sync

Calendar sync is a separate, optional consent. It uses the calendar.events scope. Access and refresh tokens are encrypted at rest. Sync is a one-way push of gig metadata you already saved in mcdesk to your Google Calendar.

Sessions and cookies

We use an HTTP-only session cookie to keep you signed in, a CSRF cookie for form protection, and short-lived OAuth state cookies during Google connect flows.

Why we process data

We process this information to provide the product: client CRM, schedule, invoices, and optional Calendar sync.

Sharing

We do not sell personal data. Processors are limited to hosting and database providers, and Google when you choose to use Google as an identity provider or Calendar sync.

Retention and deletion

We keep account data while your account exists. For MVP there is no self-serve account deletion; email hello@mcdesk.id to request deletion.

Disconnect

You can disconnect Google identity (when a password is set) and Calendar sync from Settings in the product.

Changes

We may update this policy. The “Last updated” date at the top of this page reflects the latest revision.

← Back to home