Privacy Policy
Last updated: 2026-09-04
Who we are
mcdesk (mcdesk.id) is an operational tool for professional Masters of Ceremonies. Questions about this policy: hello@mcdesk.id.
Account data
When you create an account we store your email address and a hashed password (never plaintext). Optional profile fields include stage name, phone, and bank payout details used on invoices you generate.
Google Sign-In
If you sign in or link Google, we request scopes openid, email, and profile. Identity records are stored on user_identities and used only to authenticate or link your account.
Google Calendar sync
Calendar sync is a separate, optional consent. It uses the calendar.events scope. Access and refresh tokens are encrypted at rest. Sync is a one-way push of gig metadata you already saved in mcdesk to your Google Calendar.
Sessions and cookies
We use an HTTP-only session cookie to keep you signed in, a CSRF cookie for form protection, and short-lived OAuth state cookies during Google connect flows.
Why we process data
We process this information to provide the product: client CRM, schedule, invoices, and optional Calendar sync.
Sharing
We do not sell personal data. Processors are limited to hosting and database providers, and Google when you choose to use Google as an identity provider or Calendar sync.
Retention and deletion
We keep account data while your account exists. For MVP there is no self-serve account deletion; email hello@mcdesk.id to request deletion.
Disconnect
You can disconnect Google identity (when a password is set) and Calendar sync from Settings in the product.
Changes
We may update this policy. The “Last updated” date at the top of this page reflects the latest revision.