Privacy Policy

Effective date: 10.08.2026
Controller: Doodle AG, Werdstrasse 21, 8004 Zurich, Switzerland

This Privacy Policy explains how personal data is collected, used, and protected in connection with IRL ("IRL", "we", "us"), a scheduling application that lets two people who have just met in person book a follow-up meeting with each other in a matter of seconds. IRL is a product of Doodle AG, a company incorporated under the laws of Switzerland, with its registered office at Werdstrasse 21, 8004 Zurich, Switzerland ("Doodle"). Doodle operates, maintains, and supports the IRL application and is responsible for the processing of personal data described in this Privacy Policy. IRL is powered by Doodle and leverages Doodle’s infrastructure, security practices, and privacy governance framework. Accordingly, many of the data protection principles, safeguards, and compliance measures applicable to Doodle’s products also apply to IRL, as described in this Privacy Policy. At Doodle, we take the security of personal data and the protection of user privacy seriously. We employ dedicated security professionals who focus exclusively on technical and organizational security during operations and ongoing product development. We continually take steps to protect personal data against loss, misuse, unauthorized access, unauthorized disclosure, alteration, or destruction. As a basic principle, the Swiss Federal Data Protection Act (FADP) applies to the processing of your personal data. Depending on your location, additional laws may apply, including the EU General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA). IRL is provided as a mobile application for iOS and Android and as a web application. Certain data processing activities described in this Privacy Policy may differ between the IRL mobile application, the IRL web application, and the IRL marketing website.

Data we collect

We collect the following categories of personal data in connection with IRL:
• Account and profile data, such as your name, email address, profile photo, job title, company, and the personal booking link or handle you choose. This is the information shown to the person you are booking with.
• Booking data, such as proposed and confirmed meeting times, duration, time zone, meeting title or note, venue, and the identity of the other participant.
• Calendar availability data, meaning free and busy time information from any calendar account you choose to connect.
• Device and technical data, such as device type, operating system version, app version, language settings, app-specific device identifiers, and push notification tokens.
• Usage and diagnostic data, such as feature interaction events, crash logs, and performance data.
• Support communications, meaning the content of messages you send to us. Data collected through optional device permissions, namely calendar, camera, contacts, and location, is described in sections 5 to 8.

Log data

IRL records certain requests and transactions in log files. This log data is used for troubleshooting, statistics, analytics, quality assurance, and to monitor system security, and can be analyzed to that end. IRL can publish anonymous statistics under the condition that no personally identifiable information can be derived from such statistics. IRL also uses Google Analytics to compile usage statistics. This service is provided by Google, Inc. Their privacy policy can be found at http://www.google.com/privacy. IRL anonymizes IP addresses before they are sent to Google Analytics.

Cookies

When you use the IRL web application or marketing website, the service can store cookies on your computer or device. Cookies are small pieces of information that can help identify your browser and that can store information for future visits, for example your language preferences. IRL uses cookies to keep you signed in, to track usage, and to improve ease of use and the overall user experience. Most internet browsers automatically accept cookies. You may however configure your browser at any time in such a manner that no cookies are saved on your device, or that an indication always appears when you receive a new cookie. Where required by applicable law, non-essential cookies are set only after you have given consent through our cookie banner, and you can withdraw that consent at any time.

Calendar connection

The core function of IRL is to show genuine availability and to write a confirmed meeting to your calendar. To do this you may choose to connect a calendar account such as Google Calendar, Microsoft Outlook or Microsoft 365, or Apple Calendar. Where you connect a calendar:
• We request the narrowest scope of access needed to read your availability and to create, update, or cancel the events that IRL itself creates.
• We use calendar data solely to display your availability to the person you are booking with, to prevent double booking, and to write the meeting you confirm. Availability is surfaced as free and busy time slots. We do not disclose the titles, attendees, locations, or contents of your other calendar events to the other party.
• Access is granted through OAuth. We store access and refresh tokens in encrypted form and we never receive or store your calendar account password.
• You can disconnect a calendar at any time in IRL settings. Disconnecting revokes our access going forward and deletes the stored tokens. Meetings already written to your calendar remain in your calendar and are then governed by your calendar provider. IRL’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. In particular, we do not use Google Calendar data for advertising, we do not sell it, we do not transfer it to third parties except as necessary to provide or improve the feature you requested, to comply with applicable law, or as part of a merger or acquisition, and we do not allow humans to read this data unless we have your affirmative consent, it is necessary for security purposes, it is required to comply with applicable law, or the data is aggregated and anonymized.

Camera and QR code scanning

IRL allows two people to start a booking by scanning a QR code displayed on the other person’s device or badge. Where you grant camera permission:
• The camera is active only while the scanning screen is open, and only for the purpose of detecting and decoding a QR code.
• We do not store, transmit, or retain the camera image or video feed. Only the decoded value of the QR code, which identifies the IRL profile or booking link being scanned, is processed.
• You can decline camera permission and still use IRL by sharing or entering a booking link manually

Contacts

Where you grant access to your device address book, IRL uses it to help you identify the person you are meeting and to prefill their name and contact details on a booking.
• Contact data is accessed only where you have granted permission, and is used only for the purpose stated above.
• Matching is performed on your device wherever technically possible. Contact details are transmitted to our servers only for the specific contact you select for a booking.
• We do not upload your address book for marketing purposes, we do not use your contacts to build advertising profiles, and we do not contact the people in your address book on our own initiative.
• You can revoke contacts permission at any time in your device settings, and IRL remains usable without it.

Location data

IRL may use location data to record where a meeting was arranged or is to take place, for example the trade show, conference, or office where you met, and to suggest a nearby meeting place.
• Location is collected only where you have granted permission.
• Location is associated with the specific booking and it is not used for advertising.
• You can decline or revoke location permission at any time and enter a venue manually

Data relating to the person you book with

IRL is used by two parties. When a meeting is booked through IRL, limited personal data relating to the other participant is processed, such as their name, email address, and the meeting details. Where you supply another person’s details to IRL, you are responsible for ensuring that you have a legitimate basis for sharing them with us. We process those details to create and administer the booking, to send the invitation, confirmation, and any reminders, and to write the meeting to the relevant calendars. Where a person receives an IRL booking without holding an IRL account, we process their data only to complete and administer that meeting and to comply with legal obligations. We do not use their data for marketing purposes without a separate legal basis.

Notifications and transactional messages

We send messages that are necessary to operate the service, such as booking requests, confirmations, changes, cancellations, and reminders. These are transactional messages and form part of the service rather than marketing. Push notifications can be disabled at any time in your device settings. Where we send marketing communications, we do so on the basis of your consent or another applicable legal basis, and every such message includes a mechanism to unsubscribe.

Inactive accounts

IRL can delete user accounts if they remain inactive, meaning not accessed, for 1 year or longer. You may delete your IRL account at any time through the application. Upon deletion, your account data will be removed from active systems, subject to applicable legal retention obligations and backup retention policies.

Unauthorized access

IRL implements several mechanisms to prevent unauthorized access to accounts or other data. User accounts are protected by a password or by sign-in through a third-party identity provider. Where you use a password, you should choose a secure one and ensure its confidentiality in order to prevent unauthorized access to your account. Personal data is encrypted in transit and at rest, and access by our personnel is restricted to what is necessary to operate and support the service.

Communication between you and IRL

If you send IRL a message, this message can be stored in order to process it, to compile statistical information, to improve our services and support, or to get in touch with you.

User surveys and market research

We use the data you provide exclusively to improve the user experience and to further develop our products. The results consist solely of aggregated and anonymous data. If you have given your consent, you may also be contacted by affiliated companies of the Doodle group, for example to participate in other user surveys.

Payment processing

IRL is provided free of charge at launch for app users. We do not collect or process payment card details, billing addresses, or other payment data in connection with IRL, and no in-app purchases are offered. If paid features are introduced, we will update this Privacy Policy before those features become available and will disclose the payment processing arrangements at that time. Where payments are processed by an app store provider such as the Apple App Store or Google Play, or by Doodle’s own billing provider, those parties process payment data in accordance with their own privacy policies, and Doodle would receive only limited information such as confirmation of purchase, subscription status, and a unique transaction or account identifier.

App store data disclosures

The following reflects the disclosures we make in the Apple App Store Privacy questionnaire and the Google Play Data safety form. User-entered data Information you enter into the app, such as bookings, meeting notes, venue labels, and participant details, is stored both locally on your device and on IRL’s secure servers. Local storage allows the app to function when offline. Server storage enables your data to sync across devices when you are signed in. This data is associated with your account and is not sold or shared with third parties except as described in this Privacy Policy. Data linked to you The app may collect the following data that can be linked to you:
• Contact information, such as name, email address, profile photo, job title, and company.
• Identifiers, such as account identifiers, app-specific device identifiers, and push notification tokens.
• Calendar free and busy data associated with your account, where you have connected a calendar.
• Contact details of the specific person you select for a booking, where you have granted contacts permission.
• Approximate location associated with a booking, where you have granted location permission.
• User content, such as meeting notes and venue labels. Data not linked to you The app may collect the following data that is not linked to your identity:
• Usage data, in aggregated and anonymized form.
• Diagnostics, such as crash logs and performance data. Purpose of data use Collected data is used solely for the following purposes: • Providing and maintaining app functionality.
• Analytics and performance improvement.
• Security, fraud prevention, and abuse prevention. We do not use your data for third-party advertising and we do not sell your personal data.

Transfer of personal data abroad

We are entitled to transfer your personal data abroad, including to third party companies (designated service providers), insofar as this is expedient for the data processing described in this Privacy Policy. The recipients will be obliged to protect your data to the same extent as ourselves. If the level of data protection in a particular country is lower than that applicable in Switzerland, we will ensure under contract that the level of protection for your personal data is equivalent to that applicable in Switzerland. We shall ensure this through one or more of the following measures:
• By concluding EU Model Clauses with the appointed service providers.
• Through the appointed service providers having in place Binding Corporate Rules (BCR) that are recognised by a European data protection authority.
• Data Privacy Framework (DPF). For transfers to certified organizations in the United States, we rely on the EU-U.S. Data Privacy Framework and the Swiss-U.S. Data Privacy Framework, as applicable.
• Standard Contractual Clauses (SCCs). We utilize the Standard Contractual Clauses approved by the European Commission and adapted for Swiss law, following a comprehensive Transfer Impact Assessment (TIA) to ensure the recipient can comply with these standards.

Sharing personal information

IRL uses personal information according to the Terms of Service and this Privacy Policy. IRL may share personal information with other companies or individuals only in the following limited circumstances: (i) IRL has your consent; (ii) IRL has good faith that there is a legal obligation to share the data; (iii) IRL needs to access or share the data to protect the security of the service or of other users’ data; (iv) IRL needs to access or share the data to protect IRL’s rights and property or to enforce the Terms of Service. In addition, we engage service providers who process personal data on our behalf and under our instructions, for example for cloud hosting, error monitoring, analytics, and customer support. These providers are bound by contract to process personal data only for the purposes we specify and to apply appropriate safeguards. Where you choose to use IRL together with another Doodle product, or where your organization administers your IRL account under a Doodle enterprise agreement, personal data may be shared between IRL and that Doodle product or administrator to the extent necessary to provide the combined service. Such sharing takes place within Doodle as the same controller, or, where your organization is the controller, under the terms of that agreement.

Data retention

We shall only retain your data for as long as is legally necessary or in accordance with the purpose for which they were processed. If we carry out analyses, we shall store your data until the analysis has been concluded. If we store your data on the basis of a contractual relationship with you, these data will remain stored for at least the duration of the contractual relationship and at most for the duration of the limitation periods within which any claims may be brought by or against us, or for the duration of statutory or contractual duties of retention.

Legal basis

We shall only process your personal data in accordance with the principles of data protection and where there is a legal basis to do so. Depending on the processing activity, we rely on the following legal bases:
• Performance of a contract, where processing is necessary to create your account, show availability, and create, change, or cancel the meetings you book.
• Your consent, for optional device permissions such as calendar, camera, contacts, and location, for non-essential cookies, for marketing communications, and for participation in user surveys. You can withdraw consent at any time, which does not affect the lawfulness of processing carried out before withdrawal.
• Our legitimate interests, in operating a secure service, preventing fraud and abuse, and continuously improving and further developing our products. We act on the presumption that these interests are predominant, and you may object to processing on this basis.
• Compliance with a legal obligation, where retention or disclosure is required by applicable law.

Right of erasure

In accordance with applicable European legislation you can delete your account and the bookings you own from the system in the account section of the application. It is however possible that another user invites you to a meeting again in the future. If you do not want this either, we can block your email address.

Your rights

You have the right to exercise your data protection rights at any time and to request information as to whether and which personal data relating to you has been processed by us. You may also arrange for your personal data to be corrected, blocked, or cancelled at any time in writing, enclosing appropriate proof of your identity, by email. We reserve the right to exchange correspondence with you in this regard. Please note that we may be required to retain your personal data in part even after a request for blocking or cancellation under the terms of our statutory or contractual retention requirements, such as for accounting purposes, and in such an eventuality will only block your personal data insofar as necessary for this purpose. In addition, the cancellation of your personal data may have the effect that you are no longer able to acquire or use the services registered by you. Under certain circumstances, you have the right to require us to provide you or a third party specified by you with your personal data in a commonly used format. In addition, you have the right to make a complaint concerning the data processing in question with the competent supervisory authority. You can do this with the supervisory authority at your place of residence, at your place of work, or at the place of the alleged data breach.

Additional information for California residents

If you are a California resident, the California Consumer Privacy Act, as amended, gives you specific rights regarding your personal information. The categories of personal information we collect are described in section 2 and section 16, the purposes for collection are described throughout this Privacy Policy, and the categories of recipients are described in section 19. We do not sell your personal information and we do not share it for cross-context behavioral advertising. We do not use or disclose sensitive personal information for purposes other than those permitted under applicable law. Subject to verification, you have the right to know what personal information we have collected about you, the right to request deletion or correction of that information, the right to opt out of any sale or sharing, and the right not to receive discriminatory treatment for exercising these rights. You may exercise these rights through the contact details in section 26, and you may use an authorized agent to submit a request on your behalf.

Children

IRL is a professional networking and scheduling tool and is not directed to children. We do not knowingly collect personal data from children under the age of 16. If we become aware that we have collected personal data from a child under that age without the required consent, we will delete it.

Contact person

If you have questions regarding data protection, need information, or want your data to be deleted, please contact our data protection office via email at privacy@doodle.com. The contact details for our Data Protection Officer are as follows: TUV Informationstechnik GmbH TUV NORD Group IT Security, Business Security & Privacy Am TUV 1 45307 Essen Germany Email: privacyguard@tuvit.de

Changes

IRL reserves the right to update this Privacy Policy at any time. The most current version of this policy is available at irl.doodle.com/privacy.