Privacy Policy
Am I Free privacy policy - how we collect, use, and protect your personal information
1. Introduction
Welcome to Am I Free a software service developed and provided by SHFT SDK (Pty) Ltd.
SHFT is a company incorporated in the Republic of South Africa (Registration No. 2023/746465/07), with our principal office in Cape Town, South Africa.
Your privacy matters to us. That is why Am I Free was built on a privacy-first principle: we do not permanently store the details of your calendar events. Instead, we securely transfer your data in real time between your connected calendars (Google, Microsoft Outlook, Apple iCloud). We also never sell, analyze, or monetize your calendar data.
This Privacy Policy explains: What information we collect when you use Am I Free; How we use and protect that information; Your rights and choices regarding your data.
We have written this Policy to be clear and accessible, but it is still a legal agreement between you and SHFT. By creating an account or using Am I Free, you confirm that you have read and understood this Privacy Policy and agree to its terms. If you do not agree, you must stop using the Service.
For any questions about this Privacy Policy or how we handle your information, you may contact us at support@amifree.co.
2. Information We Collect
When you use the Am I Free service (“Service”), SHFT may collect the following categories of information:
2.1 Account Information:
When you create an account, we collect personal details such as your name, email address, authentication credentials, and related identifiers necessary to establish and maintain your account.
2.2 Calendar Connection Data:
To provide the Service, we collect authorization tokens and metadata that enable secure connections to third-party calendar providers (e.g., Google, Microsoft Outlook, Apple iCloud). We do not collect or store your passwords.
2.3 Calendar Event Data:
In the course of providing synchronization services, we may temporarily access event information (such as event title, time, date, recurrence, and metadata) strictly for the purpose of completing the sync. Event contents are not permanently stored in our systems and are deleted once synchronization is completed.
2.4 Payment Information:
If you subscribe to a paid plan, payment card details, billing addresses, and related information are processed securely by our third-party payment processor (currently Stripe). We do not retain your full payment card details.
2.5 Device and Usage Information:
We may collect technical and usage information, including Internet Protocol (IP) address, device type, operating system, browser information, error logs, and performance data. This information is collected for security, troubleshooting, and Service improvement purposes.
2.6 Communications:
If you contact us directly (for example, through support requests, emails, or feedback forms), we collect the information you choose to provide, including the content of your communications and any attachments.
2.7 Cookies and Similar Technologies:
We use cookies, web beacons, and similar technologies to authenticate sessions, maintain security, and improve the functionality of the Service. Further details are set out in Section 5 (Cookies & Tracking Technologies).
3. How We Use Your Information
SHFT processes personal information only for lawful and legitimate purposes. The ways in which we use your information, described in Section 2, include the following:
3.1 To Provide and Operate the Service:
We use your Account Information, Calendar Connection Data, and Calendar Event Data to enable synchronization between your connected calendars, maintain your account, and deliver the features of the Service. Legal basis (GDPR/POPIA): Processing is necessary for the performance of a contract with you.
3.2
We use technical and usage information (including logs, device identifiers, and access tokens) to authenticate sessions, detect unauthorized access, prevent abuse, and protect the integrity of our systems. Legal basis (GDPR/POPIA): Processing is necessary for our legitimate interests in ensuring the security and proper functioning of the Service, and to comply with applicable legal obligations.
3.3 To Communicate With You:
We may use your contact details to: Send administrative and transactional messages (e.g., account confirmations, subscription notices, billing updates, service alerts); Provide customer support and respond to enquiries; Where permitted, send product updates, feature announcements, or newsletters that relate to the Service. You may opt out of non-essential communications at any time. Legal basis (GDPR/POPIA): Processing is necessary for the performance of a contract and for our legitimate interests in maintaining customer relationships; in some cases, your consent may be required.
3.4 To Process Payments:
We use payment and billing information to process subscription fees, manage invoices, and comply with financial record-keeping requirements. Legal basis (GDPR/POPIA): Processing is necessary for the performance of a contract and to comply with legal obligations.
3.5 To Improve and develop the Service:
We may use aggregated and anonymized usage information, error logs, and feedback to analyze performance, identify trends, fix issues, and develop new features. Individual calendar event content is not permanently stored or used for these purposes. Legal basis (GDPR/POPIA): Processing is necessary for our legitimate interests in improving and expanding the Service.
3.6 To Comply With Legal Requirements:
We may process and, where required, disclose information to comply with applicable laws, lawful requests, and regulatory obligations, including tax, accounting, and data protection requirements. Legal basis (GDPR/POPIA): Processing is necessary to comply with a legal obligation imposed on us.
3.7 Other Lawful Purposes:
We may also process your personal information for other purposes that are compatible with those set out above, provided such processing is permitted under applicable data protection laws.
4. How We Share Information
SHFT does not sell, rent, or monetize your personal information or calendar event data.
We only share information in the limited circumstances described below:
4.1 Service Providers and Sub-Processors:
We may share your personal information with trusted third-party service providers who perform services on our behalf, such as: Cloud hosting and infrastructure providers; Payment processors; Customer support and communication tools; Security and analytics providers. These service providers may only access and process your personal information to the extent necessary to perform their contractual obligations to us and are bound by confidentiality and data protection commitments.
4.2 Legal Compliance and Protection of Rights:
We may disclose personal information where required to do so by law, regulation, or legal process, or to protect our rights, safety, or property, and that of our users or others.
4.3 Business Transfers:
If SHFT is involved in a merger, acquisition, restructuring, sale of assets, or other corporate transaction, your personal information may be transferred to the successor entity as part of that transaction. In such cases, this Privacy Policy will continue to apply unless amended by the successor entity.
4.4 With Your Consent:
We may share your information with third parties when you give us your explicit consent to do so.
5. Data Storage & Security
5.1 No Permanent Storage of Event Data:
Am I Free is designed on a privacy-first principle. We do not permanently store the contents of your calendar events. Event information is temporarily processed only as necessary to complete synchronization and is automatically deleted once the sync has been executed.
5.2 Retention of Other Personal Information:
Account Information: Retained for as long as your account remains active and for a limited period thereafter where required by law or legitimate business needs (e.g., dispute resolution, enforcement of our agreements); Payment and Billing Information: Retained as required under applicable financial, tax, and accounting laws; Logs and Usage Data: Retained for up to three (3) months, unless a longer retention period is required for security, compliance, or legitimate business purposes.
5.3 Security Measures:
We implement appropriate technical and organizational measures to protect personal information against unauthorized access, alteration, disclosure, or destruction, including but not limited to: Encryption of data in transit and at rest; Secure OAuth2 authentication for calendar connections (no passwords are stored); Role-based access controls(RBAC) and restricted employee access; Firewalls, intrusion detection, and monitoring of suspicious activity; Regular security reviews, audits, and vendor due diligence.
5.4 Data Location:
Personal information may be processed and stored on secure cloud infrastructure operated by reputable third-party providers. These providers are subject to contractual obligations requiring compliance with applicable data protection standards.
5.5 Shared Responsibility:
While we take appropriate steps to protect your data, you remain responsible for safeguarding access to your accounts and verifying the accuracy of your calendar information.
6. Cookies & Tracking Technologies
We use cookies and similar technologies solely for purposes that are necessary to provide and secure the Service.
6.1 Use of cookies may include:
- Authentication and Session Management: To recognize you when you sign in and maintain your session;
- Security: To detect fraudulent activity and protect user accounts;
- Performance and Functionality: To monitor Service stability, error rates, and usage patterns for troubleshooting and improvement.
6.2 No Targeted Advertising:
We do not use cookies or similar technologies for targeted advertising, profiling, or the sale of personal information.
6.3 Control of Cookies:
Most web browsers automatically accept cookies, but you can usually modify your browser settings to decline cookies or alert you when cookies are being placed. If you choose to disable cookies, some features of the Service may not function properly.
6.4 Other Tracking Technologies:
We may use web beacons, log files, and similar tools in connection with cookies for limited technical and analytical purposes, as described above. These technologies do not collect calendar event contents.
7. Your Privacy Rights
Depending on where you live, you may have certain rights regarding your personal information under applicable data protection laws. SHFT respects and facilitates the exercise of these rights as described below.
7.1 European Union / United Kingdom (GDPR / UK GDPR):
If you are located in the European Economic Area (EEA) or the United Kingdom, you have the following rights under the General Data Protection Regulation (GDPR) and UK GDPR: Access: Request confirmation of whether we process your personal data and obtain a copy; Correction: Request that inaccurate or incomplete personal data be corrected; Erasure (“Right to be Forgotten”): Request deletion of your personal data where legal grounds permit; Restriction: Request limitation of how your personal data is processed; Portability: Receive your personal data in a structured, commonly used, machine-readable format and transmit it to another controller; Objection: Object to processing of your personal data where our lawful basis is legitimate interests or for direct marketing; Consent Withdrawal: Withdraw consent at any time where processing is based on consent, without affecting the lawfulness of processing before withdrawal. You also have the right to lodge a complaint with your local data protection authority.
7.2 South Africa (POPIA):
If you are located in South Africa, the Protection of Personal Information Act, 2013 (“POPIA”) grants you the following rights: Access: Request confirmation that we hold personal information about you and obtain a copy; Correction / Deletion: Request correction or deletion of personal information that is inaccurate, irrelevant, excessive, out of date, incomplete, misleading, or unlawfully obtained; Objection: Object to the processing of your personal information on reasonable grounds relating to your particular situation; Direct Marketing: Object to the processing of personal information for purposes of direct marketing; Complaints: Lodge a complaint with the Information Regulator (South Africa) if you believe your rights under POPIA have been infringed.
7.3 California and Certain U.S. States (CCPA / CPRA and Similar Laws):
If you are a resident of California, or other U.S. states with comparable privacy laws, you may have rights including: Access: Request disclosure of the categories and specific pieces of personal information we have collected about you; Deletion: Request deletion of personal information, subject to applicable exceptions; Correction: Request correction of inaccurate personal information; Opt-Out of Sale/Sharing: Request that we do not “sell” or “share” your personal information, as defined by law. (We do not sell or share personal information.); Non-Discrimination: Exercise your rights without receiving discriminatory treatment.
7.4 Exercising Your Rights:
To exercise any of the rights described above, please contact us at support@amifree.co. We may need to verify your identity before fulfilling your request. We will respond within the timeframes required under applicable law.
8. International Data Transfers
8.1 General Principle:
As SHFT is established in South Africa, your personal information may be transferred to and processed in countries outside of your country of residence. These countries may have data protection laws that are different from those in your jurisdiction and may not provide the same level of protection.
8.2 Safeguards for Transfers from the EEA, UK, and Switzerland:
Where we transfer personal data from the European Economic Area (EEA), the United Kingdom (UK), or Switzerland to a country that has not been recognized as providing an adequate level of protection by the relevant authority (such as the European Commission, UK Information Commissioner’s Office, or Swiss Federal Data Protection and Information Commissioner), we rely on lawful transfer mechanisms, including: Standard Contractual Clauses (SCCs) adopted by the European Commission (Decision 2021/914/EU), supplemented by the UK International Data Transfer Addendum where applicable; Swiss Addendum to the SCCs where required for transfers subject to Swiss data protection law; Data Privacy Framework participation or other recognized transfer frameworks, where applicable.
8.3 South African Users:
Where personal information is transferred outside of South Africa, such transfers are conducted in compliance with the Protection of Personal Information Act, 2013 (POPIA), which requires that the recipient jurisdiction or recipient entity provides an adequate level of protection or that appropriate contractual safeguards are in place.
8.4 Other Jurisdictions:
For users in other regions, we implement appropriate technical, contractual, and organizational safeguards consistent with applicable law to ensure that personal information remains protected when transferred internationally.
9. Children's Privacy
9.1 No Use by Minors:
The Service is not directed to, and may not be used by, individuals under the age of eighteen (18). We do not knowingly collect personal information from anyone under 18 years of age.
9.2 Parental or Guardian Responsibility:
By using the Service, you represent that you are at least 18 years old or that you are the parent or legal guardian of a minor who is at least 16 years old and that you consent to such minor’s use of the Service. If you are a parent or guardian and believe your child has provided us with personal information in violation of this Policy, you should contact us immediately at support@amifree.co so that we can take steps to delete such information.
9.3 Legal Compliance:
If we become aware that we have inadvertently collected personal information from a person under 18 without appropriate consent, we will promptly delete such information in accordance with applicable laws, including GDPR, POPIA, and relevant U.S. state laws.
10. Changes to This Policy
10.1
We may update or amend this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or other factors.
10.2
If we make material changes, we will provide you with reasonable notice, such as by email, through the Service, or by updating the “Last Updated” date at the top of this Policy.
10.3
Your continued use of the Service after the effective date of any revised Privacy Policy constitutes your acceptance of its terms. If you do not agree with the updated Policy, you must discontinue use of the Service.
11. Contact Us
If you have any questions, concerns, or complaints regarding this Privacy Policy or the way we handle your personal information, you may contact us at:
11.1 Am I Free Support:
Email: support@amifree.co
11.2 SHFT SDK (Pty) Ltd:
Email: support@shft.tech | Website: www.shft.tech
11.3
We will respond to all legitimate requests within the timeframes required under applicable data protection laws, including GDPR and POPIA.