KanderBooks Practice OS Privacy Policy
Effective: August 22, 2026
This policy explains how KanderBooks LLC (KanderBooks, we, us, or our) collects, uses, discloses, protects, and retains information when you use KanderBooks Practice OS, its Office and Client portals, and connected services. It supplements the KanderBooks website privacy policy.
Information we collect
We collect the account, business, workspace, contact, document, message, task, appointment, invoice, time-entry, bookkeeping, support, and audit information needed to operate Practice OS. When an authorized user connects a service, we receive only the OAuth grant and data that user permits. We do not receive provider passwords.
Google Calendar and Google Meet data
Practice OS requests only the Google identity and Calendar permissions needed to connect the user’s account and manage calendar events owned by that connected user. Practice OS can create, update, or remove an appointment’s calendar event and can request a Google Meet conference link for an eligible video appointment. It does not request access to Gmail, Google Drive, or calendars the connected user does not own.
Google API Limited Use
KanderBooks’ use and transfer of information received from Google APIs complies with the Google API Services User Data Policy, including the Limited Use requirements: https://developers.google.com/terms/api-services-user-data-policy
Google user data is used only to provide or improve the user-facing scheduling and meeting features the user requested. It is not sold, used for advertising, or used to build unrelated profiles. OAuth access and refresh tokens are encrypted before storage, kept server-side, and scoped to the connected user, practice, client context, and environment. A user can disconnect Google Calendar in Practice OS; KanderBooks then attempts to revoke the Google grant and deletes the locally stored credential envelope.
When information is disclosed
We may disclose information to authorized users within the relevant organization; assigned KanderBooks personnel; infrastructure, identity, email, storage, payment, security, scheduling, and integration providers acting under service obligations; professional advisers; or authorities when required by law. Client information is not shared across unrelated client workspaces.
Retention, disconnection, and deletion
We retain information as needed to provide the service, maintain required business and audit records, resolve disputes, enforce agreements, and comply with legal, tax, accounting, and regulatory obligations. A user may disconnect a provider without deleting all business records previously synchronized into Practice OS. Requests to access, correct, export, or delete information may be subject to identity, authority, legal-retention, backup, and audit requirements.
Contact and privacy requests
Privacy, access, disconnection, and deletion requests may be sent to contact@kanderbooks.com or through https://kanderbooks.com/contact-us/. We may need to verify the requester’s identity and authority.
