# Cal.com privacy rating

Hosted scheduling platform for booking pages, team round-robin, routing forms and workflows, with calendar and video conferencing integrations.

**Our pick.** Booking pages, team round-robin, routing forms and workflows with calendar and video integrations, in a hosted service. The MIT-licensed Cal.diy edition covers self-hosting on your own server.

## Summary

Cal.com scores 38 out of 100 (grade F) on the scheduling criteria. It meets 3 of 8 criteria: no ads or data sales, TLS configuration and security headers. It partly meets independent audit. It does not meet open source, no trackers or telemetry, transparency report and tells users about requests. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade A+.

- Website: https://cal.com
- Jurisdiction: United States. Five Eyes member. Subject to the US CLOUD Act.
- Platforms: Web
- Home page trackers: Google Fonts (not scored), Google Tag Manager, PostHog, Trustpilot (not scored), X (Twitter) Pixel
- Category: [Scheduling](https://privacyratings.com/scheduling/)
- Also rated: [Cal.ai](https://privacyratings.com/scheduling/cal-ai/) (Scheduling)
- Grade: F (38/100)

## Criteria

| Criterion | Answer | Note | Evidence |
| --- | --- | --- | --- |
| Open source | No | Closed source. The production code moved to a private repository, and only the self-hosted community fork Cal.diy remains MIT-licensed. | https://cal.com/blog/cal-com-goes-closed-source-why |
| No trackers or telemetry | No | The marketing site runs analytics and ad measurement, loading Google Tag Manager, PostHog, Facebook and LinkedIn scripts. | https://cal.com/privacy |
| No ads or data sales | Yes | Funded by paid plans. The privacy policy states personal data is never sold and booking data is not used for advertising profiles. | https://cal.com/privacy |
| Independent audit | Partial | SOC 2 Type II and annual third-party penetration test reports exist, but are only available to signed-in users. | https://cal.com/security |
| Transparency report | No | No transparency report or government request policy is published. |  |
| Tells users about requests | No | No published policy on notifying users about data requests. |  |
| TLS configuration | Yes | Grade A+ | https://www.ssllabs.com/ssltest/analyze.html?d=app.cal.com&hideResults=on |
| Security headers | Yes | Grade A+ (125/100+) | https://developer.mozilla.org/en-US/observatory/analyze?host=app.cal.com |
| Modern web standards | Not tested yet | Not tested yet. |  |

Source: https://privacyratings.com/scheduling/cal-com/
Edit: https://github.com/privacyratings/privacyratings.com/edit/main/ratings/scheduling/cal-com.md
