Privacy Policy

Last updated: 15 July 2026

TL;DR

Our home page (naboro.io) uses no analytics or tracking cookies. If you create an account, we ask for the bare minimum and share it only with services that are strictly necessary for the app to function. We never sell your data or use it for advertising.

At Naboro, we are committed to complying with GDPR and other privacy regulations. All data is encrypted in transit, and connected calendar credentials are additionally encrypted at rest.

We retain your personal information for the length of time needed to fulfill the purposes outlined in this privacy policy unless a longer retention period is required or permitted by law. You may request for your data to be deleted by contacting us at hello@naboro.io.

Your account

You can sign in with a one-time link sent to your email address, or with a Google or Microsoft account. With email sign-in we store just your email address. With Google or Microsoft we receive your basic profile: name, email address and profile photo. Your name and photo are shown in the app to other members of the buildings you belong to, and we use your email address to send the messages described below. We keep this profile data for the life of your account and never pass it to anyone else. You can revoke Naboro's access at any time in your Google or Microsoft account's security settings, and you can ask us to delete your account and everything associated with it (see "Your rights and contact").

A session cookie keeps you signed in between visits. For security, each session records the IP address and browser it was created from, and expires automatically. The sign-in form is protected by Cloudflare Turnstile, which processes technical browser data to tell people from bots — see the Cloudflare Privacy Policy for details.

Bookings and who can see them

Naboro is a shared booking system for buildings with multiple tenant companies. Bookings you create — title, description, time and room — are stored in our database and visible in full to members of your own company. Other companies in your building see only that the room is busy, together with the organizer's name and company — never the meeting title or details. Building managers can see the schedules of the rooms they manage and an audit log of booking and calendar sync activity in their building.

A room's door display, when enabled, shows that room's schedule (meeting titles and organizer names, never email addresses) to people at the room. The display is accessed through a secret link that the building can revoke at any time.

Calendar sync (optional)

A company may connect its Google, Microsoft 365 or CalDAV calendar account so bookings flow both ways between Naboro and the calendar. We request the minimum access needed: reading the list of calendars and reading and writing calendar events. Connection credentials (OAuth tokens or CalDAV passwords) are stored encrypted at rest, with the encryption key kept outside the database.

For a connected calendar we process and store event details — title, description, start and end time, recurrence, and attendee names, email addresses and response status — to show availability and keep the calendar and Naboro in sync. Calendar and meeting names also appear in the building's audit log. You can disconnect a calendar at any time. Disconnecting stops the sync and deletes the stored credentials along with the events imported from that calendar.

Calendar data is used solely to provide the booking and sync features described in this policy. We work with it in raw form only and do not build aggregated or anonymized data sets from it, do not sell it, do not use it for advertising, and do not use it to train AI models. Naboro's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Calendar data travels over encrypted connections and is stored with the hosting providers listed under "Where your data lives", which process it on our behalf. Within the app it is visible only to the people described under "Bookings and who can see them". We do not transfer it to any other party, and no person reads it except with your permission, for security purposes, or where required by law.

Emails we send

We send sign-in links and notifications, for example when someone else changes or removes your meeting. Emails are delivered through MailPace, a third-party email provider, and contain no open or link tracking. See the MailPace Privacy Policy for details.

Where your data lives

Naboro runs on Clever Cloud servers located in Paris, France. Database backups and application logs are stored on servers hosted by Contabo GmbH in Germany. See the Clever Cloud Privacy Policy and the Contabo Privacy Policy for details.

Payments

If you subscribe to a Naboro paid plan, billing information and the payment process are handled by Paddle, a third-party payment provider. We never see or store your card details. See the Paddle Privacy Policy for details.

Your rights and contact

If you have an account with Naboro you can request a copy of all information collected about you, ask us to correct it, or request removal of all information. Reach us at hello@naboro.io with any questions about this policy.


Naboro is a service operated by ROOMBELT Mateusz Zieliński · Gdańsk, Poland. See also our Terms and Conditions.