Privacy at Meeting Room 365
Privacy isn't a feature tier or a marketing checkbox. It's a design constraint that shapes every decision we make, from the services we use to the data we choose not to collect.
These aren't aspirational.
They're how we build and operate today: three constraints we hold ourselves to on every release.
Collect Less
The best way to protect data is to not have it. We store room configurations and admin email addresses. Calendar data is fetched in real-time and never persisted on our servers. No behavior tracking, no shadow profiles.
Fewer Third Parties
Every external service is a potential data leak. We're actively reducing third-party dependencies, not adding them, and we have removed Google Analytics, Hotjar, and retargeting pixels for self-hosted and EU-hosted alternatives.
Your Controls, Not Ours
All data sharing and internal analytics from room displays can be toggled off in the admin portal. Diagnostic data is used for troubleshooting and nothing else. We don't make privacy decisions for you; we give you the switches.
What a company chooses not to do says more.
More than what it claims to. Here's the list we hold ourselves to, in plain language.
Data Sales
We never sell, share, or provide your data to advertisers or data brokers. Not anonymized, not aggregated, not in any form.
Tracking Pixels
No tracking pixels in the emails we send. We don't track whether you opened a message, when, or on what device.
Endless Email
We send a handful of emails a year, not one a week. No upsell campaigns, no re-engagement drips, no feature spam.
Retargeting
No retargeting campaigns. We removed Facebook Pixel and Google Ads tracking, so our site doesn't follow you around the web.
Fingerprinting
No canvas or device fingerprinting, and no technique designed to identify you beyond a standard session.
Dark Patterns
No guilt trips when you cancel. No hidden unsubscribe, no 14-step cancellation flow. Leaving is as simple as arriving.
AI Training
Your calendar data, room configs, and account info are never used to train machine-learning models or AI systems.
Shadow Profiles
If you haven't signed up, we don't have a profile on you. We don't scrape, infer, or collect data about non-customers.
Most companies announce what they add.
We think it's more important to show what we've taken away.
| Service removed | What it did | Why we removed it |
|---|---|---|
| Google Analytics | Website analytics | Replaced with EU-hosted PostHog. No data sent to Google. |
| Hotjar | Session recordings, heatmaps | Unnecessary surveillance of user behavior. Removed entirely. |
| Headway | Changelog widget | Third-party script on every page. Replaced with an internal solution. |
| Cookiebot | Cookie consent management | Fewer tracking cookies means less need for a consent manager. |
| Facebook Pixel | Ad conversion tracking | We don't run retargeting campaigns. |
| Bing UET | Ad conversion tracking | Same reason. Removed all ad-tracking scripts. |
| External ClickHouse | User analytics hosting | Moved to internal infrastructure. Data stays in-house. |
| Sentry (most usage) | Error tracking | Reduced to minimal usage. Moving toward internal error logging. |
| Non-EU Storage | Backups, databases, object storage | Moved entirely to the EU region. |
The mechanics, in the open.
Exactly how authentication, deletion, monitoring and cookies work, in detail.
Authentication
Most customers authenticate via OAuth 2.0 through Microsoft or Google: SSO by default, no separate password. For password-based EWS deployments, auth is handled by Google Firebase. We never store passwords ourselves.
Deletion Is Real
When you delete your account, your data is actually deleted, not soft-deleted and not archived. Configuration data is removed, and calendar data was never stored in the first place.
Internal Monitoring
We're moving log aggregation, error tracking, and monitoring to internal infrastructure, so your data doesn't pass through unnecessary third-party services.
Diagnostic Data Is Optional
Displays can share status like online/offline and occupancy for troubleshooting. Every data-sharing feature has a toggle in the admin portal. Turn it off and we collect nothing.
Cookies
We set only the cookies necessary for authentication and session management. No third-party tracking or advertising cookies.
Warrant Canary
As of this page's last update, Meeting Room 365 has never received a government request for customer data, a national security letter, or a gag order.
Privacy isn't an upsell.
The protections many vendors reserve for enterprise plans are how we operate for everyone.
SSO Included
Single sign-on through Microsoft or Google is included for all customers. We don't charge extra for the security feature your IT team requires.
Public Pricing
Our pricing is on the website. No sales calls, no "contact us for enterprise pricing." Evaluate and purchase without talking to anyone.
Easy Cancellation
Cancel from the admin portal. No retention calls, no reconsider emails, no countdown timers. Your subscription, your choice.