FlowConsent
ServicesBlogExtensionSolutionsPricingTry FlowConsent
FlowConsent

FlowConsent is a GDPR-compliant cookie consent management platform.

Product

  • Services
  • Extension
  • Extension support
  • Solutions
  • Pricing
  • FlowConsent App

Legal

  • Privacy Policy
  • Terms of Service
  • Legal notice

© 2026 FlowConsent by BeBranded. All rights reserved.

FrancaisDeutschEspanol

Does your website use third-party services? Get GDPR compliant in minutes.

Try FlowConsent
  1. Home
  2. Services
  3. Other
  4. TidyCal
T

TidyCal

Preferences

Related services

AccuWeather

AccuWeather is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. AccuWeather supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, AccuWeather ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Other
A

Acuity Scheduling

Acuity Scheduling is a user preference and personalization service that helps websites deliver customized experiences based on individual visitor settings and choices. It manages preferences for content display, communication channels, and interaction styles. Acuity Scheduling integrates with website platforms to remember and apply user choices consistently across sessions. With privacy-compliant preference storage, Acuity Scheduling enhances satisfaction by ensuring tailored browsing experiences for every visitor.

Preferences

Affirm

Affirm is a versatile web technology that supports digital platforms with specialized functionality and enhanced capabilities. It provides robust tools and services that integrate with modern websites and applications seamlessly. Affirm is designed to improve operational efficiency, user experience, and digital performance. Trusted by developers and businesses alike, Affirm offers reliable solutions that scale with organizational needs and evolving web standards.

Other

Algolia

Algolia is a versatile web technology that supports digital platforms with specialized functionality and enhanced capabilities. It provides robust tools and services that integrate with modern websites and applications seamlessly. Algolia is designed to improve operational efficiency, user experience, and digital performance. Trusted by developers and businesses alike, Algolia offers reliable solutions that scale with organizational needs and evolving web standards.

Other
A

AppDynamics

AppDynamics is an analytics and measurement platform providing deep insights into digital ecosystem performance. It tracks user interactions, measures campaign effectiveness, and identifies optimization opportunities across web and mobile. AppDynamics offers customizable dashboards, automated alerts, and data export capabilities. By transforming raw data into actionable intelligence, AppDynamics empowers organizations to optimize strategy and maximize return on investment.

Analytics
A

Apple App Store

Apple App Store is a comprehensive e-commerce platform that provides businesses with all the tools needed to build, manage, and grow an online store. From product catalog management and secure payment processing to inventory tracking and order fulfillment, Apple App Store delivers a complete commerce solution. It features responsive storefront themes, SEO-optimized product pages, and powerful marketing tools to help merchants increase visibility and drive sales across channels.

Other
Get compliant — Try FlowConsent free

Free plan · 10-min setup

What does TidyCal do?

TidyCal is a user preference and personalization service that helps websites deliver customized experiences based on individual visitor settings and choices. It manages preferences for content display, communication channels, and interaction styles. TidyCal integrates with website platforms to remember and apply user choices consistently across sessions. With privacy-compliant preference storage, TidyCal enhances satisfaction by ensuring tailored browsing experiences for every visitor.

What is TidyCal

TidyCal is a scheduling and appointment booking tool operated by AppSumo, an American software publisher. Site owners embed a TidyCal calendar on their site so visitors can pick a time slot and book a meeting. The integration loads JavaScript, fonts and an iframe from tidycal.com, which means the visitor browser contacts AppSumo servers in the United States as soon as the calendar appears.

Data and cookies collected

By loading the TidyCal embed, the user shares technical metadata with AppSumo: IP address, user agent, referrer, time zone and pages where the calendar appears. If a booking is completed, TidyCal also processes name, email address, the meeting subject, custom answers and the timestamp of the appointment. TidyCal sets first party cookies on tidycal.com for session and analytics, and the booking confirmation email can include tracking pixels.

GDPR and ePrivacy implications

The TidyCal embed reads and writes information on the visitor terminal and triggers a cross border data transfer, which engages both article 5(3) of the ePrivacy Directive and chapter V of the GDPR. The integration is therefore not strictly necessary and must be loaded behind a consent gate. Loading it by default would be sanctioned by EU data protection authorities, including the CNIL.

Get GDPR compliant in 10 minutes

Free plan available · No credit card required

Try FlowConsent free

Consent and legal basis

The legal basis for displaying the calendar and dropping cookies is article 6(1)(a) GDPR (consent). Once the user actually books, the processing of their name, email and meeting topic relies on article 6(1)(b) GDPR (performance of the meeting contract). The cookie banner should mention TidyCal by name in a marketing or functional category and let users keep using the site without booking.

Data transfers

Because AppSumo is based in the United States, TidyCal usage involves a transfer of personal data to a third country. AppSumo relies on the EU US Data Privacy Framework and Standard Contractual Clauses with supplementary measures. Operators should keep the relevant DPA and transfer documentation on file and include the transfer in the cookie policy and the record of processing activities.

Practical compliance steps

Sign the AppSumo data processing addendum, gate the TidyCal embed behind your CMP, replace the default embed with a click to load placeholder, and offer at least one alternative booking channel (form or email). Document the integration, the cookies, the US transfer and the legal basis in the record of processing and update the cookie policy accordingly.

GDPR consent category

Preferences

Websites using TidyCal must obtain user consent under GDPR regulations.

Legal basisArticle 6(1)(a) GDPR for loading the embed and setting non essential cookies; article 6(1)(b) GDPR for the booking itself once the user confirms the appointment.
Risk levelmedium
Applicable regulationsGDPR, ePrivacy Directive 2002/58/EC, Schrems II case law and EU US Data Privacy Framework

DPIA considerations

A DPIA is usually not required for embedding TidyCal on a marketing site, but is recommended when the calendar is used to schedule medical, legal or financial appointments, or when the volume of booker data is significant.

Sample consent text

Our booking calendar is provided by TidyCal (AppSumo, United States). Loading the calendar will share your IP address and booking data with TidyCal. You can accept the integration in our cookie banner or contact us by email instead.

Technical details

Tracking methodembedded booking iframe and JavaScript widget loaded from tidycal.com, with first-party booking cookies and analytics cookies on the embedded page
Server locationUnited States (AppSumo / TidyCal infrastructure)
Data transferred outside the EUTidyCal is operated by AppSumo from the United States. Personal data of bookers is transferred to the US and processed under EU US Data Privacy Framework and/or Standard Contractual Clauses.

Third-party domains contacted

tidycal.comappsumo.comasset.tidycal.com

Cookies placed

NameTypeDurationPurpose
tidycal_sessionfirst-partysessionSession cookie set in the TidyCal iframe to keep the booking state and authenticate the user during the booking flow.
XSRF-TOKENfirst-partysessionCross site request forgery token used by TidyCal to validate booking form submissions.
_appsumo_sessionfirst-party2 weeksSession cookie of the AppSumo platform that hosts TidyCal, used for authentication and feature flags.

TidyCal uses cookies for user preferences — inform visitors with a consent banner.

Get started freeScan your site

Frequently asked questions

Which cookies does TidyCal set?

When the calendar is loaded on tidycal.com (in the iframe), TidyCal sets first party session cookies for authentication, CSRF protection and feature flags, plus analytics cookies tied to the AppSumo platform. On the embedding site itself, no TidyCal cookie is dropped until the visitor opens the iframe, so a click to load placeholder gives strong control.

Is consent required to embed TidyCal?

Yes. Loading the TidyCal embed triggers a request to AppSumo in the United States, sets cookies in the iframe and transfers technical metadata. This is not strictly necessary, so article 5(3) of the ePrivacy Directive and article 6(1)(a) GDPR require prior consent from the visitor before the embed loads.

What is the legal basis for processing data through TidyCal?

Loading the calendar relies on consent (article 6(1)(a) GDPR). Once a booking is confirmed, the processing of the bookers name, email, meeting topic and answers shifts to article 6(1)(b) GDPR (performance of the appointment contract). Optional analytics and marketing emails sent by TidyCal still require consent.

Does TidyCal transfer data to the United States?

Yes. TidyCal is operated by AppSumo from the United States, so personal data is transferred to a third country. AppSumo relies on the EU US Data Privacy Framework and Standard Contractual Clauses. Operators should sign the AppSumo DPA, keep the transfer documentation and inform users in the privacy policy.

Do I need a DPIA before using TidyCal?

A DPIA is not generally required for a standard booking calendar embedded on a marketing site. It becomes relevant if TidyCal is used to schedule sensitive appointments (medical, psychological, legal, financial) or if a large volume of bookers is processed, especially with profiling or marketing follow ups.

How do I implement TidyCal in a GDPR compliant way?

Replace the default embed with a click to load placeholder behind your CMP, sign the AppSumo DPA, mention TidyCal in the privacy notice and cookie policy with the US transfer mechanism, and offer an alternative booking channel by email or form. Map cookies, retention periods and data flows in the record of processing.

Are there privacy friendly alternatives to TidyCal?

EU based or self hosted alternatives include Cal.com (open source), SimplyBook.me, Calendso self hosted, Easy!Appointments and Crew Meet. Compared to TidyCal these options keep data inside the EEA or on the operator infrastructure and avoid systematic US transfers.

How should I update the cookie policy for TidyCal?

List the TidyCal embed as a functional or marketing integration, mention that the iframe sets first party cookies on tidycal.com, name AppSumo as the data processor, indicate the US transfer with the DPF and SCC mechanism, and link to the AppSumo and TidyCal privacy notices and to your CMP preference centre.