Privacy Policy
Effective date: September 1, 2026
This policy explains how American Legion Post 241 uses information through the Post 241 Calendar Admin application. The application helps specifically authorized Post administrators review Google Calendar events and choose which events appear on the Post 241 website.
Information we access
- Google identity: your verified Google account email address, used to confirm that you are on the administrator allowlist.
- Google Calendar read-only data: calendars available to the authorized account, including each calendar identifier, calendar name, primary calendar status, and access role. These fields let the administrator identify and select a readable calendar. For events in the selected calendar, the application accesses the event identifier, title, start and end times, all-day status, and cancellation status.
- Authorization credentials: an encrypted refresh token used to synchronize after consent. Short-lived access tokens are used to call Google and are not intentionally written to application logs.
- Administrative session information: security state, CSRF protection values, authentication time, and recent activity needed to protect the admin portal.
The application requests Google identity and Google Calendar read-only access. It does not request Gmail, Drive, Docs, Sheets, Contacts, or Calendar write access. It does not request or store event descriptions, locations, attendee lists, or Google event URLs.
How we use the information
We use Google user data only to authenticate authorized administrators, list calendars they can access, import upcoming calendar events, preserve publication-review choices, and maintain the public event listing. The application does not create, modify, or delete events in Google Calendar.
What becomes public
Calendar data is private by default. An authorized administrator must approve an event before it appears publicly unless the administrator explicitly selects a dedicated calendar whose complete contents are intended for automatic publication. The public website receives only an approved event's title, start time, optional end time, and all-day status. It does not expose Google event IDs, calendar IDs, descriptions, locations, attendee lists, administrative metadata, or OAuth credentials.
Website analytics
The public website uses Umami Cloud for cookie-free, aggregate website analytics to understand overall visit counts, the public pages viewed, broad traffic sources, and broad device categories. The analytics loader runs only on alpost241.org; it does not run on the Post 241 admin portal, CT160 Demo, or local development sites.
We do not use analytics cookies, advertising pixels, cross-site tracking, custom visitor identifiers, session recordings, heatmaps, or individual visitor profiles. Analytics does not create individual visitor profiles and is used only to understand and improve the public website.
Sharing and sale
We do not sell Google user data. We do not use it for advertising, surveillance, credit decisions, or training general-purpose artificial intelligence models. Approved event details are published only to provide the public event-listing feature described above. Hosting infrastructure may process or store data solely as needed to operate and secure the application. We do not otherwise share Google user data with third parties except when required by law or necessary to protect the application and its users.
Storage and security
OAuth configuration, encrypted refresh tokens, private calendar records, sessions, and lock files are stored outside the public website directory. Refresh tokens are encrypted at rest. Administrative access requires an allowlisted verified Google identity, secure sessions, CSRF protection, and HTTPS. No internet service can be guaranteed completely secure, but access is limited to the purpose and administrators described in this policy.
Retention and deletion
Authorization credentials and imported calendar data are retained while the integration remains active or as needed to preserve event review decisions and operate the public listing. Expired and cancelled events are excluded from the public feed. Authorized users may request that Post 241 Delete their stored OAuth authorization and associated private calendar data by emailing alpost241@gmail.com. Operational backups may retain deleted information for a limited period until routine rotation.
Revoke Google access
Signing out of the Post 241 portal ends the browser session but does not revoke Google authorization. To Revoke access, visit Google Account third-party connections, select the Post 241 application, and remove its access. You may also contact alpost241@gmail.com for assistance.
Google API Services User Data Policy
Post 241 Calendar Admin's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Changes and contact
We may update this policy when the application or its data practices change. The effective date above will be revised when material changes are published. Questions or privacy requests may be sent to alpost241@gmail.com or mailed to American Legion Post 241, 7605 Bluffton Rd, Fort Wayne, IN 46809.
This application is intended only for authorized Post 241 administrators. Public visitors do not need a Google account and do not authorize Google Calendar access.
