Effective and last updated August 6, 2026
What the connection does
An authorized rescue owner or administrator can connect Google Calendar from Paware's Scheduling page. Paware then creates and keeps current the future helper commitments managed in Paware, so the rescue can see them in the chosen Google account's primary calendar.
Synchronization is outbound. Paware does not import, analyze, or show the account's existing Google Calendar events. Each event Paware creates carries a private Paware reference so an interrupted sync can retry without creating duplicates.
Permissions requested
Basic account identity
OpenID and email access identify which Google account was connected and show that email to the rescue administrator.
Manage events on calendars you own
The Google Calendar permission allows Paware to create, update, and delete Paware-managed events in the connected account's primary calendar. Paware does not request access to the account's full list of subscribed calendars.
These permissions are requested only after an authorized Paware user chooses “Connect Google Calendar.” Google displays the requested access before the user approves it.
Data used and stored
Paware uses the connection for:
- The connected Google account's email address.
- The primary-calendar identifier and display label.
- OAuth access and refresh tokens needed to synchronize while the connection remains active.
- Paware shift name, helper name, location, start and end time, time zone, and private synchronization references for each event Paware creates.
- Google event identifiers, links, and version markers returned after Paware creates or updates its own events.
Tokens are encrypted in a server-side vault. They are never placed in browser storage, sent to a public rescue website, or exposed to a rescue's ordinary team members.
Your control
- A rescue owner or administrator decides whether to connect Google Calendar and chooses the Google account during Google's consent flow.
- The connected account and calendar are visible on Paware's Scheduling page.
- An owner or administrator can disconnect there at any time. Disconnecting stops future synchronization and deletes Paware's stored Google credentials.
- Events already written to Google Calendar remain in the user's calendar and can be removed there. The user can also revoke Paware from their Google Account connections.
Security and Google API Limited Use
Paware uses OAuth 2.0 authorization-code flow with PKCE, short-lived secure state cookies, server-only client credentials, encrypted token storage, organization-level permissions, and auditable connection changes. Provider tokens are used only by Paware's server-side synchronization worker.
Paware's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is not sold, used for advertising, or used to train general-purpose AI or machine-learning models.
Additional details are in the Paware Privacy Policy and Terms of Service.
Support
For connection help, privacy questions, or a Google-data deletion request, email alex@kafure.com. Include the rescue name and the connected Google email, but never send a password, authorization code, or access token.