Privacy Policy
Effective 28 July 2026
Qalam Hub is an internal operations tool for Qalam staff. This page explains what information it holds, why, and what the Google Calendar integration can and cannot see.
1.Who this covers
Qalam Hub (“the Hub”) is operated by Qalam, 4200 International Pkwy, Carrollton, TX 75007, and is available at hub.qalamone.com.
Qalam's organisation-wide privacy policy also applies, and governs where the two differ. This page adds the detail specific to the Hub.
The Hub is staff-only and invite-gated. It is not a public service and not intended for students, families, or vendors. Access comes either from an invitation issued by a Qalam administrator, or automatically from an existing Qalam Seminary or Qalam Facility staff account. Seminary students and external Facility vendors are explicitly excluded.
2.What the Hub stores
| What | Why |
|---|---|
| Your name and email address | Identifying you, signing you in, and showing who created or is assigned to work. Shared with the Qalam Seminary and Facility apps, which use the same sign-in. |
| Team membership and role | Deciding what you can see and do. A Hub role is separate from your role in the Seminary or Facility apps. |
| Work you create | Events and programs, tickets and their form answers, tasks and subtasks, projects, comments, and progress. |
| Files you attach | Stored in Cloudflare R2 object storage. Anyone who can view the item they are attached to can open them. |
| Activity records | Status changes, approvals, and an audit log of who changed what, so a request is never untraceable. |
| Notification records | Delivering in-app and email notifications through the shared Qalam processor service. |
The Hub does not collect payment information, and it does not run advertising or third-party analytics trackers. Qalam does not sell your information and does not share it for advertising.
3.Sign-in and shared identity
One person has one Qalam account across the Hub, Seminary, and Facility apps. Signing in uses a one-time email code, a password, or Microsoft single sign-on. Having an account does not by itself grant Hub access — that is a separate permission.
When you open a linked Seminary or Facility portal from the Hub, a short-lived single-use sign-in link is created so you are not asked to log in twice. It is valid once and expires quickly.
4.Google Calendar integration
Connecting Google Calendar is entirely optional. If you never connect it, none of this applies to you.
When you do connect it, the Hub requests these Google permissions:
- calendar.events.readonly — read the events on your calendars, so your own meetings can be displayed to you inside My Calendar. Read-only: the Hub cannot create, change, or delete anything on your own calendars.
- calendar.calendarlist.readonly — see the list of calendars you are subscribed to.
- calendar.app.created — used only if you switch on the optional “push Qalam events into Google” setting. It allows writing only to a calendar the Hub itself created, never to any calendar you already had.
Your own events are never stored. They are read from Google each time you open the calendar, shown to you, and discarded. They are never written into Qalam's database, never added to team or org-wide calendars, and never visible to anyone but you. Your personal appointments stay personal.
The Hub does store, to keep the connection working: a Google refresh token encrypted at rest, a short-lived access token, the permissions you granted, and your Google account address.
Optional outbound push. Off by default. If you switch it on, the Hub creates a secondary calendar named Qalam One in your account and copies your Qalam events into it — and then also stores a mapping between Qalam events and their copies. If you edit one of those copies in Google, the change may be applied back to the Qalam event when your role permits it. Switching it off stops the syncing and leaves the calendar in place for you to keep or delete.
The Hub has no access to your email, your contacts, your files, or your colleagues' calendars.
Limited use. Data obtained through Google APIs is used only to provide and improve this calendar sync. It is not sold, not transferred to others except as needed to provide the feature or where required by law, not used for advertising, and not used to train generalised artificial-intelligence or machine-learning models. Qalam's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
You can disconnect at any time from the calendar page in the Hub. Disconnecting revokes the Hub's access at Google and deletes the stored tokens and event mapping. The Qalam One calendar and the events already in it remain in your Google account — delete it there if you do not want them.
5.Calendar subscription links
The Hub can also give you a read-only calendar feed to subscribe to from Google, Apple, or Outlook. That link contains a signed token and anyone who has it can read that calendar without signing in — treat it as a password. It stops working if your Hub access is removed.
6.How long it is kept
Operational records — events, tickets, tasks, projects and their history — are retained for as long as Qalam needs them for reporting and continuity. Completed cycles of recurring programs are archived rather than deleted, so Qalam can see how work ran over time.
Notification records are pruned on a routine schedule. Google tokens are deleted as soon as you disconnect. When your Hub access is removed, your account is disabled and your name remains attached to work you did, so the record of who did what stays intact.
7.Your choices
- Connect or disconnect Google Calendar whenever you like.
- Ask an administrator what teams and permissions you hold.
- Ask for a copy of the personal information held about you, or ask for it to be corrected.
- Ask for your account to be closed. Some work records are kept for operational and audit reasons, as described above.
8.Security
Access is gated by role and team on every request, not only hidden in the interface. Google refresh tokens are encrypted at rest. Traffic is served over HTTPS. No system is perfectly secure, so please report anything that looks wrong to the address below rather than testing it further.
9.Changes
If this page changes materially, the effective date above changes with it and staff are notified in the Hub.
10.Contact
Questions about this page, or a request to access or delete your data: [email protected]. For technical issues: [email protected].