DocketSync Online

Privacy Policy

Version v2-2026-09-17 · Updated September 17, 2026 · Basha Holdings LLC

This policy explains how DocketSync Online handles account information, firm-entered information, and court-calendar data. It also describes optional calendar sharing. These disclosures describe the service's existing data flows; they do not turn on an integration for you.

What we collect and why

We use contact details for sign-in, account and service messages, support, and digests you enable. We do not sell personal information, use your case list for advertising, or send it to AI services for model training.

Calendar feeds, connections, and webhooks

These features send information to destinations you select. Depending on the feature and available fields:

Anyone with a private feed link may be able to retrieve its calendar information. Keep the link confidential. People with access to a destination calendar, mailbox, webhook service, or report may be able to see the information you send there. Their access and retention also depend on that service's settings and policies.

Google and Microsoft connections access account identity and calendar metadata to find or create the destination, and create, update, or remove DocketSync events. We do not import the contents of your other calendar events into DocketSync. Practice-management connections may look up matter or case identifiers to link an event. Authorization scopes may permit broader access than these operations; the provider's consent screen shows the requested permissions.

DocketSync Online's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. We use this information to provide the connection you request, not for advertising or training general-purpose AI models. Access by people is limited to permitted purposes such as support with your consent, security, or legal obligations.

Providers and other recipients

ProviderRole
SupabaseDatabase and account sign-in.
NetlifyWebsite hosting and server functions, including reports and integrations.
CloudflareDomain services and Turnstile abuse prevention. Turnstile processes browser and network signals; see its Privacy Addendum.
StripePayments, subscriptions, and related fraud/security processing.
ResendTransactional email, including sign-in links and enabled digests.
Google Fonts, jsDelivr, cdnjsSome pages load fonts or application libraries from these services, which receive the browser requests needed to deliver those resources.
Your selected calendar or integration providerReceives information when you enable a feed, connection, or webhook, under that provider's applicable terms and your account settings.

We also operate a server for extract processing, digests, and calendar synchronization. Authorized operations access is limited to what is needed to run and support the service. Providers may have their own legal, payment, and security responsibilities. We may disclose relevant information when required by law or our data license, or to investigate misuse and protect the service.

Browser storage

The app uses browser storage for sign-in sessions and interface preferences. Hosting and anti-abuse services may process cookies or other technical signals for their functions. Clearing browser storage can sign you out or reset preferences.

Retention and deletion

We keep account and firm information while needed to provide the service, maintain history, and meet billing, security, legal, and data-license obligations. We do not currently promise a fixed automatic deletion date after cancellation.

Removing a case from your active list is a soft removal and does not erase historical records. Cancelling a subscription does not itself request deletion. Email support@opspilot.to to request access, correction, or account deletion. We verify authority, assess what can be deleted, and explain any records that must be retained. Backup copies may remain until their applicable retention cycle ends.

Downloaded, printed, emailed, or synchronized copies may remain outside DocketSync. Removing a connection schedules cleanup of DocketSync-created events and stored connection credentials; cleanup depends on processing and continued provider access and cannot recall copies others have made.

Security and incident notices

We encrypt data in transit, restrict database access by firm and role, and encrypt stored connector credentials. Attorney access is scoped to assigned cases. We use access controls and operational safeguards, but no system can promise absolute security. We provide incident notices as required by applicable law and our contractual obligations, including to account owners and other required recipients.

Your controls

Policy updates

We publish updates here and notify account owners of material changes by email or in the app. New uses requiring consent will be explained before asking for it. Previous Privacy Policy.