Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The policy states that Calendly uses session replay and session recording tools provided by third-party service providers to record user interactions with its website, including mouse movements and webform engagement.
This analysis describes what Calendly's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision discloses that detailed behavioral interaction data, including webform engagement, is captured and potentially shared with third-party service providers operating session recording tools. Depending on jurisdiction, session recording of webform interactions may implicate wiretapping or electronic communications statutes, and the adequacy of the cookie consent mechanism as a legal basis for this collection warrants review.
Interpretive note: The legal basis for session recording under GDPR and state wiretapping statutes depends on jurisdiction-specific requirements and the adequacy of the cookie consent mechanism as notice and consent for this specific collection, which the document does not fully specify.
Under this clause, Calendly authorizes third-party service providers to collect detailed records of how users navigate its website and interact with webforms, including through session replay tools. The policy states this data is used to improve the website and services and to identify technical issues.
Cross-platform context
See how other platforms handle Session Recording and Replay Tool Use and similar clauses.
Compare across platforms →Monitoring
Calendly has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"We may also disclose information to Service Providers for certain web tracking purposes, including allowing Service Providers to directly collect information using Cookies and related tracking technologies (such as pixels and web beacons). For example, we use session replay, session recording and similar tools provided by Service Providers to record your interactions with our Website, such as how you move throughout our Website and engage with our webforms.Excerpt from Calendly's Privacy Notice
1. REGULATORY LANDSCAPE: Session recording tools that capture user interactions, including keystrokes and form inputs, may implicate the California Invasion of Privacy Act (CIPA), the Electronic Communications Privacy Act (ECPA), and analogous state wiretapping statutes in Pennsylvania, Illinois, and other states requiring all-party consent for electronic communication interception. The FTC Act may also apply if session recording is not adequately disclosed. GDPR Article 6 requires a lawful basis for processing; the notice asserts consent or legitimate interests as applicable bases. 2. GOVERNANCE EXPOSURE: Medium. The use of session replay tools is increasingly scrutinized by state attorneys general and plaintiff litigants under CIPA and similar statutes, particularly where form inputs including sensitive data fields are recorded. The adequacy of the cookie consent banner as notice and consent for this specific data collection is a reviewable question, particularly for California and Pennsylvania residents. 3. JURISDICTION FLAGS: California residents have heightened exposure under CIPA, which has been the basis for class action litigation challenging session recording practices. Pennsylvania and Illinois also have all-party consent requirements for electronic communications that may be relevant. EEA and UK residents require a valid GDPR lawful basis for behavioral tracking data collection. 4. CONTRACT AND VENDOR IMPLICATIONS: The sub-processor list should be reviewed to identify which session recording vendors receive this data. Procurement teams should confirm that data processing agreements with session recording providers limit use to analytics and service improvement, consistent with the notice's stated purpose restriction. The notice states that service providers are not authorized to use or disclose Personal Data except in connection with providing their services. 5. COMPLIANCE CONSIDERATIONS: Legal teams should assess whether the cookie consent mechanism provides adequate notice and consent for session recording specifically, including whether users who reject optional cookies are excluded from session recording. Data minimization practices for session recording tools, including whether sensitive form fields are masked, should be reviewed. State-specific consent requirements for electronic communications interception should be assessed against current session recording deployments.
This provision discloses that detailed behavioral interaction data, including webform engagement, is captured and potentially shared with third-party service providers operating session recording tools. Depending on jurisdiction, session recording of webform interactions may implicate wiretapping or electronic communications statutes, and the adequacy of the cookie consent mechanism as a legal basis for this collection warrants review.
Under this clause, Calendly authorizes third-party service providers to collect detailed records of how users navigate its website and interact with webforms, including through session replay tools. The policy states this data is used to improve the website and services and to identify technical issues.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Calendly.