#1 always store passwords encrypted
#2 UTC in DB, convert to TZ in UI
#3 store recurring events only once with recurring meta-information and deal with it in the query implementation and business logic (do NOT use separate table with crons and from time-to-time expansion - that's leads to technical debt)