Privacy policy

Last updated 2026-10-09

This policy covers the Small Rows website, the Hourly Sheets Google Sheets add-on (not released yet), the Earnings by Small Rows add-on (not released yet; see its own section) and the Freelance Billing Kit by Small Rows, a spreadsheet file you download (see Purchases). They are operated by Small Rows, Alberta, Canada ("we", "us"). Day-to-day operations, including support replies, are carried out by an AI assistant acting for the owner (see About).

The short version

Data Hourly Sheets handles

DataWhere it goesWhy
Your Toggl API tokenSaved in Google Apps Script user properties under your Google account. Sent only to api.track.toggl.com. Toggl's remaining hourly request allowance (numbers only) is saved there too.To read your time entries on your behalf, and to pace syncs within Toggl's limits.
Time entries, projects, clients, tags, user names from TogglFetched from Toggl by Google's Apps Script servers and written into your spreadsheet. Project/client/tag names (and Toggl project rates) are cached in Google's Apps Script cache for up to 6 hours.To build your Toggl Entries, Billable Summary and Invoice tabs.
Add-on settings and sync progress Your settings (workspace, date range, rounding, what counts as billable, default rate and currency, invoice client, tax label and rate, and the name you enter for the invoice), sync progress, a summary of the last sync (its dates, entry count and billable client names) and the auto-refresh choice are saved in the spreadsheet's Apps Script document properties. Other people who use the add-on in the same spreadsheet can see these. They never contain your token. Client and project rates you type in go in the Rates tab.To remember your choices and resume or update a sync.
License keySaved in your Apps Script user properties and checked with Polar's license API (api.polar.sh) when you add it and then about once a day. When license activation is switched on (planned for launch), a random install ID is also saved there and sent with the key, together with the add-on's name and version, as the activation label.To unlock paid features. The install ID is random and contains no personal information.
Sample data (only if you click “Try with sample data”)Made-up entries generated inside the add-on and written to tabs named “Sample – …” in your spreadsheet. Nothing is sent to Toggl or anyone else, and no token or setting is saved. “Remove sample tabs” deletes them.So you can see what the add-on makes before connecting an account.
Error logsGoogle Cloud logging for the add-on's project may record error messages, and a one-line status for each scheduled sync (the same summary the sidebar shows, such as the number of entries and the date range). We avoid logging tokens or entry contents.To fix bugs.

The add-on doesn't read other files in your Google Drive, your email or your contacts.

Earnings by Small Rows (not released yet)

Earnings by Small Rows copies your sales from Gumroad, Polar and Lemon Squeezy (and Ko-fi or Payhip CSV files you paste in) into your spreadsheet. It isn't available to install yet. This section describes how the current version is built, and we'll update it if that changes before release.

DataWhere it goesWhy
Your Gumroad, Polar and Lemon Squeezy API tokensSaved in Google Apps Script user properties under your Google account, so other people using the same spreadsheet can't read them. Each token is sent only to its own service (api.gumroad.com, api.polar.sh, api.lemonsqueezy.com). The sidebar only ever shows the last 4 characters. To read your sales on your behalf. The add-on only makes read (GET) requests to these services.
Orders, products, refunds, payouts, fees, tax and buyer countryFetched by Google's Apps Script servers and written into tabs in your spreadsheet (Sales, Monthly Summary, Tax Collected, Payouts). While a long sync is in progress, rows are kept in a hidden tab called “Earnings sync (temp)”, which is deleted when the sync finishes.To build your sales tabs.
Buyer email addressesOff by default. When off, emails are removed before anything is saved, so they're never written to your spreadsheet, not even to the hidden tab. If you turn them on (a Pro option) they go in the Sales tab's Customer email column. If you turn them off again, that column and any partly finished sync are wiped straight away. Only if you want them, for example to contact your own customers.
Ko-fi and Payhip import tabsWhatever you import into a tab for Ko-fi or Payhip (by default “Ko-fi import” and “Payhip import”) stays there. The add-on reads that tab but never changes or deletes it, so remove columns you don't want (such as buyer emails) before pasting.To include those sales.
Settings, sync progress and which dates each source coversSaved in the spreadsheet's Apps Script document properties. Other people who use the add-on in the same spreadsheet can see these. They never contain tokens.To remember your choices and resume or update a sync.
License keySaved in your Apps Script user properties and checked with Polar's license API (api.polar.sh) when you add it and then about once a day. When license activation is switched on (planned for launch), a random install ID (no personal information) is also saved there and sent with it, together with the add-on's name and version.To unlock Pro features.
Sample data (only if you click “Try with sample data”)Made-up orders generated inside the add-on, with no buyer emails, written to tabs named “Sample – …” in your spreadsheet. No request goes to any platform, and no token or setting is saved. “Remove sample tabs” deletes them.So you can see every tab before connecting a platform.
Error logsGoogle Cloud logging for the add-on's project may record unexpected error messages, and a one-line status for each scheduled sync (the same summary the sidebar shows: row counts and any errors). Tokens are never logged.To fix bugs.

Google permissions (OAuth scopes)

Both add-ons ask for the same four permissions:

Google API Services User Data Policy

Hourly Sheets's and Earnings by Small Rows's use and transfer of information received from Google APIs follows the Google API Services User Data Policy, including the Limited Use requirements. Data from your spreadsheet is used only to provide the add-on's features to you. It is not transferred to anyone else, used for advertising, or read by humans, except with your explicit permission (for example, if you share a screenshot with support), for security purposes, or where the law requires it.

Purchases

Payments are processed by Polar (polar.sh), which acts as merchant of record and handles sales tax. Polar's privacy policy applies to the checkout: polar.sh/legal/privacy. We receive your name, email, country, order and subscription status and license key, and use them to provide the service, handle support, refunds and accounting, and meet legal obligations.

The Freelance Billing Kit by Small Rows is sold through Polar in the same way. Polar gives you a personal download link for the file. We receive the same purchase details, except that there's no subscription or license key. The workbook contains only formulas (no macros, scripts or connections to outside data), so using it sends nothing to us or anyone else.

The website

The website is a static site hosted on Cloudflare Pages. Cloudflare may process standard request data, such as IP addresses, to serve and protect the site (Cloudflare's privacy policy). We use no cookies, no analytics and no ad trackers. If we ever add privacy-friendly, cookie-free analytics, this page will say so first.

The tax set-aside calculator, the hourly rate calculator, the tax instalment checker, the invoice generator, the quote and estimate generator, the expense and receipt log, the mileage logbook and the late-payment interest calculator run entirely in your browser. Nothing you type in them is sent to us or anyone else, or saved.

Support emails

When you email us, we keep the conversation to help you and improve the product. Replies are written by an AI assistant, which processes your message for that purpose. Please never send an API token or license key in full.

Retention and deletion

Your rights

We handle personal information in line with Canada's Personal Information Protection and Electronic Documents Act (PIPEDA). Depending on where you live (for example the EU/UK under GDPR, or California), you may have extra rights such as access, correction, deletion, portability and objection. Contact us to use them. You can also complain to your local data protection authority, or in Canada to the Office of the Privacy Commissioner.

Children

The service is meant for businesses and professionals and isn't directed at children under 16.

Changes

If this policy changes, we'll update the date above. For significant changes we'll also post in the build log.

Contact

Small Rows, Alberta, Canada. Email: smallrows@gmail.com