Privacy policy
Last updated 2026-10-09
This policy covers the Small Rows website, the Hourly Sheets Google Sheets add-on (not released yet), the Earnings by Small Rows add-on (not released yet; see its own section) and the Freelance Billing Kit by Small Rows, a spreadsheet file you download (see Purchases). They are operated by Small Rows, Alberta, Canada ("we", "us"). Day-to-day operations, including support replies, are carried out by an AI assistant acting for the owner (see About).
The short version
- We don't run servers that receive or store your time-tracking or sales data. Our add-ons run in Google Apps Script under your Google account and write data only into the spreadsheet you use them in.
- Your Toggl, Gumroad, Polar or Lemon Squeezy API token is stored in your own Apps Script user properties and is sent only to the service it belongs to.
- Earnings leaves your buyers' email addresses out unless you turn them on.
- No analytics or tracking in the add-ons or on this website.
- If you buy a plan or the kit, our payment provider Polar processes the payment. We get your license, order and contact details from Polar, never your full card number.
- We don't sell personal data and we don't use it for advertising.
Data Hourly Sheets handles
| Data | Where it goes | Why |
|---|---|---|
| Your Toggl API token | Saved in Google Apps Script user properties under your Google account. Sent only to api.track.toggl.com.
Toggl's remaining hourly request allowance (numbers only) is saved there too. | To read your time entries on your behalf, and to pace syncs within Toggl's limits. |
| Time entries, projects, clients, tags, user names from Toggl | Fetched from Toggl by Google's Apps Script servers and written into your spreadsheet. Project/client/tag names (and Toggl project rates) are cached in Google's Apps Script cache for up to 6 hours. | To build your Toggl Entries, Billable Summary and Invoice tabs. |
| Add-on settings and sync progress | Your settings (workspace, date range, rounding, what counts as billable, default rate and currency, invoice client, tax label and rate, and the name you enter for the invoice), sync progress, a summary of the last sync (its dates, entry count and billable client names) and the auto-refresh choice are saved in the spreadsheet's Apps Script document properties. Other people who use the add-on in the same spreadsheet can see these. They never contain your token. Client and project rates you type in go in the Rates tab. | To remember your choices and resume or update a sync. |
| License key | Saved in your Apps Script user properties and checked with Polar's license API (api.polar.sh) when you add it and then about once a day.
When license activation is switched on (planned for launch), a random install ID is also saved there and sent with the key, together with the add-on's name and version, as the activation label. | To unlock paid features. The install ID is random and contains no personal information. |
| Sample data (only if you click “Try with sample data”) | Made-up entries generated inside the add-on and written to tabs named “Sample – …” in your spreadsheet. Nothing is sent to Toggl or anyone else, and no token or setting is saved. “Remove sample tabs” deletes them. | So you can see what the add-on makes before connecting an account. |
| Error logs | Google Cloud logging for the add-on's project may record error messages, and a one-line status for each scheduled sync (the same summary the sidebar shows, such as the number of entries and the date range). We avoid logging tokens or entry contents. | To fix bugs. |
The add-on doesn't read other files in your Google Drive, your email or your contacts.
Earnings by Small Rows (not released yet)
Earnings by Small Rows copies your sales from Gumroad, Polar and Lemon Squeezy (and Ko-fi or Payhip CSV files you paste in) into your spreadsheet. It isn't available to install yet. This section describes how the current version is built, and we'll update it if that changes before release.
| Data | Where it goes | Why |
|---|---|---|
| Your Gumroad, Polar and Lemon Squeezy API tokens | Saved in Google Apps Script user properties under your Google account, so other people using the same spreadsheet can't read them.
Each token is sent only to its own service (api.gumroad.com, api.polar.sh, api.lemonsqueezy.com). The sidebar only ever shows the last 4 characters. |
To read your sales on your behalf. The add-on only makes read (GET) requests to these services. |
| Orders, products, refunds, payouts, fees, tax and buyer country | Fetched by Google's Apps Script servers and written into tabs in your spreadsheet (Sales, Monthly Summary, Tax Collected, Payouts). While a long sync is in progress, rows are kept in a hidden tab called “Earnings sync (temp)”, which is deleted when the sync finishes. | To build your sales tabs. |
| Buyer email addresses | Off by default. When off, emails are removed before anything is saved, so they're never written to your spreadsheet, not even to the hidden tab. If you turn them on (a Pro option) they go in the Sales tab's Customer email column. If you turn them off again, that column and any partly finished sync are wiped straight away. | Only if you want them, for example to contact your own customers. |
| Ko-fi and Payhip import tabs | Whatever you import into a tab for Ko-fi or Payhip (by default “Ko-fi import” and “Payhip import”) stays there. The add-on reads that tab but never changes or deletes it, so remove columns you don't want (such as buyer emails) before pasting. | To include those sales. |
| Settings, sync progress and which dates each source covers | Saved in the spreadsheet's Apps Script document properties. Other people who use the add-on in the same spreadsheet can see these. They never contain tokens. | To remember your choices and resume or update a sync. |
| License key | Saved in your Apps Script user properties and checked with Polar's license API (api.polar.sh) when you add it and then about once a day. When license activation is switched on (planned for launch), a random install ID (no personal information) is also saved there and sent with it, together with the add-on's name and version. | To unlock Pro features. |
| Sample data (only if you click “Try with sample data”) | Made-up orders generated inside the add-on, with no buyer emails, written to tabs named “Sample – …” in your spreadsheet. No request goes to any platform, and no token or setting is saved. “Remove sample tabs” deletes them. | So you can see every tab before connecting a platform. |
| Error logs | Google Cloud logging for the add-on's project may record unexpected error messages, and a one-line status for each scheduled sync (the same summary the sidebar shows: row counts and any errors). Tokens are never logged. | To fix bugs. |
- Anyone you share the spreadsheet with can see its tabs, including any buyer emails you chose to include.
- It uses the same four Google permissions listed below, and its manifest only allows web requests to the Gumroad, Polar and Lemon Squeezy APIs.
- It has no analytics and no servers of ours. It doesn't read other files in your Google Drive, your email or your contacts.
- Disconnecting a platform in the sidebar deletes its stored token (its rows leave the Sales tab at the next sync). For Gumroad you can also revoke the token in Gumroad's settings. Deleting the tabs deletes the synced data.
Google permissions (OAuth scopes)
Both add-ons ask for the same four permissions:
spreadsheets.currentonly: read and write only the spreadsheet the add-on is used in.script.container.ui: show the sidebar and the Help dialog.script.external_request: call the Toggl Track API (Hourly Sheets), the Gumroad, Polar and Lemon Squeezy APIs (Earnings), and Polar's license API.script.scriptapp: create the optional auto-refresh schedule.
Google API Services User Data Policy
Hourly Sheets's and Earnings by Small Rows's use and transfer of information received from Google APIs follows the Google API Services User Data Policy, including the Limited Use requirements. Data from your spreadsheet is used only to provide the add-on's features to you. It is not transferred to anyone else, used for advertising, or read by humans, except with your explicit permission (for example, if you share a screenshot with support), for security purposes, or where the law requires it.
Purchases
Payments are processed by Polar (polar.sh), which acts as merchant of record and handles sales tax. Polar's privacy policy applies to the checkout: polar.sh/legal/privacy. We receive your name, email, country, order and subscription status and license key, and use them to provide the service, handle support, refunds and accounting, and meet legal obligations.
The Freelance Billing Kit by Small Rows is sold through Polar in the same way. Polar gives you a personal download link for the file. We receive the same purchase details, except that there's no subscription or license key. The workbook contains only formulas (no macros, scripts or connections to outside data), so using it sends nothing to us or anyone else.
The website
The website is a static site hosted on Cloudflare Pages. Cloudflare may process standard request data, such as IP addresses, to serve and protect the site (Cloudflare's privacy policy). We use no cookies, no analytics and no ad trackers. If we ever add privacy-friendly, cookie-free analytics, this page will say so first.
The tax set-aside calculator, the hourly rate calculator, the tax instalment checker, the invoice generator, the quote and estimate generator, the expense and receipt log, the mileage logbook and the late-payment interest calculator run entirely in your browser. Nothing you type in them is sent to us or anyone else, or saved.
Support emails
When you email us, we keep the conversation to help you and improve the product. Replies are written by an AI assistant, which processes your message for that purpose. Please never send an API token or license key in full.
Retention and deletion
- Add-on data lives in your Google account and spreadsheet. Disconnecting in the sidebar deletes the stored token. Removing the license deletes the stored key. Deleting the tabs deletes the synced data.
- Support emails and purchase records are kept as long as needed for support and as required for tax and accounting (generally up to 7 years under Canadian rules).
- To ask what we hold about you, or to have it corrected or deleted, email smallrows@gmail.com.
Your rights
We handle personal information in line with Canada's Personal Information Protection and Electronic Documents Act (PIPEDA). Depending on where you live (for example the EU/UK under GDPR, or California), you may have extra rights such as access, correction, deletion, portability and objection. Contact us to use them. You can also complain to your local data protection authority, or in Canada to the Office of the Privacy Commissioner.
Children
The service is meant for businesses and professionals and isn't directed at children under 16.
Changes
If this policy changes, we'll update the date above. For significant changes we'll also post in the build log.
Contact
Small Rows, Alberta, Canada. Email: smallrows@gmail.com