Calrows
PricingGuidesHelpSupport

Privacy policy

Last updated: 16 September 2026

Calrows is a Google Sheets add-on that syncs spreadsheet rows with Google Calendar events. This policy explains what data the add-on accesses, what it does with it, and what it never does.

What Calrows accesses, and why

Google permissionWhat it lets Calrows doWhy it is needed
View and manage the spreadsheet the add-on is used in (spreadsheets.currentonly)Read the rows you choose to sync and write event IDs, imported events, timesheets and the Sync Log into that spreadsheet.The sheet is the source and destination of the sync. Calrows cannot see any other spreadsheet.
See, edit, share and permanently delete calendars you can access (calendar)List your calendars, create, update and delete events in the calendar you pick, and read events for imports and timesheets.Creating and updating events is the purpose of the add-on. Deleting is used only by "Remove events for deleted rows", which you trigger, and only for events Calrows itself created.
Display and run content in prompts and sidebars (script.container.ui)Show the sidebar.The user interface.
Run when you are not present (script.scriptapp)Continue a long sync after Google's time limit, and run automatic sync on the schedule you set.Large sheets and the Pro automatic sync.
Connect to an external service (script.external_request)Ask our licence server whether your Google account has a Pro subscription.To unlock Pro features. Only your email address is sent.
See your primary Google account email address (userinfo.email)Identify your account for the free-plan counter and the Pro check.So that a Pro purchase can be tied to your Google account without creating another login.

What Calrows stores

  • Inside your own spreadsheet: a hidden column of event IDs, a hidden tab listing the events Calrows created, a Sync Log tab, and your column mapping and calendar choice. This data lives in your Google Drive, under your control, and is removed when you delete those tabs or the spreadsheet.
  • In Google's Apps Script properties for your account: a monthly count of new events created on the free plan, and a cached answer to "is this account Pro". Nothing else.
  • On our licence server: only for paying customers, the email address you gave at checkout, your plan, and its expiry date. Payment details are held by Paddle, our merchant of record, never by us.

Calrows does not store your spreadsheet contents or your calendar events on any server we operate. All sync work happens inside Google's Apps Script environment, between your sheet and your calendar.

What Calrows never does

  • Never sells, rents or shares your data with anyone.
  • Never uses your data for advertising, profiling or training models.
  • Never reads spreadsheets other than the one you open the add-on in.
  • Never reads calendars you did not select, except to list their names in the calendar picker.
  • Never emails you from the add-on. Support replies come from [email protected] only when you write to us.

Who we share, transfer or disclose Google user data with

Calrows does not sell Google user data and does not share it with advertisers, data brokers or any third party for their own purposes. The only parties that ever receive any data are the service providers below, each for a single stated reason.

RecipientWhat they receiveWhy
Google (Apps Script, Sheets, Calendar)All sync operations run inside Google's own infrastructure. Your spreadsheet and calendar data never leave your Google account.Calrows is a Google Sheets add-on; Google's services are where the work happens.
Cloudflare, Inc.Your Google account email address only, sent to our licence server hosted on Cloudflare Workers when the add-on checks whether you have a Pro plan.To unlock Pro features. No spreadsheet or calendar content is ever sent.
Paddle.com Market LtdThe email address and payment details you enter yourself at checkout. Paddle is the merchant of record for Pro purchases.To process payment, tax and receipts. Paddle does not receive any Google user data from the add-on.

Beyond these, we disclose data only if required by law, for example a valid court order, or to investigate abuse of the service, and we will limit any such disclosure to what is legally required.

We do not transfer Google user data to any other person or company, including in the event of a merger or sale of the business, without first notifying users and obtaining consent where the law requires it.

How we protect your data

Calendar and spreadsheet data obtained through Google APIs is treated as sensitive. The safeguards below apply to all of it.

Where the data lives

  • Your spreadsheet contents and calendar events are never copied to any server we operate. All sync operations run inside Google's Apps Script environment, in your own Google account, under Google's security controls. The only data written by Calrows is written back into your own spreadsheet and your own calendar.
  • The only data that leaves Google is your Google account email address, sent to our licence server to check your plan. That server holds, per paying customer, the email address, the plan name and its expiry date. Nothing else.

Encryption

  • In transit: every connection Calrows makes is over HTTPS with TLS 1.2 or higher. The licence server rejects plain HTTP.
  • At rest: licence records are stored in Cloudflare Workers KV, which encrypts all data at rest. Data held in Google Sheets, Google Calendar and Apps Script properties is encrypted at rest by Google.
  • Secrets such as API keys and webhook signing keys are stored as encrypted Cloudflare secrets and are never present in the website code or in the add-on code.

Access control

  • Only the Calrows operator can access the licence server configuration and its stored records, through an account protected by two-factor authentication.
  • Every request to the licence server must present a secret key; requests without it are refused. Every webhook from our payment provider is verified with a cryptographic signature before it is acted on; unsigned or tampered webhooks are rejected.
  • No employee, contractor or third party has access to your spreadsheet or calendar data. Calrows has no mechanism to read it outside your own Google session.

Data minimisation and retention

  • Calrows requests only the Google permissions needed for its function, and reads only the spreadsheet you open it in and the calendar you select.
  • Licence records are kept while a subscription is active and deleted within 30 days of the subscription ending, or within 7 days of a request to [email protected].
  • The free-plan counter and cached plan status in Apps Script properties are removed automatically when you revoke the add-on's access.
  • Server logs contain request timestamps and response codes only, never message contents or spreadsheet or calendar data, and are retained for no more than 7 days.

Incident response

If we become aware of a security breach affecting your data, we will notify affected users by email within 72 hours of confirming it, describe what was affected, and explain the steps taken. We will also notify Google where its policies require it.

Your controls

  • Revoke Calrows' access at any time at myaccount.google.com/permissions. Access ends immediately.
  • Delete what Calrows wrote into your spreadsheet by removing the "Sync Log" and "_sync_state" tabs and the hidden "_eventId" column.
  • Ask us to delete your licence record or to export it: [email protected].

No use of Google user data for AI or machine learning

Calrows does not use any data obtained through Google APIs to develop, improve or train generalised artificial intelligence or machine learning models, and does not transfer such data to any third party for that purpose. Calrows contains no AI features.

Google API Services User Data Policy

Calrows' use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Deleting your data

  • Remove the add-on's access at any time at myaccount.google.com/permissions. Calrows loses all access immediately.
  • Delete the "Sync Log" and "_sync_state" tabs and the hidden "_eventId" column from your spreadsheet to remove everything Calrows wrote there.
  • Paying customers: email [email protected] and we delete your licence record within 7 days.

Cookies and analytics

The add-on sets no cookies and includes no analytics. This website uses no third-party analytics or advertising cookies.

Children

Calrows is not directed at children under 16 and we do not knowingly collect data from them.

Changes

If this policy changes materially we will update the date above and note the change on this page.

Contact

Questions about privacy: [email protected].

PricingHelpSupportPrivacy policyTerms of serviceRefund policyManage subscription
Google Sheets™ and Google Calendar™ are trademarks of Google LLC. Calrows is not affiliated with or endorsed by Google.