Privacy policy
Last updated: October 10, 2026
RevenueSheet (“we”, “us”) operates the website at www.revenuesheet.app and the RevenueSheet Google Sheets add-on. This policy explains what we collect, how Google user data is used, how to request deletion, and how to contact us. It is written to support Google OAuth / Workspace Marketplace verification, including Limited Use requirements.
Who we are
Legal entity name used in communications: RevenueSheet. Support: /support.
Data we process
1. Data in your spreadsheet
Order, subscription, customer, and refund rows are written into Google Sheets in your Google account when you connect Lemon Squeezy, Polar, Gumroad, or Stripe. We do not keep a separate full copy of your revenue ledger on RevenueSheet servers. If you uninstall the add-on or delete the sheet, that spreadsheet data remains under your Google account controls.
2. Source API keys
API keys or access tokens you paste into the add-on are stored in Apps Script User Properties for your Google account (not in the sheet cells, and not on RevenueSheet servers) so sync can call the source APIs. Those keys are not stored in our license database or marketing backend.
3. Account and billing data
When you purchase a paid plan we process, through Stripe:
- Email address
- Subscription and payment status
- A generated license key tied to your tier
Card numbers never touch our servers. Stripe handles payment methods. License records are stored in our license database (Upstash Redis in production, or a local store in development) so the add-on can verify tier limits.
4. Website logs
Our hosting provider (Vercel) may process standard server logs (IP address, user agent, URL) for security and reliability. We do not sell personal information.
Google user data
The add-on uses Google OAuth / Apps Script authorization limited to these scopes:
spreadsheets.currentonly: read and write only the spreadsheet the add-on is opened fromscript.external_request: HTTPS calls to Lemon Squeezy, Polar, Gumroad, Stripe, and our license APIscript.scriptapp: install time-driven triggers for scheduled refreshscript.container.ui: sidebar and menu UI inside Sheets
We do not request Google Drive, Gmail, Contacts, or Calendar scopes. Spreadsheet access is limited to the file the add-on is opened from (spreadsheets.currentonly).
Google user data (contents of the current spreadsheet) is used only to:
- Create and update tabs the add-on manages
- Write synced commerce rows and dashboard formulas
- Read settings the user keeps in the sheet and keys/license state in User Properties
Google API Services Limited Use disclosure
RevenueSheet’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
- We use Google user data only to provide and improve user-facing features that are prominent in the add-on’s interface (sync and dashboard in Sheets).
- We do not use Google user data for serving advertisements, including retargeting, personalized, or interest-based advertising.
- We do not sell Google user data or transfer it to third parties except as necessary to provide or improve features (for example, infrastructure subprocessors that process data on our behalf under contract), for security/compliance, or if you direct us to.
- We do not allow humans to read Google user data unless you give affirmative consent for specific messages, it is necessary for security/compliance, or we are required by law, and then only with access limited to the minimum needed.
Subprocessors
These processors help run the website, license checks, support forms, billing, and the add-on runtime. None of them receive your storefront API keys from us.
- Vercel: hosts the marketing site and API routes, and may retain standard HTTP request logs (IP, user agent, URL) for security and reliability
- Upstash: Redis storage for license records, support form submissions, and early-access / launch-invite emails
- Stripe: Checkout, Customer Portal, subscription state, and payment methods (card data never touches our servers)
- Google (Workspace / Apps Script / Sheets): runs the add-on in your account and holds spreadsheet rows you sync; source API keys you paste stay in Apps Script User Properties
Source commerce APIs (Lemon Squeezy, Polar, Gumroad, Stripe) are called directly from your Google Apps Script project with keys you store in User Properties. Those keys are not sent to our servers for sync.
Cookies and analytics
The marketing site does not require an account. We do not use a dark/light theme cookie. If we add privacy-preserving analytics later, this page will be updated before those scripts run.
Retention
Retention matches what the product actually stores today. We do not run automatic deletion timers in code, so records we hold stay until you ask us to delete them (or you delete them yourself where the product lets you).
- Spreadsheet rows and source API keys: in your Google account. You control retention by editing or deleting the sheet, removing keys in the sidebar, or uninstalling the add-on.
- License records (key, tier, status, Stripe customer/subscription ids, email when provided): stored in Upstash Redis (or a local file in development) until you ask us to delete them.
- Support submissions (name, email, subject, message, timestamp): stored in Upstash Redis (or a local file in development) until you ask us to delete them.
- Early-access / launch-invite emails: stored (deduped) in Upstash Redis (or a local file in development) until you unsubscribe via the one-click link in any launch email, or ask us to delete them.
- Vercel HTTP logs: retained under Vercel’s platform defaults for hosting security and operations.
- Stripe billing records: retained under Stripe’s privacy policy for processed payments and subscriptions.
Deletion and access requests
You can:
- Delete synced rows or the entire spreadsheet in Google Sheets at any time
- Remove source API keys from the add-on sidebar / script properties
- Uninstall the add-on from the Google Workspace Marketplace / Extensions menu
- Unsubscribe from the launch list via the one-click link in any launch email, or request deletion of license records, support messages, or launch-invite emails via Support (Stripe may still retain payment records under its own policy)
We aim to respond to verifiable deletion and access requests within 30 days. Stripe may retain payment records under its own policy for processed charges.
Children
The service is directed at businesses and adult operators. We do not knowingly collect personal information from children under 13 (or under 16 where that is the applicable age).
International transfers
We may process data in the United States and other countries where our subprocessors operate. Where required, we use appropriate contractual safeguards.
Changes
We may update this policy. The “Last updated” date will change; material changes affecting Google user data use will be highlighted for Marketplace users when required.
Contact
Support: /support