Privacy Policy

Last Updated: 1st November 2020

Introduction

This Privacy Policy applies to information that we collect about you when you use:

At times in this Privacy Policy we will refer to both our Websites and Add On collectively as our “Services”.

Please read this Privacy Policy carefully before using our Services, if you do not agree with any parts of it do not use our Website and/or Service. By accessing our Services you agree to this Privacy Policy.

Changes

Although most changes are likely to be minor, we may change this Privacy Policy from time to time. We encourage you to frequently check this page for any changes to our Privacy Policy. Your further use of the Services after a change to our Privacy Policy will be subject to the updated Privacy Policy

Information We Collect

We only collect information about you if we have a reason to do so — for example, to provide our Services, to communicate with you, or to make our Services better. We collect this information from three sources: if and when you provide information to us, automatically through operating our Services, and from outside sources.

Information You Provide to Us

Information We Collect Automatically

Information We Collect from Other Sources

We may also get information about you from other sources. When you use our Add On we are provided with the email address linked to your Google account. We use this to identify you within our Services but we do not store it directly.

In addition to this the payments platform for our paid subscriptions is provided by “Paddle.com Market Limited” who act as the Merchant of Record for all transactions. Information relating to payments including: name, location, contact details, and billing information that are provided by you may be stored and processed by “Paddle.com Market Limited”. All such information is subject to the privacy policy of “Paddle.com Market Limited”.

“Paddle.com Market Limited” and us have a legitimate interest to use provided data for product fulfilment, order processing, fraud prevention, and product support.

Required Permissions

Your use of our Services does not give us access to any Personal Data stored in your Google account account such as name, physical address, or credit card details.

When you run our Add On for the first time, you will see a consent screen with the permissions it requires to work:

See, edit, create and delete your spreadsheets in Google Drive

In order for our Add On to work it needs access to read the contents of the spreadsheets you have installed it in so it can determine what changes have been made. All processing of your spreadsheet data happens within Google’s servers and we do not store any data from your spreadsheets.

Send email as you

To send you email notifications we may use Google’s service that allows us to send them from your account.

Connect to an external service

If you need to send a large number of email notifications we send these via third party vendors: “Mailgun Technologies, Inc” and “Elastic Email Inc”. We connect to these third party vendors securely using HTTPS and only share with them the minimum information required to send you an email.

Allow this application to run when you are not present

Our Add On runs in the background after you or anyone with access to your spreadsheet makes changes to it.

Display and run third-party web content in prompts and sidebars inside Google applications

To provide you with a good user experience we use some third party content such as the Bootstrap CSS framework and Vue.js JavaScript framework that is hosted on an external CDN (Content Delivery Network).

How and Why We Use Information

Purposes for Using Information

We use information about you for the purposes listed below:

Sharing Information

We share information about you in limited circumstances, and with appropriate safeguards on your privacy.

A note here for those in the European Union about our legal grounds for processing information about you under EU data protection laws, which is that our use of your information is based on the grounds that: (1) The use is necessary in order to fulfill our commitments to you under the applicable terms of service or other agreements with you or is necessary to administer your account — for example, in order to enable access to our website on your device or charge you for a paid plan; or (2) The use is necessary for compliance with a legal obligation; or (3) The use is necessary in order to protect your vital interests or those of another person; or (4) We have a legitimate interest in using your information — for example, to provide and update our Services; to improve our Services so that we can offer you an even better user experience; to safeguard our Services; to communicate with you; to measure, gauge, and improve the effectiveness of our advertising; and to understand our user retention and attrition; to monitor and prevent any problems with our Services; and to personalise your experience; or (5) You have given us your consent.

Transferring Information

Because our Services are offered worldwide, the information about you that we process when you use the Services in the EU may be used, stored, and/or accessed by individuals operating outside the European Economic Area (EEA) who work for us, other members of our group of companies, or third-party data processors. This is required for the purposes listed in the How and Why We Use Information section above. When providing information about you to entities outside the EEA, we will take appropriate measures to ensure that the recipient protects your personal information adequately in accordance with this Privacy Policy as required by applicable law. These measures include:

How Long We Keep Information

We generally discard information about you when it’s no longer needed for the purposes for which we collect and use it — described in the section above on How and Why We Use Information — and we’re not legally required to keep it. For example, we keep the web server logs that record information about a visitor to one of our Websites, like the visitor’s IP address, browser type, and operating system, for approximately 30 days. We retain the logs for this period of time in order to, among other things, analyse traffic to our Websites and investigate issues if something goes wrong on one of our websites. After the thirty days are up, the deleted content may remain on our backups and caches until purged.

Security

While no online service is 100% secure, we work very hard to protect information about you against unauthorised access, use, alteration, or destruction, and take reasonable measures to do so. We monitor our Services for potential vulnerabilities and attacks.

Choices

You have several choices available when it comes to information about you:

Your Rights

If you are located in certain parts of the world, including California and countries that fall under the scope of the European General Data Protection Regulation (aka the “GDPR”), you may have certain rights regarding your personal information, like the right to request access to or deletion of your data.

European General Data Protection Regulation (GDPR)

If you are located in a country that falls under the scope of the GDPR, data protection laws give you certain rights with respect to your personal data, subject to any exemptions provided by the law, including the rights to:

You also have the right to make a complaint to a government supervisory authority.

California Consumer Privacy Act (CCPA)

The California Consumer Privacy Act (“CCPA”) requires us to provide California residents with some additional information about the categories of personal information we collect and share, where we get that personal information, and how and why we use it. The CCPA also requires us to provide a list of the “categories” of personal information we collect, as that term is defined in the law, so, here it is. In the last 12 months, we collected the following categories of personal information from California residents, depending on the Services used:

You can find more information about what we collect in the Information We Collect section above. We collect personal information for the business and commercial purposes described in the How and Why We Use Information section. And we share this information with the categories of third parties described in the Sharing Information section. If you are a California resident, you have additional rights under the CCPA, subject to any exemptions provided by the law, including the right to:

Contacting Us About These Rights

You can usually access, correct, or delete your personal data using your account settings and tools that we offer, but if you aren’t able to or you’d like to contact us about one of the other rights, scroll down to “How to Reach Us” to, well, find out how to reach us. When you contact us about one of your rights under this section, we’ll need to verify that you are the right person before we disclose or delete anything. For example, if you are a user, we will need you to contact us from the email address associated with your account. You can also designate an authorised agent to make a request on your behalf by giving us written authorisation. We may still require you to verify your identity with us.

Controllers

Check Sheet is the data controller of your Personal Dat and may be contacted in any manner set forth in the How to Reach Us section of this Privacy Policy.

How to Reach Us

If you have a question about this Privacy Policy, or you would like to contact us about any of the rights mentioned in the Your Rights section above, please contact us through our email at contact@checksheet.app.

Credit and Licensing

Adapted from Automattic’s Privacy Policy that they have kindly made available under the Creative Commons Sharealike license. As such this Privacy Policy is also made available under the same license.