Privacy Policy

This Online Privacy Policy describes the privacy practices for Tanitapps Product Sheet Workflow Plus and its website www.sheetworkflowplus.com


1. Why do we keep some of your information ?

Tanitapps products are web based; because of this they may require the use of first and last names, billing contact information, and a G Suite account as a login. Therefore, at a minimum, we may require such necessary information in order to establish your account with us.


2. Do we access, use, store, or share Google users data during Tanitapps applications usage?

Personal Information: We collect personal information from users including (at minimum) first and last names, and a G Suite email address to be used as a login. When a user registers online for a trial version of our products, Tanitapps will take steps to verify the email address supplied to us to ensure it is accurate. Upgrading to the full version of our products requires Tanitapps to collect billing and payment information via our payment processing partner Stripe . Your email address may be used to send you periodic product newsletters, offers and usage tips from Tanitapps. You can opt out of promotional emails at any time, but will still receive communications such as receipts, confirmation emails and customer service updates that are considered necessary to provide the service to you. We use the information collected to deliver services, update our records, communicate with you about products and services, and generally maintain your accounts with us. We will retain your information for as long as your account is active, as needed to provide you services, to comply with our legal obligations, resolve disputes, and enforce our agreements. If you wish to cancel your account or request that we no longer use your information to provide you services contact us at contact@sheetworkflowplus.com We do not share, sell, trade, or rent your personal information to third parties except as described in this privacy policy. Information gathered at Tanitapps is done so on a voluntary basis.


Business Information:

Information that is collected by our products is considered confidential. We will not view Business Information except as necessary to appropriately support the service or as required by law. (Business Information includes app data, documents, files, configuration settings and any other business information stored on Tanitapps products). We will not view Business Information, except as necessary to appropriately support the service, for the purpose of anticipating, diagnosing, supporting or resolving any problems that might limit or disrupt the quality of our customers’ service experience or as required by law.


Session Records:

To maintain our quality of service and to assist in the analysis of product performance, we may also gather data on connection information. The gathered information is used only to ensure the highest quality experience possible when using Tanitapps products.


Security Information:

Tanitapps also collects certain standard information about your computer for security and identification purposes. This information may include: IP addresses, domain names, access times, cookies and other unique identifying information of machines that have our software downloaded and installed on them. This information is used for the operation of the service, to identify and protect our customers and to control unauthorized use or abuse of our services. All information is encrypted in transit (TLS) and at rest. Application data is stored in a managed PostgreSQL database hosted by Supabase; our website is served through Firebase Hosting and our application backend runs on Google Cloud Run.


Web Analytics:

We continuously improve our websites and utilize different web analytic tools to help us do so. We are interested in how visitors use our websites, what they like and dislike, and where they have problems. We also use web analytic tools on our mobile applications to help gather non-personally identifiable data about download and application usage. In our use of web analytics we do collect GeoLocation data, but it is only on an aggregate basis and not tied to any individual. The web beacons used in connection with our web analytics services do not share any personally identifiable information about our website and application visitors with third parties. Our tools may gather data such as what browser a person uses, what operating systems are used, what is downloaded, and what content, products and services are reviewed when visiting or registering for services at one of our websites or mobile applications. This information is used solely to assist Tanitapps in maintaining a more effective and useful website for our customers. We track aggregate traffic patterns throughout our site but we do not correlate this information with personally identifiable data about individual users. We track domain names and browser types. Such information will not be passed to third parties without your prior consent unless where required by applicable law.


3. With whom does Tanitapps share the information?

Ensuring your privacy is important to us. We do not sell, trade or rent your personal information to third parties.
Tanitapps products and services by necessity require us to provide some of your information to third parties.
We use a number of third parties to process personal data on our behalf. These third parties have been carefully chosen and all of them comply with the EU General Data Protection Regulation 2018 (GDPR) and the new Standard Contractual Clauses (SCCs).
We currently use the following third parties (sub-processors): Google (Google Workspace APIs, Firebase Hosting and Google Cloud Run — used to serve our website and run our backend), Supabase (managed PostgreSQL database hosting), Stripe (payment processing) and Hubspot (customer communication).

Supabase hosts our managed PostgreSQL database and processes application data on our behalf under its Data Processing Addendum (https://supabase.com/legal/dpa). Data is stored in encrypted PostgreSQL databases.


4. How does Tanitapps protect my information from loss, misuse or alteration?

Tanitapps has implemented commercially reasonable precautions designed to protect the web sites and applications it hosts and the information it collects from loss, misuse, and unauthorized access, disclosure, alteration, and destruction. Nevertheless, we remind you that no security measure is perfect. Tanitapps applications are accessed via G Suite user accounts. Tanitapps is not liable for loss of passwords due to user carelessness. If you lose control over your Google account, you may lose control over your personally identifiable information. If you believe your Google Account has been compromised, we recommend that you immediately change your password or activate Google 2 step authentication.


5. Tanitapps Data Retention Policy, Data Controller and Data Protection Officer

Tanitapps is compliant with the EU General Data Protection Regulation 2018 (GDPR) and the new Standard Contractual Clauses (SCCs). Tanitapps retains your user and business data for as long as your account is active and we need it to provide the service.


The account owner can delete the account at any time. Deleting an account removes its settings, its subscription and quota records and its team membership records, and drops the account's entire database schema — destroying the application data described in 7.4. This takes effect immediately, not after a waiting period. Residual copies then age out of our database provider's encrypted backups according to its backup retention window.


Where a customer contract sets a specific deletion or return deadline, that deadline applies.


Separately, if you subscribe to our email newsletter we keep your contact details until you unsubscribe.

You can request an immediate deletion of all your data by contacting our Data Protection Officer by email.

Data Controller: Tanitapps Inc, 3790 Colorado Ave. Unit A, Boulder, CO 80303, USA

Data Protection Officer: Jeremy Rochot, Director Tanitapps Inc, email contact@sheetworkflowplus.com


On 4 June 2021 the EC published new Standard Contractual Clauses (SCCs) to help safeguard personal data. These new SCCs replaced the SCCs previously adopted by the EC in 2010 and can be used to facilitate lawful transfers of data under certain conditions. By imposing various contractual obligations, SCCs allow personal data subject to the GDPR to flow to recipients outside the European Economic Area (EEA).


Google has updated its data processing terms for Google Cloud Platform, and Google Workspace (including Workspace for Education) and Cloud Identity, to incorporate the new SCCs.


For all Google Cloud customers, this new approach:

  • offers clear and transparent support for their compliance with applicable European data protection laws;
  • simplifies the entities involved in contracting by no longer requiring any customer to deal with an additional Google entity only for SCC purposes;
  • aligns more closely with potential flows of data within the services.

Stripe updated its data processing on november 17, 2022 (https://stripe.com/fr/legal/dpa).

Hubspot also updated its data processing (https://www.hubspot.com/data-privacy/privacy-shield).


6. Data Breaches

We will report any unlawful data breach of this website’s database or the database(s) of any of our third party data processors to any and all relevant persons and authorities within 72 hours of the breach if it is apparent that personal data stored in an identifiable manner has been stolen.


7. Business information usage by Sheet Workflow Plus

7.1 How a workflow uses your spreadsheets
A workflow owner configures a workflow on a Google Sheet (the configuration spreadsheet). Its visible tabs are the request template. Each new request is a copy of those tabs in a new Google Sheet, created in the workflow owner's Google Drive, in a folder named after the workflow. The requester fills in that copy, then submits it for approval.


7.2 Sheet Workflow Plus add-on (inside Google Sheets)
The add-on only requests access to the spreadsheet it is opened in (spreadsheets.currentonly), plus the permissions needed to run as an add-on:

  • Display the add-on menu, sidebar and dialogs (script.container.ui)
  • Read and write the spreadsheet the add-on is opened in, e.g. to create the Requests log tab (spreadsheets.currentonly)
  • Call the Sheet Workflow Plus service (script.external_request)
  • Create a time-based trigger for maintenance tasks (script.scriptapp)
  • Send emails on your behalf, such as quota notices (script.send_mail)
  • Identify the current user by email address (userinfo.email)


7.3 Sheet Workflow Plus web app and service
When you sign in to the web app with Google, you may be asked to grant the following permissions. They are used by our service, acting as the workflow owner, to run your workflows:

  • Google Sheets (spreadsheets): copy the template tabs into each new request, read the cells that your workflow conditions refer to, and keep the Requests log tab of the configuration spreadsheet up to date
  • Google Drive, only files created by Sheet Workflow Plus (drive.file): create the request spreadsheets and their folder, and share each request with the people who need it at each step — the requester, then the approvers of the step in progress. We cannot see or open any other file in your Drive.
  • Gmail, send only (gmail.send): send approval requests to approvers and status updates to requesters, from the workflow owner's address
  • Basic profile (openid email profile): sign you in

Emails sent during a workflow include: approval requests to approvers, pending approval reminders, and updates to each requester on every decision, including the final one. Each email links to the request spreadsheet.


7.4 Information stored by Sheet Workflow Plus
We only store the following information:

  • Information related to your subscription
  • Users invited to your team, if applicable
  • The workflow configuration: approval steps, conditions and approvers
  • The ID and name of the configuration spreadsheet and of each request spreadsheet
  • The values of the cells your workflow conditions refer to, read when a request is submitted and before each decision
  • Approval decisions, dates and comments
  • For users who sign in to the web app: the Google authorization (refresh token) needed to act on their behalf as described in 7.3

The rest of each request stays in your own Google Drive. We do not copy the content of your spreadsheets into our database beyond the cell values listed above.


7.5 Revoking access

Sheet Workflow Plus access to the permissions listed in 7.2 is revoked as soon as the add-on is uninstalled. Access granted to the web app (7.3) can be revoked at any time from your Google Account (Security > Third-party apps with account access).


7.6 Deleting business data on Sheet Workflow Plus

The account owner can delete the account at any time from within Spreadsheet Workflow Plus. Doing so immediately deletes the account's settings, subscription and team membership records and drops the account's entire database schema, destroying the business data listed in 7.4. Residual copies then age out of our database provider's encrypted backups according to its backup retention window. You can also request deletion of all your data by contacting our Data Protection Officer by email.


7.7 Hosting and infrastructure

Our infrastructure relies on the following providers: our website is hosted on Firebase Hosting (Google), our application backend (API) runs on Google Cloud Run (Google Cloud, region us-central1), and the application data listed in 7.4 is stored in a managed PostgreSQL database provided by Supabase (hosted on AWS, US region). All data is encrypted in transit (TLS) and at rest. Your spreadsheets and Drive files stay in your own Google account — we only store the application data listed in 7.4.