Storesheet PRIVACY

Privacy policy

Last updated 7 September 2026

Storesheet moves product data between a spreadsheet you own and a Shopify store you own. This page says exactly what it touches, and what it never sees.

The short version. Storesheet has no servers and no database. Your catalog is never copied to us, because there is nowhere for us to copy it to. The add-on runs inside Google Apps Script, in your own Google account, and talks to your Shopify store directly.

The three permissions it asks for

scopewhat it allows
spreadsheets.currentonly Read and write the one spreadsheet you have open. It cannot list, open or read any other file in your Google Drive.
script.external_request Make outbound requests. Used to call the Shopify Admin API of the store you connected, and to check a licence key on the Pro plan.
script.container.ui Show the menu item and the sidebar.

That is the complete list. Storesheet does not ask for Drive access, Gmail, contacts, calendar, or your Google profile.

What it stores, and where

Storesheet stores the connection details for the Shopify stores you add: the store address, a label, and either a Client ID and Client secret pair or a legacy access token. These are saved through Google's PropertiesService, in storage that belongs to your Google account. They are not written into the spreadsheet file, which is why sharing the spreadsheet does not share access to your store.

Inside your spreadsheet it also keeps three hidden sheets: a snapshot of the catalog as it was last pulled, a record of previous values so a push can be undone, and a job log. These are ordinary sheets in your own file. Delete them and they are gone.

The developer of Storesheet cannot read any of this. There is no administrative console, no back end, and no mechanism by which your credentials or catalog reach the developer.

What it sends, and to whom

recipientwhat is sentwhy
Your Shopify store Product and variant data, and your store credentials To read your catalog and write the changes you asked for
Lemon Squeezy Your licence key only — no catalog data, no spreadsheet content To check that a Pro licence is valid, at most once a day

Nothing else leaves your Google account. Storesheet contains no analytics, no telemetry, no crash reporting, no advertising identifiers and no third-party trackers.

Google user data — Limited Use

Storesheet's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Data obtained through Google APIs is used only to provide the features described on this site; it is not transferred to any third party except as required to provide those features — that is, to your own Shopify store; it is never sold; it is never used for advertising; and no human reads it, other than you.

Retention and deletion

  • Removing a store in the sidebar deletes its stored credentials and cached token immediately.
  • Uninstalling the add-on removes the properties Storesheet saved in your Google account.
  • The hidden sheets live in your spreadsheet; deleting the sheets, or the file, deletes them.
  • Because the developer holds no copy of anything, there is nothing further to request deletion of.

Children

Storesheet is a business tool and is not directed at anyone under 16.

Changes to this policy

If this policy changes, the date at the top of the page changes with it, and any change that widens what Storesheet accesses will require you to grant permission again.

Contact

hoangvhuan@gmail.com