This Privacy Policy describes how DocuTrack HR (“the Add-on”, “we”, “our”) collects, uses, handles, and safeguards your data when you install and use our Google Sheets™ Add-on.
1. The Core Principle: What We Do NOT Do
To ensure maximum security for international schools, universities, and enterprise HR departments, we are completely transparent about what this Add-on does not and cannot do:
- No External Databases: We do not transmit, upload, or sync your spreadsheet rows, employee lists, or expiration dates to any third-party server or developer database.
- No Developer Access: The developer of DocuTrack HR has zero administrative access to your spreadsheets, your settings, your staff contact lists, or your email history.
- No Data Selling or Monetization: We do not collect, monetize, sell, lease, or share personal or organizational data with third parties or data brokers. Ever.
- No Advertising or Tracking: The Add-on contains zero third-party tracking scripts, advertising trackers, or telemetry beacons.
2. OAuth Permissions & Scopes: Exactly Why We Need Them
To automate your HR document tracking, DocuTrack HR requires specific permissions granted via Google OAuth. The Add-on operates on the principle of least privilege:
View and manage your spreadsheets (Active Sheet Only)
Why it is needed: The Add-on needs permission to read the dates, names, and email addresses in the currently active spreadsheet to calculate document expiration statuses. It writes "VALID", "APPROACHING", and "URGENT" color pills and email timestamp logs directly back into your designated output columns. It cannot access any other spreadsheets in your Google Drive™—only the specific file you have open.
Send email as you
Why it is needed: DocuTrack HR utilizes Google's standard mail service to dispatch automated email notifications to the staff addresses listed in your spreadsheet, as well as the weekly digest to your HR department. All emails originate from your own authenticated Gmail account. We cannot read, delete, or manage your inbox; we only have permission to send these automated alerts.
Allow this application to run when you are not present
Why it is needed: This permission allows the Add-on to establish time-driven background triggers (such as checking expiration dates daily at 8:00 AM or executing chunked batches for large staff rosters). This ensures automation functions reliably even when the spreadsheet is closed and no user is logged in.
Display and run third-party web content
Why it is needed: This allows the Add-on to display its interactive settings menu and configuration dashboard natively inside your Google Sheets™ sidebar.
3. Google API Services User Data Policy (Limited Use Disclosure)
DocuTrack HR's use and transfer to any other app of information received from Google APIs will adhere strictly to the Google API Services User Data Policy, including the Limited Use requirements.
We strictly limit our API usage to providing and improving the user-facing features of HR document automation. We never transfer this data to any third party, nor do we use it for serving advertisements or training artificial intelligence / machine learning models.
4. Data Storage, Retention, and Location
All settings you configure in the DocuTrack HR sidebar (such as column mappings, custom email messages, reminder thresholds, and 60-day notification logs) are stored directly inside Google's PropertiesService.getDocumentProperties().
- Location: Configuration data is stored locally as hidden document properties attached directly to your specific Google Sheet.
- Retention: Configuration data is retained only for as long as your spreadsheet exists in your Google Drive™.
- Audit Logs: The Add-on stores a rolling history of the last 50 notifications within document properties. Older logs roll off automatically. You can export a permanent archive to a dedicated spreadsheet tab at any time.
5. Data Deletion & Right to be Forgotten (GDPR Compliance)
You maintain complete, immediate control over all stored data. You can delete all DocuTrack HR configuration, settings, and logs at any time via any of the following methods:
- In-App Factory Reset: Open the sidebar, navigate to the Global Settings tab, and click Clear System Data. This instantly wipes all document properties and deletes all active triggers.
- Deleting the Spreadsheet: Deleting the Google Sheet permanently purges all associated document properties from Google servers.
- Uninstalling the Add-on: Uninstalling DocuTrack HR from Google Workspace immediately revokes all OAuth permissions and permanently cancels all future background triggers.
- License Server Erasure: If you are a PRO subscriber and wish to purge your verified email address from our AWS license registry, click "Delete Cloud License Data" in the sidebar or email us directly at
sethi+docutrack@eduflip.netfor immediate erasure within 24 hours.
6. Security Measures
Because DocuTrack HR operates within the Google Cloud infrastructure, your data benefits from Google's enterprise-grade security protocols:
- Data in transit is protected using industry-standard TLS 1.3 / HTTPS encryption.
- Data at rest is encrypted by Google Drive™ using AES-256 standards.
- License verification uses cryptographic Google OAuth OIDC/JWT tokens (bypassing vulnerable API keys and spoofing).
- Webhooks and server operations employ timing-safe cryptographic comparisons to protect against timing attacks.
7. Contact Us & Inquiries
If you have questions, compliance verification requests, or require assistance regarding this Privacy Policy, please contact our data governance team:
Lead Developer: Sethi De Clercq
Email: sethi+docutrack@eduflip.net
Website: sethideclercq.com