1. Who we are
SheetLinkWP ("we", "us", "our") operates the website sheetlinkwp.com and distributes the WordPress plugin SheetLink Forms via wordpress.org/plugins/sheetlink-forms/ and this site. Contact for privacy questions: privacy@sheetlinkwp.com.
This policy describes the personal data we collect about visitors to sheetlinkwp.com, customers of paid SheetLinkWP plans, and end users of the SheetLink Forms WordPress plugin.
2. The four data flows
SheetLinkWP is unusual in that four different data flows run in parallel, and we are a different kind of party in each. Understanding which flow you are in determines what we know about you and how we handle it.
2.1 sheetlinkwp.com visitors
When you visit our marketing website, we collect standard server-side request metadata (IP address, user agent, referrer, pages viewed, approximate location derived from IP) and use privacy-respecting analytics. We do not set third-party advertising cookies. We do not sell any visitor data.
2.2 Paid SheetLinkWP customers
When you purchase a license or create an account, we collect your name, billing email, billing address, payment method (tokenized - we never see card numbers), license key, registered WordPress site URLs, and product usage metrics (submissions processed, features active). We use this to operate your account, enforce entitlements, deliver support, and send service and billing email.
2.3 Form submissions processed by the plugin
The SheetLink Forms plugin runs inside your WordPress site. Form submissions flow from your WordPress site directly to your Google Sheet - whether you use the one-click Google connection or the classic Apps Script webhook, submission content does not transit SheetLinkWP infrastructure at all. If you use the one-click Google connection, our OAuth service handles the sign-in and token refresh: we process your Google account identifier (email address) during authentication, the resulting refresh token is stored encrypted in your own WordPress database, and access is limited to the spreadsheets you pick or create (Google's drive.file scope). Excel Online connections similarly use our OAuth broker, which holds a Microsoft refresh token encrypted at rest. In these default paths we have no knowledge of submission content. Only when you enable an add-on that uses our hosted services (Multi-CRM Routing, AI Lead Scoring, AI Analytics) does submission content pass through our systems, and only then are we a processor of that data on your behalf. The two AI features are off unless you switch them on, and they remove contact details from each submission before it leaves your site - see section 7.
2.4 SheetLink Forms hosted endpoint (sheetlinkforms.com) - beta
The hosted endpoint works differently from the WordPress plugin: pointing a form at a sheetlinkforms.com endpoint sends each submission to our servers, where it is screened for spam, stored on our infrastructure, and delivered to the account owner's connected Google Sheet, with failed deliveries retried automatically. For hosted accounts we process: the account email address (sign-in is by emailed magic link), an encrypted Google OAuth refresh token (AES-256-GCM at rest, limited to Google's drive.file scope - only the spreadsheets you pick or create, never the rest of your Drive), form configurations, and submission content together with request metadata (IP address, origin, user agent) used for spam screening, rate limiting, and delivery diagnostics. For submission content received through hosted forms we act as a processor/service provider on behalf of the account owner, who is responsible for the forms they operate and for any notice owed to the people submitting them. When a form owner enables the optional Cloudflare Turnstile challenge, the challenge interaction is processed by Cloudflare under its own privacy terms.
3. Legal bases (GDPR)
- Contract: we process account, billing, and license data to perform our contract with paid customers.
- Legitimate interests: we process website analytics and product telemetry to operate, secure, and improve our service.
- Consent: marketing email requires a separate opt-in you can withdraw any time.
- Legal obligation: tax, accounting, and regulatory records.
4. Categories of personal data we process
- Identity and contact: name, email, billing address, phone (if provided)
- Account and license: license key, plan tier, add-on entitlements, activation history, seat count, registered site URLs
- Billing: payment method token (held by Freemius, our merchant of record; Stripe for legacy subscriptions), invoice history, tax ID (if provided)
- Website and product telemetry: IP, user agent, event logs, error traces, feature usage counts
- Support communications: email threads, in-app messages
- For customers using hosted add-ons only: form submission field values routed through Multi-CRM Routing, AI Lead Scoring, or AI Analytics
5. How we use personal data
- Deliver and operate the service
- Authenticate and enforce license entitlements
- Process payments and issue invoices
- Send transactional and service email
- Provide customer support
- Diagnose bugs and prevent abuse
- Meet legal, tax, and audit obligations
- Send product updates and marketing if you have opted in - with one-click unsubscribe on every message
6. Sharing and sub-processors
We share personal data only with vetted sub-processors acting on our documented instructions. Current sub-processors:
- Freemius, Inc. - checkout, licensing, and payment processing as our merchant of record (your purchase is technically made from Freemius; they receive name, email, and payment details at checkout)
- Stripe, Inc. - payment processing for subscriptions started before August 2026
- Amazon Web Services (AWS) - cloud infrastructure, US regions
- Cloudflare, Inc. - DNS, CDN, DDoS protection
- Resend, Inc. - transactional and inbound email
- Plausible Analytics - privacy-respecting website analytics
- OpenRouter, Inc. - API gateway routing AI requests for the hosted AI Lead Scoring and AI Analytics features (routing pinned to OpenAI; no training on your data)
- OpenAI, LLC - AI inference for the same features (API terms; no training on your data)
- Google LLC (Gemini API) - automatic failover AI inference for the same features (API terms; no training on your data)
The last three apply only if you switch on AI Lead Scoring or the AI Analytics per-submission extras. If you do not, no AI provider receives anything from your site. When both AI providers are unreachable, scoring falls back to a model we host on our own infrastructure, so in that case no third party is involved in the inference at all.
We do not sell personal data. We do not share personal data with advertising networks. A Data Processing Addendum (DPA) is available on request at privacy@sheetlinkwp.com.
7. Form-submission data (when we are a processor)
When you enable an add-on that uses our hosted services:
- Multi-CRM Routing: submission field values pass through our backend and are forwarded to the destinations you configure (HubSpot, Salesforce, Zoho, Pipedrive). We retain the forwarded payload for up to 30 days for retry and diagnostic purposes.
- AI Lead Scoring: off by default; it sends nothing until you tick "Score incoming leads with AI" in SheetLink Forms > Lead Settings, and it never scores leads captured before you switched it on. When it is on, the plugin strips contact details from each submission before it leaves your WordPress site: names and phone numbers are replaced with the placeholder "provided", email addresses are reduced to their domain (
[redacted]@example.com), other identifiers such as IP address and user agent are dropped, and any email address or phone number typed into a free-text answer is redacted in place. What remains - the free-text answers and qualification fields the rating is actually based on - is processed through our scoring service, which calls OpenAI via the OpenRouter gateway, with Google's Gemini API as automatic failover and a model we host ourselves as a last resort. The model returns a score, a hot / warm / cold band, and a one-sentence explanation. We do not receive the form identifier, the form plugin name, your site URL, or any WordPress account data. We retain inference logs for 7 days. - AI Analytics: two modes depending on which features are enabled. (a) Aggregated analytics (trend detection, duplicate scan, weekly digest) use aggregated metrics only and raw PII is not retained after the aggregation step. (b) Per-submission extras (sentiment classification, summarize, categorize) send each submission's field values - scrubbed of contact details exactly as described for AI Lead Scoring above - through our scoring service, which calls OpenAI via the OpenRouter gateway (with Gemini as automatic failover and a self-hosted model as last resort) - or your own BYOK provider if configured - to compute a result. Inference logs are retained for 7 days. Per-submission extras are off by default and need two switches: the individual extra on the Analytics page, and AI consent in SheetLink Forms > Lead Settings. Turning off either one stops all requests immediately.
- SheetLink Forms hosted endpoint (sheetlinkforms.com): submissions to hosted form endpoints are stored on our infrastructure to provide spam screening, quarantine review, delivery to the connected Google Sheet, and retry on failure. Submission content is used for no other purpose.
The hosted AI features (AI Lead Scoring, AI Analytics) send submission content through the OpenRouter API gateway to OpenAI as the primary inference provider - routing is pinned to OpenAI, so no other OpenRouter host receives your data - with Google's Gemini API as an automatic failover called directly. If both are unreachable, the request falls back to a model running on our own infrastructure; that path involves no third party and no data leaves our systems. All three third parties operate under API terms that exclude training on your data, and all three are listed as sub-processors above. In every case what they receive is the scrubbed submission described above, not the original: contact details are removed on your own server before the request is made. The core delivery pipeline never involves an AI provider. For BYOK analytics configurations, submission data is instead sent to the provider you configured (OpenAI or Gemini) using your own API key under that provider's terms.
8. International transfers
Our primary infrastructure is located in the United States. For EU/UK personal data we rely on the Standard Contractual Clauses and Transfer Risk Assessments. The DPA includes the EU SCCs and UK Addendum. If you are in the EU or UK, by using our paid service you acknowledge transfer to the United States under these safeguards.
9. Retention
- Account and license records: for the life of your account plus 7 years for tax records
- Billing records: 7 years
- Support email: 3 years from last contact
- Website analytics: 14 months
- Error and security logs: 90 days
- Add-on submission payloads: 30 days (Multi-CRM Routing), 7 days (AI Scoring), 0 days raw for AI Analytics aggregated features (trend, duplicate, weekly digest), 7 days for AI Analytics per-submission extras (sentiment, summarize, categorize) when those toggles are enabled
- Hosted endpoint submissions (sheetlinkforms.com): for the life of the hosted account; deleted on account closure or on a verified deletion request
10. Your rights
Depending on your jurisdiction (GDPR in the EU/UK, CCPA/CPRA in California, PIPEDA in Canada, and similar regimes globally), you may have the right to:
- Access the personal data we hold about you
- Correct inaccurate data
- Delete personal data ("right to be forgotten")
- Receive a portable copy of your data
- Object to processing based on legitimate interests
- Withdraw consent for marketing
- Lodge a complaint with your supervisory authority
To exercise any of these rights, email privacy@sheetlinkwp.com. We respond within 30 days.
11. Children
Our service is not directed to children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us personal data, contact us and we will delete it.
12. Security
We use industry-standard safeguards: encryption in transit (TLS 1.2+), encryption at rest for sensitive data, role-based access controls, audit logging, regular dependency scans, and annual third-party penetration testing. No system is perfectly secure - if you believe your account or data has been compromised, contact security@sheetlinkwp.com immediately.
13. Cookies
We use a small set of first-party cookies for essential functions (session, CSRF protection, load balancing) and privacy-respecting analytics. We do not use third-party advertising cookies or cross-site tracking. Your browser's Do Not Track signal is honored.
14. Changes to this policy
We will post updates to this page with a new "Last updated" date. Material changes will be communicated to paid customers by email at least 30 days before they take effect.
15. Contact
Privacy questions: privacy@sheetlinkwp.com
Security disclosures: security@sheetlinkwp.com
General support: support@sheetlinkwp.com