Privacy Policy

This Privacy Policy applies to all products provided by Zetomation, including Zeto Sheet Automation, Zeto Sheet Notification & Alerts, and Zeto Form Notification & Alerts, and Zeto Sign. We do not share, rent, or sell your personal data. We only store the information required to deliver and support our add-ons.

Google API Services User Data Policy

Zetomation's use and transfer of information received from Google APIs adheres to theGoogle API Services User Data Policy, including the Limited Use requirements.

Google OAuth scopes we use

Our add-ons require specific Google permissions to function. The scopes below are listed separately for each add-on based on its Apps Script manifest.

Zeto Sheet Automation scopes

  • https://www.googleapis.com/auth/spreadsheets (Read and write spreadsheet data)
  • https://www.googleapis.com/auth/script.container.ui (Display add-on UI)
  • https://www.googleapis.com/auth/script.external_request (Call webhooks and external APIs)
  • https://www.googleapis.com/auth/script.send_mail (Send emails)
  • https://www.googleapis.com/auth/script.scriptapp (Create and manage automation triggers)
  • https://www.googleapis.com/auth/userinfo.email (Identify user)
  • https://www.googleapis.com/auth/forms (Trigger workflows from Google Form responses)
  • https://www.googleapis.com/auth/script.deployments (Create and update Apps Script deployments)
  • https://www.googleapis.com/auth/script.projects (Manage automation scripts)
  • https://www.googleapis.com/auth/script.locale (Read script locale settings)

Zeto Sheet Notification & Alerts scopes

  • https://www.googleapis.com/auth/script.container.ui (Display add-on UI)
  • https://www.googleapis.com/auth/spreadsheets (Read and write spreadsheet data)
  • https://www.googleapis.com/auth/userinfo.email (Identify user)
  • https://www.googleapis.com/auth/script.scriptapp (Create and manage notification triggers)
  • https://www.googleapis.com/auth/script.send_mail (Send notification emails)
  • https://www.googleapis.com/auth/forms (Trigger alerts from Google Form responses)
  • https://www.googleapis.com/auth/script.deployments (Create and update Apps Script deployments)
  • https://www.googleapis.com/auth/script.projects (Manage notification scripts)
  • https://www.googleapis.com/auth/script.external_request (Call webhooks and external APIs)

Zeto Form Notification & Alerts scopes

  • https://www.googleapis.com/auth/forms (Read form data and trigger workflows)
  • https://www.googleapis.com/auth/script.container.ui (Display add-on UI)
  • https://www.googleapis.com/auth/script.send_mail (Send Apps Script emails)
  • https://www.googleapis.com/auth/script.scriptapp (Manage workflow triggers)
  • https://www.googleapis.com/auth/script.external_request (Call approved external services)
  • https://www.googleapis.com/auth/userinfo.email (Identify user)

For additional information about how these permissions are used by this add-on, see Zeto Form Notification & Alerts Privacy Policy.

Zeto Sign scopes

  • https://www.googleapis.com/auth/forms.currentonly (Read and update the current Google Form)
  • https://www.googleapis.com/auth/script.external_request (Sync forms with Zetomation and load signed responses)
  • https://www.googleapis.com/auth/script.container.ui (Display sidebar and response dialogs)
  • https://www.googleapis.com/auth/userinfo.email (Identify the form owner)

Information we collect

  • Personal information: Email addresses captured via Google Sign-In for authentication and subscription management.
  • Account information: Subscription status, plan validity, and renewal history.
  • Log/activity data: Anonymous execution metrics (e.g., runtime, error rates) to improve reliability.
  • Zeto Sign form and submission data: When you use Zeto Sign, we process the Google Form title, description, question schema, Google Form identifiers, generated signing link metadata, signer answers, signature image data, and signature URLs needed to create and return signed submissions.

How we use the information

  • Service delivery: Identify accounts and enforce plan limits.
  • Support: Investigate outages, debug issues, and improve performance.
  • Communications: Send critical updates about service changes or new features.
  • Zeto Sign signing workflows: Render hosted signing forms, store signed submissions, upload signature images, show signed responses to the form owner, and submit the signed response back into the connected Google Form when available.

Data Sharing, Transfer, and Disclosure

Zetomation strictly protects your Google user data. We do not sell, rent, trade, or disclose any raw, aggregated, or anonymized Google Workspace user data to any third parties, including data brokers, advertising networks, or third-party AI/ML model training services.

The only exception to data sharing is with our secure, trusted cloud infrastructure providers (such as our secure database and web hosting services) strictly limited to what is technically necessary to host, operate, and maintain the Zeto Sign application. These infrastructure partners are bound by strict confidentiality obligations and are absolutely prohibited from accessing or using your Google data for their own purposes.

Zeto Sign Data Handling

1. Data Accessed via Google APIs (The Add-on)

When a form owner syncs a form using the Zeto Sign Google Workspace Add-on, we utilize Google APIs to read the specific form's schema (question titles and types) and metadata (form ID and owner email). This data is stored securely on Zetomation-controlled servers strictly for the purpose of rendering a mirrored, hosted signing page. The Add-on does not read, access, or store form responses from your Google account.

2. Data Collected via Zetomation (The Web App)

When a signer visits the Zetomation-hosted signing link, the submitted answers and drawn signature are collected directly by our web application. Signature images are uploaded to Zetomation-controlled storage and hosted via a public URL. Zetomation then acts as a proxy, securely posting the respondent's standard answers and the signature URL back to the original Google Form so that the connected Google Sheet can receive a standard response row.

3. Google API Limited Use Disclosure

Zeto Sign's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Data security & limited use

We rely on Google's infrastructure for Google Workspace add-on execution and use secure backend infrastructure for Zeto Sign's hosted signing pages, response APIs, database records, and signature storage. Access to backend service credentials is limited to server-side systems needed to operate the service. We adhere strictly to Google's Limited Use requirements.

Data retention and deletion

Configuration and submission data is kept only as needed to provide the service, support users, maintain reliability, and meet legal or security obligations. Form owners can remove Google-side data by deleting the source Google Form or linked Sheet. To request deletion of Zetomation-hosted Zeto Sign records or signature files, contact us at the email below.

Contact us

Questions about this policy? Email us atsupport@zetomation.com.