Privacy Policy
Last updated: July 2026
This policy explains how Form Slots ("Form Slots", "we", "us"), a product operated by Leandro Zubrezki (Argentina), handles your information when you use our Google Forms add-on and website. If you have any question, email us at support@formslots.com.
1. The Google data we access, and why
Form Slots has two parts: an add-on that runs inside your Google Form, and a server that manages the booking logic. Each requests only the access it needs.
The add-on (runs inside your form):
| Permission | Why we need it |
|---|---|
View and manage the form this add-on is installed in (forms.currentonly) |
Read the form's questions and options, set the custom closed-form message, and clear responses when you reset a round. |
Your email address (userinfo.email, openid) |
Identify you so your configuration is linked to your account. |
Display the add-on sidebar (script.container.ui) |
Show the Form Slots panel inside Google Forms. |
Connect to an external service (script.external_request) |
Let the sidebar communicate with the Form Slots server. |
The server (with your one-time authorization when you connect your account):
| Permission | Why we need it |
|---|---|
See, edit, and manage your Google Forms (forms.body) |
Read the connected form's structure and edit its options to hide full slots, and open or close the form on schedule. The Google Forms API has no "current form only" equivalent for this, so this is the narrowest scope available for editing a form from a server. |
See responses to your Google Forms (forms.responses.readonly) |
Count bookings per option and run the waitlist. Responses are the source of truth for who is confirmed and who is waiting. |
Create and manage only the Drive files this app creates (drive.file) |
Create a Google Sheet to back up your responses when you reset a round. This grants access only to files Form Slots itself creates, never to your existing Drive files. |
Your email address (openid, email) |
Identify you as the form owner. |
2. Google API Services User Data Policy: Limited Use
Form Slots' use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Concretely, we only use Google user data to provide and improve the booking features you see in the add-on, we do not transfer it to third parties except to run the service (with your consent), for security, or to comply with law, and we do not allow humans to read it except where you have asked us to or where it is required for security or by law.
3. Information we collect
- Account: your email address, from Google sign-in, to identify you.
- Your configuration: the slot limits, waitlist setting, schedule, and messages you set for each form.
- Booking state derived from your form's responses: which options are booked or waitlisted. For forms that collect email addresses, we store each respondent's email as part of this state, so we can enforce one booking per person, run the waitlist in order, and send booking emails.
- Log and activity data: technical logs (timestamps, form IDs, error messages) used to operate and debug the service.
- Email delivery results: whether a message we sent was accepted, bounced, or reported as spam. We need this to keep our email working and to stop sending to addresses that reject mail.
- Email engagement, for product emails only: the emails we send owners about the product carry a tracking pixel and links that pass through our own domain, so we can see when one is opened and which links are followed, along with the time, your IP address, and your email client. We use this only to judge whether what we send is worth sending. You can stop the open signal by blocking images in your email client, and unsubscribing stops these emails entirely. Booking emails carry neither. Confirmation, waitlist, and promotion messages have no tracking pixel and no rewritten links, and they go out from a separate sending domain, so we never learn whether a respondent opened one or what they clicked.
4. How we use your information
- To run the booking engine, waitlist, scheduling, and reset features you configure.
- To send booking emails to respondents (confirmation, waitlist, and promotion) and status notifications to you as the form owner, for forms that collect emails.
- To provide support and to keep the service secure and reliable.
- To email you, as a form owner, about the product itself: how to get started, occasional tips, changes that affect you, and sometimes news about features or pricing. You can unsubscribe from these at any time with the link in the message, and you will still receive the operational emails your forms depend on. Respondents never receive these; they only get messages about their own booking.
We do not sell your data, we do not use it for third-party advertising, and we do not use it to train machine-learning models.
5. Who processes data on our behalf (subprocessors)
- Google Cloud Platform: hosting and database (Cloud Run and Firestore), in the United States.
- Resend: delivery of the booking and notification emails described above.
- Paddle: payment processing and billing, as our Merchant of Record, if you buy a paid plan.
We do not sell your data or share it with anyone else, except as required by law or in connection with a merger, acquisition, or sale of assets, consistent with the Limited Use requirements above.
6. How we store and protect data
Data is stored on Google Cloud Platform. The OAuth token that lets our server act on your form is encrypted at rest (AES-256-GCM), and all traffic is served over TLS. Access is limited to what is needed to operate the service.
7. Data retention and deletion
- Your configuration and booking state are kept while your account is connected, so the add-on keeps working across sessions.
- The OAuth token is kept until you disconnect or uninstall the add-on, or revoke access.
- Technical logs are retained for up to 90 days.
- When you uninstall the add-on, revoke access at myaccount.google.com/permissions, or ask us by email, we delete your stored configuration, booking state, and token within 30 days.
Your form responses always remain in your own Google account. Backup Sheets created during a reset are owned by you and stay in your Google Drive; deleting them is up to you.
8. Your rights
You can review or revoke Form Slots' access at any time at myaccount.google.com/permissions. To request access to, or deletion of, the data we hold about you, email support@formslots.com.
9. Respondents
If you fill in a Google Form that uses Form Slots, your response is stored in the form owner's Google account, and Form Slots processes it on the owner's behalf to enforce the slot limits and run the waitlist. If the form collects your email, it may be used to send you a confirmation, waitlist, or promotion message about your booking. Those messages carry no tracking pixel and no rewritten links, so we do not know whether you opened one or what you clicked. We only see whether our provider could deliver it, which is what tells us the message is not silently failing. We do not use your address for anything else, and we never sell it or add it to a marketing list. Contact the form owner about the data in their form.
10. Children
Form Slots is a tool for form owners and is not directed at children under 13. We do not knowingly collect data from children.
11. Changes to this policy
We may update this policy from time to time. We will post the new version here and update the date at the top. Significant changes will be communicated where appropriate.
12. Contact
Questions about this policy or your data: support@formslots.com.