Emerge: Mail Merge

Privacy Policy

Last updated: 2026-07-11

This Privacy Policy describes how Emerge: Mail Merge (the "Add-on") handles your information. Emerge: Mail Merge is a Google Workspace add-on that runs inside Google Sheets. It reads the recipients and message template from your spreadsheet, renders a personalized email for each row, and sends it through your own Gmail account. Optionally, it can measure opens and clicks using Google Analytics.

1. Where the Add-on runs and where your data lives

The Add-on's logic runs in Google Apps Script, inside your own Google account, under the permissions you grant during installation. Your spreadsheet data, message templates, and settings stay within your Google account. The Add-on's authors do not operate a server that stores your spreadsheet contents, your templates, your recipient list, or the email you send.

The one exception is the optional analytics feature, which uses a small, stateless tracking relay described in Section 3. If you never enable analytics, the Add-on does not contact that relay.

2. Google user data and OAuth scopes

When you install Emerge: Mail Merge, Google asks you to authorize a set of OAuth scopes. We request only the scopes needed for the Add-on's features. The sections below describe each scope, the data it grants access to, and exactly how that data is used.

https://www.googleapis.com/auth/spreadsheets

What it grants: Read and write access to your Google Sheets spreadsheets.

How we use it: To read your recipient rows and column headers so each message can be personalized, and to store your message templates and campaign settings alongside the spreadsheet. The Add-on operates on the spreadsheet you open it from. It is not used to browse, collect, or transmit any other spreadsheet content.

https://www.googleapis.com/auth/gmail.send

Google's description: Send email on your behalf.

What it grants: Permission to send new outbound messages through Gmail. This scope is write-only — it does not allow reading, searching, or modifying existing messages, drafts, labels, threads, or settings.

How we use it: To deliver the personalized campaign emails you compose, one per recipient row, from your own Gmail account. Messages are sent only when you start a send. The Add-on never reads your mailbox.

https://www.googleapis.com/auth/userinfo.email

Google's description: See your primary Google Account email address.

How we use it: To identify your account and to offer your own address as the default sender / reply-to for a campaign. It is not shared with anyone.

https://www.googleapis.com/auth/userinfo.profile

Google's description: See your personal info, including any personal info you've made publicly available.

How we use it: To read your name and pre-fill the "Sender name" field so your recipients see a real name rather than a blank. You can change or clear it at any time. It is not shared with anyone.

https://www.googleapis.com/auth/analytics.edit

What it grants: Permission to create and configure Google Analytics resources in your Analytics account.

How we use it: Only when you turn on open/click tracking. The Add-on provisions a dedicated "Emerge Mail Merge" Google Analytics property, a data stream, and a write-only Measurement Protocol secret in your own Analytics account, so tracking events have somewhere to land. It does not modify your other Analytics properties.

https://www.googleapis.com/auth/analytics.readonly

What it grants: Read-only access to your Google Analytics reporting data.

How we use it: Only when tracking is enabled. The Add-on reads aggregated open and click metrics for your campaigns from the property it created and displays them in the Add-on's dashboard. It does not change any Analytics data.

https://www.googleapis.com/auth/script.scriptapp

What it grants: Permission for the Add-on to manage its own Apps Script triggers.

How we use it: To run large campaigns as a background queue. The Add-on schedules time-based triggers that send batches of messages over time, so a campaign stays within Gmail's sending limits and continues even after you close the spreadsheet. It accesses no personal data.

https://www.googleapis.com/auth/script.external_request

What it grants: Permission for the Add-on to make outbound network requests.

How we use it: To look up your profile name from Google's standard userinfo endpoint, and, when analytics is enabled, to build the tracking links embedded in your emails. The Add-on does not transmit your spreadsheet contents or email bodies to any external service.

https://www.googleapis.com/auth/script.container.ui

What it grants: Permission to display the Add-on's user interface (sidebar and dialogs) inside Google Sheets.

How we use it: Solely to show the Add-on's compose, preview, send, and dashboard screens. It accesses no user data.

3. Open and click tracking (optional)

Open/click tracking is off unless you enable it. When enabled, each message includes a 1×1 tracking pixel and its links are wrapped so they pass through a small relay we operate (at emerge.redigit.net) before redirecting to the real destination. This relay exists because email clients can only issue simple web requests, while the Google Analytics Measurement Protocol requires a server-side call.

The tracking link carries, in its URL:

When a recipient opens the email or clicks a link, their request reaches the relay. The relay forwards a corresponding event to Google Analytics and then returns the tracking pixel or redirects to the destination. It also processes standard request metadata (such as IP address and user-agent) for the duration of that request. From that metadata the relay derives, and includes in the analytics event, a coarse location (country, and where the network provides it, region and city) and the device type (device category, operating system, and browser), so you can see where and on what your recipients engaged. It does not derive or store a precise location or the raw IP address. The relay is stateless: it stores none of this data, keeps no database of recipients or events, and never receives recipients' email addresses or the body of any message. The resulting open/click metrics — including the coarse location and device breakdowns — live only in your own Google Analytics property.

4. Data security

Because your spreadsheet data, message templates, recipient lists, and email content never leave your Google account, they remain protected by Google's own infrastructure and by the account permissions you control. We keep no copy of that data on our systems. All traffic between the Add-on and Google's APIs, and between your recipients' email clients and the optional tracking relay, travels over encrypted HTTPS/TLS connections. The relay stores nothing and holds no credential to your account; the only secret it forwards is the write-only Measurement Protocol key belonging to — and confined to — your own Google Analytics property. Access to our relay's operational infrastructure is limited to authorized personnel for security and maintenance.

5. What we do not do

6. Limited Use compliance

Emerge: Mail Merge's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is used only to provide the user-facing features described above and is not transferred to others except as necessary to provide those features, to comply with applicable law, or as part of a merger or acquisition with notice to you.

7. Data retention

Templates and settings persist in your spreadsheet until you delete them or the spreadsheet. Tracking events transit the relay in memory only and are not retained by us; the aggregated metrics are retained by Google Analytics under your Analytics account's own retention settings. Standard server access logs for the relay may be kept briefly for security and operational purposes.

8. Revoking access

You can revoke the Add-on's access at any time by:

To stop tracking, turn off analytics in the Add-on; you may also delete the "Emerge Mail Merge" property from your Google Analytics account.

9. Children

The Add-on is intended for use by adults sending email from their own accounts and is not directed to children under 13.

10. Changes to this policy

We may update this policy from time to time. Material changes will be reflected by updating the "Last updated" date at the top of this page.

11. Contact

Questions about this policy can be sent to support@redigit.net.