MergeFlow Privacy Policy

Effective Date: September 9, 2026

MergeFlow ("MergeFlow", "we", "us") provides mail merge functionality for Google Workspace. This Privacy Policy explains what information MergeFlow accesses, why it is accessed, how it is used, and the choices available to you. MergeFlow is an independent product and is not affiliated with or endorsed by Google.

MergeFlow is currently a Google Workspace add-on built using Google Apps Script and Google Workspace services authorized by the user.

Information We Access

MergeFlow may access information necessary to provide the mail merge functionality you request, including:

  • Google Sheets content used for recipient data
  • Google Docs content used as message templates
  • Google Drive file identifiers and limited metadata required to connect campaign files
  • email addresses supplied by the user
  • merge-field information supplied by the user
  • information required to send messages through the user's Google account
  • basic Google account information provided through Google authentication where applicable

How We Use Information

Information accessed by MergeFlow is used to:

  • validate recipient data
  • identify merge fields
  • associate campaign Sheets and Docs
  • generate personalized previews
  • create personalized messages
  • send messages at the user's direction
  • record campaign sending status associated with the user's campaign

MergeFlow does not sell Google user data.

MergeFlow does not use Google Workspace data for advertising.

MergeFlow does not use Google Workspace data to train generalized artificial intelligence or machine learning models.

MergeFlow accesses Google user data only as necessary to provide user-requested functionality.

Google Workspace and Google APIs

MergeFlow operates within Google Workspace and uses Google APIs authorized by the user during the Google consent process. The permissions requested are those needed to read the spreadsheet and document you select, personalize your messages, and send email from your authorized Google account.

Google API Services User Data Policy

MergeFlow's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Data Storage

MergeFlow primarily processes information within the user's Google Workspace environment. Campaign configuration and sending status may be stored in or associated with Google Workspace files used by the user.

Information submitted through the MergeFlow support form—including your name, email address, selected topic, and message—is processed by Lovable's managed transactional email service and delivered to MergeFlow's support inbox. This support information may therefore be processed or stored outside your Google Workspace environment. It is used only to respond to your request and operate support.

Data Sharing

MergeFlow does not sell Google user data and does not share your Google Workspace content with third parties for their own purposes. Messages you send are transmitted through Google services using your authorized Google account. Information may be disclosed where required by law or where necessary to address fraud, abuse, or security issues.

Data Retention

Campaign configuration and sending status are stored in or associated with the Google Workspace files used for the campaign. Users may remove campaign information by deleting the relevant MergeFlow campaign data or associated files. Some information may remain subject to Google's own file retention, trash, backup, or administrative policies.

Security

We use reasonable administrative and technical measures designed to protect information handled by MergeFlow. MergeFlow also relies on the security controls of Google Workspace and your own Google account, including the account protections and sharing settings you configure.

User Choices and Access

You choose which spreadsheet and document a campaign uses, and you decide when a campaign is sent. You may revoke MergeFlow's access at any time through your Google Account permissions settings. You may also request information about this policy by contacting us.

Children's Privacy

MergeFlow is not directed to children as end users. Organizations using MergeFlow may process recipient information relating to students or minors. Those organizations are responsible for determining whether their use of MergeFlow complies with applicable privacy laws, organizational policies, and consent requirements.

Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will revise the effective date above. Continued use of MergeFlow after an update indicates acceptance of the revised policy.

Contact Us

MergeFlow · admin@mergeflow.app

See also our Terms of Service and Support page.

Questions about this policy may be sent to admin@mergeflow.app.