Holiday Formulas for Google Sheets™
Privacy policy
Last verified against the running service on 22 September 2026. Every statement below describes what the deployed software actually does, not what it is meant to do.
Spreadsheet data stays in Google
Your spreadsheet contents never reach us. A Holiday Formulas formula sends only a country or region code and the years it needs to the data service at api.holidayformulas.com. Dates you pass in, custom closure ranges, cell contents and the document itself are processed inside Google Apps Script and are never transmitted to us.
What licence verification sends and stores
For Pro owners the add-on sends a licence key and a random seat identifier, both in request headers rather than in a web address, so neither can appear in a URL, a browser history or a server access log. The key is an HMAC of your Paddle customer identifier; it contains no personal data and cannot be reversed into one.
When you use the add-on’s menu or sidebar, it reads the email address of the Google account you are signed in to, so it can tell you whether the licence you are activating will apply to this spreadsheet — Pro follows the owner of a file, not the person editing it. That is what the userinfo.email permission on the consent screen is for. The address is compared in memory and never stored, never sent to our servers and never logged. Formulas cannot read it at all.
The spreadsheet owner’s Apps Script user properties hold five values: the key, the seat identifier, whether Pro is active, the paid-through date and the time of the last verification. A separate document-level marker records the year of the last full recalculation so the add-on can tell you when the free-year window has rolled over. Formulas only read these values; they never write them.
Our licence service stores, for each licence, a hash of the key, your Paddle customer identifier, the most recent subscription identifier, when the record was created and, once a subscription ends, when it ended. For each seat it stores the seat identifier, when it was activated and, if released, when. That is the complete list. We hold no names, no email addresses and no payment details. A short-lived cache holds the derived paid-through date and subscription status for at most 6 hours, and a small marker recording that a customer’s cached entitlement was invalidated, which holds nothing but that fact and expires by itself within about half a day. Neither holds anything beyond the customer identifier, the paid-through date and the subscription status.
Payments and the companies involved
Paddle is the merchant of record for every purchase. Your name, email address, billing address and payment details are collected and held by Paddle, not by us. Cloudflare hosts this site, the holiday data service and the licence service. Google hosts your spreadsheet and runs the add-on’s code and storage.
Cloudflare Web Analytics is not enabled on this site. If that changes, this page will say so before it does.
How long we keep licence records
A licence record and its seats are deleted 90 days after the later of two dates: the day the subscription ended, and the day the coverage you paid for runs out. Taking the later of the two means a cancellation never deletes the access you already paid for. Records belonging to an active subscription are not deleted.
Contact
Planned contact: support@holidayformulas.com — placeholder, mailbox not yet verified. The operator’s identity and contact details must be completed before launch.