Call Sheet Tools Privacy Policy

Effective date: May 12, 2026 Last updated: [v2.0 release date] Applies to: Call Sheet Tools v2.0 and later (v1.5–1.6 buyers: the prior policy version applies until you upgrade)

This Privacy Policy describes how Saliga.Studio (“we,” “us,” or “our”) handles information when you use Call Sheet Tools, the Google Sheets template and bound Apps Script sold via andrewsaliga.com.

We’ve kept this short and direct: the script does specific things with specific data, and you deserve to know what.

Who we are

Saliga.Studio Operated by Andrew Saliga Tulsa, Oklahoma, USA Contact: support@saliga.studio

What the script accesses on your Google account

When you first run a Call Sheet Tools menu item, Google asks you to grant permissions. You must accept all of them for the script to function. Here’s what each permission is for, in plain language:

Permission line on the consent screen What it does in the script
See, edit, create, and delete all your Google Sheets spreadsheets Reads and writes your call sheet, and creates and maintains exactly one other file: your Crew Library spreadsheet (created in your Drive the first time you save crew to it). v1.x used a narrower “current spreadsheet only” permission; the Crew Library feature requires this broader one because the library is a separate file. The script touches no spreadsheet other than the call sheet it’s bound to and the Crew Library it created.
See and download all your Google Drive files Sounds broader than it is—used for one job: rendering the call sheet to PDF via Google’s Drive export endpoint. The endpoint requires a Drive scope; Google offers no narrower one for PDF export on a container-bound spreadsheet. The script never lists, opens, or downloads any other file in your Drive.
Connect to an external service Calls our license server, weather APIs, geocoding APIs, the Google Maps proxy, and (when you enable it) the delivery-confirmation service. Specific endpoints listed below.
Send email as you Sends call sheets and calendar invites to your crew when you use Send Call Sheet to Crew. Emails come from your Gmail address, not ours. Uses the narrow script.send_mail scope — the script cannot read, search, or delete any email in your inbox.
Allow this application to run when you are not present Runs the optional 6 AM weather refresh trigger you schedule, and the daily license re-validation trigger.
Display and run third-party web content in prompts and sidebars inside Google applications Renders the modal dialogs (Project Setup, Add Crew, etc.) the script uses.
See your primary Google Account email address Used as the recipient for the recap email, as the organizer field on calendar invites, and as the account your license binds to.

Your Crew Library and day rates

The Crew Library — including any day rates you enter — is a spreadsheet in your own Google Drive, owned by you. It is never transmitted to us or to any third party. Day rates are used only to build the hidden Crew Budget tab inside your project; they are never written to the printed call sheet, the exported PDF, or any email the script sends.

What information we collect on our servers

Two categories of data reach our infrastructure, and only these:

1. License data. Your license key and the Google account email(s) it is bound to. We store the key, its account roster (the Google accounts authorized to run copies of the template), per-account activation and validation timestamps, and a count of bound accounts. Per-license caps limit people, not spreadsheets — make as many copies as you like. As of v2.0, your copy of the template authenticates with an opaque access token rather than transmitting the license key itself on every request.

2. Delivery-confirmation records (optional). When you send a call sheet with Request delivery confirmations checked (it’s on by default, and you can turn it off per send), we store no information about your crew at all. For each recipient we receive only an opaque reference and a random token — no name, no email address, no project title, no day label — plus a send timestamp and, if the recipient taps the confirmation link, a confirmation timestamp. The mapping from those tokens back to your crew’s names and emails is kept only in your own spreadsheet (a hidden tab in your Google account) and never reaches us; the Confirmation Status window joins the two locally so you see who confirmed. These records contain no personal data, no call times, no phone numbers, no rates, and no call sheet content, and the opaque records are automatically deleted 60 days after the send. Sending with the checkbox off transmits nothing — crew confirm by replying to your email instead.

We do not collect, transmit, or have access to:

  • The contents of your call sheet (project details, schedules, phone numbers)
  • Your Crew Library, including day rates
  • Your shoot locations or the addresses you geocode¹
  • Your weather forecasts
  • The body or attachments of the emails you send through Send Call Sheet to Crew
  • Your calendar invite content

¹ Addresses you geocode pass through our Maps proxy (see below) and appear in short-lived operational logs, but are not collected or stored beyond those logs.

Third-party services the script contacts

Service What it sees Why
Google Maps Platform (Geocoding, Places, Directions APIs) — routed through our proxy at andrewsaliga.com Location addresses you enter Convert addresses to coordinates, find nearest hospitals, calculate drive times
Open-Meteo (open-meteo.com) Coordinates of your primary location and the shoot date Generate weather forecasts
api.weather.gov (U.S. National Weather Service) Coordinates of your primary location Severe weather alerts (U.S. only)
Nominatim (nominatim.openstreetmap.org) Location addresses (fallback only) Geocoding fallback when Google APIs are unavailable
Overpass API (overpass-api.de) Location coordinates (fallback only) Hospital lookup fallback when Google Places is unavailable
andrewsaliga.com (our store and proxy) Your license credential; opaque per-recipient references and tokens when delivery confirmations are enabled (no names, no emails) License activation and validation; delivery-confirmation tracking

Each service has its own privacy policy. You should review the ones you care about:

Why we use a proxy for Google Maps

Google Maps API calls go through our server at andrewsaliga.com rather than directly from your script. This means our API credentials are held centrally instead of distributed in every buyer’s bound script. The proxy forwards your Maps query and returns the result. Your query (typically an address or coordinate pair) is logged by the proxy for rate limiting and abuse prevention. Logs are retained for 30 days and used only for operational purposes (debugging, quota management). They’re not used for marketing, sold to third parties, or correlated with other data.

What we store

On our servers (andrewsaliga.com): your license key, the Google account email(s) on its roster, per-account activation and last-validation timestamps, a count of bound accounts, and the access tokens that v2 copies use to authenticate. When delivery confirmations are enabled: only the opaque per-send records described above (references, tokens, timestamps — no crew names or emails), for up to 60 days.

In your Google account (UserProperties): your license access token (v2) or key (v1.x), a display-masked copy of your key, validation timestamps and status, the file ID of your Crew Library, and a short list of your recent confirmation-tracked sends (so the Confirmation Status window knows what to ask about). Stored by Apps Script in your own Google account; we don’t have access to it.

In your Google Drive: your Crew Library spreadsheet, the hidden Crew Budget tab inside your projects, and — when you use delivery confirmations — a hidden tab in your call sheet that maps confirmation tokens back to crew names so the status window can show them. All yours, not ours.

Proxy logs (andrewsaliga.com): rolling 30-day logs of API calls for rate limiting and debugging. Each entry contains the query, timestamp, and a credential fingerprint (not the key itself). No personally identifiable information beyond what the user typed into the query field.

Retention

License records are retained for the lifetime of your purchase plus a reasonable period afterwards for dispute resolution and tax/accounting purposes (typically 7 years for U.S. tax compliance).

Delivery-confirmation records auto-delete 60 days after the send. To have a send’s records removed sooner, email support@saliga.studio with the project name and send date.

If you remove the license from your Google account using the License Status menu item, the local cache in your Google account is deleted immediately and the account’s access token is revoked on our server. The license record on our server remains.

Proxy logs auto-purge after 30 days.

Email

When you send call sheets to crew using Send Call Sheet to Crew, those emails are sent directly from your Gmail account through Google’s MailApp service. We do not see, log, or store the content of those emails — including each recipient’s personalized call time. Your crew’s names and email addresses never leave your Google account: even with Request delivery confirmations checked, we receive only opaque references and tokens, never the people behind them. The same applies to the recap email you receive in your own inbox after each send.

When a crew member taps a confirmation link, they reach a page hosted on our infrastructure that records the confirmation timestamp for that send. The link contains a random token — not their email address, and not their name — and works without any login. The page itself shows no personal information.

When you export a calendar invite using Export Calendar Invite, the resulting .ics file is generated from your sheet’s data and downloaded directly. It’s never transmitted to our servers.

Cookies and tracking

The Apps Script itself does not set cookies or use tracking technologies. The confirmation page sets no cookies and contains no analytics. Our website (andrewsaliga.com) may use cookies for normal e-commerce functionality. See the website’s privacy policy for details.

Your rights

You have the right to:

  • Access the personal information we hold about you (your license records, and any active confirmation records from your sends).
  • Correct inaccurate information.
  • Delete your data by requesting we revoke your license and remove your records. (Note: deletion may make your purchased license unusable.) Confirmation records can be deleted on request without affecting your license.
  • Object to processing or request portability of your data.

To exercise any of these rights, email support@saliga.studio. We respond within 30 days.

Because delivery-confirmation records on our servers contain no crew names or emails — only opaque tokens we cannot trace back to a person — we are unable to identify an individual crew member in those records. Crew members who want their information removed should contact the producer who sent them the call sheet; the crew name↔token mapping lives only in that producer’s own spreadsheet.

If you are in the European Economic Area, the United Kingdom, or California, you have additional rights under GDPR, UK GDPR, or CCPA respectively. Contact us at the same address.

Children

Call Sheet Tools is a professional tool sold to commercial photographers, videographers, and production teams. We do not knowingly collect data from anyone under 16. If you believe a child has provided us with information, contact us and we will delete it.

Security

We use standard industry practices: HTTPS for all transmission, third-party processors with their own security commitments (Google, Open-Meteo, OpenStreetMap), and a hosted WordPress + WooCommerce stack on andrewsaliga.com with regular updates. As of v2.0, your copy of the template authenticates with a revocable access token instead of transmitting the license key, and confirmation links use single-purpose random tokens. The bound script is inspectable in your own Apps Script editor at any time if you want to audit what runs.

No system is perfectly secure. If you suspect your account or license has been compromised, contact us immediately.

Changes to this policy

We may update this policy from time to time. The “Last updated” date at the top will reflect any changes. Material changes will be communicated via email to active license holders.

Contact

Questions, requests, or concerns:

support@saliga.studio — Tulsa, Oklahoma, USA

See Also: Terms of Service