Legal
Privacy Policy
Effective 8 October 2026.
This policy explains what personal data Sheet Reserve collects, why we use it, who receives it, how long we keep it and what rights you have. It covers https://sheetreserve.com and the emails we send.
The short version
- We collect what we need to run your account, your membership and your downloads, and to keep the service secure.
- There are no analytics, no advertising, no tracking pixels and no third-party scripts. We don't sell your personal data or share it for advertising.
- Gumroad handles payments, and we never see your card details.
- We use only strictly necessary cookies. See the Cookie Policy.
- You can delete your account yourself at any time on your account page.
Who is responsible for your data
Sheet Reserve is run by Yunus Emre Vurgun, an individual developer, as a personal project from Istanbul, Türkiye (yunusemrevurgun.com). He is the controller of the personal data described in this policy: the "controller" under the GDPR and UK GDPR, and the "veri sorumlusu" (data controller) under Türkiye's Personal Data Protection Law No. 6698 (KVKK). In this policy, "we", "us" and "our" mean him.
For any privacy question or request, email [email protected].
What we collect
| Data | What it includes |
|---|---|
| Account | Email address, name (optional), password hash, email-verification status, and account timestamps such as when the account was created |
| Sign in with Google | Only if you use it: your Google account identifier, email address, whether Google says the address is verified, and your name |
| Membership and license | Received from Gumroad: purchase email, license key (encrypted at rest), sale ID, product ID, subscription status and dates, and any refund, chargeback or dispute flags |
| Sessions | A random session token (we store only a hash of it), IP address, browser user agent, and when the session was created and last seen |
| Security log | Sign-ins, failed sign-ins, password changes and license activation events, each with IP address and user agent |
| Download log | Which sheet you downloaded, in which format, when, and from which IP address |
| Rate-limit counters | Counts of recent requests, keyed by a hashed IP address or email address |
| Support emails | Your email address and anything you write to us |
| Request data | Your IP address and details of each request, such as the page requested and your browser's user agent, which Cloudflare processes on every visit |
Passwords are stored only as Argon2id hashes, never in readable form.
We don't collect payment card details, your Google password or your Google contacts, and we don't collect analytics or advertising data.
If you use Sign in with Google
Sign in with Google uses OAuth and OpenID Connect. We request only the openid, email and profile scopes, and we use what Google sends us only to sign you in and run your account. You can remove Sheet Reserve's access in your Google Account settings at any time. To delete the data we hold, delete your Sheet Reserve account.
Our use of information received from Google follows the Google API Services User Data Policy, including its Limited Use requirements.
Membership data from Gumroad
When you buy or renew a membership, Gumroad sends us the details listed above. We use them to link the membership to your account and keep its status up to date. We check the status with Gumroad's API from time to time, and whenever Gumroad notifies us of a sale, refund, cancellation or a membership ending.
Why we use it, and our legal bases
Data protection law requires a legal basis for each use of personal data. These are ours:
| Purpose | Data used | Legal basis |
|---|---|---|
| Creating and running your account: sign-up, email verification, sign-in, password resets and keeping you signed in | Account data, Google sign-in data, sessions | Performing our contract with you (GDPR Art. 6(1)(b); KVKK Art. 5(2)(c)) |
| Providing your membership and downloads: linking the membership to your account, checking its status with Gumroad, and delivering files and free samples | Membership and license data, account data, download log | Performing our contract with you (GDPR Art. 6(1)(b); KVKK Art. 5(2)(c)) |
| Sending account emails: email verification, password resets, membership activation and security notices | Email address, name | Performing our contract with you; for security notices, also our legitimate interest in protecting your account (GDPR Art. 6(1)(f); KVKK Art. 5(2)(f)) |
| Protecting the service: spotting suspicious sign-ins, preventing fraud and abuse, applying rate limits and fair-use limits, and stopping scraping and account sharing | Sessions, security log, download log, rate-limit counters, request data, refund and dispute flags | Our legitimate interests in keeping the service, its members and its content secure (GDPR Art. 6(1)(f); KVKK Art. 5(2)(f)) |
| Answering your emails | Support emails, and account data where relevant | Our legitimate interest in responding to you, or performing our contract with you where your email concerns your account or membership |
| Meeting legal obligations, such as answering privacy requests and valid requests from authorities | The data the request concerns | Legal obligation (GDPR Art. 6(1)(c); KVKK Art. 5(2)(ç)) |
| Establishing, exercising or defending legal claims, such as a payment dispute | Membership and license data, relevant logs | Our legitimate interests (GDPR Art. 6(1)(f)); establishing, exercising or protecting a right (KVKK Art. 5(2)(e)) |
You need an email address, or a Google account, to create a Sheet Reserve account. Without one we can't give you an account, free samples or a membership. Your name is optional. We don't rely on consent for any of the processing in this policy, and we don't use your data for advertising or marketing.
Where the data comes from
All of it is collected electronically:
- from you, when you sign up, sign in, change your password or email us;
- from Google, if you use Sign in with Google;
- from Gumroad, when you buy, renew or cancel a membership or get a refund; and
- from your browser, automatically, as you use the site (IP address, user agent and cookies).
Who receives it
We don't sell personal data. We share it only with the service providers below, and with public authorities when the law requires it.
| Recipient | What they do | Data involved | Location |
|---|---|---|---|
| Namecheap, Inc. | Web hosting and outgoing email | Everything stored on our servers, and the emails we send you | Servers in the United States |
| Cloudflare, Inc. | Content delivery, and protection against DDoS attacks and bots | IP addresses and request data for every visit, and strictly necessary security cookies | US company with a global network |
| Google LLC | Sign in with Google, only if you choose to use it | The sign-in details listed above. Google also learns that you used it to sign in to Sheet Reserve | US company |
| Gumroad, Inc. | Sells the membership as merchant of record and handles payment | The purchase details you give Gumroad, and the membership details we check through Gumroad's API | US company |
Namecheap and Cloudflare process data on our behalf. Gumroad handles purchase data partly on our behalf and partly for its own purposes, such as fraud prevention; its privacy policy explains which is which. Google handles your Google account under Google's privacy policy. You can also read the privacy policies of Cloudflare and Namecheap.
International transfers
Sheet Reserve is run from Türkiye, its servers are in the United States, and Cloudflare handles traffic through data centers around the world. If you live elsewhere, your data is processed outside your country, under laws that may protect it differently. Where the law requires safeguards for these transfers, we rely on the safeguards these providers offer, such as standard contractual clauses.
How long we keep it
| Data | How long we keep it |
|---|---|
| Account data, including Google sign-in and license data | Until you delete your account |
| Accounts whose email address is never verified | Deleted after 30 days |
| Sessions | Expire 30 days after last use, or when you sign out |
| Email verification links | Expire after 24 hours |
| Password reset links | Expire after 1 hour |
| Download log and security log | 12 months |
| Rate-limit counters | From a few minutes up to 24 hours |
| Support emails | As long as needed to deal with your request and any follow-up |
| Request data processed by Cloudflare | Kept by Cloudflare under its own terms and privacy policy |
| Backups kept by our host | Roll over within 30 days |
| Gumroad's purchase records | Kept by Gumroad under its own policy |
When you delete your account on your account page, we remove the account, its sessions, tokens, download history, security log entries and the linked license record from the live database. Copies in our host's backups roll over within 30 days.
Deleting your account doesn't cancel your membership in Gumroad. If you don't want it to renew, cancel it in Gumroad first; Refunds and Cancellation explains how.
Emails we send
We send only transactional emails:
- a link to verify your email address;
- password reset links;
- security notices, such as when your password changes or when someone tries to register with your email address; and
- confirmation that your membership is active.
We don't send marketing emails.
Cookies and browser storage
We use only strictly necessary cookies: to keep you signed in, to protect forms and for Cloudflare's bot protection. The library may remember your sort and filter choices in your browser's local storage, which stays on your device. The Cookie Policy lists every cookie.
Your rights
Under the GDPR and UK GDPR
If you're in the European Economic Area or the United Kingdom, you have the right to:
- access your personal data and get a copy of it;
- correct data that is inaccurate or incomplete;
- erase your data;
- restrict how we use your data in certain situations;
- data portability, which means receiving the data you gave us in a structured, machine-readable format, or having it sent to another provider where that's technically feasible;
- object to processing based on our legitimate interests, in which case we'll stop unless we have compelling grounds or need the data for legal claims; and
- complain to a data protection authority (see "Complaints" below).
Under KVKK (Türkiye)
Article 11 of Law No. 6698 gives you the right to:
- learn whether your personal data is processed;
- request information about the processing, if it is;
- learn the purpose of the processing and whether your data is used for that purpose;
- know the third parties, in Türkiye or abroad, to whom your data is transferred;
- ask for incomplete or inaccurate data to be corrected;
- ask for your data to be erased or destroyed under the conditions in Article 7;
- ask for third parties who received your data to be told about any correction, erasure or destruction;
- object to a result that is against your interests and arises from analysis of your data solely by automated systems; and
- claim compensation for damage you suffer because your data was processed unlawfully.
Under US state privacy laws
We don't sell your personal information, and we don't share it for cross-context behavioral advertising. We use your sign-in details, which some state laws treat as sensitive, only to provide and secure your account. In the categories California law uses, we collect identifiers (such as your email address and IP address), commercial information (membership records) and internet or other electronic network activity (such as download and security logs), for the purposes and periods described above. You can ask to know, correct or delete the personal information we hold about you, and we won't treat you differently for doing so.
Because we don't sell or share personal information or track you across other sites, Global Privacy Control and Do Not Track signals don't change how we handle your data.
How to use your rights
Email [email protected], ideally from the email address on your account, and tell us what you'd like us to do. You can also delete your account yourself on your account page.
We may need to confirm that you're the account holder before we act on a request. We don't charge for requests. We'll answer within the time the law sets: one month under the GDPR and UK GDPR (which can be extended by up to two more months for complex requests), and as soon as possible and within 30 days at the latest under KVKK.
Complaints
If you have a concern, please email us first so we can try to resolve it. You also have the right to complain to a supervisory authority:
- In the European Economic Area, the data protection authority in the country where you live or work, or where you think the problem happened. The European Data Protection Board keeps a list of national authorities.
- In the United Kingdom, the Information Commissioner's Office.
- In Türkiye, the Personal Data Protection Board of the Personal Data Protection Authority (KVKK). Under KVKK, you must apply to us first. If we reject your request, our answer is insufficient or we don't answer in time, you can complain to the Board within 30 days of learning of our answer, and in any case within 60 days of the date you applied to us.
Automated decisions
Rate limits and Cloudflare's bot protection automatically slow down or block traffic that looks like abuse, such as scraping. They don't make decisions that have legal or similarly significant effects on you. If you think you've been blocked by mistake, email us and we'll look into it.
Security
We protect your data with HTTPS on every page (with HSTS), Argon2id password hashing, hashed session tokens, encrypted license keys, CSRF protection, a strict Content Security Policy, rate limiting with progressive delays on sign-in, and email verification. No system is perfectly secure, so we can't guarantee that your data will never be accessed without authorization. If a breach affects your personal data, we'll notify you and the relevant authorities as the law requires. Security has more detail, including how to report a vulnerability.
Children
Sheet Reserve isn't directed to children under 16, and we don't knowingly collect their personal data. If you believe a child under 16 has given us personal data, email us and we'll delete it.
Changes to this policy
When we change this policy, we'll post the new version here and update the effective date. We'll announce material changes on the site and by email to account holders at least 14 days before they take effect, where reasonable.
Contact
For privacy questions and requests, email [email protected]. The controller is Yunus Emre Vurgun, Istanbul, Türkiye.