Privacy policy
Last updated: 15 September 2026.
TickerFetch is an independently operated Google Sheets add-on. This page describes exactly what data is handled and why. Questions or requests: support@tickerfetch.com.
What is collected
- Your email address — when you request a licence key. It is the identifier for your licence and, if you subscribe, for your subscription.
- Your licence key — generated by us and stored alongside the email address and expiry date.
- Ticker symbols and lookup parameters — the symbols your formulas ask for, plus the formula’s arguments (such as the attribute or history range), are sent to the API so the market data can be returned.
- Request logs — server logs of API requests, including your IP address, which is also used to rate-limit the key-request form. Each request and its response — including the IP address, the licence key, the email address the key was issued to and the symbols requested — is also forwarded to a log service so that usage and errors can be monitored, and is kept there for 30 days.
- Website usage — only if you accept analytics on the consent bar: the pages you open and the buttons and forms you use, together with your IP address (used by Google for a rough location and not stored) and browser and device details, processed by Google Analytics. See Cookies and analytics.
What is not collected
- No cookies and no third-party scripts unless you accept analytics on the consent bar; declining leaves the site cookie-free. No advertising or cross-site tracking either way — Google Signals and ad personalisation are switched off.
- No contents of your spreadsheets. The add-on requests the narrowest Google permission available, which limits it to the spreadsheet it is used in, and only the ticker symbols, the formula’s lookup parameters and your key are ever sent to our server.
- No card details. If you subscribe, payment is handled entirely by Stripe.
Why, and on what basis
Your email address and licence key are processed to provide the service you asked for (performance of a contract). Request logs and rate limiting are processed to keep the service running and to prevent abuse (legitimate interests). Website analytics run only with your consent, which you can withdraw at any time under Cookies and analytics. We do not send marketing email, so there is no marketing consent to give or withdraw.
Who else processes it
- DigitalOcean — hosting.
- Resend — delivery of the key email. It receives your email address for that purpose only.
- Google — the Apps Script platform the add-on runs on, and — only if you accept analytics — Google Analytics (Google Ireland Ltd.). Analytics data may be processed in the United States under the EU–US Data Privacy Framework.
- Yahoo Finance — receives the ticker symbols in order to return market data. It does not receive your email address or key.
- Stripe — payment processing, if you subscribe.
- Axiom (EU region) — stores the API request logs described above for 30 days.
How long it is kept
Your email address, key and expiry are kept while the licence exists, and are deleted on request. Server logs rotate automatically; the forwarded request logs are kept for 30 days. Deleted records may remain in routine backups for a short period before those backups are overwritten.
Market data is cached briefly so that repeated formulas don’t re-request the same prices — for a short time inside the add-on, and for a longer but still limited period on our server, depending on how often the data changes. These caches expire automatically, are keyed by ticker symbol, and hold market data only: no personal data and no spreadsheet content.
Removing the add-on ends its access to your spreadsheets and to the licence key stored with your Google account. Your licence record on our side is kept, so the same key works again if you reinstall; ask us and we will delete it.
How it is protected
- Everything is encrypted in transit. This website, the add-on and our API communicate only over HTTPS; unencrypted requests are never served.
- Access is restricted. Only the operator can reach the systems that hold your data, and that access is protected by key-based authentication.
- No spreadsheet content is stored. The only data that leaves your spreadsheet is the ticker symbols and lookup parameters your formulas use. Nothing else — no other cell contents, no sheet names, no file metadata — is transmitted or stored.
- No card details reach us. Payments are processed by Stripe; we never see or store card data.
No method of transmission or storage is completely secure, so while these measures substantially reduce risk, they cannot remove it entirely.
Cookies and analytics
The first time you visit, a bar at the bottom of the page asks whether Google Analytics
may be used. If you decline, or never answer, nothing from Google loads and no cookies
are set. If you accept, Google Analytics sets two cookies — _ga and one
beginning _ga_ — that hold a random identifier for up to 13 months, so that
repeat visits can be told apart. Usage data is kept in Google Analytics for 14 months.
Your answer itself is kept in your browser’s storage (tf-consent) so
you are not asked on every page.
To change your answer or withdraw consent, use the button below. It deletes the analytics cookies and shows the bar again.
Your rights
You can ask for a copy of your data, correction of it, or its deletion. Email support@tickerfetch.com from the address the key was issued to and it will be handled manually — deleting the record also invalidates the key. If you are in the EU or UK you also have the right to complain to your data protection authority.
Google user data
TickerFetch’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Data obtained through those APIs is used only to provide the market-data lookup features described on this site. It is never sold or transferred to data brokers, never used for advertising, never used to determine credit-worthiness or for lending, never used to build a database, and never used to train AI or machine-learning models. No human reads this data except where you have given explicit consent, where it is necessary for security purposes or to comply with applicable law, or where the data has been aggregated and anonymised.
Google user data is accessed only inside the spreadsheet you use the add-on in. To return data, the add-on reads the cells that contain TickerFetch formulas — including the ticker symbols they reference — and writes the results back into that same spreadsheet. Those ticker symbols and lookup parameters are sent to our API and on to our market-data provider so that prices can be returned. Nothing else from your spreadsheet is transmitted to us, stored on our servers, or shared with anyone; the one piece of Google account data the add-on reads, your email address, is described under the last permission below.
The add-on requests four Google permissions, and no others:
https://www.googleapis.com/auth/spreadsheets.currentonly— read and write the single spreadsheet you use the add-on in, so that formulas can be found and their results written back. It gives no access to your other files.https://www.googleapis.com/auth/script.external_request— contact our API to fetch market data.https://www.googleapis.com/auth/script.container.ui— display the sidebar in which you paste your licence key.https://www.googleapis.com/auth/userinfo.email— read the email address of the Google account you use the add-on with. It is used for one thing: the links from the sidebar to tickerfetch.com carry it so the trial and subscribe forms there are already filled in. It is not displayed, not stored by the add-on, and sent nowhere else. The address shown next to your key in the sidebar is the one your key was issued to, returned by our API.
Changes
If this policy changes materially, the date at the top of the page changes with it.