Privacy Policy
Last updated: August 3, 2026
GMerge ("we", "us") provides a Chrome extension and web app at www.gmerge.co that help you send personalized mail-merge campaigns from Gmail. This policy explains what data we collect and how we use it.
1. Who this applies to
This policy covers the GMerge website, API, and Chrome extension. By using GMerge you agree to this policy.
2. Data we collect
- Account information: Google account email and name when you connect Gmail via OAuth.
- Authentication data: session tokens (cookie) and encrypted Gmail OAuth refresh/access tokens needed to send email on your behalf.
- Campaign content: campaign names, subjects, HTML bodies, merge tags, follow-up steps, and recipient lists (including email addresses and CSV field values you upload or paste).
- Email engagement: open and click events for tracked messages, including approximate time, link URL (for clicks), and optionally IP address and user-agent from the request.
- Billing: if you subscribe to Pro, Stripe processes payments. We store Stripe customer/subscription IDs and plan status; we do not store full card numbers.
- Extension settings: API/dashboard URL and a cached connection status stored locally in the browser via Chrome storage.
3. How we use data
We use this data only to operate GMerge's single purpose:
- Authenticate you and keep you signed in
- Send personalized mail-merge email through your Gmail account
- Schedule follow-ups and stop them on reply/unsubscribe
- Show open/click tracking and campaign status in the dashboard
- Provide subscription billing and plan limits
- Maintain security, prevent abuse, and improve reliability
4. Google / Gmail access
GMerge requests Google OAuth scopes required to send email and detect replies for follow-ups (such as Gmail send and read-related scopes). Emails are sent via the Gmail API from your account. We do not use Google user data for advertising or transfer it to third parties for unrelated purposes. Use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
5. Sharing
We do not sell your personal data. We share data only with processors needed to run the service, for example:
- Google (OAuth and Gmail API)
- Stripe (subscription payments)
- Hosting/database providers that store our application data
We may disclose information if required by law or to protect the security of the service or our users.
6. Retention
We retain account, campaign, and event data while your account is active and as needed to provide the service. You may request deletion of your account data by contacting us (see Support). Encrypted Google tokens are removed when you disconnect or we delete your account.
7. Security
We use HTTPS, httpOnly session cookies, and encryption at rest for Gmail refresh tokens. No method of transmission or storage is 100% secure; please protect access to your Google account.
8. Your choices
- Sign out from the GMerge dashboard
- Revoke GMerge access in your Google Account permissions
- Uninstall the Chrome extension
- Contact us to request export or deletion of your data
9. Children
GMerge is not directed to children under 13, and we do not knowingly collect data from them.
10. Changes
We may update this policy from time to time. The "Last updated" date at the top will change when we do. Continued use of GMerge after updates means you accept the revised policy.
11. Contact
Questions about privacy: see our Support page or email support@gmerge.co.