Sheet2Mail
Data protection briefing / version 1.0

A smaller data footprint for spreadsheet email dispatch.

This briefing explains the Sheet2Mail data flow for IT, procurement, data protection officers, and other reviewers. It is product documentation, not legal advice.

01Google SheetsThe organization keeps the roster, fields, filters, and approvals in its spreadsheet.
02DispatchThe selected recipient data is used to personalize and deliver the message through SMTP or the managed relay.
03AnalyticsOpens and clicks are matched to a one-way hash rather than a readable email address.

What remains under the organization's control

  • The source roster and the spreadsheet permissions.
  • The lawful basis, consent records, and suppression process.
  • The sender identity, domain authentication, and delivery policy.
  • Retention, access, and deletion decisions for the campaign.

What the analytics layer receives

  • A one-way cryptographic hash used to match events to a message.
  • Campaign-level delivery, open, click, and error state.
  • A link identifier for click reporting, not a contact directory.
  • No need to create a second readable contact database for reporting.

Delivery choices

Use your own SMTP server when delivery must remain in-house. Use the managed relay when the Google Workspace sending quota is the constraint. Record the selected boundary in your internal review.

Questions for your review

Confirm the applicable lawful basis, processor terms, hosting requirements, transfer safeguards, retention period, access controls, and deletion process for your organization and campaign.

The short version Keep the working data in the Sheet. Use a controlled delivery path. Measure the campaign with one-way identifiers. Treat this document as a starting point for your own legal and security assessment.