The protection of your personal information is our priority. We want you to feel safe while using our Shared Email Templates for Outlook ("Shared Email Templates" or "SET"). However, Shared Email Templates would not work if we didn't collect certain data. On this page, you can find detailed information on what data we collect, how we protect it, and where we store it.
What data we collect
Personal data
When you create an account (profile), you enter your first and last name, username, email address, and password. We collect this information so that you can sign in to your account.
Templates
While creating a template for email messages, appointments, signatures, and mail merge, you enter its name, description, and contents. All this information is saved so that you can use your templates.
Note. When you attach files from any cloud storage to your templates, we do not save your credentials for these storages, such as OneDrive or any other.
Teams
We save the names of your teams, descriptions, members, their email addresses, and teammates permissions.
When you contact our customer support service, we keep all your email and chat messages.
Required permissions
Your use of our products does not give us access to any sensitive personal data stored in your Microsoft account such as physical address or credit card details.
Depending on the Shared Email Templates feature you're going to use for the first time, you'll get the corresponding permissions request. We use each of the permissions granted by you for a specific purpose. Please see detailed descriptions below.
Permissions requests on your screen
When you're signing up for Shared Email Templates with Microsoft, this request is shown:
When you're signing in to your Shared Email Templates account with Microsoft, this request is shown:
When you're accessing OneDrive to attach a file with the ~%Attach macro, this request is shown:
When you're accessing SharePoint to attach a file with the ~%Attach macro, this request is shown:
When you're accessing OneDrive to import a mailing list for a mail merge campaign, this request is shown:
When you're starting a mail merge campaign, this request is shown:
When a Global Administrator is creating a Shared Email Templates company account via their Microsoft 365 global administrator account, this request is shown:
How we use the granted permissions
Have full access to all files user can access
We use this permission to attach files from your OneDrive when inserting a Template into the currently composed message if this Template contains macros attaching those files.
Have full access to all files you have access to
We use this permission to attach files from your OneDrive when inserting a Template into the currently composed message.
Maintain access to data you have given it access to
This permission allows Services to send the scheduled mail merge campaign messages even if you are logged out from your account and have switched off all the devices.
Read all users' basic profiles
We use this permission to read properties of users' Microsoft work or school accounts such as users' first and last names and email addresses so that a Global Administrator in a Microsoft 365 organization can create Shared Email Templates accounts for their users by importing those users' data from Azure Active Directory and so that those users can sign in to their Shared Email Templates accounts.
Read items in all site collections
We use this permission to attach files from your SharePoint when inserting a Template into the currently composed message if this Template contains macros attaching those files.
Read mail you can access
We use this permission to read the content of the currently composed message from your personal or shared mailbox.
Read user and shared mail
We use this permission to read the content of the currently composed message from your personal or shared mailbox.
Read user mail
We use this permission to read the content of the currently composed message into which a Template is going to be inserted.
Read your mail
We use this permission to read the content of the currently composed message into which a Template is going to be inserted.
Send mail as you
This permission allows Services to send the mail merge campaign messages from your mailbox.
Send mail on behalf of others or yourself
This permission allows Services to send the mail merge campaign messages on behalf of the specified mailbox.
We do not use the content of your mailbox, OneDrive or SharePoint files other than the attachments you use in your mail merge campaign.
Sign in and read user profile
We use this permission to read your name, email address, picture, and other properties of your Microsoft personal account or your Microsoft work or school account when inserting a Template into the currently composed message.
Sign you in and read your profile
We use this permission to read your name, email address, picture, and other properties of your Microsoft personal account or your Microsoft work or school account when inserting a Template into the currently composed message.
Go to Office apps > App permissions and then select Change app permissions.
In the list of your apps, hover the cursor over the Shared Email Templates icon, click the three dots in its upper-right corner, and select Remove.
Where we store the collected data
All your templates are stored in a cloud-based database hosted by Amazon Web Services. This is a protected storage inside an isolated private network. All data can only be accessed through the template sharing service, the core back-end service of Shared Email Templates.
When you create an encrypted team, you are the only person who knows the Team Password. Be sure to pass the password to your teammates in a safe way. In encrypted teams, all templates are encrypted with the SHA-256 symmetric algorithm before being saved to the cloud database.
Also, SET stores local copies of your templates (the local templates cache) in the following locations on your devices:
web browser local storage in case of the Shared Email Templates web app or the Shared Email Templates add-in running in Outlook on the web (Outlook Online)
Outlook cache in case of the Shared Email Templates add-in running in your desktop Outlook.
The local templates cache is isolated and not accessible by other browser extensions or Outlook add-ins. We store the local templates cache unencrypted because of the performance reasons. Otherwise we would have to decrypt templates each time you start Shared Email Templates, which would dramatically increase its startup time.
The local templates cache is refreshed with each change in templates, e.g. if your teammate creates a new template, the new template goes to the cache.
What data others collect, but we don't
We do not collect any payment information, such as bank account details, credit card information, and check information.
You might find that Microsoft Office telemetry is run together with the Shared Email Templates app and add-in. This is because we use Microsoft's office.js framework.
Who can access your data at our office
We develop and test our products on specially created testing configurations, so access to your data is very limited and only a few people at our office have permissions.
Read-only access (provided on request only) is given to a few of our core developers and only in case they need to figure out some complex technical thing.
Read-only access is provided to our senior system administrator to perform online monitoring and periodic maintenance of our servers and services.
Read-only access to your data is also given to our customer support service and sales specialists. They need your data to assist you when you contact us with related questions.
However, no one has permissions to access your templates and passwords, including your personal password and Team Passwords.
Note. Please be prepared that our customer support service team may ask you to send them the HTML code of your template if they think the problem is in it. However, we will never ask for your password or Team Passwords.
How we control access to your data at our office
We make a lot of effort to keep your data safe. Firstly, we restrict physical access to our office and to our computers with door locking, access control systems, alarm system, and surveillance facilities. Secondly, we restrict access to our systems by using central management of system access, no guest accounts policy, password and authentication policies.
Also, we control access to data with the help of differentiated access rights, access rights defined according to duties, measures to prevent the use of automated data-processing systems by unauthorized persons.
To prevent unauthorized access, data alteration and disclosure, all our communication channels are encrypted using virtual private networks for remote access, transport and communication of data. All our sub-networks are joined into a wholly-owned private network. Finally, all our computers are protected with antivirus software and firewall systems.
How to erase your data
To remove your data, simply delete all the teams where you are the administrator, and then delete your account in the Profile section. To have all your communications with us removed from our systems, please contact our customer support service.
How you can make sure that everything above is true
You can see all the information that is sent to our services and storages with your own eyes with the help of the Fiddler tool or your browser console. Also, you can inspect our client-side source code directly in your web browser.
Why would this app collect and send information about my emails and calendar items and send them to a third party? Who is the third party? And why are you collecting and sending them my personal information? This seems to fly in the face of everthing you say about protecting privacy.
Thank you for your comment. The only third party that can get access to your data is Microsoft itself because our add-in is built on Microsoft Office extensibility technology and your Outlook account should be connected to Microsoft 365, Exchange Online, or Outlook.com. I think we need to clarify this point and update our privacy policy. Thank you once again for sharing your feedback with us.
Thank you for your questions. The Trash folder as well as the Export / Import feature are on our roadmap for upcoming beta releases. As for the backup routine, we use a cloud-based database with its own backup scheme in Amazon Web Services.
Post a comment
Seen by everyone, do not publish license keys and sensitive personal info!
If you have any questions or issues with this add-in, please feel free to post your concerns in the comments area. As soon as we answer, a notification message will be sent to your e-mail. If you do not want to share your thoughts in public, please contact us at support@ablebits.com.