FAQs
Quick answers about Grid Tools.
Payments, pricing, security, privacy, and the dashboard. For feature questions, see Features.
Purchasing and Pricing
Plans, payments, and access.
What's included in Free?
Free includes Select rows, Scroll to column, and Hide/unhide columns. You get 25 actions/day while signed out or 50 actions/day while signed in. The allowance resets daily.
What does Pro add?
Advanced grid and bulk-management tools, workflow editor utilities, quality-of-life enhancements, and navigation tools. Subscribe monthly or annually.
How do I sign in?
Open the extension popup, enter your email, select Send code, and enter the 6-digit code from your email. Grid Tools uses passwordless verification.
What payment methods are accepted?
Via Stripe: major credit cards, digital wallets, and bank transfers.
How do I cancel?
Sign In > Dashboard > Billing > Manage plan, then cancel in the billing portal. Access continues through the end of your billing cycle.
Account and Seat Management
Users, seats, and admin controls.
How do I update my payment method?
Sign In > Dashboard > Billing > Manage plan. Update your method in the billing portal.
Can I adjust my seat count?
Yes. Dashboard > Billing > Manage plan, then adjust the seat quantity in the billing portal. Changes are prorated on your existing subscription.
How do I manage team seats?
Sign In > Dashboard > Users & seats. Invite members by email; usage is tracked against your seat count. Changes can be made at any time.
How do I set up company-wide access?
Sign In > Dashboard > Settings. Enable domain self-registration so users on your company domain can request a seat from their own dashboard, then approve requests under Users & seats. You can also get an email alert as seat usage nears your cap.
Can I add more admins?
Yes. Set a member's role to Admin under Users & seats to share seat and billing management.
Can I transfer account ownership?
Yes. Contact us to arrange a transfer.
Security and Privacy
Data handling, permissions, and infrastructure.
Does my Smartsheet data leave my browser?
No. Smartsheet content is processed in your browser and is not sent to Grid Tools servers. Grid Tools uses its API for passwordless email-code sign-in, subscription checks, and authenticated usage counts. Saved tab groups and settings stay in local browser storage.
Do you store my Smartsheet data?
No. Your data never reaches our servers, so it is never stored.
Is my data shared with third parties?
We never sell your data. Account data is handled by service providers we contract (for example, Stripe for payments and Cloudflare for infrastructure) — see the Privacy Policy. Your Smartsheet data never reaches our servers at all.
Does Smartsheet data go to third parties?
No. Never.
Can users upload data to Grid Tools?
No. No upload or storage capability.
Can I request data deletion?
Yes. Contact us.
Breach notification timeline?
We notify affected users and applicable regulators of a confirmed incident affecting user data in accordance with applicable law.
Why the 'storage' permission?
To save local extension settings, Dark Mode preference, your signed-in session (authentication tokens), the license/entitlement cache, and Saved Smartsheet Tabs groups. Saved tab names, URLs, and titles are not sent to Grid Tools servers.
Why host permissions?
Grid Tools embeds controls directly into the Smartsheet interface. Host permissions are required by browsers for this integration. This also lets us call Smartsheet's native functions instead of building our own.
Does Grid Tools tamper with Smartsheet's code?
No. Smartsheet's code is unobfuscated. Grid Tools calls it directly without modification.
Is the source code visible?
Yes. Dev Tools > Sources > Grid Tools to browse all source files. Chrome and Firefox extension stores require all code to be visible and auditable.
Can you inject code remotely?
No. Extension stores detect and block remote code injection. See Chrome's remote code policy and W3C enforcement examples.
Network access required?
Feature work runs in your browser. Outbound API calls support email-code sign-in, subscription checks, and authenticated usage counts containing an action name and timestamp.
Any agents or host software required?
No. Browser extension only — no host agents.
Any network requirements?
None. Works from any network.
Is data encrypted in transit?
Yes. TLS 1.2 or greater for all server communication.
Cloud provider?
Cloudflare.
Server locations?
North America.
DDoS protection?
Yes. All traffic proxied through Cloudflare.
Least-privilege access model?
Yes. All internal access follows least-privilege principles.
Logical access controls in place?
Yes. Role-based access controls on all servers, systems, and databases.
Is data access logged?
Yes. All access is logged and reviewed regularly.
Periodic access reviews?
Yes. Conducted regularly to ensure permissions remain appropriate.
Timeline for revoking unneeded access?
Within 2 weeks of periodic evaluation.
2FA for remote access?
Yes. Required for all remote access.
Brute-force protection?
Yes. Rate limiting and account lockout.
Secured maintenance workstations?
Yes. Encrypted hard drives required.
MFA for public-network maintenance access?
Yes. Required.
Backup and restore procedures?
Yes. Documented for all maintenance operations.
System documentation maintained?
Yes. Architecture, procedures, and configuration are documented internally.
Third-party server access?
No. Internal personnel only.
No questions match your filter.