EasyTables 1.40.13 · Technical data notice · Updated 1 October 2026

Access checks and your data

EasyTables checks access automatically on Tableau Server and Cloud before reading table data and renews that access during use. Free and pilot deployments require owner approval; paid deployments use a licence key activated for the Tableau address and site. This page describes what the current implementation processes.

What is sent

The automatic access request contains the following values:

Worksheet rows, field values, workbook contents, workbook names, full view URLs and account identifiers are not sent by the automatic access check. Tableau controls access to worksheet data; the extension processes that data in your browser.

The workbook author saves the activation code in the extension settings. The access check sends it in the request body. A saved code is not added to a URL, settings export or Excel export. After a successful Cloud access check in authoring mode, the extension also remembers that code in this browser's local storage under the observed Tableau origin. For up to 90 days after its last successful authoring use, a new workbook can offer the masked code to its author. The author must explicitly choose it before it is saved in that workbook. A viewer cannot use that control. The author can choose “Forget saved code” in a new workbook, remove an inactive code from a workbook, or clear browser site data. Cloud sites on the same Tableau address can see the same offer, but the server still checks whether the selected code is valid for the current scope.

The public activation page sends a licence key and the chosen Tableau context, address and site to the commerce service when the author submits the form; it returns a code for the author to save in the workbook.

Purchase and licence activation

Lemon Squeezy is the merchant of record for purchases. EasyTables never receives card data. To activate and validate a licence, the commerce worker sends the entered licence key to Lemon Squeezy's License API and reads the Lemon order, subscription, invoice and licence-key records needed to decide the grant, including subscription status and quantity. For the licence key itself, EasyTables stores only its SHA-256 hash, Lemon Squeezy's licence-key ID and instance ID, and the EasyTables deployment ID; it does not store the plaintext licence key.

Where the request goes

The extension sends the request over HTTPS to a same-origin Netlify proxy, which forwards it to the publisher's isolated Hetzner licensing API and PostgreSQL database. The application does not attach browser cookies or a referrer to the access request. Hosting providers still receive ordinary network metadata such as IP addresses; this page does not claim that provider logs contain no such information.

What is stored and counted

The API reads the approved deployment registration and signed entitlement. Public access requests cannot register a site, start a trial, occupy an account slot or change an existing registration. The current automatic request does not read or store an account identifier. Commerce activation is a separate one-time operation bound to the exact context, address and site entered on the activation page.

A daily job deletes payment event records after 90 days, monthly diagnostic counters at the end of each month and activation audit records after 24 months. Web-server logs are kept for 14 days and encrypted backups for up to 14 days. Licence records are kept for the licence term plus 12 months. The full schedule, legal bases, recipients and your rights are in the EasyTables privacy notice.

Observed addresses are caller assertions, not independent proof of company ownership. Browser-supplied identities do not trigger invoices, overage charges or account-based hard denials. The API returns a short access decision, without customer names, purchased capacity, prices, invoices or payment history.

What happens during an outage

An allowed decision stays in the browser's memory for at most five minutes. A temporary failure can retain it only until its original deadline; it cannot extend that deadline. An initial failed check, explicit denial or expiry blocks the table, copy and export and clears displayed data. Workbook settings are preserved. Use Try again when access is available.

Desktop authoring has a local preview without these access requests. Desktop viewing/export, Public and unknown contexts do not receive that preview. Server/Cloud export sessions require the same approved site check as interactive sessions. Missing or ambiguous site information is not replaced with a guessed identity.

Settings, support and requests

Author settings are stored in the Tableau workbook. Optional user layout persistence uses an author-selected Tableau parameter. Settings JSON can contain configuration and filter values; review it before sharing. The workbook or platform owner controls those settings.

For questions about access records or a data request, contact the publisher at eduard.nizamov@databeyond.app or use the support page. Provide the relevant Tableau address/site and describe the request. Do not email passwords, licence secrets, raw SDK account identifiers or customer datasets. Locating or acting on a request may require proportionate verification.