Agendawell for Webflow: Privacy Policy
Effective date: October 1, 2026 Agendawell is made by Great Work LLC, 651 N Broad St Suite 206, Middletown, DE 19709, USA ("we"). Contact: hello@greatwork.company. This policy covers the Agendawell app for Webflow (the Designer Extension and our backend at addons.greatwork.company).
What Agendawell does with your data
Agendawell reads the calendars you add (iCal feed addresses, or on Pro the Google calendars you pick, read-only) and writes their events into the Webflow CMS collection you choose, through Webflow's API. Events are read when a sync runs, turned into CMS field values, written to Webflow, and then dropped from memory. We keep no copy of your calendars and no copy of your CMS.
Events can contain personal data (for example an organizer's name, or names in a description). Agendawell writes only the fields you map. It never publishes organizer or attendee email addresses, and private and confidential events are skipped unless you turn that off.
What we store, and for how long
| What | Why | How long |
|---|---|---|
| Webflow access token for your site (encrypted, AES-256-GCM) | to write events to your CMS through Webflow's API | until you remove Agendawell, uninstall it, or revoke access |
| Calendar feed addresses (encrypted; shown to you masked) | to read the calendars on schedule (a feed address can work like a password) | while the sync that uses it exists; addresses added but never saved are deleted after 1 day |
| Pro: Google refresh token (encrypted) | to read the Google calendars you picked | until you press Disconnect Google, remove Agendawell, or revoke access in your Google account |
| Sync settings: collection, field mapping, rules, schedule, calendar names | to run your syncs | while the sync exists |
| Overrides you set in the Events tab (encrypted) | to apply them on every sync | while the sync exists |
| Which CMS item belongs to which event date (keyed by one-way hashes, not calendar ids), the event's dates and a fingerprint of each field written | to update the right item and keep your Webflow edits | while the sync exists; for events that ended more than 1 year ago, deleted |
| Sync log: when, counts, and per-event rows with titles and dates (encrypted) | so you can see what a sync did | 30 days |
| Site name, site ID, time zone, workspace ID, the email of the signed-in Webflow user | to identify the site for billing and send receipts | while you use Agendawell; billing records as tax law requires |
When a trial or plan ends, syncing pauses and your settings are kept so you can pick a plan later. Removing Agendawell deletes everything above for the site (see Deletion). Server logs record the time, method, path and status of each request for 30 days. They never include tokens, OAuth codes, query strings, feed addresses, request bodies or event content.
Who processes data (every third-party domain the app contacts)
| Domain | Who | What for |
|---|---|---|
| webflow.com, api.webflow.com | Webflow, Inc. | OAuth sign-in, reading your collections and writing event items |
| website-files.com (Webflow's asset hosts) | Webflow, Inc. | Webflow itself downloads event images from their links when it saves an Image field; Agendawell does not contact it |
| The hosts of the calendar addresses you add (for example calendar.google.com, outlook.office365.com, outlook.live.com, p01-caldav.icloud.com, or your own calendar server) | your calendar provider | reading the feed you gave us, over HTTPS only |
| accounts.google.com, oauth2.googleapis.com, www.googleapis.com | Google LLC | Pro only, when you connect Google: sign-in and reading events of the calendars you picked |
| addons.greatwork.company | Great Work LLC (our server, hosted by DigitalOcean in New York, USA) | runs the backend and the scheduler, licensing |
| checkout.stripe.com, billing.stripe.com | Stripe, Inc. | payments and billing (we never see card numbers) |
| greatwork.company | Great Work LLC | product, documentation, privacy and terms pages |
We don't sell personal data, don't use your calendars or content for advertising or to train AI models, and don't use advertising or analytics trackers in the app. No person at Great Work looks at your events unless you ask us to help with a specific problem and give us permission, or the law requires it.
Google user data
Agendawell's use of information received from Google APIs adheres to the Google API Services User Data Policy,
including the Limited Use requirements. Google Calendar data (read-only scope
calendar.events.readonly) is used only to put the events of the calendars you chose into your own Webflow CMS
collection. It is not used for advertising, not sold, not transferred to anyone except Webflow as you asked, and
not read by people except with your consent for support, for security, or where the law requires it. You can
revoke access with Disconnect Google in Agendawell's Settings or at myaccount.google.com/permissions; we then
delete the token.
Deletion
- Remove Agendawell from this site (Settings) deletes every sync, calendar address, override, item link and log entry for the site, revokes Google access, and revokes and deletes our Webflow token.
- Uninstall or revoke: when Webflow tells us the authorization is gone (any request answered "unauthorized", plus a daily check, because Webflow sends no uninstall notice), we delete the token and all data for its sites, usually within 24 hours.
- Your Webflow CMS items are never changed by removal or deletion, and your calendars are never changed at all.
Your rights
You can ask for a copy of your data, correction or deletion at hello@greatwork.company. If you are in the EU or UK you can also complain to your data protection authority. Where your events contain other people's personal data, you are the controller and we process it for you (see the terms for a data processing agreement).
Security
Tokens, feed addresses, overrides and the log are encrypted at rest (personal data included) with keys kept outside the database, each bound to its purpose. Feeds are fetched over HTTPS only, from public addresses only. The backend runs under its own unprivileged user on a hardened server, behind TLS. The Designer Extension never receives a Webflow or Google token.
Changes
We'll post changes here and update the date; material changes are announced in the app. This policy's retention section covers data retention for every item we store.