← Cellferry

Cellferry for Webflow: Privacy Policy

Effective date: October 1, 2026 Cellferry is made by Great Work LLC, 651 N Broad St Suite 206, Middletown, DE 19709, USA ("we"). Contact: hello@greatwork.company. This policy covers the Cellferry app for Webflow (the Designer Extension and our backend at addons.greatwork.company).

What Cellferry does with your data

Cellferry copies values between a Google Sheets tab and a Webflow CMS collection that you pair in a sync. To do that it reads the tab and the collection's items each time a sync runs (when you press Sync now or Preview, on your schedule, or about a minute after an item changes in Webflow if you turned that on), and writes the changes your sync settings call for. Your content passes through our server while a sync runs; we don't keep a copy of your sheet or your CMS, except the undo snapshot described below.

What we store, and for how long

WhatWhyHow long
Webflow access token for your site (encrypted, AES-256-GCM)to run syncs through Webflow's APIuntil you remove Cellferry, uninstall it, or revoke access
Google refresh token (encrypted)to read and write the spreadsheets you use with Cellferryuntil you disconnect Google, remove Cellferry, or revoke access in your Google Account
Names and links of the spreadsheets you created with Cellferry or pickedto show them in the panelsame as the Google token
Sync settings: collection, spreadsheet, tab, column mapping, rules, scheduleto run your syncsuntil you delete the sync or remove Cellferry
Change-detection hashes, one per mapped field per linked itemto tell which side changed since the last sync. These are one-way hashes, not your valuesuntil you delete the sync or remove Cellferry
Conflict choices you make in Activity (which side to keep, plus two hashes)to apply them on the next syncuntil applied, or the sync is deleted
Sync log: time, trigger, counts, and per-row results (row number, item name, message) (encrypted)so you can see what happened30 days
Undo snapshot of each sync's last run: the values it replaced in Webflow and in the sheet (encrypted)so you can undo that syncuntil the next run of that sync, or 30 days, whichever is first; deleted right away when you undo
Site name, site ID, workspace ID, the email of the signed-in Webflow userto identify the site for billing and send receiptswhile you use Cellferry; billing records as tax law requires

Server logs record the time, method, path and status of each request. They never include tokens, OAuth codes, query strings, request bodies, or your sheet or CMS content.

Google data

Cellferry asks Google for one permission: https://www.googleapis.com/auth/drive.file, which gives access only to spreadsheets you create with Cellferry or pick with Google's file picker (Google Picker), never to anything else in your Drive. Cellferry uses that access only to read and write the spreadsheets you sync, and to create a new spreadsheet when you ask it to. Cellferry's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We don't use Google data for advertising, we don't sell it, we don't use it to train AI models, and no person at Great Work reads it except when you ask us to help with a specific problem and give us permission, or when the law requires it.

Who processes data (every third-party domain the app contacts)

DomainWhoWhat for
webflow.com, api.webflow.comWebflow, Inc.OAuth sign-in, reading and writing your CMS, publishing, item webhooks
accounts.google.com, oauth2.googleapis.comGoogle LLCGoogle sign-in and tokens
sheets.googleapis.comGoogle LLCreading and writing the spreadsheets you sync
apis.google.com, docs.google.comGoogle LLCthe Google Picker on our picker page, links to your spreadsheets
addons.greatwork.companyGreat Work LLC (our server, hosted by DigitalOcean in New York, USA)runs the backend, licensing and the picker page
checkout.stripe.com, billing.stripe.comStripe, Inc.payments and billing (we never see card numbers)
greatwork.companyGreat Work LLCproduct, documentation, privacy and terms pages

We don't sell personal data and don't use advertising or analytics trackers in the app.

Deletion

  • Remove Cellferry from this site (Settings) deletes our Webflow webhooks, revokes Google access, deletes everything in the table above for the site, and revokes our Webflow token.
  • Uninstall or revoke: when Webflow tells us the authorization is gone (any request answered "unauthorized", plus a daily check, because Webflow sends no uninstall notice), we delete the token and all data for its sites, usually within 24 hours.
  • Disconnect Google revokes the Google token and forgets the spreadsheet list; your spreadsheets stay in your Drive.
  • Your Google Sheets and your Webflow CMS are never deleted by removal; they stay as they are.

Your rights

You can ask for a copy of your data, correction or deletion at hello@greatwork.company. If you are in the EU or UK you can also complain to your data protection authority. Where your content contains other people's personal data, you are the controller and we process it for you (see the terms for a data processing agreement).

Security

Tokens, the sync log and undo snapshots are encrypted at rest with a key kept outside the database. The backend runs under its own unprivileged user on a hardened server, behind TLS. The Designer Extension never receives a Webflow or Google token.

Changes

We'll post changes here and update the date; material changes are announced in the app.