Foliowell for Webflow: Privacy Policy
Effective date: October 1, 2026
Foliowell for Webflow is a Webflow app made by Great Work LLC, 651 N Broad St Suite 206, Middletown, DE 19709, USA ("we"). Contact: hello@greatwork.company. This policy covers what the app stores, where it comes from, who it goes to, how long we keep it and how it's deleted.
Who is who
For the account data of the person who installs and uses Foliowell (your Webflow user id and email), we are the controller. For your store's orders, customers and products, which the app reads and changes on your instructions, we act as your processor, and you (the store) are the controller toward your customers. Foliowell adds nothing to your published pages and collects nothing from your site's visitors. The one public page it runs is your store's invoice page, which your customers use only if you turn it on.
What we store
- Webflow access token: the token Webflow issues when you approve the app, encrypted at rest with AES-256-GCM. Never sent to your browser, never logged.
- Your Webflow identity: your Webflow user id and email from Webflow's ID token, to know who is asking and to send receipts.
- Your settings: business details printed on documents (name, address, tax ID, email, phone, website, footer), your logo, time zone, document language, how long links work, alert settings and the email addresses that get alerts.
- Your templates: the Word files you upload or add from our starters, every version a document still uses, and the result of checking each one.
- Numbering: your number sequences and, for each order that got a number, the order number and the document number.
- Document records: for each numbered document, the template version, the order number, the document number, how it was made and the date. No order content and no file: each time a document link is opened, the order is read from Webflow again and the PDF is made fresh.
- Automation jobs: the order number and the attempt count while a document is waiting to be made.
- Bulk files: a merged PDF or pick list you asked for, kept on our server for 24 hours so you can download it.
- Stock: the low-stock levels you set per SKU, and for each SKU the last level seen (product name, SKU code, quantity) and the alerts sent.
- Product change history and undo data: for each change you applied, who, when, what kind and how many SKUs, and for 30 days the values it replaced (prices, compare-at prices, SKU codes, inventory), encrypted, so you can undo it. A scheduled sale keeps the prices it replaced, encrypted, until it ends.
- Activity: one-line events (a document number made, an export's order count, a sale started), for the app's Activity list.
- Webhook ids: the ids of the three ecommerce notifications Foliowell created on your site.
- License state: the plan and trial dates from our billing service.
What we never store
- Copies of your orders, customers or products. Webflow stays the source of truth: the app reads them when it needs them.
- Notes and tags: they're saved on the order in Webflow (its comment field), not on our server.
- Finished invoices, except the 24-hour bulk files above.
- The order number and email someone types into your invoice page: they're used once to find the order and dropped.
- Anything about your site's visitors: no cookies, no tracking.
Where data comes from and goes
| Domain | Why |
|---|---|
| webflow.com | The OAuth approval screen (you sign in to Webflow there, not with us) |
| api.webflow.com | Read orders, products, inventory and the store currency with the token you approved; write the notes, tracking numbers, fulfillments, prices and inventory you ask for; resolve your ID token; create and remove the three notifications. Webflow sends us signed notifications for new orders, changed orders and inventory changes |
| addons.greatwork.company | Our backend (the Designer Extension talks only to it), document links, your invoice page, and our billing service |
| checkout.stripe.com, billing.stripe.com | Payment and the billing portal, opened by you in a new tab. Stripe receives your email and card details; we never see your card |
| api.resend.com | Only when email is switched on for Foliowell: sends low-stock alerts and the daily digest to the addresses you entered (product names, SKU codes and quantities; no customer data) |
| greatwork.company | The product page, documentation and these policies |
Hosting: DigitalOcean (New York), in a database only our app's own server user can read. We don't sell data, share it for advertising, or use it to train AI models. Documents are made on our server with our own code; no third-party document or AI service sees your orders.
How long we keep it (retention)
- Settings, templates, numbering, automations, stock levels: while the app is installed.
- Document records and their links: 90 days by default (you choose 7 to 730 days in Settings). After that the link stops working and the record is deleted; the order number to document number pairing in a numbering stays so a number is never given twice.
- Bulk files: 24 hours. Undo data: 30 days. Alerts and activity: 30 days. Product change history and ended sales: 1 year.
- Server request logs (method, path, status, time; no query strings, headers or bodies; document links masked): 30 days. Not logged: tokens, order content, webhook bodies, what customers type on the invoice page.
Deletion on uninstall
- Settings > Remove Foliowell deletes the notifications from your site, revokes the Webflow token and deletes everything above for the site at once. Document links stop working. Your store, and notes and tags in Webflow, aren't changed.
- Uninstalling or revoking the app in Webflow: Webflow doesn't tell apps about uninstalls, so our server deletes a token and its site data the first time Webflow refuses it, and a daily check finds every revoked token within 24 hours.
- Billing records are kept by our billing service and Stripe as tax law requires.
Your customers
Your customers' names, emails and addresses appear on the documents you make and pass through our server only while a document is being made. If a customer asks you for their data, everything Foliowell has about them is in your Webflow orders. Requests can also go to hello@greatwork.company and we'll help.
Your rights
You can ask for a copy of your data, a correction or deletion at hello@greatwork.company; we answer within 30 days. EU and UK users can also complain to their data protection authority. We'll tell you before changing this policy in a way that matters, by email and in the app.
Great Work LLC, 651 N Broad St Suite 206, Middletown, DE 19709, USA. hello@greatwork.company