Purgewell for Webflow: Privacy Policy
Last updated: October 1, 2026
Purgewell is a Webflow app made by Great Work LLC, 651 N Broad St Suite 206, Middletown, DE 19709, USA (hello@greatwork.company). This policy covers what Purgewell collects, why, where it goes, how long we keep it and how to delete it, both for you (the Webflow site owner or your team) and for the people who send your site a privacy request through Purgewell.
Two roles
- Your account data (your Webflow user email, your settings, billing): Great Work is the controller.
- Your site's visitors' data (form submissions, and the contact details someone types into your request page): you are the controller and Great Work is your processor: it processes that data only on your instructions, to run the purges and requests you start. We don't use it for anything else. The data processing terms in the Terms (section 6) apply.
What Purgewell stores
| What | Why | Kept for |
|---|---|---|
| Your site's Webflow access token, encrypted (AES-256-GCM) | To read forms, submissions, CMS items and orders, and to delete the submissions your rules and requests say to | Until you remove Purgewell, uninstall it or revoke access; then deleted |
| Site id, workspace id and site name | To apply your plan, and to show your site's name on the request page and certificates | As long as Purgewell is connected |
| Settings: privacy contact email, organization name, default law, search defaults, request page on/off, schedule hour | So the app works the way you set it | Until you remove Purgewell |
| Inventory: each form's name and page, its field names and types, the label Purgewell or you gave each field, submission counts and oldest dates | The Forms tab and the record of processing | Until the next refresh, or you remove Purgewell. No submitted values are stored |
| Your purposes, lawful bases and recipients per form | The record of processing | Until you remove Purgewell |
| Retention rules and purge runs: per run when, who, counts per form, and the ids (not contents) of submissions that failed to delete | The Retention tab and the audit log | 2 years |
| Audit log: who did what and when (rule changes, runs, request steps, exports, settings), with masked contact details | Your accountability record | 2 years |
| An open request: the requester's email addresses, phone numbers, name and message, encrypted (AES-256-GCM) | To search for their data and confirm it's them | Until you close the request (or 30 days for a request nobody confirmed) |
| An open request's working set: the fields of the submissions, CMS items and orders the search found, encrypted (AES-256-GCM) | To build the export you send them and the erasure certificate | Until you close the request, or 30 days after the search, whichever is first |
| A closed request: dates, law, outcome, contact details masked (for example "sa***@ex***.org") and as SHA-256 hashes, counts, and the certificate (record ids, never contents) | Your proof that the request was answered | 3 years after it closed |
| Confirmation links: a SHA-256 hash of the one-time token | To confirm the requester | Until used, or 7 days |
| Server request logs: time, method, path (request-page links and confirmation tokens cut off), status, duration | Security and troubleshooting | 30 days. Not logged: query strings, tokens, request bodies, emails, form contents |
What we don't store. Purgewell reads form submissions from Webflow when a purge or a search runs and keeps no copy of them, except an open request's encrypted working set described above. Exports and certificates are built when you download them and aren't kept. Purgewell adds no code, banner or cookies to your published site.
Personal data, in short. Your Webflow user email; the personal data in your site's form submissions (read during purges and searches, kept only in an open request's working set); a requester's contact details and message (kept encrypted until the request closes). We don't sell personal data, don't use it for advertising, don't use it to train AI models and don't send it to any AI service.
Third parties and every domain Purgewell talks to
| Domain | Who | What |
|---|---|---|
| api.webflow.com, webflow.com | Webflow, Inc. | Your forms, submissions, CMS items and orders through the Data API, the deletions you start, and the sign-in (OAuth) screen |
| addons.greatwork.company | Great Work LLC (our server, hosted at DigitalOcean, New York) | Purgewell's backend, the request page and confirmation links, and our licensing service (your site id, workspace id and verified email, to run your trial and plan) |
| checkout.stripe.com, billing.stripe.com | Stripe, Inc. | Payment and billing, only when you click a plan or Manage billing. Stripe holds your card details; we never see them |
| api.resend.com | Resend, Inc. | Only once email is switched on for Purgewell: the confirmation email to a requester (their address, your site name, a link) and the new-request notice to your privacy contact (no requester details) |
| greatwork.company | Great Work LLC | Product page, documentation and this policy |
Our server runs on DigitalOcean (United States). Webflow stores your site and its form submissions in the United States too. Data is encrypted in transit (TLS) everywhere and the fields above are encrypted at rest.
Retention and deletion
- Remove Purgewell (Settings) revokes the Webflow token and deletes everything Purgewell stored for your site at once: settings, inventory, rules, runs, requests (open and closed), certificates and the audit log. Download any certificates you want to keep first.
- Uninstall or revoke access in Webflow: we delete the token and your site's data the next time Webflow tells us the access is gone (on our next request or job, and at the latest by the next daily check).
- Retention runs daily: working sets 30 days after their search, unconfirmed requests after 30 days, runs and the audit log after 2 years, closed requests after 3 years.
- If your trial or plan ends, purges, searches and erasures pause and nothing is deleted for 30 days. After 30 days without a plan, everything for the site is deleted.
If you sent a request through a Purgewell request page
The website you sent it to decides what happens with your request; Purgewell is the tool they use. Your details are encrypted, used only to find your data in that website's records and to confirm it's you, and deleted from Purgewell when the request is closed (or after 30 days if you never confirm). Questions about your request go to the website; questions about Purgewell to hello@greatwork.company.
Your rights
Depending on where you live (for example the EU, UK or California), you can ask to access, correct, delete or export your personal data, and object to or restrict its use. Email hello@greatwork.company; we answer within 30 days. For data we process for a site owner, we pass your request to them. Our legal basis for your account data is the contract with you and our legitimate interest in keeping the service secure.
Children
Purgewell is a business tool and isn't meant for children under 16.
Changes
We'll post changes here and update the date above. If a change matters, we'll say so in the app.
Contact
Great Work LLC, 651 N Broad St Suite 206, Middletown, DE 19709, USA. hello@greatwork.company