← Rowstub

Rowstub privacy policy

Last updated 2026-10-03. Rowstub (the Wix app) is made by Great Work LLC, 651 N Broad St Suite 206, Middletown, DE 19709, USA. Contact: hello@greatwork.company.

Who is who

You are the owner of the Wix site where Rowstub is installed. Rowstub copies your site's own records (store orders, form entries, bookings and contacts, each only if you set up a feed for it) into Google spreadsheets in your own Google account. Your customers are the people those records are about. Rowstub processes their data on your behalf, only to put it in your spreadsheets.

What we store

  • Your site's app instance: the Wix app instance id, site id, published site address and name, and your plan status (from Wix).
  • Your settings: your feeds (which records go to which spreadsheet and tab, column names, filter rules, on or off) and the time zone for dates.
  • Your Google connection: a Google refresh token, encrypted (AES-256-GCM) with a key kept outside the database, and the ids, titles and links of the spreadsheets Rowstub created or that you picked.
  • Row pointers: for each row Rowstub wrote, the row's Rowstub ID (a letter plus the Wix record id, and the line item id for item rows), the row number it was last seen at, and a short one-way fingerprint of the row's values, so an unchanged row isn't rewritten. The fingerprint can't be turned back into the data.
  • The retry queue: for a record that's still to be sent, the Wix record id, the number of tries and the last error message.
  • The activity log: 30 days of lines like "Order 10023 added" or "Booking 3f2a91c0 failed: the spreadsheet was deleted", with record numbers and ids only.
  • Usage: how many new rows were written each month (for the plan limit).
  • Sessions: a random token for each dashboard session, deleted after 12 hours.

What we never store

The records themselves. Names, email addresses, phone numbers, addresses, order contents, form answers, booking details and contact details are read from Wix when a record changes, turned into rows in memory, written to your spreadsheet and dropped. We keep no copy, build no lists, never contact your customers and never use their data for anything but your spreadsheets. We set no cookies and add nothing to your live site.

Google data

Rowstub asks Google for one permission, drive.file: it can open only the spreadsheets it creates or that you pick in Google's file picker, nothing else in your Drive. It uses that access only to add and update rows in the spreadsheets your feeds point at, and to read their header row and the Rowstub ID column to find rows again. It doesn't read your other cells beyond those, doesn't share Google data with anyone, doesn't use it for advertising and doesn't let people read it. Rowstub's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. You can disconnect Google in the app (we revoke the token at once) or in your Google Account under Third-party connections.

Where data goes

Our server in the United States (DigitalOcean, New York). Wix, through its API, to read your records. Google, through the Sheets API, to write your spreadsheets. No analytics, no advertising networks, no other processors.

Retention and deletion

Log lines are deleted after 30 days, finished queue entries at once. Deleting a feed deletes its pointers and queue (the rows already in your spreadsheet stay; they're yours). When you uninstall Rowstub, sessions and the queue are deleted at once and everything else 30 days later (so a reinstall by mistake loses nothing), when the Google token is also revoked. You can download everything we hold for your site from the dashboard (Download what Rowstub stores) and ask us to delete it sooner at hello@greatwork.company. Your customers' data in your spreadsheets is under your control: to delete a customer's data, delete their row in your spreadsheet, and in Wix. If a customer asks us, we answer within 30 days and check the request with you first.

Security

HTTPS everywhere. Requests from Wix are verified (signed app instances, signed webhooks). The Google sign-in and file picker links are one-time codes that expire in 15 minutes. Data is written with Google's RAW input, so nothing in a record is ever run as a spreadsheet formula. The app runs as its own unprivileged user, and its web server doesn't log request addresses or links for Rowstub pages.

Changes

If this policy changes in a way that matters, we'll update the date above and tell site owners through the app.