Spokewell for Webflow: Privacy Policy
Effective date: October 1, 2026
Spokewell is a Webflow app made by Great Work LLC, 651 N Broad St Suite 206, Middletown, DE 19709, USA ("we"). Contact: hello@greatwork.company. This policy covers what the app stores, where it comes from, who it goes to, how long we keep it and how it's deleted.
Who is who
For the account data of the person who installs and uses Spokewell (your Webflow user id and email), we are the controller. For the CMS content of your sites that the app reads and writes on your instructions, we act as your processor. Spokewell doesn't collect personal data about your sites' visitors and adds nothing to your published pages. If your CMS items contain personal data (team members' names and photos, for example), it moves between your own sites the way you set up, and we keep only what's listed below.
What we store
- Webflow access token: the token Webflow issues when you approve the app, encrypted at rest with AES-256-GCM. Never sent to your browser, never logged.
- Your Webflow identity: your Webflow user id and email from Webflow's ID token, to know who is asking and to send receipts.
- Your syncs: the source site and collection, the target sites and collections, the field maps, rules, schedule and language pairs you set.
- Item links: for each target site, which source item matches which target item, and for each synced field a fingerprint (a one-way hash) of the value Spokewell last wrote and of the value Webflow stored. These let Spokewell tell a source change from an edit made on the site. They contain no content.
- Your decisions: for an item edited on a target, whether you chose Overwrite or Keep (until the next sync uses it).
- The sync log: for each run, when it ran and who started it, and per item its name, what happened, error messages from Webflow, and for changed fields a short before and after (up to 80 characters each; rich text as plain text).
- Undo data: for the newest sync of each sync setup, the values it replaced on the target sites, the ids of items it created, and the full content of items it deleted, so Undo can put them back.
- Webhook ids: the ids of the change notifications Spokewell created on source sites.
- License state: the plan and trial dates from our billing service.
What we never store
- An editable copy of your collections: Webflow stays the source of truth on every site.
- Anything from your visitors: no IP addresses, cookies or form submissions.
- Your source content outside the undo data and the short log text above.
Where data comes from and goes
| Domain | Why |
|---|---|
| webflow.com | The OAuth approval screen (you sign in to Webflow there, not with us) |
| api.webflow.com | Read the source collection and write the target collections with the token you approved; resolve your ID token; create and remove the change notifications on source sites. Webflow sends us signed notifications when source items change (only for syncs with "sync on change") |
| addons.greatwork.company | Our backend (the Designer Extension talks only to it) and our billing service |
| checkout.stripe.com, billing.stripe.com | Payment and the billing portal, opened by you in a new tab. Stripe receives your email and card details; we never see your card |
| greatwork.company | The product page, documentation and these policies |
Images and files move between your sites by their Webflow URL: Webflow fetches them for the target site. They don't pass through our server. Hosting: DigitalOcean (New York), in a database only our app's own server user can read. We don't sell data, share it for advertising, or use it to train AI models.
How long we keep it (retention)
- Syncs, item links and decisions: while the sync exists; deleted with the sync or when the app is removed.
- Sync log: 90 days. Undo data: 30 days, and only for the newest sync of each setup (older undo data is deleted when a newer sync writes).
- A workspace without an active trial or plan: everything is deleted 30 days after the plan or trial ended.
- Server request logs (method, path, status, time; no query strings, headers or bodies): 30 days. Not logged: tokens, item content, webhook bodies.
Deletion on uninstall
- Settings > Remove Spokewell deletes the change notifications from your source sites, revokes the Webflow token and deletes everything above for the workspace at once. Content already synced stays on your sites.
- Uninstalling or revoking the app in Webflow: Webflow doesn't tell apps about uninstalls, so our server deletes a token and its workspace data the first time Webflow refuses it, and a daily check finds every revoked token within 24 hours.
- Billing records are kept by our billing service and Stripe as tax law requires.
Your rights
You can ask for a copy of your data, a correction or deletion at hello@greatwork.company; we answer within 30 days. EU and UK users can also complain to their data protection authority. We'll tell you before changing this policy in a way that matters, by email and in the app.
Great Work LLC, 651 N Broad St Suite 206, Middletown, DE 19709, USA. hello@greatwork.company