← Tidingwell

Tidingwell for Webflow: Privacy Policy

Last updated: October 1, 2026

Tidingwell is a Webflow app made by Great Work LLC, 651 N Broad St Suite 206, Middletown, DE 19709, USA (hello@greatwork.company). It sends conversions from your Webflow site (form submissions and paid orders) to the ad platforms you connect. This policy covers what Tidingwell collects, why, where it goes, how long we keep it and how to delete it. It has two parts: data about you, the site owner, and data about your site's visitors and customers, which we handle only on your instructions.

Who decides what

For your visitors' and customers' data, you (the site owner) are the controller: you decide which forms and orders are sent and to which ad platforms, under your own privacy notice and consent banner. Great Work LLC processes that data on your behalf, only to send it where you configured, and acts as the controller only for your account data (your Webflow user email, billing). Ask hello@greatwork.company for our data processing terms.

What Tidingwell stores

WhatWhyKept for
Your site's Webflow access token, encrypted (AES-256-GCM)To list your forms, keep our webhooks on your site and, if you switch it on, add the click-ID capture scriptUntil you remove Tidingwell, uninstall it or revoke access; then deleted
Site id, workspace id, site name, custom domainTo apply your plan and to send the page address with order eventsAs long as Tidingwell is connected
Your ad platform connections: pixel or dataset ids, ad account id, test codes, and each access token encrypted (AES-256-GCM, only the first and last 4 characters ever shown back)To send your conversions with your own tokensUntil you remove the platform or Tidingwell
Settings and form mappings: consent mode, default country, order options, test mode, which event each form sends, which field holds an email or phone (field names only)So Tidingwell sends what you setUntil you remove Tidingwell
Prepared requests: for each conversion and platform, the request body with the customer's details already normalized and SHA-256 hashed, the ad click IDs and browser IDs, the browser's user agent, the event id, value, currency and product ids, encrypted (AES-256-GCM)So a failed send can be retried, and a conversion held while your plan lapsed can go out if you subscribeDeleted as soon as it's sent, and 72 hours after the conversion at the latest (whether sent or not)
Delivery log: the form's name or the order number, the event type, time, status per platform, the platform's error message (tokens removed), and which kinds of match keys were present (for example "email, phone"), never their valuesSo you can see what was sent and fix what failed30 days
Server request logs: time, method, path, status, durationSecurity and troubleshooting30 days. Not logged: query strings, tokens, request bodies, site ids in webhook paths

What we never store. Raw form answers, raw emails, phone numbers, names or addresses: Webflow sends them to us in each webhook, we normalize and hash them in memory for each platform, and only the hashed request is kept (above). Message fields and other answers that aren't used for matching are dropped at once. Tidingwell doesn't receive or store visitors' IP addresses (Webflow's webhooks don't include them), and it reads no CMS content, pages or assets.

Your site's visitors. When you switch click-ID capture on, a script under 2,000 characters runs on your published pages (Webflow serves it; it loads nothing from us). Only when the visitor's consent allows (see Consent below), it keeps the ad click IDs from the landing address (fbclid, ttclid, rdt_cid, epik) in one first-party cookie named _twc for 90 days, and on a form submit it adds a hidden field named tidingwell with those IDs, the ad platforms' own browser cookies (_fbp, _fbc, _ttp, _rdt_uuid, _epik), the browser's user agent, a random event id and the page address without its query string. That field travels inside the form submission to Webflow and on to us. Without consent, the field carries only the event id, the consent state, whether the browser's time zone is in Europe, and the page address. The script sets nothing else and sends nothing anywhere itself.

Consent. Tidingwell never sends a conversion for a visitor who declined tracking in your banner or uses Global Privacy Control. Visitors in the EEA, the UK and Switzerland are sent only with consent (unless you choose "My site handles consent before forms load"). You're responsible for your banner, your privacy notice to your visitors, and your agreements with the ad platforms; Tidingwell gives you the switches, not legal advice.

Your personal data. The personal data Tidingwell holds about you is your Webflow user email (sessions and receipts). We don't sell personal data, don't use it for advertising and don't use it to train AI models. Tidingwell sends nothing to any AI service.

Third parties and every domain Tidingwell talks to

DomainWhoWhat
api.webflow.com, webflow.comWebflow, Inc.Your forms, our webhooks, the capture script registration, and the sign-in (OAuth) screen. Webflow sends us each form submission and order by webhook
graph.facebook.comMeta Platforms, Inc.Conversions you send to Meta: hashed customer details, click and browser ids, user agent, event, value, products, with your token
business-api.tiktok.comTikTok (TikTok Pte. Ltd. and affiliates)The same for TikTok's Events API
ads-api.reddit.comReddit, Inc.The same for Reddit's Conversions API
api.pinterest.comPinterest, Inc.The same for Pinterest's Conversions API
addons.greatwork.companyGreat Work LLC (our server, hosted at DigitalOcean, New York)Tidingwell's backend and our licensing service: your site id, workspace id and verified email, to run your trial and plan
checkout.stripe.com, billing.stripe.comStripe, Inc.Payment and billing, only when you click a plan or Manage billing. Stripe holds your card details; we never see them
greatwork.companyGreat Work LLCProduct page, documentation and this policy

Each ad platform uses what you send under its own terms and your agreement with it. We send to a platform only after you connect it, and only to the four hosts above. Our server runs on DigitalOcean (United States); data is encrypted in transit (TLS) everywhere.

Retention and deletion

  • Remove Tidingwell (Settings) deletes our webhooks at Webflow, takes the capture script off your site, revokes Webflow's access, and deletes your platform tokens, settings, unsent conversions and the delivery log, at once. Your ad platforms keep what was already sent.
  • Uninstall or revoke access in Webflow: we delete the token and your site's data the next time Webflow tells us the access is gone (on our next request, and at the latest by the next daily check).
  • Remove a platform: its token and connection are deleted at once.
  • Prepared requests: deleted when sent, and after 72 hours at the latest. Delivery log rows: after 30 days.
  • If your trial or plan ends, Tidingwell stops sending; new conversions are held (hashed, encrypted) for 72 hours and then deleted unsent.
  • For data a platform already received, use that platform's own deletion tools. For anything we hold, email hello@greatwork.company; we answer within 30 days.

Your rights

Depending on where you live (for example the EU, UK or California), you can ask to access, correct, delete or export your personal data, and object to or restrict its use. Email hello@greatwork.company. If you're a visitor or customer of a site that uses Tidingwell, contact that site first: it decides what is sent, and we'll help it answer. Our legal basis for your account data is the contract with you; for visitor data we act on the site owner's instructions.

Children

Tidingwell is a business tool and isn't meant for children under 16. Site owners shouldn't send conversions for children.

Changes

We'll post changes here and update the date above. If a change matters, we'll say so in the app.

Contact

Great Work LLC, 651 N Broad St Suite 206, Middletown, DE 19709, USA. hello@greatwork.company