CMS Change Receipt privacy

Effective September 1, 2026

Data

We store the Webflow user and site identifiers, encrypted OAuth token, CMS collection and item identifiers, canonical field values from installation onward, field-level diffs, sync and receipt metadata, and Cazimedia billing identifiers. We do not request content write access.

Purpose

We use this data only to capture CMS history, reconcile delivery gaps, show exact differences, generate requested receipts, authenticate the account, and manage the subscription.

Retention

History is retained while the installation is active. Receipt links expire after 15 minutes. Permanent deletion removes the ledger and stored receipt objects after any active subscription is cancelled.

Processors

Cloudflare hosts the Worker, queues, rate limiter, D1 database, R2 objects, and operational logs. Webflow supplies authorized CMS data. Stripe processes subscription billing. We use no advertising, tracking, analytics, or AI service.

Security

OAuth tokens use AES-GCM encryption. Webflow and Stripe webhooks require fresh signatures, customer records are account-scoped, public actions are rate-limited, and short-lived signed links protect receipts.