Privacy Policy
Snapback ("we") — last updated [DATE]. Draft pending legal review.
What Snapback does
Snapback takes point-in-time Snapshots of the CMS content of Webflow sites you connect, shows differences between them, and (on paid plans) restores content you select. To do that we store copies of your CMS content.
Data we store
- Webflow OAuth tokens — encrypted (AES-256-GCM) at the application layer; used only to call the Webflow API on your behalf, with the scopes you approved on Webflow's consent screen.
- CMS content Snapshots — the field data and asset URLs of Items in the Collections of connected sites (primary locale only). We do not store asset files themselves.
- Account and billing data — your Webflow workspace/site identifiers, plan tier, and Stripe customer/subscription identifiers. Payment card details are handled by Stripe and never touch our servers.
- Operational logs — job and restore audit records needed to run and support the service.
What we don't do
- We do not sell or share your content or personal data with third parties, except the processors below.
- We do not read or use your CMS content for anything other than providing Snapshots, Diffs and Restore.
- We never request Webflow scopes beyond what the feature you use needs (read-only until you enable Restore).
Processors
Supabase (database hosting, EU region), Stripe (payments), [HOSTING PROVIDER] (application hosting). Each processes data only to provide their service to us.
Retention and deletion
- Snapshots follow your plan's retention window (free: last 5 per Collection; paid: 30/90/365 days).
- If your subscription lapses, data is retained 90 days, then deleted after an email warning.
- Uninstalling the app deletes stored Webflow tokens. You can request full deletion of all stored data at any time via [SUPPORT_EMAIL].
Contact
[LEGAL ENTITY NAME], [ADDRESS]. Questions or requests: [SUPPORT_EMAIL].