HewnFlow — Privacy Policy
Hewnpath ("we", "us") respects your privacy. This policy explains what data the HewnFlow Webflow app and hewnflow-api.hewnpath.workers.dev service ("Service") collect, why, and what rights you have under GDPR and equivalent laws.
1. What we collect
From your Webflow Designer (the app)
- License key you paste in Settings (Pro / Agency only).
- Device identifier — a SHA-256 hash of your Webflow user id combined with a per-install random nonce. We never see the raw Webflow user id.
- Audit metadata — categories selected, page count, issue count, duration in milliseconds. Used for free-tier rate limiting and aggregate analytics.
- Site identifier (Pro/Agency only) — to enforce site-count limits on your plan.
From Polar (our merchant of record)
When you purchase Pro or Agency:
- License key (generated by Polar, prefixed
HFL-) - Email address
- Polar subscription id, customer id, benefit grant id
- Subscription status (active / cancelled / expired / refunded)
2. What we never collect
- Page contents, element ids, class names, style declarations
- Site identifiers beyond the opaque id used for plan enforcement
- Variable names or values
- Real IP address (logged only in short-form rate-limit counters)
3. Why we collect it
- License key + device id: enforce the three-device activation limit, detect abuse.
- Audit metadata: free-tier monthly cap, aggregate product analytics.
- Site identifier: enforce site-count limit per tier (1 / 5 / unlimited).
- Email: license delivery, renewal notice, material policy changes.
4. Lawful basis (GDPR Art. 6)
- License + activation tracking: contract performance (Art. 6(1)(b)).
- Aggregate analytics: legitimate interest in product quality (Art. 6(1)(f)). Opt out in Settings.
5. Storage and retention
- License records: lifetime of subscription + 30 days after cancellation.
- Device activations: while license is active.
- Audit metadata: 90 days rolling.
- Webhook events (idempotency): 12 months.
Storage: Cloudflare D1, region EEUR (Milan).
6. Third parties
- Cloudflare — infrastructure. Privacy
- Polar Software, Inc. — merchant of record. Privacy
- Bunny.net — Inter font on marketing pages. Privacy
- Webflow — host platform. Privacy
We do not sell, rent, or share your data with any other third party.
7. Your rights (GDPR)
You can at any time:
- Access — copy of all data we hold
- Rectification — correct inaccurate data
- Erasure — delete your account and records
- Portability — machine-readable export
- Objection — opt out of analytics in Settings
- Lodge a complaint with your national data protection authority
Email [email protected] with subject "GDPR request". We respond within 30 days.
8. Children
Not intended for users under 16. Contact us if you believe a child provided data.
9. Changes
Material changes announced in-app and via Polar customer email at least 30 days before effect.
10. Contact
Hewnpath
Email: [email protected]
Country: Italy