Legal

Privacy policy

The data Buywell needs for accounts, the editor, and workflow execution.
BUYWELL / PRIVACY

This document describes the rules for using the service, its workspace, and workflow execution.

1. Data we process

Buywell stores account and profile data, subscription information, workflows and revisions, connections, adapter/module settings, run history, and step results.

Product analytics processes visited sections, referral source, UTM tags, country, device type, and operating-system and browser families. Analytics does not store IP addresses or complete User-Agent values.

A protected session is stored for sign-in. A profile image is stored only when uploaded. External-service credentials are kept separately from workflows.

2. Why data is used

Data supports registration and sign-in, workspace storage, workflow validation and execution, history display, plan limits, abuse prevention, and support responses.

Pseudonymous visit statistics help evaluate traffic sources, the path to registration, and product-feature usage. They are not used for third-party behavioral advertising.

3. Connected services

During execution, Buywell sends a module or adapter only the data required by selected events and steps. Users choose the connection and are responsible for a lawful basis for the transfer.

An external provider may process received data under its own terms.

4. Keys and credentials

Passwords, API keys, and other credentials are not part of workflow exports or module packages. Buywell stores only the required access-key representation or encrypted value when a secret is needed for an external API call.

5. Storage

Data is retained while needed for account operation, security, and obligations. A plan history window limits the displayed run range but does not replace separate backup and technical-log retention rules.

Detailed visits and page views are retained for up to 12 months; only daily aggregate counts without personal details remain afterward.

6. Cookies and browser data

Buywell uses HttpOnly cookies for the authenticated session and its own product analytics. Analytics cookies distinguish a browser and a 30-minute visit and are not available to client-side JavaScript.

Language, theme, and tour state are stored locally in the browser. Buywell does not use these values for third-party behavioral advertising.

7. Protection

Access is restricted by account and role. Buywell checks workflow and connection ownership, separates credentials from ordinary data, and applies technical protection measures.

No storage method eliminates risk completely; users must also protect email, passwords, sessions, and external-service keys.

8. Data control

Name and profile image can be changed in the profile. Workflows and connections can be removed in their respective sections when that operation is available. Access, export, or deletion questions may be sent to [email protected].

9. Changes and contact

The current policy and update date are published here. Privacy questions: [email protected].