SchemaPilot
Home User Guide Support Dashboard Plans Privacy Terms
Legal

Privacy Policy

Effective: August 6, 2026 · Last updated: August 6, 2026

This policy explains how SchemaPilot collects, uses, stores, and protects information when you install, authorize, or use the SchemaPilot Webflow App, this website, or the license dashboard. Written for Webflow Marketplace transparency requirements.

This Privacy Policy applies to SchemaPilot (the “App”), operated by SchemaPilot / Appsrow (“we”, “us”, “our”), including:

  • App website & UI: https://schemapilot.appsrow.com
  • Designer panel UI: https://schemapilot.appsrow.com/app
  • License dashboard: https://schemapilot.appsrow.com/dashboard/
  • API & OAuth: https://api-schemapilot.appsrow.com
  • Install: https://api-schemapilot.appsrow.com/auth/install

Who we are

Data controller: SchemaPilot (Appsrow)
Publisher: Independent Webflow Marketplace developer - not Webflow, Inc., not affiliated with or endorsed by Webflow except as a listed app publisher.
Website: https://schemapilot.appsrow.com
Support: sales@appsrow.com (send email) · Support page

Your use of Webflow is also governed by Webflow’s Terms and Webflow’s Privacy Policy. App access via Webflow APIs is subject to the Webflow Developer Terms of Service and Marketplace Guidelines.

Marketplace install, OAuth & Hybrid ID tokens

When you install from the Marketplace or use Connect Webflow, you approve OAuth on Webflow. We request only scopes required to read and write schema/SEO data:

  • sites:read - list and identify sites
  • pages:read / pages:write - SEO fields and page updates you request
  • custom_code:read / custom_code:write - registered JSON-LD scripts on static pages
  • cms:read / cms:write - CMS fields for collection-item schema
  • authorized_user:read - identify the Webflow user for session management and Hybrid auth

We do not request payment scopes from Webflow. Install starts at https://api-schemapilot.appsrow.com/auth/install; callback is https://api-schemapilot.appsrow.com/auth/webflow/callback.

Hybrid App authentication: After OAuth, the Designer Extension may call Webflow’s webflow.getIdToken() and send the ID token to our API (POST /auth/designer-id-token). We verify it with Webflow’s token resolve endpoint using your stored OAuth access token, then issue a short-lived app session token for the panel UI. This is the recommended Designer + Data Client pattern - not a password form.

We do not read, collect, or act on password, login, or other credential fields in your Webflow site content or forms.

Information we collect

Account & billing (Dashboard)

  • Name, email address, and password hash when you create a SchemaPilot Dashboard account
  • License keys, plan type, status, page/AI limits, and optional binding to a Webflow site ID
  • Order amounts, status, and payment processor references (Razorpay order/payment IDs) - not full card numbers
  • Password reset / email OTP codes for verification (time-limited)

Information you provide in the App

  • Webflow OAuth authorization when you install or connect
  • License keys you paste to activate features
  • SEO titles, descriptions, and schema JSON you edit or generate
  • Email and message content if you contact support

Information from Webflow (with your permission)

  • Workspace and site identifiers, site names, and domains
  • Page metadata, URLs, SEO fields, custom code relevant to schema
  • CMS collection structure and item field data you select in the App
  • Authorized user identity needed for Hybrid session resolve

We do not read your Webflow password. We access data needed for features you use.

Automatically collected

  • Server logs (IP, timestamps, request paths, error codes) for security and operations
  • Session cookies for OAuth, dashboard login, and app session continuity

Cookies & browser storage

  • Session cookies on the API and dashboard hosts for OAuth and account login
  • localStorage may store an app Bearer token so the Designer panel stays connected on the same device, and may cache non-personal SEO health flags (e.g. keys prefixed safPageHealthV1) cleared on disconnect
  • sessionStorage may hold AI consent and short-lived UI caches
  • We do not use third-party advertising or cross-site tracking cookies in the app

Custom code and schema on your sites

When you save, we write JSON-LD and related SEO fields through the official Data API. Static pages use registered inline scripts (Custom Code API). CMS items use CMS fields plus a template Embed you control. Your published site does not call our API on every visitor load, and we do not collect visitor telemetry from your site.

AI-assisted features (OpenAI)

When you click Generate, excerpts such as page title, description, URL, and schema context may be sent to OpenAI to produce suggestions. You initiate each generation. We do not train public models on your content for our own purposes. Nothing is sent for AI until you confirm/generate.

How we use information

  • Authenticate Webflow workspaces and Designer sessions (OAuth + ID token resolve)
  • Generate, preview, and save schema and metadata at your request
  • Issue and validate license keys and entitlements (page and AI limits)
  • Process payments via Razorpay and unlock licenses after successful pay
  • Operate, secure, monitor, and improve the App and dashboard
  • Respond to support and comply with legal obligations

We do not sell your personal information. We do not show ads in the App.

Legal bases (EEA / UK)

Where GDPR / UK GDPR applies, we process data based on:

  • Contract - provide the App, dashboard, and paid licenses you request
  • Legitimate interests - security, abuse prevention, reliability
  • Consent - where required (e.g. certain marketing emails, if ever used)
  • Legal obligation - tax/accounting records for paid orders where required

Third-party processors

  • Webflow, Inc. - OAuth, your site content, and Data API (Privacy)
  • OpenAI - Generate features only (Privacy)
  • Razorpay - payment processing for Pro plans (card/UPI data handled by Razorpay under its terms)
  • Email delivery (e.g. Resend) - OTP and password-reset emails
  • Hosting & databases - HTTPS hosting; MongoDB (or equivalent) for OAuth/app data; MySQL for dashboard accounts, licenses, and orders

Processors handle data to deliver the service under contractual safeguards where applicable.

Retention, uninstall & deletion

  • Disconnect in App: You sign out in the UI; we revoke the app token and attempt cleanup of app-registered custom code on authorized sites while the OAuth token is still valid. Local caches are cleared.
  • Marketplace uninstall / revoke: Ends Webflow authorization. Use Disconnect first when possible. POST https://api-schemapilot.appsrow.com/webhooks/uninstall with a valid app Bearer may also trigger cleanup.
  • Published site content remains under your Webflow account until you edit or republish after cleanup.
  • Dashboard accounts: kept while active; email us to delete account data, subject to retention needed for security and paid-order records.
  • Licenses & orders: retained as needed for entitlement, support, and legal/tax requirements.
  • Request deletion: email sales@appsrow.com from your account email, or use Disconnect / revoke in Webflow.

Security

We use HTTPS, access controls, hashed passwords for dashboard accounts, and industry-standard practices. No online service is 100% secure. Protect your Webflow and Dashboard credentials and revoke the App when you stop using it.

International transfers

Data may be processed in countries where we or our providers operate (including India and cloud regions used by Webflow, OpenAI, and Razorpay). We use appropriate safeguards where required by law.

Your rights

Depending on your location, you may have rights to access, correct, delete, restrict, or object to processing, and to lodge a complaint with a supervisory authority. Contact sales@appsrow.com.

California residents: We do not sell personal information. You may request access or deletion from the same contact; we will verify using your account email where practical.

Children

The App and Dashboard are not directed to children under 16. We do not knowingly collect their data.

Changes

We may update this policy by posting a new version here and updating the date above. Material changes for existing users may also be noted on the website. Continued use after the effective date means you accept the updated policy.

Contact

Privacy & data requests

sales@appsrow.com

Send email

schemapilot.appsrow.com

Support center · Terms of Service

© 2026 SchemaPilot · Independent Webflow Marketplace app Privacy · Terms · User Guide · Support · Plans