Algolia Search and Sync Privacy Policy
1. Scope
This Privacy Policy explains how Candid Leap LLC ("Candid Leap", "we", "us") handles personal information in connection with Algolia Search and Sync (the "App").
The App connects selected Webflow CMS content to an Algolia account controlled by the customer, provides tools in the Webflow Designer, and supplies a front-end search script for customer websites.
This Policy covers information about people who install or operate the App and information that passes through our systems while providing the App.
Visitor search queries on a published site normally go directly from the visitor's browser to the customer's Algolia account and do not pass through Candid Leap servers
2. Information We Collect and Process
2.1 Installation and Account Information
We may process:
- Webflow site ID, site name and related site metadata;
- the installing user's Webflow user ID and email address where Webflow provides it;
- additional notification email addresses you choose to add;
- App configuration, mappings, locales, sync settings and connection status.
2.2 Credentials
To operate the App, we may store:
- a Webflow OAuth access token;
- Algolia Application ID;
- restricted Algolia sync API key;
- search-only key; and
- index configuration.
Webflow OAuth tokens and Algolia sync keys are encrypted with AES-256-GCM before storage.
The search-only key is designed for public browser-side use.
2.3 CMS Content
When a sync runs, the App fetches content from the Webflow Collections you mapped, transforms selected fields in memory, and writes them to your Algolia index.
CMS field values are not intentionally stored in our database or webhook queue.
The webhook queue carries content identifiers rather than CMS field values.
Operational error diagnostics are sanitized to avoid storing or transmitting CMS field values or sensitive credentials.
2.4 Sync History and Operational Logs
We keep sync job metadata such as:
- site and collection identifiers;
- timestamps;
- operation status;
- counts;
- record identifiers; and
- error summaries.
Application logs may include request metadata, client IP addresses, site identifiers and server error details.
Request bodies, credentials and query strings are excluded or redacted from normal application logs.
2.5 Product Analytics
We use PostHog in our backend and Webflow Designer extension to understand product usage and reliability.
Analytics events are keyed to site identifiers and may include feature usage, counts, durations and error categories.
We do not intentionally send CMS content, credentials or operator email addresses to PostHog.
Session replay, autocapture, heatmaps, pageview tracking and surveys are disabled.
2.6 Support and Email
If you contact us or receive service notifications, we may process your email address, site information, support message and operational status information.
Transactional emails are delivered using Postmark.
3. Information We Do Not Normally Receive
We do not normally receive:
- your Webflow password;
- your Algolia dashboard password;
- your payment card or Webflow billing information;
- visitor search queries sent directly from the published site to Algolia; or
- screen recordings or keystrokes from the Webflow Designer extension.
4. How We Use Information
We use information:
- to authenticate and operate the App;
- to read the Collections you configure and sync them to your Algolia account;
- to process Webflow webhooks, scheduled syncs and manual syncs;
- to provide service and failure notifications;
- to secure, monitor and troubleshoot the App;
- to provide support and improve the product; and
- to comply with legal obligations and establish, exercise or defend legal claims.
We do not sell personal information or share it for cross-context behavioral advertising.
5. Roles and Legal Bases
For information about people who install, configure or operate the App, Candid Leap generally acts as the controller.
For personal data contained in mapped Webflow CMS content that we process according to a customer's instructions, the customer is the controller, or a processor acting for another controller, and Candid Leap acts as a processor or subprocessor.
That processing is governed by our DPA.
Where GDPR or UK GDPR applies to information for which Candid Leap is the controller, we rely as appropriate on:
- performance of a contract;
- our legitimate interests in operating and securing the business service;
- compliance with legal obligations; and
- consent where consent is specifically requested.
6. Providers and Sharing
Webflow and Algolia are customer-directed services connected through accounts owned by the customer.
Your relationship with those providers is governed by your own agreements with them.
The public search script is distributed through npm and jsDelivr.
Like other public CDNs, jsDelivr may receive technical request information such as a visitor's IP address and user agent when the script is loaded.
We may also disclose information where required by law, to protect our legal rights, or in connection with a merger, acquisition, financing, reorganization or sale of assets.
7. Cookies, Browser Storage and Algolia Insights
The published search script sets no cookies or persistent visitor identifiers by default.
Algolia Insights is off by default. If a customer enables Insights, related search analytics are sent directly from the visitor's browser to the customer's Algolia account and do not pass through Candid Leap servers.
A persistent _ALGOLIA cookie is used only if the customer separately enables Algolia's cookie-based user token behavior.
The customer is responsible for any notices or consent required on its website.
8. International Processing
Candid Leap is based in the United States.
Our backend and database operate in the United States, PostHog is configured to use its US cloud, and Cloudflare processes webhook traffic through its global edge network.
Where applicable data protection law requires safeguards for an international transfer, we will use appropriate safeguards as described in our DPA.
9. Security
We use technical and organizational measures designed to protect information processed through the App, including:
- AES-256-GCM encryption for stored Webflow OAuth tokens and Algolia sync keys;
- TLS for network connections to our application and service providers;
- HMAC verification and replay protection for incoming Webflow webhooks;
- short-lived authenticated API tokens and per-site authorization checks;
- rate limiting and internal shared-secret authentication for service-to-service requests; and
- log redaction for credentials, authorization headers, tokens and email fields.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
We do not currently make specific claims about production database backups until those backups are enabled and verified.
10. Retention and Deletion
We retain site configuration, credentials, mappings and sync history while the App remains installed and connected, unless a shorter period is required by law or we adopt a shorter operational retention period.
sync history remains for the life of the installation and is removed when the site's active database records are deleted.
When you disconnect or uninstall the App, we delete the site's stored credentials, configuration, mappings and sync history from our active database.
Your Algolia index and records remain in your own Algolia account.
Queue messages already accepted before deletion may remain until processed or expired, for up to 14 days.
They contain content identifiers rather than CMS field values and cannot use credentials after those credentials have been deleted.
Operational logs, analytics records and email delivery records may remain for the retention periods of the relevant service provider or where retention is required for security, legal or dispute-resolution purposes.
11. Your Privacy Rights
Depending on where you live and the law that applies, you may have rights to:
- access your personal information;
- correct inaccurate information;
- request deletion;
- restrict or object to certain processing;
- withdraw consent where processing is based on consent;
- receive a portable copy of certain information; or
- complain to a data protection authority.
If your request concerns personal data contained in a customer's Webflow CMS or Algolia index, we may direct you to that customer because the customer controls that information.
We will not discriminate against you for exercising rights provided by applicable privacy law.
12. Children
The App is a business and professional tool and is not directed at children.
Customers must not intentionally use the App to process children's personal information where prohibited by applicable law.
13. Changes to This Policy
We may update this Privacy Policy from time to time.
We will publish the revised version with a new effective date and make reasonable efforts to notify users of material changes.
14. Contact
Candid Leap LLC
1417 N Catalina St
Los Angeles, CA 90027
United States
Privacy questions and requests: algolia-support@candidleap.com

