Canoewell for Zendesk: Privacy Policy
Effective date: October 1, 2026 Publisher: Great Work LLC, 651 N Broad St Suite 206, Middletown, DE 19709, USA Contact: hello@greatwork.company
This policy explains what information the Canoewell app for Zendesk Support (the "App") processes, where it is kept, and your choices. It covers only the App, not Zendesk's or Paddle's products, which are governed by their own privacy policies. Paddle is the merchant of record for your sales; its relationship with your customers is described in Paddle's own terms and privacy notice.
1. Summary
- The App runs in your browser inside Zendesk Support, through the Zendesk Apps framework. Great Work LLC operates no server for it and receives no data from it.
- It reads from and writes to two places only: your Zendesk account (as the signed-in agent, with that agent's permissions) and your Paddle Billing account or accounts (with the API key you create).
- Your Paddle API key is stored by Zendesk as a secure setting. Zendesk adds it to requests on their way to Paddle's API (api.paddle.com or sandbox-api.paddle.com); the key is never sent to agents' browsers and Great Work never sees it.
- The App keeps nothing outside Zendesk and Paddle: no copies, archives, caches or indexes, no browser storage, no background collection, no analytics or usage statistics, no cookies of its own, no export, and no AI services.
2. What the App processes, and why
| Data | Why | Where it lives |
|---|---|---|
| The ticket's id, brand and requester (name, email); on user profiles the user's id, name, email | To find the matching Paddle customer and choose the Paddle account | Read from Zendesk into browser memory while the App is open |
| The requester's other email addresses (identities), and if your admin set a mapping, their user record (one user field) | To match every address and the mapping you chose | Read from Zendesk into browser memory |
| Paddle customers matching those emails or the mapped customer id, and for the customer shown: subscriptions (items, prices, discount, dates, status, scheduled changes), recent and past-due transactions (amounts, dates, status, invoice numbers, line items, payment attempts with card type, last four digits, expiry month and year, and the failure reason), refunds and credits (amounts, status, reason), credit balance | To show the billing picture to the agent | Read from Paddle into browser memory while the App is open |
| A temporary invoice PDF link, when an agent opens an invoice | To show the invoice | Opened in a new browser tab; not kept |
| A temporary customer portal link for updating the payment method, when an agent adds it to a reply | So the customer can change their card with Paddle | Added to the agent's reply draft; it becomes part of the ticket only if the agent sends the reply |
| An action the agent confirms (refund request, invoice credit, cancellation or removal of a scheduled change, pause or resume, discount) | The purpose of the App | Sent to your Paddle account. Refund and credit reasons include the Zendesk ticket number |
| An internal note and a tag describing each action, with the agent's name | So your team can see what was done | Written to the ticket in your Zendesk account |
| The installation's plan name and settings (not the key), and the agent's id, name, role and groups | To show the plan, apply who may take actions, and name the agent in notes | Read from Zendesk |
When the sidebar closes, everything it held in memory is gone. What the App wrote stays in your Zendesk and Paddle accounts under your control and their retention settings.
3. What Great Work LLC receives
Nothing from the App. If you email us for support, we receive what you send (we ask you not to send customer data, card details, passwords or keys) and keep it in our email system for as long as needed to help you, at most 24 months. Billing for the App is handled by Zendesk through Stripe; we receive the subscription records Stripe provides to sellers (your Zendesk domain, the plan, payment status and billing contact), which we keep as long as tax and accounting law requires.
4. Sharing
We do not sell, rent or share personal information. The App sends data only to your Zendesk account and to the Paddle API of your own Paddle accounts. We have no subprocessors for the App itself.
5. AI and model training
The App uses no AI services, and no data processed by the App is used to train any model.
6. Security
The App has no server or database to breach. It loads the Zendesk Apps framework from Zendesk's CDN. Paddle requests go through Zendesk's proxy with the key in a secure setting that can only be used in a request header, and only toward Paddle's two API hosts. Paddle has no idempotency keys, so the App sends each write once and, if the answer is lost, re-reads Paddle instead of sending it again. Actions are off for everyone except admins until an admin allows more roles, every action needs a confirmation, refunds and credits above a limit you set need an admin, and cancelling immediately is admin-only unless you allow it. Report a security issue to hello@greatwork.company; we treat it as urgent.
7. Your choices and rights
- Admins choose who may take actions, which actions exist, the refund limit and the discounts agents may apply, and can uninstall at any time. Uninstalling deletes the stored keys; revoke the API key in Paddle as well. Notes and tags already on tickets stay until you delete them.
- Requests about personal data in your Zendesk or Paddle account go to your administrator, who controls that data. Questions about this policy: hello@greatwork.company.
- If you are in the EEA, UK or California, you have rights to access, correct and delete personal information we hold about you (in practice, support emails and billing records). Write to us.
8. Changes
We will post changes here with a new effective date and, for material changes, email the billing contact of each paying account at least 14 days before they apply.