Creelwell for Shopware: Privacy Policy
Effective date: October 1, 2026 Publisher: Great Work LLC, 651 N Broad St Suite 206, Middletown, DE 19709, USA Contact: hello@greatwork.company
This policy explains what information the Creelwell app for Zendesk Support (the "App") processes, where it is kept, and your choices. It covers only the App, not Zendesk's or shopware AG's products, which are governed by their own policies.
1. Summary
- The App runs in your browser inside Zendesk Support, through the Zendesk Apps framework. Great Work LLC operates no server for it and receives no data from it.
- It reads from and writes to two places only: your Zendesk account (as the signed-in agent, with that agent's permissions) and your Shopware 6 shop or shops (with the integration you create).
- Your integration's secret access key is stored by Zendesk as a secure setting. Zendesk adds it to the sign-in request on its way to the shop domain you entered; it is never sent to agents' browsers and Great Work never sees it. Shopware answers with a short-lived access token (10 minutes by default) limited to the integration's role; the App keeps it in browser memory only and forgets it when the sidebar closes.
- The App keeps nothing outside Zendesk and Shopware: no copies, archives, caches or indexes, no browser storage, no background collection, no analytics or usage statistics, no cookies of its own, no export, and no AI services.
2. What the App processes, and why
| Data | Why | Where it lives |
|---|---|---|
| The ticket's id, brand and requester (name, email); on user profiles the user's id, name, email | To find the requester's orders and choose the shop | Read from Zendesk into browser memory while the App is open |
| The requester's other email addresses (identities), and if your admin set a mapping, one user field | To match every address and the mapping you chose | Read from Zendesk into browser memory |
| Customer records (accounts and guest records) with those emails, and their orders: order number and date, items with product numbers and options, prices, discounts, totals, shipping method and address, the buyer's name, email and customer number, payment method and state, captures and refunds with their reasons, delivery states and tracking codes, the customer's checkout comment, the order's internal comment, the state history with its comments, the sales channel | To show the order history to the agent | Read from Shopware into browser memory while the App is open |
| The shop's sales channel names | To label orders by sales channel | Read from Shopware into browser memory |
| An action the agent confirms (state change, refund, internal comment, tracking code) | The purpose of the App | Sent to Shopware. State changes and refunds carry the Zendesk ticket id and the agent's name in the history comment or refund reason; internal comment lines carry the date, the agent's name and the ticket id |
| An internal note and a tag describing each action, with the agent's name | So your team can see what was done | Written to the ticket in your Zendesk account |
| The installation's plan name and settings (not the secret), and the agent's id, name, role and groups | To show the plan, apply who may take actions, and name the agent in notes | Read from Zendesk |
When the sidebar closes, everything it held in memory is gone, including the access token. What the App wrote stays in your Zendesk account and your Shopware shop under your control and their retention settings.
3. What Great Work LLC receives
Nothing from the App. If you email us for support, we receive what you send (we ask you not to send customer data, card details, passwords, access keys or secrets) and keep it in our email system for as long as needed to help you, at most 24 months. Billing for the App is handled by Zendesk through Stripe; we receive the subscription records Stripe provides to sellers (your Zendesk domain, the plan, payment status and billing contact), which we keep as long as tax and accounting law requires.
4. Sharing
We do not sell, rent or share personal information. The App sends data only to your Zendesk account and to your Shopware shop's Admin API. We have no subprocessors for the App itself. Your payment extension and payment provider receive a refund request from Shopware when an agent refunds through the App; that is between your shop and your provider.
5. AI and model training
The App uses no AI services, and no data processed by the App is used to train any model.
6. Security
The App has no server or database to breach and installs nothing in Shopware. It loads the Zendesk Apps framework from Zendesk's CDN. Requests to your shop go through Zendesk's proxy over HTTPS. The secret access key is a secure setting that can only travel in the body of the sign-in request and only to the shop domain you entered. The short-lived token that Shopware returns reaches the browser of agents who open the App, so the App refuses integrations with administrator rights: the token can only do what the integration's role allows. We recommend a role with read permissions only unless you want actions. Actions are off for everyone except admins until an admin allows more roles, every action needs a confirmation, refunds above a limit you set need an admin, and recording a payment as paid by hand is admin-only. Report a security issue to hello@greatwork.company; we treat it as urgent.
7. Your choices and rights
- Admins choose who may take actions, which actions exist and the refund limit, and can uninstall at any time. Uninstalling deletes the stored secret; delete the integration in Shopware as well, which stops new tokens at once. Notes and tags already on tickets stay until you delete them.
- Requests about personal data in your Zendesk account or your shop go to your administrator, who controls that data. Questions about this policy: hello@greatwork.company.
- If you are in the EEA, UK or California, you have rights to access, correct and delete personal information we hold about you (in practice, support emails and billing records). Write to us.
8. Changes
We will post changes here with a new effective date and, for material changes, email the billing contact of each paying account at least 14 days before they apply.