Exhibitwell privacy policy
Last updated: October 5, 2026
Exhibitwell is made by Great Work LLC, 651 N Broad St, Suite 206, Middletown, DE 19709, USA ("we"). This policy covers the Exhibitwell app for your CRM's app marketplace and the pages at hl.greatwork.company/disputes, including the policy acceptance pages your customers open.
What we collect
When you install Exhibitwell on a business account, your CRM gives us access tokens for the permissions you approve. We use them for that business account only.
For each dispute (from your Stripe account, or one you add by hand) we store its id, reason, amount, status, response deadline, the customer's contact id and the payment id it belongs to. When you collect evidence, we read the following about that one customer and keep it as an evidence snapshot for the dispute:
- The contact's name, email, phone, address, the date they were added and their source.
- The disputed payment (amount, date, status, processor charge id, the IP address it was paid from, what it paid for) and the amounts, dates and statuses of the customer's other payments.
- The order or invoice lines (item names, quantities, amounts).
- Documents the customer signed in your CRM: name, status, signing time, signer name, IP address and browser. If you also use our document app on the same business account and leave the setting on, the names, dates and file links of documents it generated for the customer.
- Form answers that are about terms, refunds, cancellation or consent (for example a ticked "I agree to the refund policy" box), with the submission time. We do not keep the other answers on the form.
- Appointment titles, times and attendance status.
- Short excerpts of messages with the customer (by default up to 30 messages of up to 280 characters, from 60 days before the payment up to the dispute; you can lower these). Runs of 12 or more digits, such as card numbers, are removed. Internal comments and activity entries are not read into the snapshot.
Recorded evidence. When your workflows use the "Record evidence" step, or you add a milestone yourself, we store the contact id, the kind (for example delivered or lesson completed), the time, and the short label and detail you set.
Policy acceptances. When your workflow sends a policy acceptance link and the customer clicks "I agree", we store the contact id, the exact policy text and version they saw, the time, their IP address and their browser's user agent. Opening the link without clicking records nothing.
Your Stripe key. If you connect Stripe, we store your restricted key encrypted. We refuse full secret keys. The key is only ever sent to Stripe, in the request header, to list your disputes, read the disputed charge (if you allowed it) and, only when you confirm a submission in the app, upload the pack and send evidence to that dispute.
Your team. To email reminders, we read your users' names and emails, and create a contact (tagged
dispute-alerts) in your own account for each team member you choose to alert.
When you open Exhibitwell inside your CRM, your CRM shares a signed record of who you are (user id, name, email, role and business account id). We use it to confirm you are an admin of that business account.
What we do with it
Only what the app does for you: build dispute evidence packs and checklists, remind you about deadlines, run your workflow triggers, and send evidence to Stripe when you confirm. We don't sell data, use it for advertising, combine it across customers or use it to train any model. The app makes no calls to any AI service.
Where it is stored and how it is protected
On our server in the United States (DigitalOcean, New York). Access tokens, the Stripe key, evidence snapshots, recorded evidence, policy texts and acceptances, settings and notes are encrypted at rest with AES-256-GCM. Connections use HTTPS. Pages customers open set no cookies and load nothing from other sites.
How long we keep it
- Evidence snapshots and packs: until the dispute closes, then 180 days.
- Recorded evidence and policy acceptances: the period you set in Settings (540 days at most, 120 at least), because disputes can arrive months after a purchase.
- When a contact is deleted in your CRM, we delete their recorded evidence and acceptances and erase the customer details and snapshot from their disputes.
- When you uninstall the app or click Disconnect, we delete everything for that business account immediately, including the Stripe key.
Sharing
We send evidence to Stripe only for disputes from your connected Stripe account and only after you confirm. We use DigitalOcean (hosting). Otherwise we disclose data only if the law requires it.
Your choices
You can untick any item before downloading or sending a pack, lower or turn off message excerpts, turn off generated documents, shorten retention, remove the Stripe key at any time, and Disconnect to delete everything. Your customers can ask you to delete their data; deleting their contact in your CRM deletes it from Exhibitwell too.
Contact
hello@greatwork.company. We reply within one business day.