← Kickwell

Kickwell privacy policy

Last updated: October 3, 2026

Kickwell is made by Great Work LLC, 651 N Broad St, Suite 206, Middletown, DE 19709, USA ("we"). This policy covers the Kickwell app for your CRM's app marketplace and the pages at hl.greatwork.company/onboarding, including the onboarding pages your clients open from their email or text messages.

Who is who

You (the business that installs Kickwell to onboard your clients) are the controller of your clients' data. We process it for you, as a processor, only to run Kickwell.

What we collect

When you install Kickwell, your CRM gives us access tokens for the permissions you approve. With them we read and store:

  • Your client accounts' names, and the email and phone number on each account, to list them and suggest who to send the checklist to.
  • Your checklists and settings (your business name, team email, logo link, colors, reminder rules).
  • For each onboarding: the client contact's name, email and mobile number you enter, the answers the client submits (for example business details, brand colors, hours, domain and DNS provider, the business texting registration details such as legal name and business registration number, and profile links), the names, sizes and links of files they upload, which steps are done, and an activity history (sent, reminded, saved, completed).
  • Workflow trigger registrations (the workflow id and the address your CRM gives us to start it).

When you open Kickwell inside your CRM, your CRM shares a signed record of who you are (user id, name, email, role and company id). We use it to confirm you are signed in. When a client opens their link, our server sees their IP address, which we use only to limit repeated attempts and do not store.

The files themselves are not stored by us: they are sent straight to the client account's media library in your CRM, and we keep only their name, size and link. We do not read conversations, contacts, payments or anything else in the client accounts.

Why we use it

Only to show your clients their checklist, send the link and reminders, save answers and files into the client's account where you mapped them, start workflows that use the Kickwell triggers and show you the progress and history. We do not sell data, use it for advertising, or train models on it.

Where it goes

  • Your CRM. Links and reminders are sent through your own account's email and SMS. Because your CRM can only message contacts, the client contact is added to your own account (tagged "onboarding"). Mapped answers are written to the client account's custom values and business profile; files to its media library.
  • No one else. We use no subprocessors besides our host: a DigitalOcean server in New York, USA.

How it is protected

Access tokens, checklists, client details, answers, file links, trigger addresses and the history are encrypted at rest with AES-256-GCM. All traffic uses HTTPS. Each client link is signed, unique to one onboarding, expires (60 days by default) and can be replaced at any time, which stops the old link working. Client pages send no referrer, can't be embedded in other sites and are hidden from search engines. Requests from your CRM are checked: webhooks by their digital signature, the dashboard by your CRM's signed user record, trigger registrations by a secret key. Every query is limited to your own company.

How long we keep it

Open onboardings are kept while they are open. Finished and cancelled onboardings are deleted 12 months after their last change, or right away when you delete them. When a client account removes the app, we delete its onboardings. When you uninstall Kickwell, or press Disconnect inside the app, we delete the access tokens and everything we store for your company right away. Files, custom values and contacts we created in your CRM stay there, under your control. Server logs that may contain IP addresses are kept for up to 14 days.

Your rights

You can see and delete every onboarding inside the app and delete everything by uninstalling. For access, correction or deletion requests under GDPR, UK GDPR or CCPA, email hello@greatwork.company. If you are a client of one of our customers, contact that business first; we act on their instructions.

Changes

We will post changes here and update the date above. Material changes are announced in the app.

Contact

hello@greatwork.company. We reply within one business day.