← Larkwell

Larkwell for Zendesk: Privacy Policy

Effective date: October 1, 2026 Publisher: Great Work LLC, 651 N Broad St Suite 206, Middletown, DE 19709, USA Contact: hello@greatwork.company

This policy explains what information the Larkwell app for Zendesk Support (the "App") processes, where it is kept, and your choices. It covers only the App, not Zendesk's or Zoho's products, which are governed by their own privacy policies.

1. Summary

  • The App runs in your browser inside Zendesk Support, through the Zendesk Apps framework. Great Work LLC operates no server for it and receives no data from it.
  • It reads from and writes to two places only: your Zendesk account (as the signed-in agent, with that agent's permissions) and your own Zoho account (Zoho CRM, Zoho Books, Zoho Billing and Zoho Inventory, whichever you use), signing in with the Zoho Self Client you create.
  • Your client secret and refresh tokens are stored by Zendesk as secure settings. Zendesk adds them to the sign-in request on its way to Zoho's sign-in host for your data center (accounts.zoho.com, accounts.zoho.eu and so on); they are never sent to agents' browsers and Great Work never sees them. When an admin makes the first refresh token in the setup check, Zoho shows it once in that admin's browser so it can be pasted into the setting; the App does not keep it.
  • Zoho answers the sign-in with an access token that lasts one hour. The App keeps it in memory only, in the agent's open Zendesk tabs, to read and write your Zoho account, and it is limited to the scopes you granted. The App refuses to run with a token that can manage Zoho CRM settings or Zoho Books banking.
  • The App keeps nothing outside Zendesk and Zoho: no copies, archives, caches or indexes, no browser storage, no background collection, no analytics or usage statistics, no cookies of its own, no export, and no AI services.

2. What the App processes, and why

DataWhyWhere it lives
The ticket's id and subject and the requester's name and email; on user profiles the user's id, name and email; on organization profiles the organization's id, name and domainsTo find the matching Zoho records and to link actions back to the ticketRead from Zendesk into browser memory while the App is open
The requester's other email addresses (identities)To match every address they useRead from Zendesk into browser memory
Zoho CRM contacts matching those emails and, for the record shown: name, emails, title, phone, lead source, owner and dates; the account (name, number, website, industry, size, city, country, type, revenue, owner); deals (name, amount, stage, probability, close date, owner); recent tasks, meetings, calls and notes (subject or title, text, dates, owner); accounts matching an email or organization domainTo show the CRM picture to the agentRead from Zoho into browser memory while the App is open
Zoho Books customers linked to that contact or account or matching those emails, with their outstanding balance, recent invoices (number, dates, status, total, balance) and payments (number, date, amount, mode)To show what the customer owesRead from Zoho into browser memory
Zoho Billing customers and subscriptions (plan, amount, status, dates)To show the customer's subscriptionsRead from Zoho into browser memory
Zoho Inventory customers, sales orders (number, date, status, total) and their shipments (carrier, tracking number, status, date)To show orders and deliveryRead from Zoho into browser memory
The organizations your token can reach in Books, Billing and Inventory (id, name, currency), and whether the token can read CRM security profiles or Books bank accountsTo pick the organization, refuse overly broad tokens and run the setup checkRead from Zoho into browser memory; nothing from these probes is shown or kept
An action the agent confirms (create a contact, add a note, log a call)The purpose of the AppSent to your Zoho CRM. Notes and calls carry the ticket number and link (unless the agent turns the link off), the ticket subject, the agent's name and what the agent typed; never the ticket conversation
An internal note and a tag describing each action, with the agent's nameSo your team can see what was doneWritten to the ticket in your Zendesk account
The installation's plan name and settings (not the secrets), the account subdomain, the count of agents and admins, and the agent's id, name, email, role and groupsTo check the plan, apply who may take actions and name the agent in notesRead from Zendesk

When the agent's Zendesk tabs close, everything the App held in memory, including the access token, is gone. What the App wrote stays in your Zendesk and Zoho accounts under your control and their retention settings.

3. What Great Work LLC receives

Nothing from the App. If you email us for support, we receive what you send (we ask you not to send customer data, passwords, secrets or tokens) and keep it in our email system for as long as needed to help you, at most 24 months. Billing for the App is handled by Zendesk through Stripe; we receive the subscription records Stripe provides to sellers (your Zendesk domain, the plan, payment status and billing contact), which we keep as long as tax and accounting law requires.

4. Sharing

We do not sell, rent or share personal information. The App sends data only to your Zendesk account and to Zoho's sign-in and API hosts for your data center. We have no subprocessors for the App itself.

5. AI and model training

The App uses no AI services, and no data processed by the App is used to train any model.

6. Security

The App has no server or database to breach. It loads the Zendesk Apps framework from Zendesk's CDN. Zoho requests go through Zendesk's proxy. The client secret and refresh tokens are secure settings that can only be used in a request body and only for a fixed list of Zoho-owned hosts. The access token the App receives is bounded by the scopes of your refresh token: the setup guide's scopes read customer records and create contacts, notes and calls, and cannot edit or delete records, change settings or touch banking. The App checks the token every time it opens and refuses broad tokens. Admins also choose who may take actions in Zendesk, and every action needs a confirmation. Revoking the token in Zoho Accounts (Security > Connected Apps) or deleting the Self Client stops all access at once. Report a security issue to hello@greatwork.company; we treat it as urgent.

7. Your choices and rights

  • Admins choose who may take actions, which actions exist, which Zoho products are shown and whether domain matching is on, and can uninstall at any time. Uninstalling deletes the stored secrets; revoke the refresh tokens in Zoho as well. Notes and tags already on tickets, and records created in Zoho CRM, stay until you delete them.
  • Requests about personal data in your Zendesk or Zoho account go to your administrator, who controls that data. Questions about this policy: hello@greatwork.company.
  • If you are in the EEA, UK or California, you have rights to access, correct and delete personal information we hold about you (in practice, support emails and billing records). Write to us.

8. Changes

We will post changes here with a new effective date and, for material changes, email the billing contact of each paying account at least 14 days before they apply.