Loyalwell for Zendesk: Privacy Policy
Effective date: October 1, 2026 Publisher: Great Work LLC, 651 N Broad St Suite 206, Middletown, DE 19709, USA Contact: hello@greatwork.company
This policy explains what information the Loyalwell app for Zendesk Support (the "App") processes, where it is kept, and your choices. It covers only the App, not Zendesk's, LoyaltyLion's, Yotpo's or Smile's products, which are governed by their own privacy policies.
1. Summary
- The App runs in your browser inside Zendesk Support, through the Zendesk Apps framework. Great Work LLC operates no server for it and receives no data from it.
- It reads from and writes to two places only: your Zendesk account (as the signed-in agent, with that agent's permissions) and the loyalty program or programs you connect (LoyaltyLion, Yotpo Loyalty & Referrals or Smile.io, with the API keys you create).
- Your API keys (and Yotpo GUID) are stored by Zendesk as secure settings. Zendesk adds them to requests on their way to your platform's API (api.loyaltylion.com, loyalty.yotpo.com or api.smile.io); the keys are never sent to agents' browsers and Great Work never sees them.
- The App keeps nothing outside Zendesk and your loyalty platform: no copies, archives, caches or indexes, no browser storage, no background collection, no analytics or usage statistics, no cookies of its own, no export, and no AI services.
2. What the App processes, and why
| Data | Why | Where it lives |
|---|---|---|
| The ticket's id, brand and requester (name, email); on user profiles the user's id, name, email | To find the matching loyalty customer and choose the program | Read from Zendesk into browser memory while the App is open |
| The requester's other email addresses (identities) | To match every address they use | Read from Zendesk into browser memory |
| Loyalty customers matching those emails, and for the customer shown: points balance, pending, earned, spent and expiring points, program status, tier with dates and progress, birthday (day and month, and year if given), referral link and referrer, insight segment, order count, points history (activities, adjustments, expiries, redemptions with their reasons), redeemed rewards and their codes | To show the loyalty picture to the agent | Read from your loyalty platform into browser memory while the App is open |
| The rewards your program offers the customer, and your tier list | To offer rewards the agent can issue and name the next tier | Read from your loyalty platform into browser memory |
| An action the agent confirms (add or deduct points with a reason, issue a reward) | The purpose of the App | Sent to your loyalty platform. The reason is shown to the customer in their points history. On Smile, a merchant-only note with the Zendesk ticket number and the agent's name is stored with the transaction |
| An internal note and a tag describing each action, with the agent's name and any reward code | So your team can see what was done | Written to the ticket in your Zendesk account |
| The installation's plan name and settings (not the keys), and the agent's id, name, role and groups | To show the plan, apply who may take actions and their point limits, and name the agent in notes | Read from Zendesk |
When the sidebar closes, everything it held in memory is gone. What the App wrote stays in your Zendesk and loyalty accounts under your control and their retention settings. If an agent clicks "Add code to reply", the code is placed in that agent's reply draft in Zendesk; nothing is sent until the agent sends the reply.
3. What Great Work LLC receives
Nothing from the App. If you email us for support, we receive what you send (we ask you not to send customer data, passwords or API keys) and keep it in our email system for as long as needed to help you, at most 24 months. Billing for the App is handled by Zendesk through Stripe; we receive the subscription records Stripe provides to sellers (your Zendesk domain, the plan, payment status and billing contact), which we keep as long as tax and accounting law requires.
4. Sharing
We do not sell, rent or share personal information. The App sends data only to your Zendesk account and to the API of the loyalty platform you connected. That platform processes the data in those requests under its own terms and privacy notice. We have no subprocessors for the App itself.
5. AI and model training
The App uses no AI services, and no data processed by the App is used to train any model.
6. Security
The App has no server or database to breach. It loads the Zendesk Apps framework from Zendesk's CDN. Loyalty requests go through Zendesk's proxy with keys in secure settings that can only be used in a request header, and only toward the three loyalty API hosts. No loyalty platform has idempotency keys, so the App re-reads the customer before each change, sends it once and, if the answer is lost, re-reads the customer instead of sending it again. Every action needs a confirmation, and agents are limited to 500 points per action unless an admin sets other limits. Report a security issue to hello@greatwork.company; we treat it as urgent.
7. Your choices and rights
- Admins choose who may take actions, which actions exist and how many points each role may move, and can uninstall at any time. Uninstalling deletes the stored keys; delete the keys in your loyalty platform as well. Notes and tags already on tickets stay until you delete them.
- Requests about personal data in your Zendesk or loyalty account go to your administrator, who controls that data. Questions about this policy: hello@greatwork.company.
- If you are in the EEA, UK or California, you have rights to access, correct and delete personal information we hold about you (in practice, support emails and billing records). Write to us.
8. Changes
We will post changes here with a new effective date and, for material changes, email the billing contact of each paying account at least 14 days before they apply.