Okaygate privacy policy
Last updated: October 2, 2026
Okaygate is made by Great Work LLC, 651 N Broad St, Suite 206, Middletown, DE 19709, USA ("we"). This policy covers the Okaygate app for your CRM's app marketplace and the pages at hl.greatwork.company/approvals, including the approval pages approvers open from their email or text messages.
What we collect
When you install Okaygate on a business account, your CRM gives us access tokens for the permissions you approve. With them, for that business account only, we read and store:
- What you put in the approval step: the request title and details (which can include values your workflow fills in, such as an amount or a name), the steps and rules, and settings like reminders and deadlines.
- Approvers: names, email addresses and mobile numbers of the team members, addresses and numbers you name, or the value of the contact field you choose, as needed to send them the request.
- The contact the workflow is running for: its id, and its name, email and phone only if you choose "the contact approves".
- Decisions: who approved or rejected, when, and the comment they wrote.
- The ids of the workflow, the step and the opportunity the request belongs to.
When you open Okaygate inside your CRM, your CRM shares a signed record of who you are (user id, name, email, role and business account id). We use it to confirm you are signed in and to show what is waiting on you. When an approver opens a link, our server sees their IP address, which we use only to limit repeated attempts and do not store.
We do not read conversations, notes, payments or any contact other than the one in the workflow.
Why we use it
Only to send approval requests and reminders, record decisions, continue your workflows, start workflows that use the Approval decided trigger, add a decision note to the contact and show the history in the app. We do not sell data, use it for advertising, or train models on it.
Where it goes
- Your CRM. Approval messages are sent through your CRM's own email and SMS. Because your CRM can only message contacts, an approver who isn't already a contact is added as one, tagged "approver". We add a note to the contact when a request is decided.
- No one else. We use no subprocessors besides our host: a DigitalOcean server in New York, USA.
How it is protected
Access tokens, request titles and details, approver details, comments and the history are encrypted at rest with AES-256-GCM. All traffic uses HTTPS. Approval links are signed and unique to one approver and one step, stop working once the step is decided, and expire with the request. Opening a link only shows a confirm page; a decision is recorded only after the approver presses Confirm. Requests from your CRM are checked: webhooks by their digital signature, the decisions page by your CRM's signed user record, workflow actions by a secret key.
How long we keep it
Pending requests are kept until they are decided, cancelled or expire. Decided requests and their history are deleted 12 months after they close. When you uninstall Okaygate, or click Disconnect inside the app, we delete the access tokens and every request, decision and history entry for that business account right away. When a contact is deleted in your CRM, we delete the requests and history for that contact. Contacts and notes we created in your CRM stay there, under your control. Server logs that may contain IP addresses are kept for up to 14 days.
Your rights
You can see every request and its history inside the app and delete everything by uninstalling. For access, correction or deletion requests under GDPR, UK GDPR or CCPA, email hello@greatwork.company. If you are an approver or a contact of one of our customers, contact that business first; we act on their instructions as a processor.
Changes
We will post changes here and update the date above. Material changes are announced in the app.
Contact
hello@greatwork.company. We reply within one business day.