← Pursewell

Pursewell for Zendesk: Privacy Policy

Effective date: October 1, 2026 Publisher: Great Work LLC, 651 N Broad St Suite 206, Middletown, DE 19709, USA Contact: hello@greatwork.company

This policy explains what information the Pursewell app for Zendesk Support (the "App") processes, where it is kept, and your choices. It covers only the App, not Zendesk's, PayPal's or Braintree's products, which are governed by their own privacy policies.

1. Summary

  • The App runs in your browser inside Zendesk Support, through the Zendesk Apps framework. Great Work LLC operates no server for it and receives no data from it.
  • It reads from and writes to three places only: your Zendesk account (as the signed-in agent, with that agent's permissions), your PayPal business account (with the REST app credentials you create) and your Braintree account (with the API key you create).
  • Your PayPal secret and Braintree private key are stored by Zendesk as secure settings. Zendesk adds them to requests on its own servers on their way to PayPal's or Braintree's API hosts; they are never sent to agents' browsers and Great Work never sees them.
  • PayPal answers the sign-in with an access token that lasts up to 9 hours. That token is held in the memory of the browsers of agents allowed to see payments while the App is open, and is never stored, logged or written anywhere. The App refuses a PayPal app whose token could send payouts or credits to new recipients.
  • The App keeps nothing outside Zendesk, PayPal and Braintree: no copies, archives, caches or indexes, no browser storage, no background collection, no analytics or usage statistics, no cookies of its own, no export, and no AI services.

2. What the App processes, and why

DataWhyWhere it lives
The ticket's id and requester (name, email); on user profiles the user's id, name, emailTo find that person's paymentsRead from Zendesk into browser memory while the App is open
The requester's other email addresses (identities)To match every address they pay withRead from Zendesk into browser memory
PayPal Transaction Search pages for the search window you set (default 90 days)PayPal's search has no filter by payer, so the App reads the pages and keeps only rows whose payer email belongs to the requester. Other customers' rows are discarded as each page arrives and never shown, kept or sent anywhereBrowser memory, for the moment a page is processed
For the requester: PayPal payments (amount, date, type, status, invoice id, payer name and email), refunds, disputes (reason, amount, stage, status, respond-by date) and subscriptions (status, plan id, next and last payment, failed payments, balance owed); Braintree transactions (amount, date, status, order id, card brand and last four digits or PayPal payer email, customer name and email), refunds, disputes and subscriptionsTo show the payment picture to the agentRead into browser memory while the App is open
An action the agent confirms (refund, void, cancel, suspend, reactivate, charge a past-due balance)The purpose of the AppSent to your PayPal or Braintree account. PayPal refunds carry the reason and the Zendesk ticket number; PayPal emails the reason to the payer
An internal note and a tag describing each action, with the agent's nameSo your team can see what was doneWritten to the ticket in your Zendesk account
The installation's plan name and settings (not the secrets), the account's agent count, and the agent's id, name, role and groupsTo show the plan, check the plan band, apply who may see and act, and name the agent in notesRead from Zendesk

When the sidebar closes, everything it held in memory is gone. What the App wrote stays in your Zendesk, PayPal and Braintree accounts under your control and their retention settings.

3. What Great Work LLC receives

Nothing from the App. If you email us for support, we receive what you send (we ask you not to send customer data, card details, passwords, secrets or keys) and keep it in our email system for as long as needed to help you, at most 24 months. Billing for the App is handled by Zendesk through Stripe; we receive the subscription records Stripe provides to sellers (your Zendesk domain, the plan, payment status and billing contact), which we keep as long as tax and accounting law requires.

4. Sharing

We do not sell, rent or share personal information. The App sends data only to your Zendesk account and to the PayPal and Braintree APIs of your own accounts. We have no subprocessors for the App itself.

5. AI and model training

The App uses no AI services, and no data processed by the App is used to train any model.

6. Security

The App has no server or database to breach. It loads the Zendesk Apps framework from Zendesk's CDN. Secrets travel only inside Zendesk's proxy, only toward the four PayPal and Braintree API hosts listed in the App's manifest. Refunds carry PayPal's and Braintree's idempotency keys, so a lost answer is resent with the same key and can never refund twice; other actions are sent once and re-read instead of resent. Actions are admin-only until an admin allows more roles, every action needs a confirmation, refunds above a limit you set need an admin, and charging a balance is off until you turn it on. Report a security issue to hello@greatwork.company; we treat it as urgent.

7. Your choices and rights

  • Admins choose who sees payments, who may take actions, which actions exist and the refund limit, and can uninstall at any time. Uninstalling deletes the stored secrets; also delete the PayPal app and the Braintree API key you made for Zendesk. Notes and tags already on tickets stay until you delete them.
  • Requests about personal data in your Zendesk, PayPal or Braintree account go to your administrator, who controls that data. Questions about this policy: hello@greatwork.company.
  • If you are in the EEA, UK or California, you have rights to access, correct and delete personal information we hold about you (in practice, support emails and billing records). Write to us.

8. Changes

We will post changes here with a new effective date and, for material changes, email the billing contact of each paying account at least 14 days before they apply.