← Questwell

Questwell: Privacy Policy

Effective 2026-10-05. Great Work LLC, 651 N Broad St Suite 206, Middletown, DE 19709, USA. Contact: hello@greatwork.company.

This policy explains what information the Questwell app for Zendesk Support (the "App") processes, why, and where it goes. It does not cover Zendesk's or Microsoft PlayFab's products, which are governed by their own policies.

In short

  • The App runs entirely in your agents' browsers inside Zendesk. It talks only to your Zendesk account (as the signed-in agent) and your PlayFab title (with the title secret key you entered, through Zendesk's app proxy). The key is a Zendesk secure setting: Zendesk inserts it into the X-SecretKey header on the way to your title's PlayFab address (<title id>.playfabapi.com); it is never sent to agents' browsers and Great Work never sees it.
  • The App keeps nothing outside Zendesk and PlayFab: no copies, archives, caches or indexes, no browser storage, no export, no background processing, no analytics, nothing used to train AI.
  • Great Work LLC receives no data from the App. We see only what you send us in a support email and the billing information Zendesk shares with app developers.

What the App processes

DataWhyWhere it goes
The ticket's id, subject, description and requester (name, email), and the PlayFab id ticket field if you set one; on user profiles the user's id, name and emailTo find the player: by the requester's emails, and by PlayFab ids and Steam ids written in the ticketRead from Zendesk into browser memory while the App is open
The requester's other email identitiesTo match a player registered with any of their addressesRead from Zendesk into browser memory
The ticket's commentsTo find earlier Questwell notes, so caps count every grant on the ticket and a note is never posted twiceRead from Zendesk into browser memory
The signed-in agent's id, name, role and groups; the account's agent countPermissions, naming the agent in notes, and checking the plan covers your teamRead from Zendesk into browser memory
The player's PlayFab account: PlayFab id, display name, username, login email, creation and login dates, how they joined, linked platform ids and names (Steam, Xbox, PSN, Nintendo, Apple, Google, Facebook, Twitch, Battle.net, OpenID, device and custom ids)To show the agent who the player isRead from PlayFab into browser memory while the App is open
The player's bans (reason, dates, active), currency balances, inventory items (item, dates, price paid, uses, annotation), lifetime spend and memberships, contact emails and tags, statistics, segments, and only the player data keys you listTo answer the ticketRead from PlayFab into browser memory. IP addresses on bans are never shown
An action the agent confirms (grant currency or an item, ban with a reason and length, lift a ban, revoke an item, send the recovery email, reset a listed statistic)The purpose of the AppSent to PlayFab. Grants carry the Zendesk ticket number, the agent's Zendesk user id and a marker in PlayFab's custom tags, and granted items carry the ticket number in their annotation, so your PlayFab records point back to the ticket
A record of each actionAudit trail for your teamOne internal note and one questwell_* tag on the Zendesk ticket

Retention

Nothing is retained by the App. Data read for the sidebar disappears when the sidebar closes. Notes and tags written to your Zendesk tickets, and grants, bans and other changes in PlayFab, stay in those systems under your control and their retention settings.

Sharing and subprocessors

None. The App sends data only between your browser, your Zendesk account and your PlayFab title. We have no subprocessors for the App itself. Zendesk bills the subscription and shares billing details with us as described in Zendesk's Marketplace terms.

Security

The App has no server or database to breach. It loads the Zendesk Apps framework from Zendesk's CDN. PlayFab requests go through Zendesk's proxy over HTTPS, with the key inserted by Zendesk into the X-SecretKey header only, and only for your title's PlayFab address (the title id must be a short code of letters and digits, so the address cannot point anywhere else). PlayFab secret keys cannot be limited to some calls, so we recommend a key made only for Zendesk, with an expiry date and PlayFab's per-key IP allowlist set to Zendesk's outbound addresses, and narrowing who may grant and moderate in the App.

Your choices

  • Admins decide who sees players, who may grant, who may moderate, which actions are on, the currency caps, the grantable items, the longest ban and which player data keys are shown.
  • Uninstalling the App deletes the stored key; you can also disable or delete the key in PlayFab Game Manager at any time. Notes and tags already on tickets stay until you delete them.
  • Requests about personal data in your Zendesk account or PlayFab title go to your organization, which controls that data. We can help you answer them.
  • You can ask us for any information we hold about you (in practice, support emails and billing records). Write to hello@greatwork.company.

Changes

We will post changes here with a new effective date, and email account owners about material changes.