Questwell: Privacy Policy
Effective 2026-10-05. Great Work LLC, 651 N Broad St Suite 206, Middletown, DE 19709, USA. Contact: hello@greatwork.company.
This policy explains what information the Questwell app for Zendesk Support (the "App") processes, why, and where it goes. It does not cover Zendesk's or Microsoft PlayFab's products, which are governed by their own policies.
In short
- The App runs entirely in your agents' browsers inside Zendesk. It talks only to your Zendesk
account (as the signed-in agent) and your PlayFab title (with the title secret key you entered,
through Zendesk's app proxy). The key is a Zendesk secure setting: Zendesk inserts it into the
X-SecretKey header on the way to your title's PlayFab address (
<title id>.playfabapi.com); it is never sent to agents' browsers and Great Work never sees it. - The App keeps nothing outside Zendesk and PlayFab: no copies, archives, caches or indexes, no browser storage, no export, no background processing, no analytics, nothing used to train AI.
- Great Work LLC receives no data from the App. We see only what you send us in a support email and the billing information Zendesk shares with app developers.
What the App processes
| Data | Why | Where it goes |
|---|---|---|
| The ticket's id, subject, description and requester (name, email), and the PlayFab id ticket field if you set one; on user profiles the user's id, name and email | To find the player: by the requester's emails, and by PlayFab ids and Steam ids written in the ticket | Read from Zendesk into browser memory while the App is open |
| The requester's other email identities | To match a player registered with any of their addresses | Read from Zendesk into browser memory |
| The ticket's comments | To find earlier Questwell notes, so caps count every grant on the ticket and a note is never posted twice | Read from Zendesk into browser memory |
| The signed-in agent's id, name, role and groups; the account's agent count | Permissions, naming the agent in notes, and checking the plan covers your team | Read from Zendesk into browser memory |
| The player's PlayFab account: PlayFab id, display name, username, login email, creation and login dates, how they joined, linked platform ids and names (Steam, Xbox, PSN, Nintendo, Apple, Google, Facebook, Twitch, Battle.net, OpenID, device and custom ids) | To show the agent who the player is | Read from PlayFab into browser memory while the App is open |
| The player's bans (reason, dates, active), currency balances, inventory items (item, dates, price paid, uses, annotation), lifetime spend and memberships, contact emails and tags, statistics, segments, and only the player data keys you list | To answer the ticket | Read from PlayFab into browser memory. IP addresses on bans are never shown |
| An action the agent confirms (grant currency or an item, ban with a reason and length, lift a ban, revoke an item, send the recovery email, reset a listed statistic) | The purpose of the App | Sent to PlayFab. Grants carry the Zendesk ticket number, the agent's Zendesk user id and a marker in PlayFab's custom tags, and granted items carry the ticket number in their annotation, so your PlayFab records point back to the ticket |
| A record of each action | Audit trail for your team | One internal note and one questwell_* tag on the Zendesk ticket |
Retention
Nothing is retained by the App. Data read for the sidebar disappears when the sidebar closes. Notes and tags written to your Zendesk tickets, and grants, bans and other changes in PlayFab, stay in those systems under your control and their retention settings.
Sharing and subprocessors
None. The App sends data only between your browser, your Zendesk account and your PlayFab title. We have no subprocessors for the App itself. Zendesk bills the subscription and shares billing details with us as described in Zendesk's Marketplace terms.
Security
The App has no server or database to breach. It loads the Zendesk Apps framework from Zendesk's CDN. PlayFab requests go through Zendesk's proxy over HTTPS, with the key inserted by Zendesk into the X-SecretKey header only, and only for your title's PlayFab address (the title id must be a short code of letters and digits, so the address cannot point anywhere else). PlayFab secret keys cannot be limited to some calls, so we recommend a key made only for Zendesk, with an expiry date and PlayFab's per-key IP allowlist set to Zendesk's outbound addresses, and narrowing who may grant and moderate in the App.
Your choices
- Admins decide who sees players, who may grant, who may moderate, which actions are on, the currency caps, the grantable items, the longest ban and which player data keys are shown.
- Uninstalling the App deletes the stored key; you can also disable or delete the key in PlayFab Game Manager at any time. Notes and tags already on tickets stay until you delete them.
- Requests about personal data in your Zendesk account or PlayFab title go to your organization, which controls that data. We can help you answer them.
- You can ask us for any information we hold about you (in practice, support emails and billing records). Write to hello@greatwork.company.
Changes
We will post changes here with a new effective date, and email account owners about material changes.