Sacolawell: Privacy Policy
Effective 2026-10-05. Great Work LLC, 651 N Broad St Suite 206, Middletown, DE 19709, USA. Contact: hello@greatwork.company.
This policy explains what information the Sacolawell app for Zendesk Support (the "App") processes, why, and where it goes. It does not cover Zendesk's or Nuvemshop's (Tiendanube's) products, which are governed by their own policies.
In short
- The App runs entirely in your agents' browsers inside Zendesk. It talks only to your Zendesk account (as the signed-in agent) and the Nuvemshop API for your store (through Zendesk's app proxy). When you connect your store, Nuvemshop issues an access token for Great Work's Sacolawell partner app, and Zendesk receives and keeps it. Zendesk inserts the token into a request header on its way to the Nuvemshop API; it is never sent to agents' browsers and Great Work never sees it. The same applies to a token you paste into the secure "Access token" setting.
- The App keeps nothing outside Zendesk and Nuvemshop: no copies, archives, caches or indexes, no browser storage, no export, no background processing, no analytics, nothing used to train AI.
- Great Work LLC receives no data from the App. We see only what you send us in a support email, the billing information Zendesk shares with app developers, and the store information Nuvemshop shows partners about stores that installed our partner app (store name and id).
What the App processes
| Data | Why | Where it goes |
|---|---|---|
| The ticket's id, subject, first message and requester (name, email); on user profiles the user's id, name, email | To find the requester's orders by email, and by CPF/CNPJ and order numbers written in the ticket | Read in the agent's browser only while the sidebar is open |
| The requester's other email addresses (Zendesk identities) | To look up every address | Same |
| The current agent's id, name, role, groups and language | To apply your action rules, name the agent in notes and pick the UI language | Same |
| Nuvemshop orders found for those emails, documents and numbers: order number, statuses, dates, contact name, email, phone and CPF/CNPJ (or DNI/CUIT), the customer account (name, email, document, total spent, customer since), shipping address, customer note, staff order note, items, prices, totals, discounts, coupon, payment method, card brand and installments, shipments with carrier, tracking number, link and tracking events | To show the agent the requester's orders. Orders that don't match the requester's exact email or a document in the ticket are dropped in memory and never shown (an order the ticket names is listed by number with a masked email) | Read in the agent's browser only while the sidebar is open, then discarded |
| Customer accounts matching a CPF/CNPJ from the ticket (id, name, email, document) | To find orders placed under that document with another email | Same |
| An action the agent confirms (a line added to the order note, a cancellation with its reason, customer email and restock choices) | The purpose of the App | Sent to your Nuvemshop store |
| A record of each action | Audit trail for your team | One internal note and one sacolawell_* tag on the Zendesk ticket |
The App never requests the buyer's IP address or browser details (Nuvemshop's client_details),
card numbers or payment transactions. Order note lines, cancellations, notes and tags written to
your orders and tickets stay in those systems under your control and their retention settings.
Sharing and subprocessors
None. The App sends data only between your browser, your Zendesk account and the Nuvemshop API. We have no subprocessors for the App itself. Zendesk bills the subscription and shares billing details with us as described in Zendesk's Marketplace terms.
Security
The App has no server or database to breach. It loads the Zendesk Apps framework from Zendesk's CDN. Nuvemshop requests go through Zendesk's proxy over HTTPS, with the token inserted by Zendesk into the request header only, and only for the Nuvemshop API hosts. The partner app asks Nuvemshop for orders and customers access only.
Your choices
- Admins decide who may take actions and which actions are on (cancelling is off by default).
- Uninstalling the App deletes the stored token from Zendesk; uninstall Sacolawell in your Nuvemshop admin's apps list as well to revoke the token at Nuvemshop. Note lines, cancellations and tags already written stay until you change them.
- Requests about personal data in your Zendesk account or store go to your organization, which controls that data. We can help you answer them, including under Brazil's LGPD (Lei 13.709/2018) and Argentina's Personal Data Protection Law (Ley 25.326).
- You can ask us for any information we hold about you (in practice, support emails and billing records). Write to hello@greatwork.company.
Changes
We will post changes here with a new effective date, and email account owners about material changes.