Sluicewell privacy policy
Last updated: October 3, 2026
Sluicewell is made by Great Work LLC, 651 N Broad St, Suite 206, Middletown, DE 19709, USA ("we"). This policy covers the Sluicewell app for your CRM's app marketplace and the pages at hl.greatwork.company/leads, including the inbound lead addresses and the return pages your clients open from a delivered lead's note.
Who is who
You (the business that installs Sluicewell to deliver leads to client accounts) are the controller of the lead data. We process it for you, as a processor, only to run Sluicewell.
What we collect
When you install Sluicewell, your CRM gives us access tokens for the permissions you approve. With them, and from the leads you send us, we read and store:
- Your client accounts' names, to list them and label reports.
- Your campaigns and client settings: territories (ZIP codes, states, radius areas), weights, delivery hours, caps, credit balances and their history, tags, pipeline choices and prices you enter for reports.
- Each lead you send us: name, email, phone number, address, company and any answers your form included, the campaign, where it came from (inbound address, workflow, API or entered by hand), where it was delivered and the delivery log (which client accounts were considered and why one was chosen or skipped).
- When the Distribute lead workflow action runs in your account, the name, email, phone and address of that workflow's contact.
- For duplicate checks, keyed one-way hashes (HMAC) of lead phone numbers and emails per client account. They can't be turned back into the number or address.
- Return requests (reason and comment) sent from the return page, and workflow trigger registrations (the workflow id and the address your CRM gives us to start it).
When you open Sluicewell inside your CRM, your CRM shares a signed record of who you are (user id, name, email, role and company id). We use it to confirm you are signed in. When a page or inbound address is called, our server sees the caller's IP address, which we use only to limit repeated attempts and do not store.
If a campaign uses radius areas, the lead's address is sent to our own geocoding service at geo.greatwork.company to find its coordinates; that service keeps a shared cache of address coordinates and a monthly count of lookups for billing, not lead names or contact details.
Why we use it
Only to route and deliver your leads to the client accounts you choose, prevent duplicates, keep credit balances, handle returns, start workflows that use the Sluicewell triggers, show you the delivery log and reports, and bill usage beyond your plan through your CRM. We do not sell data, use it for advertising, or train models on it, and we never use one customer's leads for another.
Where it goes
- Your CRM. Each delivered lead is created as a contact (with your tags, an optional opportunity and a note) in the client account it is routed to, and the triggers start workflows in that client account and in your own account. Usage beyond your plan is charged to your own account's wallet by your CRM.
- No one else. We use no subprocessors besides our host: a DigitalOcean server in New York, USA.
How it is protected
Access tokens, lead details, campaign and client settings, the delivery log, return requests and trigger addresses are encrypted at rest with AES-256-GCM. All traffic uses HTTPS. Inbound addresses contain a long random key you can replace at any time; API keys are stored only as hashes. Return links are signed, specific to one lead and expire at the end of your return window; return pages send no referrer, can't be embedded in other sites and are hidden from search engines. Requests from your CRM are checked: webhooks by their digital signature, the dashboard by your CRM's signed user record, workflow actions and trigger registrations by a secret key. Every query is limited to your own company.
How long we keep it
Lead details (name, email, phone, address, answers, return comments, the delivery log text) are erased 90 days after a lead is delivered, returned, held or rejected. The ledger line that remains (lead id, campaign, client account, times, ZIP code, status) and the credit history are deleted after 400 days. When a client account removes the app, we delete its client settings, credits and duplicate hashes and erase the details of leads delivered to it. When you uninstall Sluicewell, or press Disconnect inside the app, we delete the access tokens and everything we store for your company right away. Contacts, opportunities and notes we created in your CRM stay there, under your control. Server logs that may contain IP addresses are kept for up to 14 days.
Your rights
You can see every lead inside the app and delete everything by uninstalling. For access, correction or deletion requests under GDPR, UK GDPR or CCPA, email hello@greatwork.company. If you are a person whose details were sent as a lead, contact the business that collected them first; we act on their instructions.
Changes
We will post changes here and update the date above. Material changes are announced in the app.
Contact
hello@greatwork.company. We reply within one business day.