← Tillwell

Tillwell for Zendesk: Privacy Policy

Effective date: October 1, 2026 Publisher: Great Work LLC, 651 N Broad St Suite 206, Middletown, DE 19709, USA Contact: hello@greatwork.company

This policy explains what information the Tillwell app for Zendesk Support (the "App") processes, where it is kept, and your choices. It covers only the App, not Zendesk's or Stripe's products, which are governed by their own privacy policies.

1. Summary

  • The App runs in your browser inside Zendesk Support, through the Zendesk Apps framework. Great Work LLC operates no server for it and receives no data from it.
  • It reads from and writes to two places only: your Zendesk account (as the signed-in agent, with that agent's permissions) and your Stripe account (with the restricted key you create).
  • Your Stripe key is stored by Zendesk as a secure setting. Zendesk adds it to requests on their way to api.stripe.com; the key is never sent to agents' browsers and Great Work never sees it.
  • The App keeps nothing outside Zendesk and Stripe: no copies, archives, caches or indexes, no browser storage, no background collection, no analytics or usage statistics, no cookies of its own, no export, and no AI services.

2. What the App processes, and why

DataWhyWhere it lives
The ticket's id, brand and requester (name, email); on user profiles the user's id, name, emailTo find the matching Stripe customer and choose the Stripe accountRead from Zendesk into browser memory while the App is open
The requester's other email addresses (identities), and if your admin set a mapping, their user record (one user field, external id)To match every address and the mapping you choseRead from Zendesk into browser memory
Stripe customers matching those emails, ids or metadata, and for the customer shown: subscriptions, recent invoices, recent payments (amounts, dates, status, card brand and last 4 digits, refund amounts, failure reasons), disputes, product namesTo show the billing picture to the agentRead from Stripe into browser memory while the App is open
An action the agent confirms (refund, subscription change, invoice or receipt email)The purpose of the AppSent to your Stripe account. Refunds carry the Zendesk ticket id and agent id in Stripe metadata
An internal note and a tag describing each action, with the agent's nameSo your team can see what was doneWritten to the ticket in your Zendesk account
The installation's plan name and settings (not the key), and the agent's id, name, role and groupsTo show the plan, apply who may take actions, and name the agent in notesRead from Zendesk

When the sidebar closes, everything it held in memory is gone. What the App wrote stays in your Zendesk and Stripe accounts under your control and their retention settings.

3. What Great Work LLC receives

Nothing from the App. If you email us for support, we receive what you send (we ask you not to send customer data, card details, passwords or keys) and keep it in our email system for as long as needed to help you, at most 24 months. Billing for the App is handled by Zendesk through Stripe; we receive the subscription records Stripe provides to sellers (your Zendesk domain, the plan, payment status and billing contact), which we keep as long as tax and accounting law requires.

4. Sharing

We do not sell, rent or share personal information. The App sends data only to your Zendesk account and to Stripe's API for your Stripe account. We have no subprocessors for the App itself.

5. AI and model training

The App uses no AI services, and no data processed by the App is used to train any model.

6. Security

The App has no server or database to breach. It loads the Zendesk Apps framework from Zendesk's CDN. Stripe requests go through Zendesk's proxy with the key in a secure setting limited to the Authorization header and to api.stripe.com. We recommend a restricted key with only the permissions in our setup guide; a read-only key works for the sidebar without actions. Actions are off for everyone except admins until an admin allows more roles, every action needs a confirmation, and refunds above a limit you set need an admin. Report a security issue to hello@greatwork.company; we treat it as urgent.

7. Your choices and rights

  • Admins choose who may take actions, which actions exist and the refund limit, and can uninstall at any time. Uninstalling deletes the stored keys; delete the restricted key in Stripe as well. Notes and tags already on tickets stay until you delete them.
  • Requests about personal data in your Zendesk or Stripe account go to your administrator, who controls that data. Questions about this policy: hello@greatwork.company.
  • If you are in the EEA, UK or California, you have rights to access, correct and delete personal information we hold about you (in practice, support emails and billing records). Write to us.

8. Changes

We will post changes here with a new effective date and, for material changes, email the billing contact of each paying account at least 14 days before they apply.