Twinewell for ShipStation: Privacy Policy
Effective date: October 1, 2026 Publisher: Great Work LLC, 651 N Broad St Suite 206, Middletown, DE 19709, USA Contact: hello@greatwork.company
This policy explains what information the Twinewell app for Zendesk Support (the "App") processes, where it is kept, and your choices. It covers only the App, not Zendesk's or ShipStation's products, which are governed by their own policies.
1. Summary
- The App runs in your browser inside Zendesk Support, through the Zendesk Apps framework. Great Work LLC operates no server for it and receives no data from it.
- It reads from and writes to two places only: your Zendesk account (as the signed-in agent, with that agent's permissions) and your ShipStation account or accounts (with the API key and secret you provide).
- Your API key and secret are stored by Zendesk as secure settings. Zendesk adds them to requests on their way to ssapi.shipstation.com; they are never sent to agents' browsers and Great Work never sees them.
- The App keeps nothing outside Zendesk and ShipStation: no copies, archives, caches or indexes, no browser storage, no background collection, no analytics or usage statistics, no cookies of its own, no export, and no AI services.
2. What the App processes, and why
| Data | Why | Where it lives |
|---|---|---|
| The ticket's id, brand, subject, first message and requester (name, email); on user profiles the user's id, name, email | To find the requester's orders (by full name and by order numbers written in the ticket) and choose the ShipStation account | Read from Zendesk into browser memory while the App is open |
| The requester's other email addresses (identities) | To keep only orders whose customer email is one of them | Read from Zendesk into browser memory |
| ShipStation orders under the requester's full name or with an order number from the ticket: order number, dates, status, customer name, email and user name, bill-to and ship-to addresses, items, prices, totals, tax and shipping, payment method, requested and set shipping service, customer notes, gift message, internal notes, tags, store; for an order the agent opens, its labels (tracking number, carrier, service, ship date, label cost, items) and fulfillments marked as shipped elsewhere | To show the requester's orders to the agent. Orders whose email is not one of the requester's addresses are discarded in memory and never shown; for an order number from the ticket that belongs to another email, the agent sees only that it exists and a masked email | Read from ShipStation into browser memory while the App is open |
| The account's store names and order tags | To label orders by store and offer tags | Read from ShipStation into browser memory |
| An action the agent confirms (hold, release, tag, internal note, ship-to fix, cancel) | The purpose of the App | Sent to ShipStation. Notes, ship-to fixes and cancellations add a line to the order's internal notes with the date, the agent's name, the Zendesk ticket id and a one-time reference; a ship-to fix keeps the old address in that line |
| An internal note and a tag describing each action, with the agent's name | So your team can see what was done | Written to the ticket in your Zendesk account |
| The installation's plan name and settings (not the key or secret), and the agent's id, name, role and groups | To show the plan, apply who may take actions, and name the agent in notes | Read from Zendesk |
When the sidebar closes, everything it held in memory is gone. What the App wrote stays in your Zendesk account and your ShipStation account under your control and their retention settings.
3. What Great Work LLC receives
Nothing from the App. If you email us for support, we receive what you send (we ask you not to send customer data, card details, passwords, API keys or secrets) and keep it in our email system for as long as needed to help you, at most 24 months. Billing for the App is handled by Zendesk through Stripe; we receive the subscription records Stripe provides to sellers (your Zendesk domain, the plan, payment status and billing contact), which we keep as long as tax and accounting law requires.
4. Sharing
We do not sell, rent or share personal information. The App sends data only to your Zendesk account and to the ShipStation API. We have no subprocessors for the App itself.
5. AI and model training
The App uses no AI services, and no data processed by the App is used to train any model.
6. Security
The App has no server or database to breach and installs nothing in ShipStation. It loads the Zendesk Apps framework from Zendesk's CDN. ShipStation requests go through Zendesk's proxy over HTTPS with the key and secret in secure settings that may only be used as the Basic authentication user name and password, and only for ssapi.shipstation.com. ShipStation API keys can't be limited to some actions, so the App limits actions itself: they are off for everyone except admins until an admin allows more roles, each type can be switched off, cancelling is off by default, and every action needs a confirmation. Report a security issue to hello@greatwork.company; we treat it as urgent.
7. Your choices and rights
- Admins choose who may take actions and which actions exist, and can uninstall at any time. Uninstalling deletes the stored key and secret; you can also regenerate the keys in ShipStation. Notes and tags already on tickets and lines in ShipStation order notes stay until you delete them.
- Requests about personal data in your Zendesk account or your ShipStation account go to your administrator, who controls that data. Questions about this policy: hello@greatwork.company.
- If you are in the EEA, UK or California, you have rights to access, correct and delete personal information we hold about you (in practice, support emails and billing records). Write to us.
8. Changes
We will post changes here with a new effective date and, for material changes, email the billing contact of each paying account at least 14 days before they apply.