Zendesk and Freshdesk
Privacy notice
Effective October 1, 2026
This notice covers Canadesk’s Zendesk and Freshdesk app for Stripe and its public website. The organization installing the app chooses its connections and controls who can use them.
What the app reads
The app reads customer identifiers, names and email addresses, payment and refund details, relevant ticket references, and subscription status and dates. It retrieves helpdesk requester details, ticket subjects, statuses and public messages with author names and roles. Provider responses can include private notes. The backend removes these before returning conversations to the app. They are not displayed or sent to a model.
We use these records to retrieve tickets, show billing references and provide summaries you request. The app does not issue refunds, change subscriptions or write helpdesk messages.
What Canadesk stores
We do not maintain a database of ticket bodies, billing history or generated summaries for this app. Helpdesk responses pass through backend memory. This is not a zero-storage service.
- Helpdesk connection. Firebase stores encrypted Zendesk access and refresh tokens or a Freshdesk API key. It also stores the helpdesk account, connected user identity, authorizing Stripe user identifier, scopes and connection dates. Identity and configuration fields are not encrypted by the application.
- Authorization state. Firebase stores the account, mode, user, helpdesk and verification data needed to complete OAuth. State stops being valid after ten minutes. Consumed state is deleted. Abandoned state currently has no automatic deletion schedule.
- AI settings. Firebase stores provider, model, custom instructions, feature choices, generation settings, connection-test results and the identifier of the user who changed the settings. Do not put credentials or unnecessary personal information in instructions.
Optional AI summaries
Summaries run when requested. The extension sends selected public messages, ticket facts, relevant Stripe facts, source identifiers and instructions directly to the chosen model provider. Canadesk’s backend does not receive the assembled model request, model API key or generated answer. OpenRouter forwards requests to the provider serving the selected model.
Stripe Secret Store holds the model key at account scope. Users of this app on that Stripe account can access it through the same Stripe API. Administrator-only settings are not a separate security boundary for that key.
The app excludes raw Stripe objects, payment-method details, internal notes and credentials from model requests. It also removes recognizable email addresses, phone numbers and key-shaped strings from message text. This does not guarantee anonymization. Messages may still contain personal or sensitive information. Enable summaries only when your organization is authorized to send this information to the selected provider.
Providers and locations
Railway hosts the backend. Google Firebase stores connection and configuration records. Stripe hosts the extension and stores model keys. Your selected helpdesk supplies ticket data. Your model provider processes requested summaries under its own terms and retention settings. Cloudflare and our website hosting provider process requests to this public website.
These services may process data outside your country. We do not promise a particular storage region or EU-only processing. We do not sell app data or use customer conversations for advertising.
Retention and deletion
Disconnect in app settings removes the active helpdesk connection record for that Stripe account and mode. It does not revoke the credential at the helpdesk. Revoke it there if needed. AI settings remain until changed or deleted on request. Uninstalling does not automatically delete backend records. Contact us to request removal of remaining connection, authorization or configuration records. We verify authority before changing account data.
Loaded records and summaries can be cached in extension memory. Some repeated conversation reads are reused for one minute. Tab preferences use Stripe session storage. Removing backend records does not remove records already held independently by Stripe, the helpdesk or the model provider.
Access logs can contain IP addresses, request times, paths and response codes. The backend does not intentionally log ticket bodies or model content. OAuth URLs are excluded from request logging. Hosting logs and backups have their own retention settings. Deletion from the active database does not guarantee immediate removal from backups.
Privacy requests
Email [email protected] to ask about access, correction, deletion or other privacy rights that apply to you. Include the Stripe account identifier and test or live mode when relevant. Do not send passwords, API keys or customer conversations. End customers should also contact the organization that holds their Stripe and helpdesk records. You can complain to the relevant data protection authority where applicable.
This notice does not waive privacy rights or replace a data processing agreement where one is required. Changes to these practices will be reflected here with an updated effective date.