Privacy Policy
1. What this app is
VTEX Order Tracker is a ticket sidebar app that runs entirely inside your Freshdesk account. It reads a few fields from the ticket in front of the agent, asks your store's VTEX account (through its OMS and Master Data APIs) about the matching customer and orders, and, when you ask it to, writes what it found into ticket fields you created.
We operate no servers. The app is HTML and JavaScript executed in the agent's browser inside Freshdesk. There is no backend of ours between your helpdesk and VTEX, and no copy of your data reaches us.
2. Data the app reads
From the Freshdesk ticket the agent has open:
- the ticket id and subject;
- the requester's e-mail address and name;
- the values of the ticket custom fields you configured the app to use.
From the VTEX APIs, in response to a lookup:
- customer profile (Master Data): name, e-mail, phone, CPF/CNPJ, company and trade name for business customers, registration date;
- order records (OMS): order id, order group and sequence number, status, items with their prices and pictures, payments (method, card brand and last digits, instalments, transaction id, boleto link), delivery and billing addresses, carrier, shipping option, delivery estimate, tracking code and link, and the order's history.
3. Where that data goes
<account>.<environment>.com.br(for almost every store,<account>.vtexcommercestable.com.br): receives the search term (order id, order group, sequence number, e-mail or CPF/CNPJ) and your application key and token, in order to look the customer or order up.<your-subdomain>.freshdesk.com: receives the field values you asked the app to write, and the ticket id, in order to update the ticket.
Those are the only two destinations for your data. The app contacts no analytics service, no error-reporting service, no advertising network and no endpoint belonging to us.
Two things are loaded by the agent's browser directly, and neither request carries ticket or customer data: the item pictures, from the image addresses VTEX returns with the order, and the Freshworks Crayons interface components, from cdn.jsdelivr.net.
4. Data we store
None. The app keeps no database and writes nothing to Freshdesk's data store. Everything shown in the sidebar lives in the browser tab for as long as the ticket is open: successful answers are kept in memory for up to 60 seconds so the same lookup is not repeated, and all of it is discarded when the agent navigates away.
The values you type on the installation page (the VTEX account name and environment, the application key and token, your Freshdesk subdomain and API key, and the field names) are held by the Freshworks platform in its installation-parameter store, inside your own Freshdesk account. Credentials are declared as secure parameters: they are never returned to the app's JavaScript, and the app can only reference them inside request templates that the platform fills in when it makes the call. When you enter them, the installation page checks them against VTEX and Freshdesk through those same templates; once saved, the page only ever sees them masked. We have no access to them at any point.
Uninstalling the app removes those parameters along with it. Because we store nothing, there is nothing for us to delete afterwards and no retention period to declare.
Payment for the app is handled by Freshworks, on your Freshworks account. We receive no card, bank or billing data. Freshworks identifies subscribing accounts to us so that we can bill and support them; that is account-level commercial information about the organisation, not personal data about your customers or your agents, and the app itself neither reads nor stores it.
5. Legal basis and roles
You (the merchant) are the controller of the personal data involved. We are neither a controller nor a processor of it, because it never reaches us: the app moves data between two services you already have accounts with. Your existing agreements with Freshworks and with VTEX govern the data held in each.
6. Sub-processors
None.
7. Security
- Every outbound call is HTTPS.
- Credentials are stored as Freshworks secure installation parameters and referenced only by template substitution, never read by app code.
- The VTEX application key only needs read roles (OMS View order and List orders, Master Data Read only documents). The app never changes anything in your store.
- All text arriving from VTEX or from the ticket is written to the page as text, never as markup, so a value typed by a shopper cannot execute in the agent's browser.
- Links that arrive from third parties (tracking URLs, product images, payment links) are used only when they are
httporhttpsaddresses. - The app calls only the read endpoints it needs to show the customer and the order.
8. Children
The app is a business tool for support agents and is not directed at children.
9. Changes
Material changes will be published at this URL with a new "last updated" date, and, where the Marketplace requires it, in the app's release notes.
10. Contact
Reach us through our contact page.