Privacy Policy
This Privacy Policy explains how ASA Labs LLC handles information through the ASA Labs website, Zendesk applications, documentation, and related services.
About ASA Labs
ASA Labs LLC is a New York limited liability company that develops Zendesk applications, support workflow tools, and related operational systems.
In this policy, “ASA Labs,” “we,” “us,” and “our” refer to ASA Labs LLC. “Customer” and “you” refer to the person or organization using the website, an application, or another ASA Labs service.
Services covered by this policy
This policy applies to the ASA Labs website, public product pages, documentation, and the following applications:
- Quick Links
- ResolveReady
- Access Monitor
- Escalation Guard
- PII Shield
- Rollout Control
It also applies to trials, previews, updates, and future versions of these services unless a separate privacy notice is provided.
Website information
The public ASA Labs website does not currently require visitors to create an account. If you contact ASA Labs, we may receive the information you choose to provide, such as your name, email address, organization, and the contents of your message.
We use this information to respond to inquiries, provide support, communicate about our services, and maintain business records.
Website analytics and cookies
ASA Labs uses Google Analytics on its public website and product pages to understand traffic and improve site performance, content, and usability.
Website analytics may process information such as pages viewed, referral source, browser and device information, approximate geographic region, IP-derived information, cookie or device identifiers, and general usage patterns.
Website analytics are separate from the ASA Labs applications running inside Zendesk. Google Analytics is not used to collect Zendesk ticket content through those applications.
You may limit cookies through your browser settings or use available browser controls that restrict analytics tracking.
Information used inside Zendesk
ASA Labs applications may access Zendesk information needed to provide their features. Depending on the application and customer configuration, this may include:
- Ticket IDs, status, tags, fields, forms, and metadata
- Ticket subjects, comments, or internal notes when needed by a feature
- Requester, organization, agent, role, group, and assignee information
- Zendesk account, brand, time zone, and application configuration
- Information entered by agents into an ASA Labs application
Accessing information inside Zendesk does not necessarily mean that the information is transmitted to or stored by ASA Labs. The product-specific sections below explain how each application uses Zendesk information.
Limited product telemetry
Certain applications send ASA Labs limited product telemetry to help operate, secure, support, and improve the services. Depending on the application, this may include:
- Application name and version
- Subscription plan
- A randomly generated installation identifier
- Feature or configuration counts
- Event type and timestamp
This telemetry is not designed to include ticket content, customer conversations, detected sensitive values, configured URLs, workflow responses, requester information, agent names or email addresses, or Zendesk account subdomains.
The randomly generated installation identifier distinguishes one application installation from another for product analytics. It is not intended to identify an individual, but it may allow activity from the same installation to be recognized over time.
Browser-based tools
ASA Labs offers free tools that may allow you to paste or upload Zendesk configuration data, including field names, IDs, keys, option values, and other configuration metadata. Unless a tool states otherwise, this information is processed locally in your browser and is not transmitted to, viewed by, or stored by ASA Labs. Files and exports generated by these tools remain on your device unless you choose to save or share them.
ASA Labs may collect anonymous usage events, such as when a tool is opened, valid input is processed, a placeholder is copied, or an export is generated. These events do not include pasted JSON, uploaded files, Zendesk subdomains, field names, field IDs, keys, option values, ticket content, or customer information.
These tools are intended for configuration data. Users should not provide ticket content, customer records, credentials, API tokens, or personal information.
Quick Links
Quick Links may read ticket, requester, organization, user, and account context to populate administrator-configured links and placeholders.
Quick Links configuration is stored in Zendesk or Zendesk-provided application storage. ASA Labs telemetry is not designed to include configured link labels, destination URLs, ticket content, ticket field values, requester information, or agent identities.
If click tracking is enabled, Quick Links applies an administrator-configured tag to the Zendesk ticket. That tag remains in the customer’s Zendesk account.
ResolveReady
ResolveReady reads Zendesk ticket information, fields, forms, requester and organization information, groups, tags, and workflow configuration to display applicable workflows and evaluate whether their requirements have been completed.
Workflow configuration is stored using Zendesk-provided application storage. Ticket content and workflow responses are not designed to be transmitted to or stored by ASA Labs.
ResolveReady telemetry may include a random app-specific installation identifier, app version, plan, event type, aggregate counts of workflows, active workflows, steps, required steps, and whether solve blocking is enabled. It is not designed to include Zendesk subdomains, ticket IDs or content, workflow names or responses, requester or agent data, field values, tags, forms, groups, or error messages.
Access Monitor
Access Monitor may access ticket and user information needed to evaluate configured monitoring rules. When a rule matches, it may write an internal note, add tags, update the Access Monitor: View Log ticket field, or add existing Zendesk agents as followers.
These records remain in the customer’s Zendesk account. Monitoring configuration is stored within Zendesk, with a browser-based cache that may be used as a fallback.
If follower alerts are configured, Access Monitor may use the Zendesk user search API to resolve configured email addresses to existing Zendesk agent accounts. Those addresses are used for that configured function and are not included in ASA Labs telemetry.
Access Monitor telemetry may include a random app-specific installation identifier, app version, plan, event type, and aggregate counts of configured and active monitoring rules. It is not designed to include Zendesk subdomains, ticket IDs or content, requester or agent data, viewer identity, rule names or conditions, alert email addresses, tags, internal note text, or view-log field values.
Escalation Guard
Escalation Guard reads the current ticket ID and administrator-saved escalation templates to display and submit escalation forms. When an agent submits an escalation, the app writes a private internal note, adds configured routing tags, and, on Pro when configured, updates mapped Zendesk ticket fields.
Escalation templates and configuration are stored through Zendesk. Information entered by agents is written to the Zendesk ticket and is not designed to be included in ASA Labs telemetry.
Escalation Guard telemetry may include a random app-specific installation identifier, app version, plan, event type, and aggregate counts of templates, active templates, configured fields, routing tags, and mapped fields. It is not designed to include Zendesk subdomains, ticket IDs or content, customer or requester data, agent identity, template or field content, routing-tag values, mapped-field IDs or values, or internal note text.
PII Shield
PII Shield reads ticket content and related Zendesk information to detect and help manage potentially sensitive information. Depending on customer configuration, it may inspect subjects, comments, internal notes, requester or user information, ticket fields, and custom detection patterns.
Detection occurs through the application within the customer’s Zendesk environment. Ticket content, detected values, and redacted values are not designed to be sent to or stored by ASA Labs.
PII Shield telemetry may include configuration-level counts, such as the number of enabled detector types or whether solve blocking is enabled. It does not include the detected information itself.
Rollout Control
Rollout Control accesses Zendesk configuration and ticket information needed to create, manage, and evaluate configured rollouts. This may include triggers, webhooks, custom objects, application settings, ticket tags, eligibility information, and rollout assignments.
Rollout configuration, rollout records, and ticket assignment tags are stored within the customer’s Zendesk account. Rollout Control is not designed to transmit ticket subjects, comments, internal notes, requester information, or other ticket content to ASA Labs.
Rollout Control requires a Zendesk administrator to authorize the ASA Labs global OAuth client. The permissions requested are shown during Zendesk’s authorization process and are limited to the Zendesk resources needed to create and maintain the enrollment webhook and apply rollout tags. OAuth does not provide ASA Labs with the administrator’s Zendesk password.
To maintain this connection, ASA Labs stores the customer’s Zendesk subdomain, enrollment webhook identifier, OAuth access and refresh tokens, token expiration information, connection date, and connection status through our infrastructure provider. These credentials are used only to create, authenticate, refresh, repair, and disconnect the Rollout Control enrollment webhook.
OAuth connection records are retained while the connection is active or as reasonably necessary to operate and secure Rollout Control. Selecting “Prepare to uninstall” within Rollout Control deletes the associated OAuth credentials and connection record from ASA Labs systems and attempts to deactivate the enrollment webhook. Uninstalling the Zendesk application without completing this step may not automatically notify ASA Labs or delete the external OAuth connection record. Customers may also contact ASA Labs to request deletion.
Rollout Control telemetry may include a random app-specific installation identifier, app version, plan, event type, aggregate active rollout count, total rollout count, treatment percentage, and event timestamp. It is not designed to include Zendesk subdomains, ticket IDs or content, requester or agent data, rollout names or descriptions, eligibility rules, ticket assignment records, tags, API tokens, OAuth credentials, webhook identifiers, or error messages.
How information is used
ASA Labs may use information covered by this policy to:
- Provide and maintain the website and applications
- Respond to support requests and business inquiries
- Understand product adoption and application performance
- Detect misuse, errors, security risks, or service disruptions
- Improve features, documentation, reliability, and usability
- Administer subscriptions and comply with legal obligations
ASA Labs does not use Zendesk customer or ticket data to train public or third-party artificial intelligence models.
Service providers and disclosure
ASA Labs may use hosting, database, analytics, security, authentication, email, payment, and infrastructure providers to operate its website and applications. These providers may process limited information on behalf of ASA Labs for the services they provide.
For Rollout Control, ASA Labs uses Cloudflare to host the OAuth connection service and store the limited connection information described in the Rollout Control section above.
ASA Labs does not sell customer data or application data and does not share it for targeted advertising.
Information may also be disclosed when reasonably necessary to comply with law, respond to valid legal process, protect the rights or security of ASA Labs or others, investigate misuse, or complete a merger, financing, acquisition, or sale of business assets.
Third-party links
ASA Labs guides and tools may link to Zendesk and other third-party websites. Information you provide after leaving ASA Labs is governed by the third party’s own privacy practices.
Data retention
ASA Labs retains contact information, business records, website analytics, and product telemetry only for as long as reasonably necessary for the purposes described in this policy, including support, security, product improvement, dispute resolution, and legal compliance.
Information written to Zendesk, including internal notes, tags, ticket fields, configuration, and rollout records, is controlled by the customer’s Zendesk retention settings and workflows. Uninstalling an application may not remove records previously written to Zendesk.
Security
ASA Labs uses reasonable administrative, technical, and operational safeguards designed to protect information under its control. These safeguards may include access controls, credential protection, limited data collection, and security features provided by our hosting and infrastructure providers.
No electronic system is completely secure. Customers remain responsible for managing Zendesk permissions, administrator access, integrations, application settings, and internal security policies.
Your choices and requests
Zendesk administrators can control application configuration, optional features, user permissions, OAuth authorization, and application installation. Revoking authorization or uninstalling an application may limit or stop its functionality.
Before uninstalling Rollout Control, administrators should use the “Prepare to uninstall” option within the application to remove the OAuth connection record maintained by ASA Labs and deactivate the enrollment webhook. Customers may also contact ASA Labs to request deletion of a Rollout Control OAuth connection record.
You may contact ASA Labs to ask about information you have provided directly or to request access, correction, or deletion where applicable. Because product telemetry is not designed to contain an individual’s identity or Zendesk subdomain, ASA Labs may be unable to connect a telemetry record to a particular person or customer.
Children’s privacy
ASA Labs services are intended for business and professional use and are not directed to children under 13. ASA Labs does not knowingly collect personal information from children through these services.
Changes to this policy
ASA Labs may update this Privacy Policy as its services, data practices, or legal obligations change. The effective date at the top of this page will be updated when changes are made.
When reasonably required, ASA Labs will provide notice of material changes through the website, an application, the applicable Marketplace listing, or another appropriate channel.
Contact
Questions or requests regarding this policy may be sent to:hello@asa-labs.com