Privacy Policy
Last updated: July 18, 2026
This policy explains what personal data Tickbook (“we”, “us”) collects when you use tickbook.app, the Tickbook application, and the Tickbook widget, and how we handle it. Tickbook is an early-access product; we keep data collection to the minimum the service needs to function.
Data we collect
- Account data — your name, work email address, and a salted password hash when you register. Optional multi-factor authentication secrets are stored encrypted.
- Workspace content — tickets, conversations, contacts, knowledge articles, guides, and attachments that you or your customers create inside your workspace. This content belongs to your organization.
- Waitlist data — the email address you submit on our homepage, used only to manage early access.
- Technical data — server logs (IP address, user agent, request metadata) retained for security and reliability, and session cookies required to keep you signed in. We do not use advertising trackers or third-party analytics cookies.
How we use data
- To provide, secure, and operate the service (authentication, support inboxes, the embeddable widget).
- To send transactional email such as email verification, password resets, and invitations.
- To investigate abuse, debug failures, and maintain audit trails of privileged actions.
We do not sell personal data and we do not use your workspace content for advertising.
Subprocessors
| Provider | Purpose |
|---|---|
| Resend | Transactional email delivery |
| Self-hosted infrastructure (EU/US cloud VM) | Application hosting, database, and object storage |
Retention
Workspace content is retained while your organization account is active, subject to the retention period configured in your workspace settings. Expired sessions, verification tokens, and stale invitations are purged automatically. Encrypted database backups are retained for 14 days. When an organization is deleted, its content is removed from the live database and ages out of backups within that window.
Your rights
Depending on where you live (including under the GDPR), you may have the right to access, correct, export, or delete your personal data, and to object to or restrict certain processing. Workspace administrators can anonymize contact records directly in the product. For anything else, contact us and we will respond within 30 days.
Security
All traffic is encrypted with TLS. Passwords are hashed, session tokens are kept in HttpOnly cookies out of reach of page JavaScript, privileged actions are audit-logged, and access to production infrastructure is restricted.
Contact
For privacy questions or data requests, email privacy@tickbook.app.
Changes
We will update this page when our practices change and revise the date above. Material changes will be announced to registered users by email.