Skip to content

Privacy Policy

Last updated: 31 July 2026

This page is a draft for review — it is not legal advice and may not yet reflect final business decisions.

1. Who we are

TickIt Easy (operated by [FILL: registered legal entity name and address], "we", "us", or "our") provides the queue management Service described in the Terms and Conditions. This Privacy Policy explains what personal data we collect, why we collect it, and the rights you have over it.

For privacy questions, contact us at Info@tickiteasy.app.

2. Data we collect

We collect the following categories of personal data: - Account data: name, email address, a hashed password, sign-in sessions (IP address and user agent), and, if you choose Google sign-in, your Google account identifier; billing-related identifiers such as a Stripe customer ID. - Organisation data: organisation name, slug, logo, plan, billing cycle, member accounts, and invitation emails. - Guest and ticket data: ticket number, queue position, status, business date, a client-generated device identifier stored on the guest's device, and, if a guest creates an account, a link to that account. - Payment data (paid tickets): Stripe Checkout session and payment intent identifiers, amount, currency, status, and refund records. - Push notification subscriptions: the browser push endpoint and encryption keys, used only to deliver call notifications. - Partner API keys: key identifiers and hashed keys, permissions, and rate-limit usage.

3. How we use data

We use personal data to: provide and operate the Service (issuing tickets, calling guests, and syncing displays); send transactional email (account verification and invitations); process billing and payments; deliver push notifications when you enable them; prevent abuse and maintain security; and comply with legal obligations.

We do not sell personal data and we do not use it for advertising.

4. Legal bases for processing (GDPR)

If you are in the EEA or the UK, our legal bases are: - Performance of a contract: to provide the Service and manage billing. - Legitimate interests: to keep the Service secure, prevent abuse, and improve reliability. - Consent: where you opt in to push notifications. - Legal obligation: where we must retain records for tax or other legal reasons.

5. Third parties we share data with

We use service providers to run the Service: - Stripe: subscription billing and payment processing (stripe.com/privacy). - Resend: sending transactional email (resend.com/privacy). - Google: optional sign-in (policies.google.com/privacy). - Database and infrastructure hosting: PostgreSQL database hosting and cloud infrastructure providers that store data on our behalf.

We share only the data each provider needs to perform its role and require providers to protect it.

6. Cookies and local storage

We do not use advertising or analytics cookies. The Service uses: - Session cookies required for signed-in accounts. - Local storage on the guest's device for a device identifier and the guest's recent ticket history.

Because we do not run third-party analytics or advertising, there is no cross-site tracking of guests.

7. Data retention

We keep personal data only as long as needed for the purposes above: - Account and organisation data: while your account is active, and afterwards for [FILL: registered legal entity name and address]. - Ticket and session data: [FILL: registered legal entity name and address]. Sessions are automatically closed after they end, and unpaid pending checkouts expire automatically. - Payment records: as required by Stripe and by applicable financial record-keeping law. - Push subscriptions: until you unsubscribe or they stop working.

8. Your rights

If you are in the EEA, the UK, or another jurisdiction granting similar rights, you may request: - Access to the personal data we hold about you. - Rectification of inaccurate data. - Erasure ("right to be forgotten"). - Restriction of processing. - Data portability in a structured, machine-readable format. - Objection to processing based on legitimate interests. - Withdrawal of consent at any time (for push notifications and any consent-based processing).

To exercise these rights, email Info@tickiteasy.app. We will respond within one month. You also have the right to lodge a complaint with a supervisory authority.

9. International transfers

Your data is stored on hosting infrastructure that may be located outside your country. Where we transfer personal data from the EEA or the UK to other countries, we rely on appropriate safeguards, including the European Commission's standard contractual clauses where required.

[FILL: registered legal entity name and address]

10. Security

We protect data with: encryption in transit (HTTPS); hashed passwords and hashed API keys; per-organisation data isolation; and restricted access to production data. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

11. Children

The Service is not directed at children under [FILL: registered legal entity name and address]. We do not knowingly collect personal data from children. If you believe a child has provided us personal data, contact Info@tickiteasy.app and we will delete it.

12. Changes to this Privacy Policy

We may update this Privacy Policy from time to time. Material changes will be reflected in the "last updated" date and, where practicable, notified by email or through the Service.

13. Contact

For privacy questions or to exercise your rights, email Info@tickiteasy.app.

[FILL: registered legal entity name and address]