TickKet — Privacy Policy
Effective date: June 12, 2026 Last updated: June 12, 2026
⚠️ DRAFT — for review. Placeholders in [brackets] need your real details. Have a lawyer review before launch. Prepared with AI assistance; not legal advice. Verify every claim below matches the live system before publishing — overstating privacy practices is itself a legal risk.
This policy explains what [TickKet, LLC — update when formed; until then: Chris Hayworth, d/b/a "TickKet"] ("TickKet," "we," "us") collects when you use tickket.app (the "Service"), why, how long we keep it, and how to get rid of it.
The short version
TickKet is built so that we hold as little as possible:
- We never ask for — and cannot receive — your loyalty, airline, hotel, or bank passwords. There is no place in TickKet to enter them.
- Balance screenshots are read once and discarded; we keep only the program name, the number, and a timestamp — never the image.
- Emails you forward to us are parsed and discarded; we keep the extracted trip or balance details, not the message.
- You can delete any stored item, or your whole account, at any time.
What we collect and why
Account basics. Email address, name (if provided via Google sign-in), and sign-in credentials (a password hash if you use a password; we never see your Google password). Why: to operate your account.
Trips and reservations. Flight, hotel, and dining details you add manually or forward by email. Why: to show your itinerary and send alerts you've enabled.
Loyalty balances. Program name, points/miles number, optional status tier, the source ("scanned," "from email," "entered"), and when it was updated. Why: to show your portfolio and its estimated value.
Receipts. Receipt images and extracted details (merchant, amount, category) you choose to scan. Why: expense tracking you asked for. Stored until you delete them.
Approximate location. A city-level location (from your device, with your permission, or a city you pick) retained up to 180 days. Why: local weather, news, and nearby-restaurant features. We do not collect precise GPS trails.
Preferences and settings. Notification toggles, dietary preferences, display options. Why: so the app behaves the way you set it.
Payment information. Handled by Stripe; we never see or store full card numbers. We keep your subscription status.
Service logs. Basic technical logs (errors, request metadata) for security and debugging, retained briefly. We do not run third-party advertising or cross-site tracking, and we do not sell or rent personal information. [Verify: if any analytics tool is added later, disclose it here.]
What we deliberately do not collect
- Loyalty-program, airline, hotel, or banking passwords — never asked for, no field exists for them.
- Screenshot images — processed in memory to extract the balance, then discarded.
- Forwarded email bodies — parsed for trip/balance details, then discarded.
- Precise, continuous GPS location.
- Advertising identifiers or data-broker profiles.
Who processes data for us
We use a small set of service providers, each only for what's listed:
| Provider | What they do for TickKet |
|---|---|
| Cloudflare | Hosting, storage, and email routing |
| Anthropic (Claude) | AI features: reading balance screenshots, parsing forwarded emails, Hugo chat. Sent content is processed to provide the feature; [verify current API data-retention terms and state them here] |
| Stripe | Subscription payments |
| Twilio | SMS alerts (phone number, message content) — only if you opt in |
| Resend | Sending email from TickKet to you |
| [Flight-data provider — currently AeroDataBox] | Flight status lookups (flight numbers, dates; not your identity) |
| Open-Meteo / news & market data sources | Weather, news, and market info (city or ticker queries; not your identity) |
We share data with no one else, except if required by law or to protect the Service from abuse, and in a business transfer (in which case this policy continues to apply to data collected under it).
How long we keep things
| Data | Retention |
|---|---|
| Balance screenshots / forwarded email bodies | Not stored — read and discarded |
| Loyalty balances, trips, receipts, preferences | Until you delete them or your account |
| City-level location | Up to 180 days |
| Account record | Until you delete your account |
| Technical logs | [verify — state actual log retention, e.g., 30 days] |
Your choices and rights
- See and delete: trips, balances, and receipts can be deleted in the app. For a full account deletion (account, trips, balances, receipts, preferences, location), contact [support@tickket.app] [until an in-app "Delete account" button ships — recommended addition].
- Disconnect: SMS and email-forwarding features can each be turned off independently in Settings.
- Notifications: every alert channel has its own toggle.
Depending on where you live (for example, the EU/UK under GDPR or California under CCPA/CPRA), you may have rights to access, correct, delete, or port your personal information, and to complain to a supervisory authority. We honor these requests for all users regardless of location — contact us and we will respond within 30 days. We do not "sell" or "share" personal information as those terms are defined in the CCPA.
Security
Sign-in uses industry-standard methods; OAuth tokens are stored encrypted; data in transit is encrypted with TLS. No system is perfectly secure — if we learn of a breach affecting your data, we will notify you as required by law.
Children
The Service is not directed to children and may not be used by anyone under 18. We do not knowingly collect data from children; if you believe a child has provided us data, contact us and we will delete it.
Changes to this policy
We'll post updates here and, for material changes, notify you in the app or by email at least 14 days before they take effect.
Contact
[support@tickket.app — set up this routing rule in Cloudflare] [Postal address — required by some laws and by email-marketing rules (CAN-SPAM); a registered-agent or PO Box address works. Add before launch.]