‹ Back to TickKet

TickKet — Privacy Policy

Effective date: June 12, 2026 Last updated: June 12, 2026

⚠️ DRAFT — for review. Placeholders in [brackets] need your real details. Have a lawyer review before launch. Prepared with AI assistance; not legal advice. Verify every claim below matches the live system before publishing — overstating privacy practices is itself a legal risk.

This policy explains what [TickKet, LLC — update when formed; until then: Chris Hayworth, d/b/a "TickKet"] ("TickKet," "we," "us") collects when you use tickket.app (the "Service"), why, how long we keep it, and how to get rid of it.

The short version

TickKet is built so that we hold as little as possible:

What we collect and why

Account basics. Email address, name (if provided via Google sign-in), and sign-in credentials (a password hash if you use a password; we never see your Google password). Why: to operate your account.

Trips and reservations. Flight, hotel, and dining details you add manually or forward by email. Why: to show your itinerary and send alerts you've enabled.

Loyalty balances. Program name, points/miles number, optional status tier, the source ("scanned," "from email," "entered"), and when it was updated. Why: to show your portfolio and its estimated value.

Receipts. Receipt images and extracted details (merchant, amount, category) you choose to scan. Why: expense tracking you asked for. Stored until you delete them.

Approximate location. A city-level location (from your device, with your permission, or a city you pick) retained up to 180 days. Why: local weather, news, and nearby-restaurant features. We do not collect precise GPS trails.

Preferences and settings. Notification toggles, dietary preferences, display options. Why: so the app behaves the way you set it.

Payment information. Handled by Stripe; we never see or store full card numbers. We keep your subscription status.

Service logs. Basic technical logs (errors, request metadata) for security and debugging, retained briefly. We do not run third-party advertising or cross-site tracking, and we do not sell or rent personal information. [Verify: if any analytics tool is added later, disclose it here.]

What we deliberately do not collect

Who processes data for us

We use a small set of service providers, each only for what's listed:

Provider What they do for TickKet
Cloudflare Hosting, storage, and email routing
Anthropic (Claude) AI features: reading balance screenshots, parsing forwarded emails, Hugo chat. Sent content is processed to provide the feature; [verify current API data-retention terms and state them here]
Stripe Subscription payments
Twilio SMS alerts (phone number, message content) — only if you opt in
Resend Sending email from TickKet to you
[Flight-data provider — currently AeroDataBox] Flight status lookups (flight numbers, dates; not your identity)
Open-Meteo / news & market data sources Weather, news, and market info (city or ticker queries; not your identity)

We share data with no one else, except if required by law or to protect the Service from abuse, and in a business transfer (in which case this policy continues to apply to data collected under it).

How long we keep things

Data Retention
Balance screenshots / forwarded email bodies Not stored — read and discarded
Loyalty balances, trips, receipts, preferences Until you delete them or your account
City-level location Up to 180 days
Account record Until you delete your account
Technical logs [verify — state actual log retention, e.g., 30 days]

Your choices and rights

Depending on where you live (for example, the EU/UK under GDPR or California under CCPA/CPRA), you may have rights to access, correct, delete, or port your personal information, and to complain to a supervisory authority. We honor these requests for all users regardless of location — contact us and we will respond within 30 days. We do not "sell" or "share" personal information as those terms are defined in the CCPA.

Security

Sign-in uses industry-standard methods; OAuth tokens are stored encrypted; data in transit is encrypted with TLS. No system is perfectly secure — if we learn of a breach affecting your data, we will notify you as required by law.

Children

The Service is not directed to children and may not be used by anyone under 18. We do not knowingly collect data from children; if you believe a child has provided us data, contact us and we will delete it.

Changes to this policy

We'll post updates here and, for material changes, notify you in the app or by email at least 14 days before they take effect.

Contact

[support@tickket.app — set up this routing rule in Cloudflare] [Postal address — required by some laws and by email-marketing rules (CAN-SPAM); a registered-agent or PO Box address works. Add before launch.]