Privacy Policy

Last updated: 3 August 2026

1. Who we are

Tickback ("Tickback", "we", "us") provides a shared task-management app available at tickback.co.uk and as mobile apps. This policy explains what personal data we collect, why, and your rights over it.

Data controller: Tickback Ltd, a company registered in England and Wales (company number 16727735), registered office 12 Ford Close, Ferndown, Dorset, BH22 8AA. Questions or requests: support@tickback.co.uk.

2. The data we collect

CategoryWhat it includesWhy
AccountEmail address, display name, and a securely hashed password.To create and secure your account and let project members recognise you.
Your contentProjects, tasks, sections, due dates, comments, templates, any photos you attach to tasks, and who they're assigned to.To provide the core service and sync it across your devices and project members.
TechnicalBasic connection data (e.g. IP address, device/browser type) processed by our hosting providers, and a session token stored on your device.To keep you signed in, deliver the service and keep it secure.
Push notificationsA device token, if you enable push notifications on our native apps.To send you alerts such as a task waiting for your confirmation. You can turn these off in your device settings.
Activity recordIn projects using compliance mode: a log of each change to a task — what changed, when (by our servers' clock), and the name of the account that made it. We do not keep email addresses in this log. Photos record whether they were taken in the app or chosen from a device library.So the project owner has a record of who did what that can be relied on by their insurer, their client or a regulator. See section 6.
Company detailsA company name and logo, if the account holder adds one.To put their business name on the reports and audit packs they export.

We do not sell your data, and we do not use third-party advertising or cross-site tracking.

Tickback is designed so that sensitive personal information isn't needed: nothing in the core product — recording a task, completing it, confirming it — requires health, biometric or other special-category data, and we don't ask for any. Free-text fields and photographs are yours to fill in, so please don't put sensitive personal information into task titles, comments or photos where it isn't necessary. Where a business chooses to process such data in its own projects, it remains responsible as controller for having a lawful basis and an Article 9 condition for doing so, and for telling the people affected.

3. How sharing works inside the app

3a. Business accounts: who is responsible for your data

If you use Tickback because your employer or a company you work for invited you to their project, that company decides what goes in it and how long it's kept. For that content they are the data controller and we act as their processor — we hold and protect the data on their instructions. We remain the controller for your own account details (your email, name and password).

This matters for one practical reason: if you ask us to erase a record of work you did on their project, we usually can't do it unilaterally — it's their record, not ours. We'll pass your request to them and help them action it. Your account itself is always yours to delete.

4. Legal bases (UK/EU GDPR)

5. Service providers (sub-processors)

We use a small number of trusted providers to run Tickback. They process data on our behalf under agreements that require appropriate safeguards:

ProviderPurposeWhere it processes
SupabaseDatabase, authentication, real-time sync, and transactional email such as password resets and sign-up confirmations (stores your account and content).EU (Frankfurt, Germany)
NetlifyHosting and delivery of the web app.USA
StripePayment processing for web subscriptions. Stripe handles your card details directly — we don't see or store them.USA / EU
ApplePayment and subscription billing for purchases made through the iOS App Store.USA / EU
RevenueCatManages and validates in-app (App Store / Play Store) subscriptions and entitlements.USA
AffonsoAffiliate referral tracking. Sets a cookie to attribute a referral, and only if you arrive via an affiliate link.EU
ExpoDelivers push notifications (processes a device push token). Native apps only.USA
hCaptchaBot and abuse protection on sign-up and login.USA

Your account and content are stored in the European Union (Frankfurt, Germany). Some of the providers above are based in the United States and may process limited technical data — such as an IP address, a device push token or payment metadata — outside the UK/EEA. Where they do, those transfers are covered by the UK International Data Transfer Addendum and/or EU Standard Contractual Clauses. The table above lists every provider we use; we will update it before adding another.

6. How long we keep it

We keep your account and content for as long as your account is active. If you delete your account, we delete your profile and the projects you own, and associated tasks, comments and photos are removed, except as set out below. We aim to complete deletion within 30 days. Backups are cycled out on our providers' normal schedules.

Compliance projects are different, on purpose. A project in compliance mode exists to be a record that can still be relied on later — often years later, and often by someone other than the person who made it. So:

Where we act as a processor for a business (see section 3a), how long these records are kept is that business's decision. If you want a compliance record about you removed or corrected, contact the project owner in the first instance, or email us and we'll put you in touch.

7. Your rights

Subject to UK/EU data-protection law, you can request to access, correct, delete, restrict or port your personal data, and object to certain processing. Note the limits described in sections 3a and 6 on compliance records held on a business's behalf. To exercise any of these, email support@tickback.co.uk. You also have the right to complain to the UK Information Commissioner's Office (ICO) at ico.org.uk.

8. Security

Connections are encrypted in transit (HTTPS/TLS), and your data is encrypted at rest by our database provider. Access to your content is enforced at the database level — not merely hidden in the app — so people can only reach projects they belong to, and per-member permissions control what they can do inside one. Photographs are re-encoded when you upload them, which removes embedded metadata such as GPS location and camera details. Passwords are stored only as salted hashes; we never see them. No system is perfectly secure, but we take reasonable steps to protect your data and ask that you keep your password confidential.

9. Children

Tickback is designed for adults (and, in family use, for adults to manage tasks for their household). It isn't directed at children, and accounts are intended for users aged 13 or over. Where children take part in a family project, a parent or guardian is responsible for their use.

10. Changes to this policy

We may update this policy as the app evolves. We'll change the "last updated" date above and, for significant changes, give notice in the app.

11. Contact

Questions about your privacy or this policy? Email support@tickback.co.uk.