Privacy Policy
Last updated: 3 August 2026
1. Who we are
Tickback ("Tickback", "we", "us") provides a shared task-management app available at tickback.co.uk and as mobile apps. This policy explains what personal data we collect, why, and your rights over it.
Data controller: Tickback Ltd, a company registered in England and Wales (company number 16727735), registered office 12 Ford Close, Ferndown, Dorset, BH22 8AA. Questions or requests: support@tickback.co.uk.
2. The data we collect
| Category | What it includes | Why |
|---|---|---|
| Account | Email address, display name, and a securely hashed password. | To create and secure your account and let project members recognise you. |
| Your content | Projects, tasks, sections, due dates, comments, templates, any photos you attach to tasks, and who they're assigned to. | To provide the core service and sync it across your devices and project members. |
| Technical | Basic connection data (e.g. IP address, device/browser type) processed by our hosting providers, and a session token stored on your device. | To keep you signed in, deliver the service and keep it secure. |
| Push notifications | A device token, if you enable push notifications on our native apps. | To send you alerts such as a task waiting for your confirmation. You can turn these off in your device settings. |
| Activity record | In projects using compliance mode: a log of each change to a task — what changed, when (by our servers' clock), and the name of the account that made it. We do not keep email addresses in this log. Photos record whether they were taken in the app or chosen from a device library. | So the project owner has a record of who did what that can be relied on by their insurer, their client or a regulator. See section 6. |
| Company details | A company name and logo, if the account holder adds one. | To put their business name on the reports and audit packs they export. |
We do not sell your data, and we do not use third-party advertising or cross-site tracking.
Tickback is designed so that sensitive personal information isn't needed: nothing in the core product — recording a task, completing it, confirming it — requires health, biometric or other special-category data, and we don't ask for any. Free-text fields and photographs are yours to fill in, so please don't put sensitive personal information into task titles, comments or photos where it isn't necessary. Where a business chooses to process such data in its own projects, it remains responsible as controller for having a lawful basis and an Article 9 condition for doing so, and for telling the people affected.
3. How sharing works inside the app
- Tasks, comments and other content in a project are visible to the members of that project.
- Your display name is visible to people you share a project with.
- Your email address is visible only to the owner of a project you're a member of — not to other members.
- You only ever see projects you've created or been invited to.
3a. Business accounts: who is responsible for your data
If you use Tickback because your employer or a company you work for invited you to their project, that company decides what goes in it and how long it's kept. For that content they are the data controller and we act as their processor — we hold and protect the data on their instructions. We remain the controller for your own account details (your email, name and password).
This matters for one practical reason: if you ask us to erase a record of work you did on their project, we usually can't do it unilaterally — it's their record, not ours. We'll pass your request to them and help them action it. Your account itself is always yours to delete.
4. Legal bases (UK/EU GDPR)
- Performance of a contract — to provide the service you sign up for.
- Legitimate interests — to keep the service secure, working and improving, balanced against your rights.
- Consent — where required, e.g. optional communications; you can withdraw it at any time.
5. Service providers (sub-processors)
We use a small number of trusted providers to run Tickback. They process data on our behalf under agreements that require appropriate safeguards:
| Provider | Purpose | Where it processes |
|---|---|---|
| Supabase | Database, authentication, real-time sync, and transactional email such as password resets and sign-up confirmations (stores your account and content). | EU (Frankfurt, Germany) |
| Netlify | Hosting and delivery of the web app. | USA |
| Stripe | Payment processing for web subscriptions. Stripe handles your card details directly — we don't see or store them. | USA / EU |
| Apple | Payment and subscription billing for purchases made through the iOS App Store. | USA / EU |
| RevenueCat | Manages and validates in-app (App Store / Play Store) subscriptions and entitlements. | USA |
| Affonso | Affiliate referral tracking. Sets a cookie to attribute a referral, and only if you arrive via an affiliate link. | EU |
| Expo | Delivers push notifications (processes a device push token). Native apps only. | USA |
| hCaptcha | Bot and abuse protection on sign-up and login. | USA |
Your account and content are stored in the European Union (Frankfurt, Germany). Some of the providers above are based in the United States and may process limited technical data — such as an IP address, a device push token or payment metadata — outside the UK/EEA. Where they do, those transfers are covered by the UK International Data Transfer Addendum and/or EU Standard Contractual Clauses. The table above lists every provider we use; we will update it before adding another.
6. How long we keep it
We keep your account and content for as long as your account is active. If you delete your account, we delete your profile and the projects you own, and associated tasks, comments and photos are removed, except as set out below. We aim to complete deletion within 30 days. Backups are cycled out on our providers' normal schedules.
Compliance projects are different, on purpose. A project in compliance mode exists to be a record that can still be relied on later — often years later, and often by someone other than the person who made it. So:
- Tasks in a compliance project are archived rather than deleted, and the activity log can't be edited or removed by anyone, including us through the app.
- The log keeps the name of whoever performed each action, as it stood at the time, and an internal reference that is not an identifier outside Tickback. It deliberately survives the person closing their account — otherwise a year-old record would no longer say who did the work, which would defeat the point of keeping it. We keep the name and nothing more: no email address, because the record does not need one to be meaningful.
- Because of this, deleting your account does not delete compliance records of work you did on someone else's project. Your profile, your own projects and your other content are still deleted.
- A project owner can permanently destroy a compliance project at any time, by archiving it and then deleting it. When they do, we keep a single summary line — the project name, its owner, how many records it held, the dates they covered, and who deleted it and when. We keep that so it's never possible to destroy records without a trace; it contains no task content.
Where we act as a processor for a business (see section 3a), how long these records are kept is that business's decision. If you want a compliance record about you removed or corrected, contact the project owner in the first instance, or email us and we'll put you in touch.
7. Your rights
Subject to UK/EU data-protection law, you can request to access, correct, delete, restrict or port your personal data, and object to certain processing. Note the limits described in sections 3a and 6 on compliance records held on a business's behalf. To exercise any of these, email support@tickback.co.uk. You also have the right to complain to the UK Information Commissioner's Office (ICO) at ico.org.uk.
8. Security
Connections are encrypted in transit (HTTPS/TLS), and your data is encrypted at rest by our database provider. Access to your content is enforced at the database level — not merely hidden in the app — so people can only reach projects they belong to, and per-member permissions control what they can do inside one. Photographs are re-encoded when you upload them, which removes embedded metadata such as GPS location and camera details. Passwords are stored only as salted hashes; we never see them. No system is perfectly secure, but we take reasonable steps to protect your data and ask that you keep your password confidential.
9. Children
Tickback is designed for adults (and, in family use, for adults to manage tasks for their household). It isn't directed at children, and accounts are intended for users aged 13 or over. Where children take part in a family project, a parent or guardian is responsible for their use.
10. Changes to this policy
We may update this policy as the app evolves. We'll change the "last updated" date above and, for significant changes, give notice in the app.
11. Contact
Questions about your privacy or this policy? Email support@tickback.co.uk.