Privacy Policy

Tickety is accessible from https://tickety.top. This Privacy Policy describes the categories of information that are collected and recorded by Tickety and how they are used.

If you have additional questions or require more information about our Privacy Policy, do not hesitate to contact us.

This Privacy Policy applies only to our online activities and is valid for visitors to our website and users of our Discord bot. This policy is not applicable to any information collected offline or via channels other than this website and the Discord bot.

1. Data Controller

Tickety is used inside Discord servers that other people own and run, so who is responsible for a given piece of personal data depends on where it comes from.

We are the controller for the data we decide the purposes of: your Tickety account and dashboard login, your use of our website, billing and subscription records, and the logs and security data we keep to run and protect the service. This Privacy Policy governs that data.

The server is the controller for the data created inside a Discord server that has added Tickety: tickets and the messages in them, transcripts, application questions and answers, verification records, polls and giveaway entries. The server owner and the administrators they appoint decide to install Tickety, decide which features to switch on, decide what questions to ask and what to collect, and decide who in their server can see it. For that data we act as a processor on their instructions, and we process it to provide the service to them and for no independent purpose of our own.

That allocation has a practical consequence. If you are a member of someone else's Discord server and you want to see, correct or delete something you wrote in a ticket or an application, or you want to know why it was collected, the server that runs Tickety is the party responsible and you should ask them first. We do not have the relationship with you that would let us answer for them, and we will not override a server's decisions about its own data. Where we are required to assist a controller with such a request, we will do so through that server rather than directly. Server owners and administrators are responsible for having a lawful basis for what they collect, for telling their members about it, and for their own compliance with data protection law.

If you have any questions about this Privacy Policy or our data practices, or if you wish to exercise any of your data protection rights in respect of data for which we are the controller, please contact us at [email protected].

2. How We Rely on the Law

This Privacy Policy explains what we do with personal data and why. Most of our processing is not based on consent: we process personal data because it is necessary to provide the service you or your server has asked us for, because we have a legitimate interest in operating and protecting the service, or because the law requires it. Section 5 sets out which basis applies to which purpose.

Where we do rely on your consent, we ask for it separately and in clear terms, and you may withdraw it at any time without affecting the lawfulness of processing carried out before you withdrew it. Withdrawing consent does not affect processing that rests on another legal basis, and it does not remove our obligation to keep records we are required by law to keep.

3. Information We Collect

We collect information by fair and lawful means. When you invite Tickety, we use the Discord API to retrieve information about your server, such as its name, icon, approximate member count and the identity of its owner, and we keep a limited record of it so that the bot and the dashboard can operate and show you the servers Tickety is in. Other information about your server is retrieved from Discord when it is needed rather than kept by us.

When you visit our website, our servers may automatically log the standard data provided by your web browser. This data is considered "non-identifying information", as it does not personally identify you on its own. It may include your computer's Internet Protocol (IP) address, your browser type and version, the pages you visit, the time and date of your visit, the time spent on each page, and other details.

When logging into our web dashboard, we also collect all guild objects for the servers you are a member of. This is so we can verify your ownership / status in the server, and provide a list of servers to manage.

Where a server administrator enables the verification module, we also record, for each verification attempt, the Discord user and server involved, the time, the outcome and reasons for it, a risk score, and technical signals about the browser or device used to complete the check, including identifiers derived from that device and browsing session, an approximate country, and indications that an anonymising, privacy or automation tool appears to be in use. Section 6 of our Terms of Service describes what the module does with them.

4. How We Use Your Information

We use the information we collect in various ways, including to:
  • Provide, operate, and maintain our website and Discord bot
  • Improve, personalize, and expand our services
  • Understand and analyze how you use our website
  • Develop new products, services, features, and functionality
  • Communicate with you for service-related purposes
  • Process transactions and manage subscriptions
  • Find and prevent fraud, abuse, and security issues
  • Comply with legal obligations
Your data is not shared with any third-party services except as described in this policy.

5. Legal Basis for Processing (GDPR)

If you are from the European Economic Area (EEA), our legal basis for collecting and using your personal information depends on the data concerned and the context in which we collect it. We rely on the following bases under Article 6 of the GDPR:
  • Performance of a contract (Article 6(1)(b)): operating the bot and the dashboard, creating and running tickets, applications, verification, giveaways and polls, providing premium features and addons, and providing support
  • Legitimate interests (Article 6(1)(f)): keeping the service secure and available, preventing abuse, fraud and evasion of bans, debugging and improving the service, measuring how it is used, and defending legal claims. We balance these against your rights, and you may object as described in Section 13
  • Legal obligation (Article 6(1)(c)): keeping tax, accounting and transaction records, and responding to lawful requests
  • Consent (Article 6(1)(a)): only where we ask for it separately, such as non-essential cookies and analytics
Payment processing is carried out by Paddle as merchant of record. Paddle decides how it processes payment data and is a controller in its own right for that processing, under its own privacy policy.

6. Data Retention

We aim to keep personal information only for as long as we need it for the purposes set out in this Privacy Policy, and for as long as we need it to comply with our legal obligations, resolve disputes, prevent abuse and enforce our agreements. We do not commit to fixed retention periods: how long a particular record is needed depends on what it is and on what happens next in the server it belongs to.

Typically:
  • Data about a Discord server is kept while a Tickety bot is in that server. After the last bot is removed, the server is marked for deletion and its data is deleted by an automated process that runs periodically. Deletion is not immediate, we do not commit to a deletion date, and if a bot is added back before the data has been deleted the deletion is cancelled.
  • Some records about a server survive that deletion. They include the server's entitlements and AI credit balances, and, for a server that has at any time held a paid subscription, its configuration and set-up, so that the set-up is still there if the server returns.
  • Account data is kept for as long as you use the service, and afterwards for as long as we need it for the purposes described above.
  • Payment and transaction records are kept for as long as tax, accounting and financial regulations require, and for as long as we may need them to handle a refund, a chargeback or a legal claim.
  • Records used to detect and prevent fraud, abuse and security incidents, including verification records, are kept for as long as they remain useful for that purpose.
  • Where we hold operational logs, backups or other technical copies, they are overwritten or cycled out on their own schedule, which does not track the deletion of the data they were taken from.
  • Aggregated or statistical information that no longer identifies anyone may be kept indefinitely.
A server administrator can delete most of their own server's data at any time from the bot or the dashboard. When we no longer have a purpose for personal information, we aim to delete it or to keep it only in a form that no longer identifies anyone.

7. International Data Transfers

Your information may be transferred to, and maintained on, computers located outside of your state, province, country, or other governmental jurisdiction where the data protection laws may differ from those of your jurisdiction.

Our own servers and database are located within the European Union. Some of the providers described in Section 8 are established outside the European Economic Area, including in the United States, so using the service can involve a transfer of personal data outside the EEA.

Where we transfer personal data outside the EEA we rely on a transfer mechanism recognised by Chapter V of the GDPR: an adequacy decision of the European Commission where one covers the provider, and otherwise the European Commission's standard contractual clauses together with the additional safeguards required by Article 46. We do not rely on your consent as the basis for these transfers. You may ask us for information about the mechanism used for a particular provider by contacting us at [email protected].

We take the steps we consider appropriate to apply the safeguards described above. We cannot control the laws or practices of the countries data is transferred to and we give no assurance as to the level of protection available in any of them.

8. Third-Party Services

We use third-party companies and individuals to help us provide the service. Where they act as our processors, our contract with them requires them to process personal data only on our instructions and for the purposes we specify. Some recipients are controllers in their own right and decide for themselves how they process the data they receive; we do not control what they do with it and we are not responsible for their acts or omissions.

The categories of recipient are: Discord, which is the platform the service runs on and a controller in its own right; Paddle, our merchant of record for payments, and the provider we used before it, each a controller in its own right for that processing; providers of hosting, storage and content delivery; providers of AI features, where a server has those features switched on; providers of security and anti-abuse checks; and providers of logging and website analytics.

Each operates under its own privacy policy, and those acting as our processors are bound by a written agreement under Article 28 of the GDPR. We may change providers at any time without notice to you. If you need to know which provider we use for a particular purpose in order to exercise a right you have under data protection law, contact us at [email protected].

We do not sell, trade, or rent your personal identification information to others.

9. Disclosure of Information

We may disclose your personal information in the following situations:
  • Legal Requirements: If required to do so by law or in response to valid requests by public authorities (e.g., a court or government agency)
  • Vital Interests: To protect and defend our rights or property
  • Fraud Prevention: To prevent or investigate possible wrongdoing in connection with our service
  • Safety: To protect the personal safety of users or the public
  • Business Transfers: In connection with a merger, acquisition, or sale of assets, your personal information may be transferred

10. Log Files

Like most online services, we keep operational logs. These record events such as Internet Protocol (IP) addresses, browser type, the date and time of a request, the pages or endpoints requested, and errors. We use them to operate and secure the service, to diagnose faults, and to detect and prevent abuse. Our legal basis is our legitimate interest in keeping the service running and secure under Article 6(1)(f) of the GDPR.

An IP address can in some circumstances identify you, so we treat this information as personal data. We do not use it to build a profile of you or to identify you as an individual for any other purpose. Logs are kept only for as long as they are needed for the purposes above and are then deleted or overwritten on a rolling basis. We do not commit to a fixed log retention period.

11. How We Protect Your Data

We take technical and organisational measures that we consider appropriate to the risk, as required by Article 32 of the GDPR. No method of transmission over the internet and no method of electronic storage is completely secure, and we do not warrant, guarantee or represent that any information you transmit to us, or that we hold, will remain secure or free from unauthorised access, loss or alteration. Transmission of personal information to and from our site is at your own risk, and you should only access the services within an environment you consider secure.

Keeping your Discord account, its credentials and its authorised applications secure is your responsibility, and we are not responsible for anything that follows from a compromise of your Discord account or of a server you belong to. Nothing in this Section limits any liability that cannot lawfully be limited.

12. Cookies

We use "cookies" to collect information about you and your activity across our site. A cookie is a small piece of data that our website stores on your computer, and accesses each time you visit so we can understand how you use our site and serve you content based on preferences you have specified.

13. Your Rights

In some regions, such as the European Economic Area, you have rights that allow you greater access to and control over your personal information. You may review, change, or terminate your account at any time.

In some regions (like the European Economic Area), you have certain rights under applicable data protection laws. These may include the right (i) to request access and obtain a copy of your personal information; (ii) to request rectification or erasure; (iii) to restrict the processing of your personal information; and (iv) if applicable, to data portability. In certain circumstances, you may also have the right to object to the processing of your personal information. To make such a request, please use the contact details provided below. We will consider and act upon any request in accordance with applicable data protection laws.

If we are relying on your consent to process your personal information, you have the right to withdraw your consent at any time. Please note however that this will not affect the lawfulness of the processing before its withdrawal.

If you are resident in the European Economic Area and you believe we are unlawfully processing your personal information, you also have the right to complain to your local data protection supervisory authority. You can find their contact details here: https://edpb.europa.eu/about-edpb/about-edpb/members_en

14. California Privacy Rights (CCPA)

If you are a California resident, you have the right to request that we disclose certain information about our collection and use of your personal information over the past 12 months. Under the California Consumer Privacy Act (CCPA), you have the following rights:
  • Right to Know: You have the right to request that we disclose what personal information we collect, use, disclose, and sell
  • Right to Delete: You have the right to request the deletion of your personal information, subject to certain exceptions
  • Right to Opt-Out: You have the right to opt out of the sale of your personal information (Note: We do not sell personal information)
  • Right to Non-Discrimination: You have the right not to receive discriminatory treatment for exercising your CCPA rights
To exercise any of these rights, please contact us using the contact information provided below.

15. Children's Information

Another part of our priority is adding protection for children while using the internet. We encourage parents and guardians to observe, participate in, and/or monitor and guide their online activity.

Tickety does not knowingly collect any personally identifiable information from children under the age of 13. If you think that your child provided this kind of information on our website, we encourage you to contact us, and we will take the steps we consider appropriate to remove such information from our records.

Our website, products and services are directed to people who are 13 years old or older and are not directed to children under 13, and we do not knowingly collect information from them. We do not verify the age of anyone who interacts with a bot inside a Discord server, and a server is responsible for who it admits. If we learn that we have collected personal information from a child under 13 without verification of parental consent, we will delete that information in accordance with applicable law.

16. Do Not Track Signals

Do Not Track ("DNT") is a preference you can set in your web browser to tell websites that you do not want to be tracked. There is no common industry or legal standard for recognising or responding to DNT signals, and browsers implement them differently.

Because no uniform standard exists, we do not currently respond to DNT signals and our behaviour does not change when one is set. You can control cookies through your browser settings and through any cookie controls we offer on our website.

17. Links to Other Websites

Our service may contain links to other websites that are not operated by us. If you click on a third-party link, you will be directed to that third party's site. We strongly advise you to review the Privacy Policy of every site you visit.

We have no control over and assume no responsibility for the content, privacy policies, or practices of any third-party sites or services.

18. Security Breach Notification

Where a personal data breach affects personal data for which we are the controller, we will notify the competent supervisory authority where Article 33 of the GDPR requires us to do so. Where the breach is likely to result in a high risk to your rights and freedoms, we will also communicate it to you without undue delay, in the manner and to the extent Article 34 of the GDPR requires, which may be by a public communication rather than an individual message. We are not required to communicate a breach to you where an exception in Article 34(3) applies.

Where the controller is the Discord server rather than us, as described in Section 1, our role is to notify that server without undue delay after we become aware of a breach so that it can meet its own obligations to its members. Notifying members is then that server's responsibility and not ours.

Nothing in this Section commits us to any timescale, form of notice or content of notice beyond what applicable law requires of us.

19. Account Security

You are responsible for maintaining the confidentiality of your account credentials and for any activities that occur under your account. We recommend:
  • Using a strong, unique password for your Discord account
  • Enabling two-factor authentication on your Discord account
  • Not sharing your login credentials with others
  • Logging out from shared devices
  • Regularly reviewing authorized applications
If you believe your account has been compromised, please contact us immediately and revoke Tickety's access through Discord's authorized applications settings.

20. AI Features and Automated Decision-Making

A server administrator can switch on AI features for their server. Where they are on, content from that server is sent to our AI provider so the feature can produce a result. Depending on which features are enabled, that content can include ticket messages and replies, the text of an application, the text of a poll request, and text read out of an image that has been uploaded. It is sent under our agreement with the provider, which does not permit the provider to use it to train its models, and it is processed to return a result rather than to build a profile of you.

These features are used to summarise and triage tickets, suggest or draft replies, read text out of images, propose poll topics, and screen applications. AI output can be wrong, and we do not treat it as a substitute for a human decision.

We do not use automated decision-making that produces legal effects concerning you. Where a server has enabled automatic screening of applications, an application can be declined without a person reading it first. That decision is made by the server that configured it, using rules and instructions the server sets, and it affects only your application to that server. If it happens to you, you can ask that server to look at it again: the server keeps the record and can reopen or reverse the outcome, and every server retains the ability to review applications by hand. If you cannot reach the server, contact us at [email protected] and we will try to put you in contact with someone at that server. We cannot require a server to reconsider its decision and we do not undertake to obtain any particular outcome for you.

We do not use your personal data to train our own models, and we do not carry out profiling for advertising.

21. Transcripts

Another part of the services we provide is Transcripts. A transcript is a copy of a closed ticket that is sent to the ticket creator when the ticket is closed. This can be useful if the creator wants to refer to something said in the ticket. You can also view a transcript on the tickety.top website by having the ID of the transcript.

Where a server has transcripts switched on, Tickety stores them on its own systems. You can ask us to delete a transcript by emailing us at [email protected]. Because the server is the controller of its own transcripts, as described in Section 1, we will normally refer such a request to that server, and we may decline a request that does not come from someone entitled to make it or that we are not required to act on. This does not affect a request you are entitled to make under data protection law in respect of personal data concerning you. We do not commit to keeping any transcript for a minimum period and we may delete transcripts at any time.

Transcripts are optional and controlled by the server: Saving transcripts is a per-panel setting that the server administrator controls, and it can be switched off. Where it is off, closed tickets from that panel are not stored. Saving image attachments can be switched off separately, and on a premium server the administrator can also restrict who is able to view a transcript. These choices are made by the server, not by us and not by the individual member, and they apply from the moment they are changed rather than to tickets already closed.

Transcript Data Contents: Transcripts may contain message content, usernames, user IDs, timestamps, attachments, and other data exchanged within the ticket channel. The server administrator decides whether to enable transcripts and what is collected in a ticket, and is responsible for informing their users about transcript storage, for having a lawful basis for it, and for ensuring compliance with the privacy regulations applicable in their jurisdiction.

22. Premium Subscriptions & Payment Data

Our order process is conducted by our online reseller Paddle.com. Paddle.com is the Merchant of Record for all our orders. Paddle provides all customer service inquiries and handles returns. A small number of older subscriptions are still billed by the payment provider we used before Paddle.

This means your card details are given to Paddle and never to us. We do not see, receive or store your card number, CVV, expiry date or any part of your card number at any point. Paddle is a controller in its own right for the payment data it handles, and processes it under its own privacy policy and its own security standards.

What we hold on our own systems is limited to what we need to know that a server is paid for and to support you if something goes wrong:
  • The Paddle subscription and customer identifiers for your subscription
  • Which server the subscription pays for, its plan, its addons and its status
  • When we last received a billing event for it
  • Your AI credit balance and the record of credits granted and spent
Invoices, receipts and the underlying transaction records are held by Paddle. We keep the records we are required to keep for tax and accounting purposes, and for as long as we may need them to handle a refund, a chargeback or a legal claim.

23. Discord Bot Permissions & Data Access

When you invite Tickety to your Discord server, you grant the bot certain permissions. We request the permissions the bot needs in order to offer the features available to your server, including features you may not have switched on yet, and the permissions we request may change as the service changes. The bot may access:
  • Server information (name, icon, member count)
  • Channel information (for ticket management)
  • Role information (for permission verification)
  • Message content in the channels in which enabled features operate
  • Member information when interacting with the bot
The bot processes message content in the channels in which the features your server has enabled operate, which can include ticket channels, application and verification flows, and any channel a server administrator has configured a module to act in. We do not monitor a server's channels generally, we do not sell message content, and we do not use it to train our own models. What a server chooses to enable, and therefore what the bot sees, is decided by that server and not by us.

24. Data Portability

Where we are the controller of personal data concerning you, where you provided that data to us, and where we process it by automated means on the basis of your consent or of a contract with you, you have the right under Article 20 of the GDPR to receive it in a structured, commonly used and machine-readable format. That right covers the data you gave us. It does not extend to data we derived or inferred, to data about other people, or to data whose disclosure would adversely affect the rights and freedoms of others.

For data created inside a Discord server, including tickets, transcripts, applications and verification records, the server is the controller as described in Section 1, and a request of this kind is for that server to answer rather than us. We supply data in the format in which we hold it and we are not obliged to build an export that does not already exist.

To request a copy of your data, please contact us at [email protected]. We will respond within the period allowed by the applicable law, which for requests under the GDPR is one month and may be extended by two further months where a request is complex or where we receive a number of requests from you.

25. Service Availability & Data Processing

Our services are provided on an "as is" and "as available" basis. We do not guarantee uninterrupted service and we give no undertaking as to uptime or availability. During maintenance, outages, incidents, or disruption at the platforms the service depends on:
  • Data processing may be suspended, delayed or interrupted
  • Some or all features may be unavailable
  • Queued, scheduled or automated operations may be delayed, repeated or not carried out at all
  • Data created or in transit during that period may be incomplete or lost
We are not obliged to give notice of maintenance, and any notice we do give is a courtesy rather than a commitment.

26. Data Deletion Requests

If you wish to have data deleted, you may email us at [email protected]. We handle deletion requests in accordance with applicable data protection law, and we may ask you for the information we need in order to identify you or to establish that you are entitled to make the request. Where the data belongs to a Discord server rather than to you personally, that server is the controller as described in Section 1, the request is for it to decide, and we will refer the request there. Deletion does not extend to the categories described in Section 6 that we continue to hold, to backups, logs and other technical copies until they are cycled out in the ordinary course, or to anything we are required or entitled to keep.

27. Contact Information

If you have questions or comments about this policy, you may email us at [email protected]. We will handle your request within the period allowed by the applicable law, and we may extend that period where the request is complex or where we receive a number of requests from you.

For data protection inquiries, please include "Privacy" in the subject line so that your request is routed correctly.

28. Changes to This Privacy Policy

We may update our Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last Updated" date below.

Where a change materially affects how we handle personal data, we will take the steps we consider appropriate to bring it to your attention, which may include a notice on this website or in the service. We are not obliged to notify you individually, and where we do not, publishing the updated Privacy Policy on this page is the notice you receive.

You are advised to review this Privacy Policy periodically for any changes. Changes to this Privacy Policy are effective when they are posted on this page. Your continued use of our service after any modifications indicates your acceptance of the updated policy.

29. Governing Law

This Privacy Policy shall be governed by and construed in accordance with the laws of the European Union and applicable national laws, without regard to conflict of law principles. If you are accessing our services from outside the EU, you agree to the transfer of your information to the EU and its processing in accordance with this policy.

30. Severability

If any provision of this Privacy Policy is found to be unenforceable or invalid under any applicable law, such unenforceability or invalidity shall not render this Privacy Policy unenforceable or invalid as a whole. Such provisions shall be deleted without affecting the remaining provisions herein.

31. Last Updated

This Privacy Policy was last updated on September 8, 2026.
Copyright © 2026 Tickety.top - All Rights Reserved.