The operator of TicketIt (“TicketIt,” “we,” “us,” or “our”), respects the privacy of individuals who visit our websites, create or use a TicketIt account, interact with the TicketIt software-as-a-service platform, communicate with us, or otherwise use our products and services.
This Privacy Policy (“Privacy Policy”) explains how TicketIt collects, uses, discloses, stores, and otherwise processes personal information in connection with our websites, hosted software platform, applications, services, communications, and related offerings (collectively, the “Services”).
This Privacy Policy also describes certain rights and choices that may be available to individuals regarding their personal information.
By accessing or using the Services, you acknowledge the practices described in this Privacy Policy.
This Privacy Policy should be read together with the TicketIt Terms of Service and any other privacy, data-processing, or contractual terms that may apply to your relationship with TicketIt.
1. SCOPE OF THIS PRIVACY POLICY
This Privacy Policy applies to personal information that TicketIt processes in connection with the operation and provision of the Services, including information relating to website visitors, prospective customers, account holders, administrators, authorized users, individuals who communicate with TicketIt, and other persons who interact directly with us.
TicketIt is primarily a business-to-business software provider. In many circumstances, organizations use TicketIt to process information about their own employees, contractors, customers, suppliers, representatives, or other individuals.
When an organization submits or otherwise processes personal information through the Services and determines the purposes and means for which that information is processed, that organization generally acts as the controller, business, or equivalent responsible party under applicable privacy law, and TicketIt processes the information on its behalf as a processor, service provider, or equivalent role.
In those circumstances, requests relating to personal information controlled by a TicketIt customer should generally be directed to that customer. TicketIt will assist its customers with such requests where required by applicable law and the applicable contractual relationship.
Where TicketIt determines the purposes and means of processing personal information, including information used to administer accounts, operate our website, manage subscriptions, provide customer support, secure the Services, and conduct our own legitimate business operations, TicketIt acts as the controller or equivalent responsible party.
2. PERSONAL INFORMATION WE COLLECT
The personal information TicketIt collects depends upon how an individual interacts with the Services, the functionality being used, the configuration selected by the applicable customer, and the information voluntarily submitted to us.
2.1 Account and Profile Information
When an account is created or administered, we may collect information such as an individual’s name, business email address, organization, job title or role, account identifier, profile information, preferred language, permissions, account status, and authentication-related information.
We may also maintain information regarding the organization, workspace, team, department, service unit, or other organizational structure with which an Authorized User is associated.
Passwords and authentication credentials are handled using security controls appropriate to the authentication architecture of the Services. TicketIt does not intend to store passwords in plain text.
2.2 Customer Content and Ticket Information
The Services permit customers and Authorized Users to create, receive, assign, process, manage, and resolve Tickets and related business workflows.
As a result, the Services may process information contained in Ticket titles, descriptions, categories, priorities, statuses, comments, communications, assignments, attachments, files, timestamps, activity history, workflow events, service-level information, and other content submitted by users.
The nature of this information is principally determined by the customer using the Services.
Customers and Authorized Users should not submit personal information that is unnecessary for the purpose for which a Ticket or workflow is being managed.
2.3 Administrative and Organizational Information
We may process information relating to account administration, organizational structure, user permissions, roles, teams, service units, workflow configurations, business calendars, account settings, branding preferences, invitations, account expiration dates, and other configuration information.
2.4 Subscription and Billing Information
When a customer purchases or manages a Subscription, we may process information such as the customer’s Subscription Plan, number of Seats, billing status, transaction identifiers, billing contact information, subscription dates, renewal status, amounts charged, currency, and related commercial information.
Payment transactions may be processed by third-party payment providers.
Where payment information is submitted directly to a payment provider, TicketIt does not intend to receive or store complete payment card numbers, card security codes, or other full payment credentials unless expressly required for a particular payment method and appropriately disclosed.
2.5 Communications and Support Information
When an individual contacts TicketIt through a contact form, support channel, email, or other communication mechanism, we may collect the information submitted as part of that communication.
This may include name, business email address, company, subject matter, support request, correspondence, attachments, and information necessary to investigate or respond to the inquiry.
2.6 Device, Usage and Technical Information
When individuals access or use the Services, certain technical information may be collected automatically.
This may include IP address, browser type, operating system, device information, session information, login timestamps, pages or functionality accessed, referring URLs, application events, error logs, performance information, authentication events, security events, and other diagnostic or technical information.
This information may be collected through server logs, application telemetry, cookies, local storage, similar technologies, or third-party infrastructure used to provide the Services.
2.7 Audit and Security Information
TicketIt may maintain records relating to actions performed within the Services for security, accountability, troubleshooting, and audit purposes.
These records may include information regarding account creation, login activity, permission changes, administrative actions, Ticket activity, assignments, status changes, configuration changes, and other relevant events.
2.8 Information Generated Through Analytics and AI Features
Where customers use analytics or artificial intelligence functionality, TicketIt may process information necessary to generate the requested analysis, summary, classification, recommendation, or other output.
This may include Ticket information, operational metrics, response and resolution times, workflow events, assignment information, aggregated user-performance information, and other data relevant to the requested functionality.
AI-generated outputs may themselves constitute or contain personal information depending on the underlying information and the nature of the output.
3. SOURCES OF PERSONAL INFORMATION
TicketIt may obtain personal information directly from the individual, from the organization that provides the individual with access to TicketIt, from Administrators or other Authorized Users, automatically through use of the Services, from integrated Third-Party Services, from payment providers, and from other sources where permitted by applicable law.
Where an organization creates an account or invites an individual to TicketIt, certain information about that individual may be provided to TicketIt before the individual directly interacts with the Services.
4. HOW WE USE PERSONAL INFORMATION
TicketIt processes personal information for purposes reasonably related to providing, operating, maintaining, protecting, and improving the Services and conducting our business.
We may use personal information to create and administer Accounts; authenticate users; provide access to the Services; manage roles and permissions; process Tickets and workflows; provide requested features; operate dashboards, analytics, and reporting; process and administer Subscriptions; communicate with customers and users; respond to inquiries and support requests; personalize account settings and user experience; maintain security; detect and prevent fraud, misuse, unauthorized access, and other harmful activity; diagnose technical problems; monitor performance and reliability; maintain audit records; comply with legal obligations; enforce our agreements; protect our rights and those of our customers and users; and develop, maintain, and improve the Services.
We may also use information to communicate with existing or prospective business customers regarding TicketIt products and services where permitted by applicable law. Individuals may opt out of promotional electronic communications using the unsubscribe mechanism included in such communications when applicable.
5. CUSTOMER-CONTROLLED DATA
TicketIt customers determine much of the information that is submitted to and processed through the Services.
When TicketIt processes personal information solely on behalf of a customer and pursuant to that customer’s instructions, TicketIt does not independently determine the purposes for which that information is used except as necessary to provide, secure, maintain, and support the Services or as otherwise permitted by applicable law and the applicable agreement with the customer.
If you are an Authorized User, employee, contractor, customer, supplier, or other individual whose personal information has been submitted to TicketIt by an organization, questions concerning that organization’s use of your information should generally be directed to the organization responsible for the Account.
TicketIt may refer privacy requests relating to customer-controlled information to the applicable customer or assist the customer in responding to such requests as required by applicable law.
6. LEGAL BASES FOR PROCESSING
Where applicable law requires TicketIt to identify a legal basis for processing personal information, TicketIt may rely on one or more legal bases depending on the circumstances.
These may include processing necessary to perform a contract or take steps requested before entering into a contract; processing necessary for TicketIt’s legitimate interests or those of another party where those interests are not overridden by applicable privacy rights; compliance with legal obligations; protection of TicketIt, its customers, users, or others; and consent where consent is required or appropriate.
Where processing is based on consent, individuals may withdraw that consent as provided by applicable law. Withdrawal does not affect the lawfulness of processing performed before withdrawal.
7. HOW WE DISCLOSE PERSONAL INFORMATION
TicketIt does not disclose personal information indiscriminately. We may disclose information where reasonably necessary to provide and operate the Services, conduct our business, comply with law, or protect legitimate interests.
Service Providers and Processors
TicketIt may disclose personal information to vendors and service providers that perform services on our behalf, including cloud infrastructure, database hosting, authentication, storage, security, monitoring, analytics, payment processing, communications, artificial intelligence, software development, customer support, and related technology services.
Such providers are permitted to process personal information only for appropriate purposes and subject to applicable contractual and legal requirements.
Customer Organizations and Authorized Users
Information processed within a customer Account may be made available to Administrators and other Authorized Users in accordance with the permissions, roles, workflows, assignments, and settings established by the customer.
Customers are responsible for configuring appropriate permissions within their Accounts.
Integrations
Where a customer enables an integration with a Third-Party Service, TicketIt may transmit or make information available to that service as necessary to perform the integration requested by the customer.
Third-Party Services may process information pursuant to their own privacy policies and contractual terms.
Professional Advisers
TicketIt may disclose information to attorneys, accountants, auditors, insurers, consultants, and other professional advisers where reasonably necessary for legitimate business or legal purposes and subject to appropriate confidentiality obligations.
Legal and Safety Requirements
TicketIt may disclose personal information if we reasonably believe disclosure is required by law, legal process, court order, governmental request, or regulatory requirement, or where disclosure is reasonably necessary to protect the rights, safety, security, property, or integrity of TicketIt, our customers, users, or others.
Corporate Transactions
Personal information may be disclosed or transferred in connection with an actual or proposed merger, acquisition, financing, investment, corporate restructuring, sale of assets, change of control, insolvency, bankruptcy, or similar transaction.
Any recipient will remain subject to applicable privacy obligations regarding the information transferred.
8. SALE OF PERSONAL INFORMATION AND TARGETED ADVERTISING
TicketIt does not currently sell personal information for monetary consideration as part of its business model.
TicketIt also does not currently use personal information obtained from the authenticated TicketIt application to provide third-party targeted advertising based on an individual’s activity across unrelated businesses, websites, or applications.
If TicketIt materially changes these practices, we will update this Privacy Policy and provide any notices, consent mechanisms, or opt-out rights required by applicable law before engaging in such processing.
9. ARTIFICIAL INTELLIGENCE
Certain features of TicketIt may use artificial intelligence or machine-learning technologies to analyze information and provide summaries, classifications, recommendations, insights, or other functionality requested by customers.
When an AI Feature is used, TicketIt may transmit information necessary to perform the requested operation to an artificial intelligence service provider acting on TicketIt’s behalf.
TicketIt seeks to limit such processing to information reasonably necessary to provide the applicable functionality.
Unless a customer expressly agrees otherwise, TicketIt will not intentionally use identifiable Customer Confidential Information to train a general-purpose artificial intelligence model for the benefit of unrelated customers.
AI-generated information may contain inaccuracies and should be appropriately reviewed by users before being relied upon for significant decisions.
TicketIt does not intend its general AI functionality to make autonomous decisions producing legal or similarly significant effects concerning individuals.
10. AGGREGATED AND DE-IDENTIFIED INFORMATION
TicketIt may create aggregated or de-identified information from information processed through the Services.
We may use such information for analytics, security, capacity planning, product development, benchmarking, research, service improvement, and other legitimate business purposes.
Where information is treated as de-identified, TicketIt will take reasonable measures designed to prevent the information from being associated with an identified or identifiable individual and will not intentionally attempt to re-identify it except where permitted by applicable law for purposes such as evaluating the effectiveness of de-identification controls.
11. COOKIES AND SIMILAR TECHNOLOGIES
TicketIt may use cookies, browser storage, pixels, SDKs, and similar technologies to operate and secure our website and Services, maintain authenticated sessions, remember preferences, understand product usage, diagnose technical issues, measure performance, and improve the user experience.
Some technologies may be strictly necessary for the Services to function and therefore cannot reasonably be disabled while using certain functionality.
Where TicketIt uses non-essential cookies or similar technologies for purposes requiring consent under applicable law, TicketIt will provide appropriate choices or consent mechanisms.
Additional information may be provided through a separate Cookie Notice or cookie-management interface.
12. DO NOT TRACK AND GLOBAL PRIVACY CONTROLS
Certain browsers offer “Do Not Track” signals. Because there is not a universally accepted standard governing all uses of such signals, TicketIt may not respond to traditional browser Do Not Track signals unless required by applicable law.
Where applicable law requires recognition of legally valid opt-out preference signals, including supported universal opt-out mechanisms, TicketIt will process such signals as required by applicable law for the relevant processing activity.
13. DATA RETENTION
TicketIt retains personal information only for as long as reasonably necessary for the purposes for which it was collected or processed, including to provide the Services, maintain customer Accounts, satisfy contractual obligations, comply with legal and regulatory requirements, resolve disputes, enforce agreements, maintain security records, prevent fraud, and preserve appropriate business records.
Retention periods may vary depending on the type of information, the nature of the customer relationship, applicable contractual requirements, the sensitivity of the information, and applicable law.
Customer Data may be retained during the term of the applicable customer relationship and for a limited period following termination to permit data recovery, account administration, dispute resolution, legal compliance, and completion of backup cycles.
Information stored in backups may remain until the relevant backup is overwritten or deleted in accordance with TicketIt’s normal backup practices.
Where information is no longer reasonably required, TicketIt may delete, anonymize, or de-identify it.
14. INFORMATION SECURITY
TicketIt maintains commercially reasonable administrative, technical, and organizational measures designed to protect personal information against unauthorized access, acquisition, disclosure, alteration, destruction, or loss.
These measures may include access controls, authentication mechanisms, logical customer isolation, encrypted communications, audit logging, security monitoring, vulnerability-management practices, backup and recovery controls, and secure software-development practices.
No method of electronic transmission, storage, or information-security control can guarantee absolute security. Accordingly, TicketIt cannot guarantee that unauthorized third parties will never defeat security measures or improperly access information.
Individuals are responsible for protecting their credentials and should promptly notify their Account Administrator or TicketIt if they suspect unauthorized access to an Account.
15. DATA BREACHES AND SECURITY INCIDENTS
TicketIt maintains processes designed to identify, investigate, contain, and respond to security incidents affecting personal information.
If TicketIt becomes aware of a personal data breach or security incident for which notification is required by applicable law, TicketIt will provide legally required notifications to affected parties, customers, regulators, or other appropriate recipients within the applicable timeframes.
Where TicketIt processes affected personal information on behalf of a customer, TicketIt will notify and cooperate with the customer in accordance with applicable law and contractual obligations.
16. INTERNATIONAL DATA TRANSFERS
TicketIt is intended to be offered to businesses in multiple jurisdictions.
Accordingly, personal information may be processed in the United States and in other countries where TicketIt, its affiliates, or its service providers operate.
Those jurisdictions may have privacy and data-protection laws that differ from the laws of the individual’s jurisdiction.
Where applicable law requires safeguards for international transfers of personal data, TicketIt will implement an appropriate transfer mechanism, which may include contractual safeguards, data-processing agreements, standard contractual clauses, adequacy mechanisms, or other legally recognized transfer arrangements.
17. PRIVACY RIGHTS
Depending on where an individual resides and the laws applicable to the processing, the individual may have certain rights regarding personal information.
These rights may include the right to request confirmation of whether personal information is being processed; obtain access to personal information; correct inaccurate information; request deletion; obtain a portable copy of certain information; withdraw consent where processing is based on consent; object to or restrict certain processing; obtain information regarding categories of third parties to whom information has been disclosed; and opt out of certain forms of targeted advertising, sale of personal information, or qualifying automated profiling.
These rights are not absolute. Applicable law may permit or require TicketIt to decline or limit a request in certain circumstances.
TicketIt will not unlawfully discriminate against an individual for exercising applicable privacy rights.
18. DELAWARE PRIVACY RIGHTS
Residents of Delaware may have rights under the Delaware Personal Data Privacy Act and other applicable Delaware privacy laws, subject to applicable statutory requirements, limitations, and exemptions.
Where applicable, these rights may include requesting confirmation of whether TicketIt processes personal data, accessing personal data, correcting inaccuracies, requesting deletion, obtaining a portable copy of certain personal data, obtaining information regarding third parties or categories of third parties to which personal data has been disclosed as required by applicable law, and opting out of processing for targeted advertising, sale of personal data, or certain profiling used in connection with decisions producing legal or similarly significant effects.
A Delaware resident whose privacy request is denied may also have the right to appeal that decision in accordance with applicable law.
TicketIt will provide instructions regarding any further available complaint mechanism if an appeal is denied and applicable law requires such information.
19. HOW TO EXERCISE PRIVACY RIGHTS
Individuals may submit privacy requests through the privacy or contact mechanism made available on the TicketIt website or through another method designated by TicketIt.
TicketIt may need to verify the identity of the person submitting a request before fulfilling it. Verification requirements will depend on the nature of the request and the sensitivity of the information involved.
Where permitted by applicable law, an authorized agent may submit certain requests on behalf of an individual. TicketIt may request evidence demonstrating the agent’s authority.
TicketIt will respond to verified requests within the period required by applicable law.
If a request concerns personal information that TicketIt processes solely on behalf of a customer, TicketIt may direct the requesting individual to the applicable customer and will provide appropriate assistance to that customer where required.
An individual is not required to create a new TicketIt Account solely to submit a privacy request.
20. APPEALS
Where applicable law provides a right to appeal TicketIt’s refusal to act upon a privacy request, the individual may submit an appeal through the same privacy contact mechanism or another appeal method identified in TicketIt’s response.
TicketIt will review the appeal and respond within the period required by applicable law.
Where required, a denial of an appeal will include information regarding how the individual may submit a complaint to the appropriate regulatory or governmental authority.
21. SENSITIVE PERSONAL INFORMATION
TicketIt is a general business software platform and is not designed by default for the unrestricted processing of highly sensitive personal information.
Customers should avoid submitting sensitive personal information unless such information is reasonably necessary for an authorized business purpose, the customer has determined that the Services are appropriate for that processing, and all required legal conditions have been satisfied.
Depending on applicable law, sensitive personal information may include information concerning racial or ethnic origin, religious beliefs, health conditions, sexual orientation, precise geolocation, genetic or biometric information used for identification, government identification numbers, account credentials, or other categories designated as sensitive by law.
Where TicketIt itself acts as a controller and applicable law requires consent before processing sensitive personal information, TicketIt will obtain such consent before engaging in that processing.
22. CHILDREN’S PRIVACY
TicketIt is a business software service and is not directed to children.
Individuals under eighteen (18) years of age should not independently create a TicketIt Account unless their access is lawfully authorized by an organization and permitted under applicable law.
TicketIt does not knowingly collect personal information directly from children for the purpose of marketing or providing consumer services to children.
If TicketIt learns that it has collected personal information from a child in circumstances that violate applicable law, TicketIt will take appropriate steps to delete or otherwise address the information.
23. THIRD-PARTY WEBSITES AND SERVICES
The Services may contain links to or integrations with websites, applications, platforms, or services operated by third parties.
TicketIt does not control the independent privacy practices of those third parties.
This Privacy Policy does not govern personal information that an individual provides directly to a third party or that a third party independently processes for its own purposes.
Individuals should review the privacy notices of relevant third parties before providing information to them.
24. BUSINESS TRANSFERS
If TicketIt is involved in a merger, acquisition, financing, reorganization, bankruptcy, receivership, sale of assets, or other corporate transaction, personal information may be disclosed or transferred as part of that transaction or related due diligence.
Any successor that assumes control of personal information will remain subject to applicable legal obligations concerning that information.
Where required by applicable law, TicketIt will provide notice regarding material changes to the controller of personal information or the manner in which it will be processed.
25. CHANGES TO THIS PRIVACY POLICY
TicketIt may update this Privacy Policy from time to time to reflect changes in the Services, our processing practices, applicable law, technology, or business operations.
When we update this Privacy Policy, we will revise the “Last Updated” date displayed at the beginning of the Policy.
If a change materially affects the manner in which we process personal information, TicketIt will provide additional notice where required by applicable law. Such notice may be provided through the Services, through an Account, by email, or through another appropriate communication mechanism.
We encourage users to review this Privacy Policy periodically.
26. ADDITIONAL JURISDICTION-SPECIFIC RIGHTS
TicketIt may make the Services available in jurisdictions that provide privacy rights or impose requirements in addition to those described in this Privacy Policy.
Where applicable law grants individuals additional rights that cannot legally be waived, TicketIt will honor those rights to the extent required.
TicketIt may publish jurisdiction-specific privacy disclosures, supplements, or notices where appropriate. Any such supplement will form part of this Privacy Policy with respect to individuals covered by that supplement.
27. DATA PROCESSING ON BEHALF OF CUSTOMERS
Where TicketIt processes personal information on behalf of a customer, the processing relationship may additionally be governed by a Data Processing Agreement or other contractual terms.
Such agreements may address, among other matters, the subject matter and duration of processing, categories of personal information, categories of data subjects, processing instructions, confidentiality, information security, subprocessors, international transfers, deletion or return of information, audit rights, and assistance with applicable privacy obligations.
If there is a conflict between this Privacy Policy and an applicable Data Processing Agreement concerning personal information processed by TicketIt solely on behalf of a customer, the Data Processing Agreement will control with respect to that processing.
28. CONTACT US
The operator of TicketIt is responsible for the personal information it controls as described in this Privacy Policy.
Questions regarding this Privacy Policy, privacy practices, or requests to exercise applicable privacy rights may be submitted through the privacy or contact form available on the TicketIt website.
TicketIt may designate a dedicated privacy email address or additional privacy-request mechanism from time to time. The applicable contact mechanism will be made available through the Services or TicketIt website.
29. EFFECTIVE DATE
This Privacy Policy becomes effective on the Effective Date identified above and remains effective until replaced by a subsequent version.
Continued use of the Services following an update to this Privacy Policy constitutes acknowledgment of the updated Policy to the extent permitted by applicable law. Where applicable law requires consent for a particular change in processing, TicketIt will obtain such consent separately.