Skip to main content
Legal

Privacy Policy

Last updated: August 1, 2026

This Privacy Policy complies with the Australian Privacy Act 1988 (Privacy Act), EU General Data Protection Regulation (GDPR), California Consumer Privacy Act (CCPA and CPRA), and other applicable data protection laws. We are committed to protecting your privacy and being transparent about our data practices.

The short version

Ticket Tool is a Discord ticket bot operated by JTF Labs. This is a quick summary; the full detail is below.

  • We collect the Discord and ticket data needed to run the bot and dashboard. Our website also uses Google Analytics: in the EEA, UK, and Switzerland it runs only if you accept it in the cookie banner; elsewhere it runs by default and you can opt out at any time.
  • We do not sell your personal data.
  • Your data is stored on servers in the United States.
  • You can access, correct, export, or delete your data (see Section 7).

1. Introduction & Scope

This Privacy Policy describes how Ticket Tool ("we", "us", or "our"), operated by JTF LABS PTY LTD (ABN 93 693 353 347), collects, uses, stores, and protects your personal information when you use our Discord bot and web dashboard services.

This policy applies to:

  • The Ticket Tool Discord bot
  • Our web dashboard
  • All related services and features

This policy uses "you" to mean two kinds of user, and applies to both: (1) server operators who add, configure, and run Ticket Tool in their own Discord server, and (2) end users who open a ticket in a server that uses Ticket Tool. Some features and settings (for example deleting a Ticket Tool dashboard account) apply only to operators who hold such an account; end users can still exercise their privacy rights at any time by contacting us (see Section 7).

By using Ticket Tool, you agree to the collection and use of information in accordance with this policy. If you do not agree with our policies and practices, please do not use our services.

2. Information We Collect

2.1 Discord Data

When you use Ticket Tool, we may collect:

  • Discord User IDs and usernames
  • Discord Server (Guild) IDs and names
  • Channel and Role IDs
  • Message content within tickets, which we store to generate transcripts and provide support. This applies only to messages sent inside a ticket you open. We do not read or store messages from other channels. You can request deletion of this data at any time (see Section 7).
  • Timestamps of interactions

2.2 Authentication Data

When you log in to our web dashboard via Discord OAuth2, we receive access to your basic Discord profile information, including your user ID, username, avatar, email address, and the list of Discord servers you belong to.

2.3 Configuration Data

We store the configuration settings you create, including ticket categories, panels, flows, commands, and other customization options.

2.4 Usage and Analytics Data

Through Google Analytics on our website, we may collect:

  • Page views and navigation patterns
  • Anonymized IP addresses
  • Browser type, device information, and operating system
  • Performance metrics (page load times)

Note: In the EEA, United Kingdom, and Switzerland, analytics is off by default and only runs if you accept it in our cookie banner (Google Consent Mode). In other regions analytics runs by default, and you can opt out at any time via the cookie banner or the Cookie preferences link in the site footer.

3. How We Use Your Information

3.1 Legal Basis for Processing (GDPR)

We process personal data under the following legal bases:

  • Contract Performance: Authentication, ticket management, subscription billing (necessary to provide our service)
  • Legitimate Interest: Security monitoring, fraud prevention, error logging, service improvement, and website analytics outside the regions where consent is required
  • Consent: Analytics tracking in the EEA, United Kingdom, and Switzerland; marketing communications (where implemented)
  • Legal Obligation: Compliance with applicable laws, responding to legal requests

3.2 Purposes of Data Processing

We use the collected information to:

  • Provide and maintain the Ticket Tool service
  • Process and manage support tickets
  • Generate ticket transcripts
  • Authenticate users on the web dashboard
  • Apply your configured settings and customizations
  • Process subscription payments via Stripe
  • Prevent fraud and ensure security
  • Improve and optimize our services (see Section 8 for how analytics consent works)
  • Communicate important updates about the service

4. Data Storage and Security

4.1 Security Measures

We use technical and organizational security measures including:

  • TLS/SSL encryption for all data in transit
  • Encrypted, access-restricted backups stored in isolated object storage
  • AES-256-GCM encryption for sensitive configuration data
  • httpOnly, secure session cookies
  • IP-based rate limiting to prevent abuse
  • CORS restrictions and security headers
  • Ongoing security monitoring and review of significant changes

4.2 Data Location

Our primary servers are hosted in the United States. Backups and some of our service providers (see Section 6) are also located in the United States or operate globally. Because your data is processed in the United States, we apply appropriate safeguards to these transfers, such as Standard Contractual Clauses where required (Section 6.3 describes the safeguards that apply to our service providers). If you have specific data residency requirements, contact us before subscribing.

5. Data Retention

We retain personal data only as long as necessary for the purposes outlined in this policy:

Data TypeRetention Period
User AccountsUntil account deletion is requested
Session Tokens30 days (automatic expiration)
Tickets & TranscriptsRetained until the server deletes them or you request deletion. On a verified deletion request we remove the personal data we hold about you, including your ticket messages. Copies already posted into a Discord server (for example a transcript in a log channel) are controlled by that server and must be removed by the server owner or via Discord.
Audit LogsUp to 2 years (operational), 5 years (financial records, per Australian record-keeping requirements)
Analytics Data14 months (Google Analytics default)
Rate Limiting Data1-15 minutes (automatic expiration)
BackupsAfter removal from our live systems, deleted personal data may still persist in secure, access-restricted backups until they are overwritten in the normal rotation cycle (within 60 days), after which it is permanently removed. We do not restore-and-retain deleted data; outstanding deletions are re-applied after any restore.

You can delete your configuration data at any time from the dashboard. If you remove the bot from your server without deleting it first, your configuration is retained (marked inactive) so you can re-add the bot later without reconfiguring. Deleting your account or configuration from the dashboard does not remove ticket messages or transcripts held for the servers you used; to erase those, contact us (see Section 7).

Exception: We may retain certain data longer when required by law (e.g., tax records, legal disputes, security investigations).

6. Third-Party Data Sharing

6.1 We Do NOT Sell Your Data

Important: We do NOT sell, trade, or rent your personal information to third parties for marketing purposes. We never have, and we never will.

6.2 Service Providers (Data Processors)

We share data with third-party service providers who assist in operating our service. These providers process data only on our instructions and under contractual obligations:

Service ProviderPurposeData Shared
Discord Inc.Bot platform & authenticationUser IDs, messages, guild data
Stripe Inc.Payment processingEmail, customer ID, subscription info
Google LLCWebsite analytics (opt-in in the EEA, UK, and Switzerland; on by default elsewhere with opt-out, see Section 8)Anonymized IP, page views, browser info
Cloudflare Inc.CDN & DDoS protectionIP addresses, request headers
Cloudflare Inc. (when AI features are enabled)AI ticket assistance (summaries, suggested replies, automation)Ticket message content and prompts for the relevant ticket
Functional Software, Inc. (Sentry)Error monitoringIP address, user agent, and error context when an error occurs; session replay is captured only on errors, with text content masked
Resend, Inc.Transactional email (data exports, notifications)Email address and the contents of the message we send you
Twilio Inc. (optional)SMS notificationsPhone numbers (if configured)

AI features: AI ticket assistance is optional and only runs when a server or organization enables it. When it does, the relevant ticket content and prompts are sent to our AI processor (Cloudflare) to generate the response, and are not used to train their models. If you configure your own AI provider (bring-your-own-key), that content is sent instead to the provider you choose and is handled under that provider's terms, not ours.

6.3 International Data Transfers

Some service providers (Discord, Stripe, Google, Cloudflare, Sentry) are located in the United States. We ensure appropriate safeguards for international transfers:

  • EU-US Data Privacy Framework certification (Stripe, Google, Cloudflare)
  • Standard Contractual Clauses (SCCs) where applicable
  • Reliance on our providers' own data protection commitments and regional processing controls

6.4 Other Disclosures

We may share data:

  • When required by law or to respond to legal process
  • To protect our rights, privacy, safety, or property
  • To investigate fraud, security incidents, or violations of our Terms
  • In connection with a merger, acquisition, or sale of assets (with notice)

7. Your Privacy Rights

7.1 Rights Under GDPR (EU/UK Users)

If you are located in the European Union or United Kingdom, you have the following rights:

  • Right of Access (Article 15): Request a copy of your personal data
  • Right to Rectification (Article 16): Correct inaccurate data
  • Right to Erasure (Article 17): Request deletion of your data ("right to be forgotten"). On a verified request we delete the personal data we hold about you. We may retain a minimal record only where the law requires it (for example tax or financial records).
  • Right to Data Portability (Article 20): Receive your data in a machine-readable format (JSON)
  • Right to Object (Article 21): Object to processing based on legitimate interest (e.g., opt-out of analytics)
  • Right to Restrict Processing (Article 18): Temporarily limit how we use your data
  • Right to Withdraw Consent: Withdraw consent for analytics or marketing at any time

7.2 Rights Under CCPA (California Users)

If you are a California resident, you have the following rights:

  • Right to Know: Request disclosure of personal information collected, used, and shared
  • Right to Delete: Request deletion of your personal information
  • Right to Opt-Out of Sale: We do NOT sell personal information (no opt-out needed)
  • Right to Non-Discrimination: We will not discriminate against you for exercising your rights
  • Right to Correct: Request correction of inaccurate data (CPRA)

7.3 Rights Under the Australian Privacy Act (Australian Users)

If you are in Australia, the Australian Privacy Principles (APPs) give you the right to:

  • Access (APP 12): Request access to the personal information we hold about you
  • Correction (APP 13): Ask us to correct information that is inaccurate, out of date, or incomplete
  • Complain: Raise a concern about how we handle your personal information

We apply the same request process and identity verification to all users worldwide (see Section 7.4). If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner (OAIC), described in Section 12.

7.4 How to Exercise Your Rights

To exercise any of these rights, please contact us using one of the following methods:

  1. 1.Email: Send a request to ppa.loot-tekcit@ycavirp (recommended for data export and deletion requests)
  2. 2.Discord: Contact us in our support server (for general privacy inquiries)

We respond to requests within 30 days (GDPR/CCPA requirement). Deleting your Ticket Tool account from the dashboard removes only your account and dashboard data. To also erase your ticket messages, attachments and transcripts from the servers you used, email us an erasure request; once your identity is verified we action it within 7 days. Deleting your Discord account does not start this on its own, since we are not notified when a Discord account is deleted.

For data export requests, we provide your data in machine-readable JSON via secure download link or email attachment.

Verification: To protect your privacy, we may need to verify your identity before processing your request. We may ask you to re-authenticate via Discord or provide additional verification to confirm account ownership.

8. Cookies and Tracking

8.1 Types of Cookies

We use the following types of cookies:

Essential Cookies (Always Active)

  • Session Cookies: Authenticate you and keep you logged in (httpOnly, secure, 30-day expiration)
  • CSRF Tokens: Protect against cross-site request forgery attacks
  • user_consent_preferences: Stores your cookie consent choice (1 year)
  • Cloudflare Turnstile: Bot protection on forms and interactive tools; Cloudflare may set cookies to distinguish humans from bots

These cookies are necessary for the website to function and cannot be disabled.

Preference and Attribution Cookies

  • theme: Remembers your light or dark theme choice (1 year, shared across ticket-tool.app subdomains)
  • tt_currency: Remembers your display currency for pricing (1 year, shared across ticket-tool.app subdomains)
  • tt_ref: Set only when you arrive via an affiliate link; records the referring affiliate so they can be credited if you subscribe (60 days, shared across ticket-tool.app subdomains)

Analytics Cookies

  • Google Analytics: Track page views, user interactions, and website performance

In the EEA, United Kingdom, and Switzerland these cookies are set only if you accept them in the cookie banner. Elsewhere they are enabled by default, and you can disable them at any time via the cookie banner or the Cookie preferences link in the site footer.

8.2 Managing Cookies

You can control cookies through:

  • Cookie Banner: Choose which cookies to accept when you first visit our site
  • Cookie Preferences Link: Reopen the cookie banner at any time via the Cookie preferences link in the site footer
  • Browser Settings: Most browsers allow you to block or delete cookies (note: blocking essential cookies will prevent login)

9. Data Breach Notification

In the unlikely event of a data breach that affects your personal information:

  • We will notify the appropriate supervisory authority within 72 hours of discovering the breach (GDPR requirement)
  • If the breach poses a high risk to your rights and freedoms, we will notify you directly via email or Discord
  • We will provide clear information about the nature of the breach, likely consequences, and measures taken to address it
  • We maintain a breach register documenting all security incidents for regulatory compliance
  • For eligible data breaches under Australia's Notifiable Data Breaches (NDB) scheme, we notify the Office of the Australian Information Commissioner (OAIC) and affected individuals as soon as practicable

Report a security vulnerability: Email ppa.loot-tekcit@ytiruces - Do not report publicly.

10. Children's Privacy (COPPA Compliance)

Ticket Tool is not intended for users under the age of 13 (or the minimum age required by Discord in your jurisdiction). We do not knowingly collect personal information from children under 13.

Discord's Age Requirement: Discord requires all users to be at least 13 years old (or older in some jurisdictions). By using our service through Discord, you confirm you meet Discord's age requirements.

If we become aware that we have collected personal data from a child under 13 without parental consent, we will take steps to delete that information as soon as possible.

11. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or service features.

How we notify you:

  • Update the "Last updated" date at the top of this page
  • For material changes: Send email notification to registered users (at least 30 days before changes take effect)
  • Post announcements in our Discord support server

We encourage you to review this Privacy Policy periodically. Your continued use of Ticket Tool after changes are posted constitutes acceptance of the updated policy.

12. Supervisory Authority

If you are located in Australia, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au if you believe we have mishandled your personal information.

If you are located in the European Union or United Kingdom, you have the right to lodge a complaint with your local data protection supervisory authority if you believe we have violated your data protection rights.

EU Supervisory Authorities: Find your supervisory authority