Privacy Policy

Last updated: February 16, 2026

This Privacy Policy describes how Ticksupply ("we," "us," or "our") collects, uses, shares, and protects your personal information when you use our website, dashboard, API, and related services (collectively, the "Service").

We process personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

For privacy inquiries, contact us at legal@ticksupply.com.

1. Information We Collect

Account Data

When you create an account, we collect your username, first name, last name, and email address. Authentication credentials are managed securely by our authentication provider — we never see or store these.

Billing Data

We store billing identifiers to link your account to payments. All sensitive payment information — card numbers, billing addresses, and payment methods — is stored and processed by Stripe. We never see or store your payment credentials.

Usage Data

We collect daily aggregated usage metrics per account: stream-hours (concurrent streams) and export volume. These are used for billing calculations.

We track product analytics events, including feature usage and errors, through our analytics provider (PostHog, EU-hosted).

Technical Data

Through our analytics and hosting providers, we also collect IP addresses, browser and device information, referrer URLs, and page view data. Vercel (our hosting provider) processes IP addresses and browser information as part of serving the Service.

Communication Data

If you delete your account, we collect optional feedback (a selected reason and free-text details). Customer support is handled via email, and correspondence is retained in our email systems.

Cookies and Tracking

We use cookies for authentication and analytics. For full details, see our Cookie Policy.

2. Sources of Data

  • Directly from you: Account registration, subscription configuration, export requests, API key creation, and deletion feedback.
  • Automatically: Analytics (page views, clicks, browser and device info), performance measurement (Web Vitals), and usage metering (stream-hours, export volume).
  • From third parties: User identity from our authentication provider.

Providing your account data (name, email) is required to use the Service. Without it, we cannot create or maintain your account.

3. How We Use Your Information

Contract Performance

  • Providing the Service: Managing your account, processing subscriptions, running data collection, generating exports, and authenticating you.
  • Billing and payments: Calculating usage, processing payments, metering overage, and managing subscription lifecycle.
  • Customer support: Responding to your inquiries.

Legitimate Interests

  • Security and fraud prevention: Protecting the security and integrity of the Service and your account.
  • Service improvement: Using analytics to understand how users interact with the Service, identify issues, and improve the product.
  • User feedback analysis: Analysing account deletion feedback to understand why users leave.

These interests have minimal privacy impact: we collect only what is necessary, use EU-hosted analytics, and do not profile users.

Legal Obligation

  • Tax records: Retaining billing records for 7 years as required by UK tax law.
  • Legal requests: Processing data to comply with valid legal obligations or lawful requests from authorities.

Consent

  • Marketing: We do not currently send marketing emails. If we do in future, we will obtain your explicit opt-in consent first. You can withdraw consent at any time.
  • Non-essential cookies: Consent for analytics cookies is managed per our Cookie Policy.

4. Who We Share Data With

Data Processors

We share personal data with the following service providers who process data on our behalf:

  • Clerk — Authentication and account management. US-based.
  • Stripe — Payment processing and billing. US-based.
  • PostHog — Product analytics. EU-hosted.
  • Supabase — Database hosting. UK region (London).
  • Vercel — Frontend hosting and performance analytics. US-based.
  • AWS — Cloud infrastructure. Primary region UK (London).

Other Disclosures

  • Law enforcement: We may disclose personal data in response to valid legal process (court orders, subpoenas, regulatory requests) or where required by law. We will attempt to notify you unless legally prohibited.
  • Business transfers: In the event of a merger, acquisition, or sale of assets, personal data may be transferred. You will be notified and given the opportunity to delete your account.

What We Do Not Do

  • We do not sell, rent, or trade your personal data to third parties.
  • We do not share personal data with advertisers.

5. International Transfers

Our primary database is hosted in the United Kingdom (London). Analytics data is processed in the EU.

Clerk, Stripe, and Vercel are US-based and may process personal data in the United States. Transfers to US-based processors are protected by Standard Contractual Clauses (SCCs) with the UK International Data Transfer Agreement (IDTA) addendum, as provided in each processor's data processing agreement.

Market data collectors may run in other regions for latency purposes, but they handle only market data — not personal data.

You can request a copy of the applicable safeguards by contacting legal@ticksupply.com or by viewing each processor's publicly available DPA.

6. Data Retention

  • Account data (name, username, settings): Retained while your account is active. Deleted when you delete your account.
  • Billing records (subscription history, usage aggregates): Retained for 7 years after the relevant transaction, as required by UK tax law.
  • Analytics data: Retained per our analytics provider's data retention settings.
  • Deletion feedback: Retained for analytics purposes.

After Account Deletion

When you delete your account:

  1. Account data is deleted.
  2. Your authentication account is deleted.
  3. Billing records are retained for 7 years (legal obligation).
  4. Deletion feedback is retained for analytics.
  5. Analytics and payment processor data are retained per their respective policies.

7. Your Rights

Under the UK GDPR, you have the following rights:

  • Access — Request a copy of the personal data we hold about you.
  • Rectification — Update your name and username via your account settings. For other corrections, contact us.
  • Erasure — Delete your account via the dashboard. Billing records are retained for 7 years per legal obligation.
  • Restrict processing — Request that we restrict processing while we review your request.
  • Data portability — Request your data in a structured, machine-readable format.
  • Object — Object to processing based on legitimate interests. We will stop unless we have compelling grounds.
  • Withdraw consent — Withdraw consent for marketing or non-essential cookies at any time without affecting prior processing.

How to Exercise Your Rights

Contact legal@ticksupply.com with your request. We will respond within 30 days. We may ask you to verify your identity before processing your request.

Complaints

You have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk if you are not satisfied with how we handle your data.

8. Children

The Service is restricted to users aged 18 and over, as stated in our Terms of Service. We do not knowingly collect personal data from anyone under 18. If we discover that we have collected data from a person under 18, we will delete it promptly.

9. Automated Decision-Making

We do not use automated decision-making or profiling that produces legal or similarly significant effects. Billing calculations (usage metering, overage computation) are automated but are mechanical computations based on objective metrics, not profiling.

10. Market Data

Market data (prices, trades, order book depth) is factual financial data and is not personal data. This Privacy Policy covers only personal data related to your account and service usage, not the market data you collect or export through the Service.

Your subscription configurations (which data feeds you subscribe to) are linked to your account and are therefore personal data.

11. Security

We implement the following measures to protect your data:

  • API key secrets are stored as one-way cryptographic hashes — we cannot recover your original key.
  • Credentials are encrypted at rest.
  • Database connections use TLS encryption.
  • Export artifacts are encrypted at rest.
  • Rate limiting protects against abuse.
  • Account-level isolation ensures you can only access your own data.

12. Changes to This Policy

We will notify you of material changes via email and/or a prominent notice on the dashboard. Material changes take effect 30 days after notification. Non-material changes (formatting, clarifications) are effective upon posting. Continued use of the Service after the effective date constitutes acceptance.

13. Contact

If you have questions about this Privacy Policy or our data practices: