Legal

Privacy Policy

Draft — not in effect This document has no version in force and no effective date. It has not been reviewed by a qualified professional and must not be relied on.

Effective date: [TO BE SET AT PUBLICATION] Version: 0.2.0

This Privacy Policy explains how Black Tide Studio, an Arizona sole proprietorship operating TicketQuill (“TicketQuill,” “we,” “us,” or “our”), processes personal information through the TicketQuill Discord application, dashboard, website, and related support.

TicketQuill is not affiliated with, sponsored by, endorsed by, or operated by Discord Inc. Discord independently processes information under its own policies and terms.

1. The short version

Three commitments define the TicketQuill data boundary:

  1. Ticket conversations and attachment bytes stay in Discord. We do not intentionally copy normal ticket transcripts or attachment files into TicketQuill storage.
  2. We do not sell personal information. We do not sell, rent, broker, or provide personal information to data brokers or advertisers for their own purposes.
  3. We do not train AI models on private customer content. Any future AI dataset will be limited to synthetic data, data we own, or data covered by a separate explicit opt-in and legal/product review.

2. Who controls the data

TicketQuill has more than one privacy role depending on the processing activity.

Data you control

When a Discord server administrator configures TicketQuill to collect ticket information from server members, the administrator or organization generally determines what information is requested, why it is collected, who can access it, and how long it should be retained. To the extent applicable law recognizes that relationship, TicketQuill acts as a processor/service provider for that information and processes it on the customer’s documented instructions.

Data TicketQuill controls

TicketQuill independently determines purposes for certain operational information, including account and entitlement administration, security and fraud prevention, support correspondence, acceptance records, legal records, and product analytics. For those activities, TicketQuill may act as a controller/business.

If a person asks us about information controlled by a Discord server administrator, we may direct the request to that administrator or assist the administrator as required by applicable law and any applicable DPA.

3. What we process

Discord identity and authority

Depending on the features used, we may process:

We do not require a Discord email address merely to identify a Discord user.

Configuration

We process configuration needed to operate TicketQuill, including panels, buttons, forms, appearance, routing, staff settings, assets, plan configuration, and related identifiers.

Ticket operational data

We may process ticket identifiers, channel/message references, timestamps, status, routing information, and form answers submitted through TicketQuill.

Ticket content boundary

TicketQuill does not intentionally store the full contents of ticket conversations or attachment bytes in its own normal storage layer. Discord remains the system where the ticket conversation and attachments are ordinarily stored.

However, operational systems may temporarily receive limited technical information needed to execute a Discord event or command. We design the system to minimize such retention and do not use ticket content for advertising or AI training.

Security and sessions

We may process hashed or opaque session identifiers, user-agent information, security events, request metadata, and an IP-derived value where reasonably necessary for security or abuse prevention. We do not retain raw IP addresses for behavioral analytics.

Billing and entitlement references

We may receive or store Discord subscription, entitlement, event, reconciliation, and related transaction identifiers needed to determine whether a server has paid access.

We do not receive or store payment-card numbers, CVC/security codes, or raw payment-method credentials through TicketQuill’s normal Discord monetization flow. Payment details are handled by Discord or the applicable payment/mobile platform under its own terms.

Support and legal records

If you contact us, we process the information you provide and information reasonably necessary to handle the request. We may also maintain records of Terms acceptance, privacy requests, security incidents, legal notices, and other compliance activities.

4. Sensitive information

TicketQuill is not designed to collect highly sensitive personal information through ticket forms.

Customers must not configure TicketQuill to intentionally request or collect, unless we expressly authorize it in writing and the use is legally reviewed:

If we become aware that such information has been submitted to TicketQuill systems, we may delete or isolate it and contact the responsible customer where appropriate.

5. Why we process information

Depending on the data and applicable law, we process information to:

Where the GDPR or UK GDPR applies to processing for which TicketQuill is a controller, our legal bases may include performance of a contract, legitimate interests, compliance with a legal obligation, and consent where consent is actually required or used. The applicable legal basis depends on the specific processing activity.

6. Analytics, cookies, and marketing

We aim to use first-party, privacy-preserving analytics. Depending on the production stack, analytics may include visits and referrers, conversion events, selected plan, aggregate feature usage, churn, coarse country-level information, performance/error signals, campaign attribution, and surveys.

We do not intentionally combine analytics with ticket answers or private ticket content, and we do not use analytics to create cross-site advertising profiles.

Cookies and similar technologies. Essential technologies may be used where necessary for authentication, security, or requested functionality. Non-essential analytics or marketing technologies will be disabled until any consent required by applicable law is obtained.

We do not use advertising pixels as part of the current production design.

Where applicable, we honor recognized Global Privacy Control signals for processing that legally falls within the scope of such signals.

Marketing communications are separate from operational messages and require an opt-in where applicable. Marketing messages include an unsubscribe mechanism. Security, billing, service, legal, and other operational messages may be sent when reasonably necessary to provide or protect the Service.

7. How we use service providers

We use service providers only where reasonably necessary and seek to limit the information each provider receives.

Current known providers:

Provider Purpose Location / role
Hetzner Online GmbH Application and database hosting Helsinki, Finland / hosting infrastructure
Porkbun LLC Domain registration and email forwarding United States / domain and mail infrastructure

Our database is self-hosted on our Hetzner infrastructure rather than a separate managed database service.

Discord is a separate platform provider and monetization/payment intermediary for purchases made through Discord. Discord is not treated as a TicketQuill subprocessor merely because TicketQuill operates on Discord; Discord independently determines its own processing under its own terms and policies.

We will update this list when a new provider materially processes personal information for TicketQuill. Where applicable, customers will receive notice and an opportunity to object under the DPA.

8. International transfers

TicketQuill is based in the United States and currently hosts its primary application/database infrastructure in Finland.

If personal information subject to EU/EEA or UK transfer restrictions is transferred to a country that does not have an applicable adequacy decision or other lawful transfer mechanism, we will use an appropriate safeguard required by applicable law, such as the applicable Standard Contractual Clauses or another lawful mechanism.

We do not describe a vendor’s generic “published safeguards” as a substitute for an actual transfer mechanism. The specific mechanism depends on the vendor, transfer, and applicable law.

If TicketQuill becomes subject to a requirement to appoint an EU or UK representative, we will make that representative’s details available as required by law.

9. Retention

We keep information only for as long as reasonably necessary for the purposes described here, subject to legal, security, accounting, dispute, and backup requirements.

Data Target retention
Active server configuration While the bot is installed and active
Configuration after removal Up to 30 days for recovery, then deletion/purge
Ticket operational metadata/form answers held by TicketQuill Only while needed for the configured workflow and applicable retention period; deletion requests are processed without unnecessary delay
Web sessions Up to 7 days where technically feasible
Security/access logs Up to 90 days unless needed longer for an active security or legal matter
Raw analytics Up to 13 months
Aggregated/deidentified analytics May be retained indefinitely where it no longer identifies individuals
Support correspondence Up to 2 years, unless a longer period is needed for an active dispute, legal obligation, or security matter
Billing, accounting, tax, consent, and required legal records Up to 7 years, or longer only where legally required or reasonably necessary for an active matter
Backups Up to 30 days on a rolling basis

Retention periods are targets, not guarantees that every copy is destroyed at the exact same moment. Deletion may occur asynchronously as systems, backups, and caches expire.

10. Your privacy rights

Depending on where you live and the role TicketQuill has for the relevant information, you may have rights including access, correction, deletion, portability, restriction, objection, and withdrawal of consent where consent is the legal basis.

Send requests to privacy@ticketquill.com.

We may need to verify identity and authority before fulfilling a request. Where the requested information is controlled by a Discord server administrator, we may refer the request to that administrator or assist them in responding.

We will respond within the period required by applicable law. We may extend or decline a request only where applicable law permits it, and we will explain the reason where required.

If you are in the EEA/UK and believe applicable data-protection law has been violated, you may have the right to complain to the supervisory authority in your country or jurisdiction.

11. Children and age-related use

TicketQuill is not directed to children and is not marketed as a child-focused service. We do not intentionally collect dates of birth for general account creation.

Customers must not use TicketQuill to knowingly collect children's personal information in violation of applicable law or configure TicketQuill to solicit unnecessary information from children.

U.S. COPPA may apply to general-audience online services if they have actual knowledge that they collect personal information from children under 13, and separate rules may apply to child-directed services. citeturn1search0turn1search8

The UK Children’s Code can apply to online services likely to be accessed by children even when children are not the intended audience. We therefore do not represent that a simple “adults only” statement by itself resolves UK children's-privacy obligations. If TicketQuill begins intentionally serving or materially targeting children or child-focused communities, we will conduct a separate compliance review before doing so. citeturn0search5turn0search7

12. Security

We use reasonable technical and organizational measures appropriate to the nature of the information we process, including access controls, credential protection, logging, backups, security monitoring, and incident-response procedures appropriate to the Service.

No online service can guarantee absolute security. If we discover a security incident affecting personal information, we will assess it and provide notices required by applicable law and our contractual commitments.

Security reports may be sent to security@ticketquill.com.

13. Data processing requests and DPA

For customers using TicketQuill as a processor/service provider, our Data Processing Addendum describes the processing relationship, confidentiality, security, subprocessors, assistance with data-subject requests, incident cooperation, deletion/return, audits, and international-transfer mechanisms where applicable.

The DPA is not a substitute for the customer’s own legal obligations as controller/business and does not make TicketQuill responsible for the customer’s collection choices or instructions.

14. Changes to this Privacy Policy

Each published version will identify a version number and effective date.

We may update this Policy to reflect changes in the Service, law, vendors, security practices, or data processing. For material changes, we will provide reasonable notice. Where consent is the legal basis for a materially changed processing activity, we will obtain new consent where required rather than treating continued use as consent.

15. Contact

Black Tide Studio Arizona, United States