Legal

Privacy policy

What ReTicketDesk collects, why it is needed, which providers help run the service, and how to request access, export, correction, or deletion.

Last updated July 9, 2026

Who is responsible for the data

ReTicketDesk is the service operator and data controller for website, account, product-administration, and support-contact data. The operational contact is hello at reticketdesk dot com. Customers control the support conversations they place in a workspace; for that content, the customer is the controller and ReTicketDesk acts as processor under the public data processing addendum.

Data we process

  • Account details such as name, email address, avatar, sign-in method, and membership.
  • Workspace content such as inboxes, contacts, tickets, messages, internal notes, drafts, tags, saved replies, assignments, and audit events.
  • Resend connection details, including receiving addresses, provider identifiers, encrypted API credentials, and webhook configuration.
  • Subscription status, plan, billing interval, and Paddle customer or transaction identifiers. ReTicketDesk does not receive full card numbers.
  • Product and website telemetry such as page paths, button events, browser information, referrer domain, and Core Web Vitals. Query strings, visible text, session recordings, and customer message content are excluded from website analytics.
  • Messages you send to product support, including the address and context needed to answer the request.

Why we use it

We process account and workspace data to provide the service, secure workspaces, route email, send replies, maintain subscriptions, prevent abuse, and answer support requests. Contract performance is the primary basis for providing the product. Security, reliability, and limited product analytics are based on legitimate interests where permitted. Legal records are retained when required by law.

ReTicketDesk does not sell personal data and does not use customer conversations to train machine-learning models. Marketing analytics respects browser Do Not Track, masks page text and element attributes, strips URL queries and fragments, and does not record sessions.

Service providers and transfers

The API, database, and secret storage are deployed in Microsoft Azure North Europe. Cloudflare, Resend, Google, Paddle, and PostHog support delivery, authentication, billing, and masked site analytics. Some provider operations may occur outside the European Economic Area under the provider's contractual safeguards. The current provider list and each provider's role are published on the security page.

Retention and deletion

Account and workspace data are kept while the workspace is active and for the limited period needed to close the account, resolve billing or security issues, and satisfy legal duties. A verified workspace owner can request export or deletion. Deleted data may remain temporarily in restricted provider backups until those backups rotate, but it is not restored for ordinary product use.

Payment and tax records are retained by Paddle under its buyer terms and legal duties. Security logs are retained only for operational and investigation needs.

Your choices and rights

Depending on your location, you may request access, correction, export, restriction, objection, or deletion. Workspace-content requests should normally be made through the customer organization that controls the workspace. We may verify identity and workspace authority before acting on a request.

You may also complain to the data-protection authority in your country. Browser Do Not Track disables ReTicketDesk website analytics where the browser supplies that signal.

Policy changes

Material changes are published here with a new date. Changes that materially reduce customer rights or alter workspace-content processing will also be communicated through an appropriate product or account channel.

Questions about these terms can be sent through the contact page. Do not email passwords, API keys, payment-card details, or customer message exports.