Tickbook privacy policy
Last updated: 1 October 2026
Details coming soon
Tickbook lets shops on Shopify run customer charge accounts: customers buy now and pay later, at the shop's till (Shopify POS) and online. This policy explains what data the app handles, why, who it's shared with and how long it's kept.
For the shop's customers, the shop is the data controller and we are its processor. We use customers' data only to provide the app to the shop.
What we collect and why
About the shop (from Shopify, when the app is installed): the shop's myshopify.com address, name, email address, currency, time zone and Shopify plan; and the Shopify user who uses the app (id, name and email), so each change in the app's audit log says who made it.
About the shop's customers who have an account:
- from Shopify: the customer's Shopify id, and their name and email, read when needed (for example to email a statement or receipt);
- from the shop's orders and payments: account sales, payments, refunds and adjustments, with date, amount and reference (such as a purchase order number), and which till or staff member recorded each;
- entered by the shop: the account's credit limit, status and notes, and an old account number if accounts were imported.
Only if the shop turns these features on: authorised buyers (which buyer made each purchase and the shop's name for them); text messages (the customer's mobile number and a record of their agreement or opt-out); manager approval at the till (which manager approved which sale, when); importing accounts (names, emails, phone numbers and balances in the file, kept only while the import is under way; unfinished uploads are deleted after 14 days).
Statements: when the app issues a statement it keeps a copy (HTML and PDF, including the customer's name and account activity) so the shop can show exactly what was sent.
We never collect card or bank details. Online payments go through the shop's own Shopify checkout; Shopify handles card details.
Who we share it with
- Shopify, where the app runs and the data comes from.
- Railway (railway.com), our hosting provider, which runs the app in its EU West region, and Neon (neon.tech), which hosts the app's database in London (AWS eu-west-2).
- Cloudflare (cloudflare.com), which stores the app's nightly backups of the database in the EU (R2), each kept for 30 days. Each backup is encrypted before it leaves our servers, and Cloudflare can't read it.
- Resend (resend.com), which delivers the app's emails (receipts, statements, reminders). It receives the recipient's email address and the email's contents.
- Twilio (twilio.com), only if the shop uses text messages. It receives the customer's mobile number and the text.
- Xero or Intuit QuickBooks, only if the shop connects its accounting system. The shop's own books receive account sales and payments, and each customer's name and email to match a contact. We keep only an encrypted connection to it and a log of what was sent (ids and amounts, no names or emails).
We don't sell data, use it for advertising, or share it with anyone else unless the law requires it.
How long we keep it
- While the app is installed: the account records are kept while the shop uses Tickbook. Amounts and dates can't be edited; a missing reference (such as a PO number) can be added once, and that's logged, so the shop has a reliable record.
- Email and text logs record what was sent and when, not the address or message.
- Server logs are kept by our host for 30 days (Railway Pro) and don't contain customers' names, emails or phone numbers.
- When a customer asks the shop to delete their data (a Shopify customers/redact request), we remove their name, contact details, references and notes, anonymise their account and delete any text-message agreement. The amounts stay on the shop's books without saying whose they were. We keep a one-way code of the customer's id so late-arriving work (for example from an offline till) doesn't store it again; the id can't be recovered from it.
- When a shop uninstalls: its data is kept for 48 hours in case it reinstalls, then deleted when Shopify asks (shop/redact). We keep only the shop's myshopify.com address and the date its free trial started, so a trial is given once per shop.
- Data sent to the shop's own Xero or QuickBooks stays in the shop's books; the shop deletes it there if needed.
Customers' rights
Customers should contact the shop they buy from, which controls their data. When the shop receives a request through Shopify, Shopify passes it to us; we prepare data requests for the shop to download in the app and complete requests within 30 days.
Security
Data is encrypted in transit (HTTPS) and at rest. Accounting connections are also encrypted by the app. The app uses a database role that can't change the database structure or the protections that stop account records being edited.
Details coming soon
Contact
Details coming soon