TICKEY

TICKEY · Legal

Privacy Policy

Effective and last updated: August 10, 2026

This Policy explains how we collect, use, store, share, and protect personal data when you use the TICKEY app, TICKEY devices, and related cloud services, and how you can exercise your rights. Please read it before creating an account or using the relevant features.

Service provider

ENIAC TECHNOLOGY LIMITED

Provides and operates the international edition of the TICKEY app, TICKEY devices, and related services.

Data we process

Account and verification data: email address or phone number, verification codes, a secure hash of your password, account region, login sessions, and masked account identifiers. We do not store your password in plain text.

Content you create or submit: photos, pixel animations, templates, drafts, albums, text, QR codes, NFC content, sharing records, and related filenames, ordering, and display settings. Guest-mode drafts generally remain on your device and are sent to our servers only when you choose to upload, share, sync, or configure cloud content.

Device and connection data: TICKEY identifiers, model, firmware version, connection status, battery level, Bluetooth or NFC results, network configuration status, device name, and your selected device icon.

Feature and connected-service data: when you enable weather, location, Google Calendar, Google Tasks, Apple Calendar, Apple Reminders, Microsoft To Do, Todoist, or similar features, we process the location, authorization tokens, calendar events, tasks, or settings needed to provide them. We do not receive your third-party password.

Operational and security data: app version, language, time zone, errors and diagnostics, request time, IP address, and necessary security logs. For app-store purchases, we may receive order, product, and purchase status data, but not your full card details.

Sources of data

Data may come directly from you, from a connected TICKEY device, from your operating system or a third-party service with your permission, or be generated automatically to operate and secure the service. We process only what is reasonably necessary for the identified feature.

Purposes and legal bases

We use data to create and secure accounts, deliver verification codes, maintain sessions, connect and manage devices, edit and upload content, sync albums and templates, run automations or integrations you select, process purchases, provide support, troubleshoot, prevent fraud and abuse, and comply with law.

Depending on location, we rely on performance of our contract, your consent, compliance with legal obligations, and legitimate interests such as service and network security where those interests do not override your rights. You may withdraw consent at any time; this does not affect processing that was lawful before withdrawal.

Device permissions and local processing

Camera and photo permissions support image selection, capture, and cropping; Bluetooth, nearby-device, or location permissions support device discovery and connection; NFC supports reading or writing content you select; network access supports accounts, cloud content, and connected services.

Permissions are requested in context and can be revoked in system settings, although the related feature may stop working. During device setup, Wi-Fi credentials are sent at your direction to the selected device. Unless the interface clearly says otherwise, we do not store the Wi-Fi password in your account cloud service.

Google user data

When you connect Google Calendar, we request read-only access to your calendar-list names and identifiers and, for calendars you select, event identifiers, titles, start and end times, all-day status, time zones, calendar names, update times, and cancellation status. When you connect Google Tasks, we request read-only access to task-list names and identifiers and task identifiers, titles, due dates, completion status, and update times.

We use this data only to synchronize and display your schedule and tasks on your own TICKEY device. TICKEY does not create, edit, complete, share, or delete Google calendars, events, task lists, or tasks.

Our servers request privacy-minimized fields from Google APIs. We store encrypted OAuth credentials and the minimum normalized snapshots needed for device display. We do not retain event descriptions, attendees, meeting links, locations, or Google task notes.

We do not sell Google user data or use it for advertising, credit decisions, or generalized artificial-intelligence model training. Personnel may access Google user data only when you affirmatively request support, when needed for security or legal compliance, or in aggregated form that cannot identify you.

TICKEY's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Sharing, processors, and disclosures

We may provide the minimum necessary data to vendors supporting hosting, cloud storage, email or SMS verification, app-store payments, error diagnostics, and customer support. We require appropriate contractual and security protections.

If you enable Google Calendar, Google Tasks, Apple Calendar, Apple Reminders, Microsoft To Do, Todoist, or another connected service, we exchange the minimum necessary data with that provider at your direction to perform the integration you requested. The provider’s own privacy policy also applies to its processing. We do not sell personal data or share it for cross-context behavioral advertising.

We may disclose data as required by law, to respond to a competent authority, to protect users or the public, or as part of a merger, reorganization, or asset transfer, with notice where legally required.

International transfers

Connected-service providers and hosting infrastructure may process data in countries other than the one where you live, depending on the provider and service region you choose. Where required, we use contractual, technical, and organizational safeguards and provide any notice, consent, or transfer mechanism required by applicable law.

Retention

We retain data only as long as necessary: verification codes normally for no more than 10 minutes; refresh sessions normally for no more than 30 days; account and cloud content while the account remains active, until you delete it or close the account; and security or transaction records for the period needed to resolve disputes, prevent abuse, and meet legal obligations.

Connected-service OAuth credentials, bindings, synchronization cursors, and privacy-minimized snapshots are retained while that connection is active. Disconnecting a provider removes those credentials and active synchronized data and requests token revocation from the provider, subject to short operational processing time.

When retention ends, we delete or anonymize data. If immediate deletion from backups or legally restricted systems is not possible, we isolate the data and limit further processing.

Security

We use reasonable safeguards including encryption in transit, access controls, token and password hashing, encrypted storage of connected-service tokens, least privilege, logging, and backups. No internet service is completely secure. We will notify affected users and regulators of a breach when required by law.

Your rights and choices

Depending on applicable law, you may request access, a copy, correction, completion, deletion, or portability of your data; withdraw consent; restrict or object to processing; close your account; and request information about automated decisions or this Policy. You may also complain to your local data protection authority.

You can manage local content, permissions, and some account details in the app. You can disconnect a connected service from its data-source settings. If an in-app control is unavailable, contact hello@eniacelec.com. We may verify your identity before acting on a request and will not discriminate against you for exercising a privacy right.

Children

The service is not directed to children below the applicable age of digital consent in their location, unless a parent or guardian provides valid consent and supervision. If you believe a child submitted data without appropriate consent, contact us.

Third-party services and links

Third-party sign-in, calendar, task, payment, app-store, website, and device services are independently operated. Please review their privacy notices and permissions. We cannot make commitments for processing that a third party independently controls.

Changes and contact

We may update this Policy as features, technology, or law change. We will provide an in-app or other prominent notice of material changes and obtain renewed consent where required. The date above identifies the current version.

For privacy questions, rights requests, or complaints, email hello@eniacelec.com. ENIAC TECHNOLOGY LIMITED will handle the request within the period required by law.

Contact

Questions about this document or your rights?

hello@eniacelec.com