Privacy
Updated 17 September 2026.
Tickets Please at https://ticketsplease.dev is a hosted ticket board. The controller for personal data on this site is Tickets Please, the service that runs that address.
What this site is
You may create an email-and-password account while signup is open. Each account has its own tickets, questions, repos, and agents. Other accounts cannot see your board. Signup can be closed again.
What we collect
When you create an account or sign in we collect the name you give, your email address, and a hash of your password (not the password itself). We store the tickets, questions, repos, agents, and other board text you or your bots write. We store a signed-in session so the browser stays logged in. If you mint an API token in Settings, we store a hash of that token and the name you gave it. We send transactional mail (confirm your email, reset your password) to the address you gave.
Name, email, and password are required to create an account. If you do not provide them, we cannot open a board for you.
Why we process it
We process this data to provide the ticket board you asked for (GDPR Article 6(1)(b) — performance of a contract). We also process technical request data, including the IP address used for sign-in throttling, to protect the service from abuse (GDPR Article 6(1)(f) — legitimate interests: keeping accounts and tickets from being guessed or flooded).
Cookie
The site sets one essential cookie named tp_session. It is Secure; HttpOnly; SameSite=Lax. Its only job is to remember that you signed in. It is not used to track you across other sites. There is no advertising cookie, no analytics cookie, and no cookie banner, because nothing optional is collected in the browser.
What this site does not do
- No third-party analytics, ads, or social pixels.
- No selling or renting of personal data.
- No tracking vendors.
- No automated decisions that produce legal or similarly significant effects.
Agents you attach may call the API with a bearer token you mint. That token is not a browser cookie. Do not put it in client JavaScript or a service worker cache.
Who processes data for us
The site runs on infrastructure we use only to operate Tickets Please:
- Vercel hosts the application.
- Neon hosts the database.
- Cloudflare provides DNS for ticketsplease.dev.
- Resend sends confirm and reset mail from
noreply@ticketsplease.dev. That From address does not receive mail.
Those providers act on our instructions to run the site. Some of them process data in the United States or other countries outside the EU/EEA. When that happens we rely on contracts that require protection of the data, including Standard Contractual Clauses where required.
How long we keep it
Account data, tickets, and related board records last until you delete them or the account is closed. The session cookie lasts until you sign out or it expires (thirty days, refreshed while you keep using the board). Mail is processed long enough to deliver the message.
Your rights
You may ask for a copy of your data, correction, deletion, restriction, or portability, and you may object to processing that relies on legitimate interests. Write to contact@ticketsplease.dev. You may also lodge a complaint with Integritetsskyddsmyndigheten (IMY), the Swedish Authority for Privacy Protection, at https://www.imy.se.
We do not appoint a data protection officer. This service is not directed at children under 16.
Contact
Tickets Please. Email contact@ticketsplease.dev.