Privacy Policy
Last updated: 31 August 2026
Who we are
TicketCrew is a support-ticket system for Discord servers. The operator of this instance is the data controller. [Operator: insert your legal entity, address and contact email.]
What we store
When you sign in to the dashboard
- Your Discord user id, username and avatar hash.
- Your Discord OAuth access and refresh tokens, encrypted at rest with AES-256-GCM.
- A cached list of the servers you are in, kept for 60 seconds to avoid rate-limiting Discord.
We request only the identify and guilds OAuth scopes. We do not receive your email address, your messages outside tickets, or the ability to act as you.
When a ticket is opened in a server
- The Discord user id and display name of whoever opened it.
- Message IDs, author IDs and timestamps for counters and response-time analytics. New message bodies and attachment contents are not archived by the website.
- Answers submitted in the pre-ticket form.
- Ticket metadata: category, priority, tags, timings, staff assignment, close reason.
- Satisfaction ratings and comments, if the server has ratings enabled.
- Staff-only internal notes, which the ticket opener never sees.
What we never store
- Messages from channels that are not tickets.
- Direct-message conversations. Optional rating requests are sent by DM.
- Payment card details. [Operator: update if you add a payment processor.]
- Attachment file contents. Transcript files link to Discord attachments instead of copying them.
Why we store it
To provide the service: to show a ticket to the staff handling it, to build a transcript, to apply the routing and closing rules a server owner configured, and to produce the analytics that server owner asked for. The legal basis is the legitimate interest of the server operator in running support, and your consent in choosing to open a ticket.
AI processing
If a server enables the AI assistant, ticket content is sent to that server's configured provider (Anthropic or OpenAI) to produce a summary or a suggested reply. This is off by default and controlled entirely by the server owner. Generated replies are never sent to a member without a human reviewing them unless the server owner has explicitly turned that on.
How long we keep it
- Transcripts are generated in temporary memory only when a transcript channel is selected in the panel settings, then uploaded to that Discord channel. There is no website viewer or new transcript archive. Discord retains the uploaded file; the server controls access and deletion there. Legacy records from earlier releases are retained until a data-deletion request is fulfilled.
- Tickets and analytics are kept while TicketCrew is installed in the server.
- Your session expires after seven days. Signing out clears it immediately.
- Everything for a server is deleted when the server owner uses the delete function, immediately and irreversibly.
Who can see your data
Staff of the Discord server the ticket belongs to, according to the roles that server configured. Discord channel permissions control access to uploaded transcripts. Anyone who downloads a file can share that copy; only give the transcript channel to trusted staff.
Your rights
You can request access to, correction of, or deletion of your personal data. There is no self-service export or bulk delete in the dashboard: those requests go through us, so that one person cannot erase a whole server's history from a button. Contact us and we will action it. If you are a member rather than a server owner, you can also contact the server's staff. [Operator: insert your contact route.]
If you are in the EU or UK you also have the right to lodge a complaint with your local data protection authority.
Security
- OAuth tokens, integration credentials and webhook secrets are encrypted at rest.
- API keys are stored only as SHA-256 hashes and shown once.
- Sessions are signed, httpOnly cookies; mutating requests carry a CSRF token.
- Every permission check runs on the server against live Discord state.
Changes
We will update the date at the top when this changes. Material changes will be announced in the dashboard.
See also our Terms of Service and data handling summary.