Privacy Policy
Last updated: May 4, 2026
Who we are
Ticketize.it (“we”, “us”) is an issue-tracker synchronization service. You can reach us at [email protected] for any privacy-related question or request.
What we collect and why
- Account data. Your email address and a bcrypt-hashed password. Used to authenticate you and to send transactional email (password reset, email verification).
- Atlassian OAuth credentials. Access and refresh tokens issued by Atlassian when you connect a Jira Cloud site, along with the cloud ID and site URL. We use them solely to read and write issues in the projects you configure for synchronization. Tokens are encrypted at rest with AES-256-GCM envelope encryption.
- Synchronized Jira issue content. For issues inside the projects you configure, we mirror summary, description, status, type, priority, labels, assignee email, reporter email, and timestamps. Raw Jira API responses are retained for up to 30 days for operational reliability, then deleted automatically.
- Billing data. If you upgrade to a paid plan, we store a Stripe customer ID. Card details are processed by Stripe and never reach our servers.
- Operational logs. Request and response metadata, sync attempts, and errors. Retained for up to 90 days.
What we don't do
We don’t sell your data, share it with advertisers, or use it to train AI models. We don’t collect data from Jira projects you haven’t explicitly configured for synchronization.
Sub-processors
- Stripe — payment processing.
- Amazon SES — transactional email delivery.
- Atlassian — origin of the data we synchronize on your behalf.
Data location
Application data is stored in our European data centre. Encrypted backups are held in object storage in the same region.
Your rights
You can access, export, correct, or delete your account and all associated data at any time. Email [email protected] or use the in-app delete-account flow. Deletion removes your account, the tenants you own, integrations, OAuth tokens, and all synchronized issue mirrors within 30 days.
Disconnecting Jira
Removing an integration in the Ticketize.it UI revokes our copy of your Atlassian OAuth tokens and stops further synchronization. You can additionally revoke the OAuth grant from your Atlassian account settings at any time.
Security
Atlassian tokens are encrypted at rest with AES-256-GCM envelope encryption (per-environment key-encryption-key, per-integration data-encryption-key). Customer data is isolated at the database row level using PostgreSQL Row-Level Security policies tied to your tenant identifier. We use HTTPS exclusively, store passwords using bcrypt, and apply security updates on a regular cadence.
Changes to this policy
We may update this policy as the service evolves. Material changes will be announced by email at least 14 days in advance, and the “last updated” date above will reflect the most recent revision.
Contact
Questions about this policy or your data: [email protected].