HomeFeaturesHow It WorksUse CasesTestimonialsAbout UsContact
    Back to home

    Legal

    Privacy Policy

    This policy explains what personal information Tickflows collects, why we collect it, who we share it with, and the choices you have. It applies to the Tickflows website and to the Tickflows Project OS application.

    Last updated: August 19, 2026Applies to: the Tickflows website and app

    On this page

    • 1. Introduction
    • 2. Our role
    • 3. Information we collect
    • 4. How we use information
    • 5. Legal bases
    • 6. Cookies and storage
    • 7. How we share information
    • 8. AI-assisted features
    • 9. Attendance and location
    • 10. Data retention
    • 11. How we protect information
    • 12. Your rights and choices
    • 13. International transfers
    • 14. Children’s privacy
    • 15. Changes to this policy
    • 16. Contact us

    1. Introduction

    Tickflows (“Tickflows”, “we”, “us”, or “our”) is a project, ticketing, and team operations platform built and operated by Cheche Systems in Addis Ababa, Ethiopia. We provide the Tickflows Project OS to organisations and their members.

    We respect your privacy and are committed to handling personal information responsibly and transparently. This policy describes how we handle personal information when you visit our website, create an account, or use Tickflows as a member of an organisation.

    By using Tickflows you agree to the practices described here. If you do not agree with this policy, please do not use the service.

    2. Our role: controller and processor

    Tickflows is used by organisations. That means we handle personal information in two different capacities, and your rights differ slightly depending on which one applies.

    As a data controller

    We decide how information is handled when it relates to running the service itself — creating and securing accounts, verifying identity, support requests, and website visits. This policy governs that processing.

    As a data processor

    When your employer or organisation uses Tickflows, the content they put into their workspace — projects, tasks, tickets, chat messages, attendance records, HR files — belongs to that organisation. They decide what is collected, who can see it, and how long it is kept. We process it on their instructions.

    If you are a member of an organisation and want your workspace data corrected or deleted, contact your organisation’s administrator first. If you contact us directly, we will refer your request to them and support them in responding.

    3. Information we collect

    3.1 Account and profile information

    When you register or are invited to an organisation, we collect:

    • Your first and last name.
    • Your email address, used for sign-in, verification, invitations, and notifications.
    • Your mobile phone number, used for one-time verification codes and account recovery.
    • Your password, which is stored only as a salted cryptographic hash — never in plain text.
    • Your profile details, such as job title, avatar, and the preferences you choose to set.
    • Your organisation memberships, roles, teams, and permissions.

    3.2 Workspace content

    In the course of normal use, you and your colleagues create content that may contain personal information about you or others:

    • Projects, sprints, tasks, subtasks, checklists, and their assignments and due dates.
    • Tickets, ticket activity, comments, and status changes.
    • Chat rooms, direct messages, mentions, and read state.
    • Files and images you upload as attachments to tasks, tickets, projects, or chats.
    • Test cases, test runs, announcements, and calendar entries.

    3.3 HR, attendance, and leave information

    Organisations that enable the HR module process additional employment-related information about their members:

    • Check-in and check-out timestamps, hours worked, and overtime.
    • Work mode for each shift — office, field, or remote — and field location notes.
    • Geographic coordinates captured at check-in and check-out, and whether the point fell inside a geofence zone defined by your organisation.
    • Leave requests, leave types, balances, approvals, review notes, and any supporting documents you attach.
    • Attendance flags raised by the system and the reasons recorded for them.

    Section 9 explains location handling in more detail.

    3.4 Technical and usage information

    • Activity and audit logs recording actions taken in the workspace — the module, the action, its severity, a description, and the time.
    • Task and ticket activity history showing what changed and who changed it.
    • Presence and online status, so colleagues can see who is available.
    • Device and connection information such as browser type and IP address, processed by our servers and infrastructure providers to deliver and secure the service.
    • Web push subscription identifiers, if you allow browser notifications.

    3.5 Information you send us directly

    If you fill in the contact form on our website or email our team, we receive your name, email address, and the content of your message so that we can respond.

    We do not intentionally collect special categories of personal data (such as health, religious, or biometric information). Please do not upload such information to Tickflows unless your organisation has a lawful basis and has instructed you to.

    4. How we use information

    We use personal information to:

    • Create your account, verify your email address and phone number, and sign you in securely.
    • Provide the core service — projects, tasks, tickets, chat, HR, and reporting.
    • Enforce the roles and permissions your organisation has configured, so people see only what they should.
    • Send transactional messages: invitations, verification codes, password resets, mentions, assignments, reminders, and other notifications you have not turned off.
    • Maintain audit logs for security, accountability, and troubleshooting.
    • Detect, investigate, and prevent fraud, abuse, and security incidents.
    • Respond to your support and contact enquiries.
    • Improve the reliability, performance, and usability of the service.
    • Comply with legal obligations and enforce our terms.

    We do not sell personal information. We do not use your workspace content to serve advertising, and we do not use it to train general-purpose AI models.

    5. Legal bases for processing

    Where data protection law requires a legal basis, we rely on the following:

    • Performance of a contract — to deliver the service you or your organisation signed up for.
    • Legitimate interests — to secure the platform, prevent abuse, keep audit records, and improve the product, balanced against your rights.
    • Consent — for optional features you switch on, such as browser push notifications and device location for attendance check-in. You may withdraw consent at any time.
    • Legal obligation — where we must retain or disclose information to comply with applicable law.

    6. Cookies and local storage

    Tickflows uses a small number of cookies and browser storage entries, all of them necessary for the product to work. We do not use advertising cookies, and we do not embed third-party marketing or analytics trackers on our website.

    What we storePurpose
    Authentication tokenKeeps you signed in and identifies your session and active organisation.
    Active organisation and projectRemembers which workspace and project you were last working in.
    Interface preferencesRemembers choices such as sidebar state and help widget position.
    Session profile cacheStores basic profile details locally so the interface loads without an extra round trip.

    You can clear this data at any time through your browser settings. Doing so signs you out and resets your interface preferences.

    7. How we share information

    We share personal information only in the situations below.

    • Within your organisation — colleagues and administrators can see the content and activity your permissions expose to them. Administrators can access workspace data, audit logs, and HR records for their organisation.
    • Service providers — vendors who help us operate the platform, listed below. They may process personal data only on our instructions and are bound by confidentiality obligations.
    • Legal and safety — where we are required by law, or where disclosure is necessary to protect our rights, our users, or the public.
    • Business transfers — if Tickflows is involved in a merger, acquisition, or sale of assets, information may be transferred, subject to this policy.

    Service providers we rely on

    ProviderUsed forData involved
    Cloud hosting providerRunning the application, database, and file storageAll service data, including uploaded files
    Email delivery providerVerification, invitation, and notification emailsName, email address, message content
    AfroMessageOne-time SMS verification codesMobile phone number, verification code
    Google (Gemini API)In-product help assistant and AI-assisted featuresThe question you ask and the context needed to answer it
    OpenAIAI-assisted featuresThe content submitted to the feature
    Browser push servicesDelivering web push notificationsPush subscription identifier and notification content

    8. AI-assisted features

    Tickflows includes an in-product help assistant and other AI-assisted features. When you use them, the text you submit — along with the context needed to answer — is sent to our AI providers for processing and returned to you as a response.

    • AI features are used to generate responses to you, not to profile you or make automated decisions about you.
    • We do not permit our AI providers to use your submissions to train their models.
    • AI output can be inaccurate. Do not rely on it for legal, financial, medical, or employment decisions without human review.
    • Avoid pasting sensitive personal information into AI features unless your organisation has approved it.

    9. Attendance and location data

    If your organisation enables geofenced attendance, Tickflows asks your browser or device for your location at the moment you check in or check out. This is one of the more sensitive kinds of data the platform handles, so we want to be specific about it.

    • Location is captured only at the moment of a check-in or check-out action. Tickflows does not track your location continuously or in the background.
    • We record the coordinates, the time, and whether the point fell inside a geofence zone your organisation defined.
    • Your browser or device asks for permission before sharing location, and you can refuse or revoke it in your device settings.
    • If you decline, your organisation may require an alternative check-in method or may mark the record for manual review — that policy is set by your employer, not by Tickflows.
    • Attendance records, including location, are visible to authorised HR and management roles within your organisation.

    Your organisation is responsible for telling you how it uses attendance and location data, and for having a lawful basis to do so under local employment and data protection law.

    10. Data retention

    We keep personal information for as long as it is needed for the purposes described in this policy.

    • Workspace content is retained for as long as your organisation maintains its Tickflows account, or until the organisation deletes it.
    • Account information is retained while your account is active. When an account is deactivated, we retain it for a limited period so it can be restored and so audit records stay coherent.
    • Audit and security logs are retained for a limited period to support investigations and accountability.
    • Verification codes and invitation tokens expire shortly after they are issued.
    • Contact form messages are retained for as long as needed to handle your enquiry and keep a record of it.

    When information is no longer needed we delete it or anonymise it. Backups are overwritten on a rolling schedule, so deleted data may persist in backups for a short period after it is removed from the live system.

    11. How we protect information

    We apply technical and organisational safeguards, including:

    • Encryption in transit using HTTPS/TLS.
    • Passwords stored only as salted cryptographic hashes, never in recoverable form.
    • Signed, expiring session tokens scoped to your active organisation.
    • Role-based access control, so users and administrators reach only the modules and records their role permits.
    • Multi-tenant isolation, so each organisation’s data is scoped to that organisation.
    • Audit logging of significant actions across the platform.
    • Email and SMS verification before an account becomes active.

    No system is perfectly secure. Please use a strong, unique password, keep your credentials confidential, and tell us immediately if you believe your account has been compromised.

    12. Your rights and choices

    Depending on where you live, you may have some or all of the following rights over your personal information:

    • Access — request a copy of the personal information we hold about you.
    • Correction — ask us to fix inaccurate or incomplete information.
    • Deletion — ask us to delete personal information, subject to legal and contractual limits.
    • Restriction and objection — ask us to limit or stop certain processing.
    • Portability — receive certain information in a structured, machine-readable format.
    • Withdraw consent — turn off optional features such as push notifications or location sharing at any time.

    You can update much of your information yourself from your profile and notification settings. For anything else, contact us using the details in section 16. We will respond within a reasonable time and may need to verify your identity first.

    Where the data belongs to your organisation’s workspace, we will forward your request to that organisation, which is responsible for deciding how to respond.

    13. International transfers

    Tickflows is operated from Ethiopia, and some of our service providers process data in other countries. Where information is transferred across borders, we take steps to ensure it remains protected by appropriate contractual and technical safeguards. By using Tickflows, you understand that your information may be processed outside your country of residence.

    14. Children’s privacy

    Tickflows is a workplace tool intended for use by adults. It is not directed at children, and we do not knowingly collect personal information from anyone under 18. If you believe a child has provided us with personal information, contact us and we will delete it.

    15. Changes to this policy

    We may update this policy as the product and our legal obligations evolve. When we do, we will revise the “Last updated” date at the top of this page. If the changes are significant, we will provide a more prominent notice — for example, an in-app message or an email to account administrators. Continuing to use Tickflows after an update means you accept the revised policy.

    16. Contact us

    If you have questions about this policy, or want to exercise any of the rights described above, get in touch:

    Tickflows — Cheche Systems

    • [email protected]
    • +251 912 345 678
    • Addis Ababa, Ethiopia

    If you are a member of an organisation using Tickflows, your organisation’s administrator is usually the fastest route for questions about your workspace data.

    Tickflows Logo

    Tickflows

    Project OS

    Tickflows helps teams streamline project workflows, collaborate clearly, and deliver work faster with confidence.

    Product

    • Features
    • Pricing
    • Integrations
    • Enterprise

    Resources

    • Documentation
    • Guides
    • API Status
    • Blog

    Company

    • About
    • Careers
    • Legal
    • Contact

    Support

    • Help Center
    • Privacy Policy
    • Terms of Service
    • Cookies

    © 2026 Tickflows. All rights reserved.

    Built by Cheche Systems