Privacy policy
Last updated: 11 July 2026
How TickAI collects, uses, stores, and protects personal data.
Overview
This Privacy Policy explains how TickAI collects, uses, stores, and shares personal data when you visit our website, create an account, use the service, contact us, or are a prospective customer we contact.
Who we are
TickAI is provided by Community Maps Ltd ("TickAI", "we", "us", "our"), a company registered in Guernsey, Channel Islands, with company number 75120. You can contact us using the details in the Contact section below.
For account, billing, marketing, and product-usage data described in this policy, TickAI is the data controller.
Where you, or the organisation you represent, submit a website, URL, or file to TickAI for scanning or analysis, TickAI acts as a data processor on that organisation's behalf for any personal data contained in that content, and the organisation acts as controller of that content. See our Data Processing Agreement for the terms that apply to that processing.
Guernsey's data protection law — the Data Protection (Bailiwick of Guernsey) Law, 2017 — is recognised by both the UK and the European Commission as providing an adequate level of protection for personal data. Where UK GDPR or EU GDPR also applies to our processing (for example, because we offer the service to, or monitor the behaviour of, people in the UK or EEA), we comply with those obligations too.
Information we collect
We may collect:
- account and organisation data such as your name, email address, login activity, and organisation details;
- billing and subscription records, including Stripe customer and subscription identifiers (we do not store full payment card numbers — card payments are handled by Stripe);
- support and communications data when you contact us;
- technical and security information such as device, browser, approximate location, IP address, and security logs, including IP addresses recorded against login sessions for account security and administrative audit purposes;
- product usage information such as scans run, sites submitted, review actions, and settings changes;
- scan and content metadata — the URLs, files, and associated information needed to analyse the content you ask us to review, together with the resulting analysis (see Content and scan data below for how the underlying content itself is handled); and
- prospective-customer data, where we run outreach to businesses that have not created a TickAI account, limited to publicly available business contact details (see Prospective customers and outreach below).
How we use personal data
We use personal data to:
- provide, secure, and maintain TickAI;
- create and administer accounts and organisations;
- process payments and manage subscriptions;
- perform scans, analysis, review workflows, and audit exports;
- communicate with you about your account, support requests, service updates, and security matters;
- prevent fraud, abuse, and unauthorised access;
- improve the service, reporting, reliability, and user experience; and
- tell prospective customers about TickAI, as described in Prospective customers and outreach below.
Legal bases
Where UK GDPR or EU GDPR applies, we generally process personal data because:
- it is necessary to perform our contract with you or your organisation;
- it is necessary for our legitimate interests in operating, securing, and improving TickAI, or in promoting TickAI to relevant businesses (balanced against your rights and expectations, and subject to your right to object at any time);
- you have given consent, where consent is the appropriate basis (for example, for certain non-essential cookies, or for marketing outreach in countries that require opt-in consent); or
- processing is required to comply with a legal obligation.
Content and scan data
When you submit a site, URL, or asset for analysis, we process the information needed to crawl, inspect, and document the relevant content.
Where possible, we and our analysis providers work from the content's original URL rather than making a permanent copy of it: images and video are typically sent by reference to our detection providers rather than downloaded into TickAI's own storage. We retain the resulting analysis (scores, classifications, review decisions, and audit trail) together with the metadata needed to identify what was analysed, rather than a standing archive of the underlying files.
If your organisation's production domain is changed, related scan data may be archived in a form recoverable by an administrator, to allow recovery if the change was made in error, before being permanently deleted. We keep this archived data only for as long as necessary for that purpose.
We aim to retain only the information necessary to provide the product, maintain audit trails, support the service, and meet legal or security obligations.
Prospective customers and outreach
We sometimes contact prospective customers who have not created a TickAI account, using publicly available business contact information (for example, a work email address published on a company website), to tell them about TickAI.
Our legal basis for this is our legitimate interest in promoting TickAI to relevant businesses. In countries where the law requires opt-in consent for this kind of outreach, we apply stricter rules or do not send unsolicited marketing email.
Every outreach email includes a way to unsubscribe. If you unsubscribe or ask us to stop, we keep your address on a suppression list so we can honour that request, and do not contact you again. You can also object to this processing at any time using the contact details below. We keep prospective-customer data only for as long as it is useful for outreach or necessary to honour an opt-out.
Cookies and similar technologies
We use cookies and similar technologies for core site functionality, authentication, and security, and — only once you have accepted them through the cookie banner on our site — for analytics and advertising, including Google Ads and Microsoft Clarity.
We also use Microsoft Clarity to understand how our site is used. Clarity runs for all visitors, but until you accept optional cookies it operates in a cookieless mode on the basis of our legitimate interest in improving the site: no analytics cookies are set, and each page you view is recorded in isolation rather than linked to your other page views or visits. Clarity applies masking to the content it captures.
If you decline non-essential cookies, no analytics or advertising cookies are set, Clarity remains in the cookieless mode described above, and the other advertising tools are not loaded. You can change your choice at any time by clearing your browser's site data for tickai.app, which will show the banner again on your next visit.
Cloudflare Turnstile
We use Cloudflare Turnstile on selected forms and flows to help detect bots and protect the service from abuse. When Turnstile runs, Cloudflare may receive technical and interaction data such as IP address, browser and device characteristics, and signals needed to distinguish human visitors from automated traffic.
For more information about how Cloudflare processes Turnstile data, please see Cloudflare's Turnstile Privacy Addendum.
Sharing personal data
We may share personal data with service providers that help us operate TickAI, such as providers for hosting, infrastructure, authentication, email, payments, security, analytics, and customer support.
We may also share information:
- where required by law, regulation, legal process, or governmental request;
- to protect the rights, safety, and security of TickAI, our users, or others; or
- as part of a merger, acquisition, financing, or asset sale, subject to appropriate safeguards.
Sub-processors
Our service providers may include platforms such as Supabase (database and authentication), Vercel (hosting), Stripe (payments), Resend (email delivery, including transactional email and the outreach described above), Cloudflare (Turnstile bot protection), Browserless (rendering websites during a scan), Replicate (hosting the machine-learning models used for content analysis), Sightengine (image and video detection), Google (Ads, once you have accepted non-essential cookies), and Microsoft (Clarity analytics, once you have accepted non-essential cookies).
We may update our providers from time to time as the service evolves; the current list of the categories above reflects our providers as of the date at the top of this policy.
International transfers
Guernsey has been assessed by the UK and the European Commission as providing an adequate level of data protection, so personal data can flow freely between Guernsey and the UK/EEA without additional safeguards.
Several of our sub-processors are based outside Guernsey, the UK, and the EEA, including in the United States. Where that is the case, we rely on the safeguards those providers put in place, such as the EU-US Data Privacy Framework, UK extension to that framework, or Standard Contractual Clauses, to ensure the transfer is lawful.
Data retention
We keep different categories of data for different lengths of time, depending on what it's needed for:
- Account and organisation data is kept for as long as your account is active. If you (as an organisation owner) delete your account, we delete the associated data from our production systems; residual copies may remain in encrypted backups for a limited period before being overwritten.
- Scan, review, and audit-trail data is kept for the life of the account, because it is the compliance record the service exists to produce, and is deleted when the account is deleted.
- Billing records are kept for as long as required for tax and accounting purposes — typically up to 6 years.
- Security and session logs, including IP addresses recorded against login sessions, are kept only for as long as necessary for security monitoring, abuse prevention, and audit purposes.
- Prospective-customer data is kept only for as long as it is useful for outreach, or, where you have opted out, on a suppression list for as long as necessary to honour that opt-out.
- Domain-change archives (see Content and scan data above) are kept only for as long as necessary to allow recovery from an accidental change.
Your rights
Depending on where you are located, you may have the right to:
- access the personal data we hold about you;
- correct inaccurate personal data;
- request deletion of your personal data;
- restrict or object to certain processing;
- receive a copy of your personal data in a portable format; and
- withdraw consent at any time, where processing relies on consent, without affecting processing that happened before you withdrew it.
An organisation owner can delete their account and organisation at any time from account settings, which removes the associated data as described in Data retention above. For any other request, contact us using the details below and we will respond within the time required by applicable law.
If you are not satisfied with how we've handled your request, you have the right to complain to a data protection supervisory authority — in Guernsey, the Office of the Data Protection Authority (odpa.gg). If you are located in the UK or EEA, you may also be able to complain to your local supervisory authority.
Children's privacy
TickAI is a business tool and is not directed at, or intended for use by, children. You must be at least 18 to create an account. We do not knowingly collect personal data from children.
Automated processing
TickAI's AI detection features produce scores and classifications intended to support a human reviewer's decision. We do not use these outputs to make decisions about you, the visitor to a scanned website, that produce legal or similarly significant effects without human involvement — decisions about how to act on a detection result are made by the organisation that submitted the content for review.
California privacy rights
We do not sell personal data. If you are a California resident, you may have additional rights under the California Consumer Privacy Act, including the right to know what personal data we hold about you and to request its deletion. You can exercise these rights using the contact details below.
Security
We use technical and organisational measures designed to protect personal data, including encryption in transit, access controls, and restricted administrative access. No system is completely secure, but we work to reduce risk and respond to incidents appropriately, including notifying affected customers and, where legally required, regulators, without undue delay if we become aware of a breach affecting your personal data.
Changes to this policy
We may update this Privacy Policy from time to time. If we make a material change, we will post the updated version here and revise the effective date.
Contact
If you have a privacy question or want to exercise your rights, please contact us using the details on our contact page.

