Skip to content

Privacy

Last updated

tickatap is a guide to a city. You say where you are, we lay out what is on, and the taps become one day with real times and the travel in between. This page says what that costs you in data.

The short version

  • You can use the planner without an account, and most people do. We do not make you sign up to see anything.
  • We never take your payment, so we never see your card. Every purchase happens on the seller’s own site.
  • Google Analytics is on. Nothing else follows you around the web — there are no ad networks, no retargeting pixels and no data brokers in this product.
  • We do not sell personal information.

What we collect

When you have no account

Most of the product works signed out. What we keep is tied to a random token your browser holds, not to a name:

  • The city or address you type into a location box, and the radius you set. That is the question the guide answers.
  • The plan itself — the dates, the stops, who tapped what, and a spending cap if someone set one. A plan you start without an account belongs to a host token in your browser; a plan you join by link belongs to a participant token in yours.
  • A random click id. It lives in your browser under tickatap.attribution.v1, contains nothing personal, and exists so a link you follow this afternoon can be matched to the plan you built this morning. That is how we find out whether a link earned anything. See the affiliate disclosure.
  • Your device location, only if you ask us to use it. One screen has a button that reads your location; your browser asks you first, and saying no changes nothing except that you type where you are instead.

When you make an account

  • Your email address, and your password stored only as a hash. The plain password is never written down anywhere. Sign-in tokens are stored the same way — as a hash, so a leaked row cannot be replayed.
  • What you choose to add: a display name, a handle like sam#1231, a home city and its coordinates, notification preferences and spending limits.
  • Taste signals. An append-only list of what you liked, skipped or picked. It is what the “why am I seeing this” line reads from, and it is the reason the guide gets better. You can delete individual signals in Settings.
  • Short notes about your taste, in plain sentences, written so the planner can look them up later — for example “picked a quiet bar with a patio”. Same data as the signals above, in a form a model can read.
  • Plans you make or join, and who else is in them.

Two limits inside group plans are worth stating because they are built into the database, not into a promise. A member’s spending cap never leaves the server — only the group’s lowest cap does, with no name on it. And when somebody passes on a stop, the group sees who passed and never why: there is no column to store a reason in.

Everyone

Ordinary web server logs, and a count of requests per IP address. The counter is there because several things on the public site cost us money to answer — a plan is a model call, a location lookup is a billed Google call — and an endpoint with no ceiling is an invitation to run somebody else’s workload on our bill.

What we send to other companies

This is the whole list. If a company is not here, we do not send it anything.

  • Google Analytics 4 — page views and a handful of product events. It runs on www.tickatap.com and has since 18 August 2026. Google sets its own cookies. If the measurement id is ever removed, the script is not loaded at all rather than loaded and idle.
  • Google Places and Google Maps — what you type into a location box goes to Google so it can be completed, and the radius screen draws a Google map. We keep the Google place id for the address you pick, and its coordinates for at most 30 days. We do not store the suggestion lists or the formatted address text.
  • Anthropic, Google (Gemini) and DeepInfra — one of these writes the plan. What you type into the planner is sent to whichever is configured, along with the candidate places we are asking it to choose between. Anything that came from an outside source is wrapped as data before it reaches the prompt, so a web page cannot give the model instructions on your behalf.
  • Ticketmaster and SeatGeek — we ask them what is on in a city on a date. We do not tell them who is asking.
  • Clerk — the account system this product is built to move onto. Where it is switched on it receives your email address and handles the password so we never see it. Today the live site still signs you in through our own API, which is the email and password hash described above.
  • Whoever you buy from. Follow a buy link and you are on the seller’s site under their privacy policy. Our link carries a tracking id and nothing else — never your name, never your email.
  • Heroku — where the site, the API and the database run.

Cookies and things kept in your browser

  • tickatap.attribution.v1 — the random click id described above. Local storage, not a cookie.
  • Plan tokens — local storage. They are what make a plan you started, or joined by link, still yours when you come back.
  • _ga and _ga_* — set by Google Analytics.
  • A sign-in cookie, once you have an account and are signed in.

Blocking or clearing any of these does not lock you out of the product. You lose the thread back to plans you made anonymously, which is the trade.

Getting your data, and getting rid of it

Export works today. Settings → Privacy builds one JSON file out of everything the API will hand back for your account — profile, settings, taste, tickets, plans — and saves it. The file states its own scope inside itself, because a file called “my data” that quietly leaves half of it out is worse than no file.

Delete does not work yet, and the button says so. There is a delete control in the same place, and when the API cannot take the request it tells you plainly that nothing was deleted rather than showing a green tick. Until the deletion job ships, ask us and we will do it by hand.

How long we keep things is not settled, and we would rather say that than publish a number we do not keep to.

Children

tickatap is not built for children and is not directed at anyone under 13. If you think a child has given us something, tell us and we will remove it.

Where we operate

We are a US product and the data lives in the US. If you are somewhere else you are welcome here, but that is where your data goes.

Changes

When this changes, the date at the top changes with it. There is no version of this page that quietly rewrites itself.

Contact

Email yoonbocho1@gmail.com. That address is read by a person, and it is the right place for anything on this page — a question, a correction, a request to see or delete what we hold.