1. Who we are and when this policy applies
TicketSys is a store-workflow service operated under the iTMate name in Australia. In this policy, “TicketSys”, “iTMate”, “we”, “us” and “our” refer to the operator of the TicketSys service.
This policy applies when a person uses TicketSys, visits a TicketSys page, receives a TicketSys customer update, submits a store-registration request, contacts support, or has their information entered into TicketSys by an authorised participating store.
Participating stores use TicketSys to manage jobs and communicate with their customers. Those stores remain responsible for ensuring that information they enter is collected lawfully, is accurate and is used appropriately. Customers do not need to create a TicketSys account to receive a secure job-tracking link or respond to a quote.
2. Information we collect and hold
The information handled depends on how TicketSys is used and may include:
- Store and staff information: names, work contact details, store number and address, business or franchise affiliation, role, access status, onboarding details and support communications.
- Customer and job information: customer name and mobile number, an email address entered by a customer to receive a requested service or warranty PDF, job or docket number, item and service details, repair notes, status updates, quotes, approvals or declines, collection records, customer messages and related timestamps.
- Photos and documents: docket photographs, item or repair photographs, generated service or warranty PDFs, and screenshots or attachments intentionally uploaded by an authorised user.
- Technical and security information: IP address, browser or app type, device and operating-system information, session identifiers, request timestamps, security events, diagnostic information and audit records showing which authorised user performed an action.
- Customer-link activity: secure-link access, quote responses, collection or reward actions, PDF download or email-delivery requests, and SMS preference choices.
- Website registration information: manager or franchisee name, email, mobile number, store details, preferred contact method and information included in an onboarding request.
TicketSys is not intended to collect payment-card details, government identifiers, health information or other sensitive information. Users should not enter that information unless it is genuinely necessary and authorised.
3. How information is collected
We collect information directly when a person enters it, uploads a photo, responds through a secure link, submits a form or contacts support. We also receive information from participating stores and their authorised staff when they create or update a job. Technical information is collected automatically when our systems receive a request, primarily for session operation, fraud prevention, rate limiting, troubleshooting and security.
The mobile app may request access to the camera or photo library only when a user chooses a feature that needs it. A selected image is transmitted only when the user submits or processes it. TicketSys stores the last selected store code on the device for convenience; it does not save the store’s operational PIN in the app.
4. Why we use personal information
We use personal information to:
- provide and secure store accounts and staff access;
- create, update and locate repair, collection and special-job records;
- prepare and deliver customer SMS updates, secure tracking links and customer-requested service or warranty PDFs by email;
- record quote decisions, job progress, collections and customer preferences;
- process docket details, photos and attachments requested by an authorised user;
- provide support, investigate faults, maintain audit histories and prevent misuse;
- review store registrations, administer subscriptions and manage the service;
- improve reliability, accessibility and workflow design using aggregated or de-identified observations; and
- meet legal obligations and establish, exercise or defend legal claims.
We do not sell personal information and do not use TicketSys information for third-party behavioural advertising.
Security and record integrity
Customer names and mobile numbers may remain stored in the TicketSys database even when they are not being actively used for a message or current workflow. Maintaining this limited identifying information helps keep the correct customer associated with the correct job, prevent mistaken disclosure or collection, verify legitimate support, access or deletion requests, investigate suspected misuse or security incidents, resolve disputes and preserve an accountable audit trail.
Storage for these security and record-integrity purposes does not authorise unrelated marketing, data sale or unnecessary use. The retention and deletion safeguards described below continue to apply.
5. OCR, automation and staff review
When an authorised user chooses docket scanning, TicketSys may send a cropped or reduced copy of the selected image to OpenAI to extract fields such as a customer name, mobile number and job number. The extracted result is an assistance tool only. Store staff are expected to check the fields before using or sending them.
TicketSys does not use OCR or other automated processing to make decisions that significantly affect a person’s rights or interests. Quote, repair and collection decisions remain with the participating store and its authorised staff.
6. When information is disclosed
We disclose information only where reasonably necessary for the purposes above, including to:
- the participating store, relevant franchise group, authorised managers and staff;
- Cloudflare, which provides network protection, application hosting, database, private object-storage and transactional email-delivery infrastructure;
- OpenAI, when an authorised user invokes optional OCR processing;
- Texto, which receives the destination mobile number and message content needed to deliver an SMS;
- Apple, Expo and related platform providers to the extent required to distribute, operate or diagnose the mobile application;
- professional advisers, insurers, auditors or contractors bound by confidentiality; and
- regulators, courts, law-enforcement bodies or another party where required or authorised by law.
We require service providers to handle information only for the contracted service, apply appropriate safeguards and provide protection consistent with this policy and applicable requirements. If the service or business is reorganised or transferred, information may be transferred with appropriate confidentiality and privacy protections.
7. Overseas processing
TicketSys is operated from Australia. Some service providers operate global infrastructure, so personal information may be processed or stored in Australia, the United States and other countries in which those providers maintain secure facilities or support operations. Privacy laws in another country may differ from Australian law.
We take reasonable steps when selecting and configuring providers, minimise the information sent for each task, restrict access and use contractual, technical and organisational safeguards appropriate to the information.
8. Cookies, sessions and analytics
TicketSys uses essential cookies or similar storage to maintain secure sign-in sessions, remember necessary preferences and protect the service. We may collect limited server logs and diagnostics to detect faults and security events. We do not use third-party advertising cookies or track users across unrelated apps and websites for advertising.
9. Retention and deletion
We retain information only for as long as reasonably required to provide the service, complete and support store jobs, maintain security and audit records, resolve disputes, meet warranty or record-keeping needs, and comply with law. The appropriate period varies by record type and the participating store’s legitimate operational requirements.
An email address entered only to receive a requested watch service or warranty PDF is passed to the email service for delivery and is not stored in TicketSys. A one-way recipient hash and delivery event may be retained for security, audit and rate-limiting purposes.
When information is no longer required, we take reasonable steps to delete or de-identify it. Deletion from active systems may not immediately remove protected backup copies; backup data is isolated from ordinary use and expires through the normal backup cycle. We may retain a minimal record where required to document a request, maintain security or comply with law.
A person may request deletion or withdraw consent by contacting us. We will assess the request, verify identity where necessary, coordinate with the relevant store and explain any information that must be retained. SMS recipients can use the preference link supplied with an eligible message or contact the store.
10. Security
We use safeguards designed for the nature of the information, including encrypted HTTPS connections, restricted store access, role and session controls, private storage, secret management, audit trails, rate limits, security monitoring and backups. Access is limited to authorised people and providers that need it for their work.
No online service can guarantee absolute security. Users must protect their credentials, use authorised devices and promptly report suspected misuse. If a data breach occurs, we will investigate, contain it and provide notifications where required by applicable law.
11. Access, correction and privacy choices
You may ask to access personal information we hold about you, correct inaccurate or outdated information, or request deletion. Contact us with enough information to identify the relevant store or job, but do not email a PIN, password or unnecessary identity document.
We may need to verify your identity and consult the participating store before responding. We will respond within a reasonable period and will explain if a request cannot be completed in full. We do not ordinarily charge for making a request; if an access request requires substantial work, we will discuss any permitted charge first.
12. Children
TicketSys is a business operations service and is not directed to children. A store may enter limited contact or job information relating to a customer who is under 18 where lawful and appropriate for the service. We do not knowingly create staff accounts for children or use children’s information for marketing.
13. Complaints
If you believe TicketSys has mishandled personal information, contact us with a description of the issue. We will acknowledge the complaint, investigate it, coordinate with the relevant participating store where necessary and communicate the outcome. If you are not satisfied, you may be entitled to contact the Office of the Australian Information Commissioner.
14. Contact us
For privacy questions, access or correction requests, deletion requests, consent withdrawal or complaints:
TicketSys Privacy
Operated under the iTMate name
Australia
it@ticketsys.cc
15. Changes to this policy
We may update this policy when the service, providers or legal requirements change. The current version will remain available at this URL and will show its effective and last-updated dates. Material changes will be communicated through the service or another appropriate channel.