01Information We Collect
- Account information. Your email address, a hashed password, and any messages you send us for support.
- License & activation data. Your license key and tier, a hashed device fingerprint / hardware identifier, activation and reset timestamps, and the IP address used at activation. We use these to bind a license to your device and enforce seat limits.
- Operational telemetry. Application version, module/feature usage, task success and error counts, and periodic “heartbeat” liveness signals, associated with your license.
- Checkout history (opt-in). If you turn on “sync checkout history to my account” in the desktop app, we store a record of each completed or pending checkout: the site, the outcome, when it happened and how long it took, the event name, session and seat, the quantity, the order number, the amount and currency reported by the site, and a masked form of the ticketing-site account (for example
ab***@example.com). We do not upload ticket numbers or payment links. This is off until you turn it on, and you can turn it off or delete it at any time (see “Your Rights”). - Diagnostic logs (on request). When you press “upload log”, the desktop app sends that run’s encrypted task log so we can investigate a problem you reported. It is sent only when you ask for it, and it can contain the details of what that run did.
- Discord link (optional). If you link your Discord account, we store your Discord user ID, display name and avatar alongside your Sharkit account, plus which server role we last granted you. Your avatar is served through our own site, so Discord does not see your IP address when a page shows it. We use these to add you to our server, to keep your role in step with your license, and to stop one Discord account being used to hold roles on several Sharkit accounts. Unlinking removes your roles and keeps the record so that check still works; you can ask us to delete it (see “Your Rights”).
- Where a feature requires it. Some features only work if the information they operate on reaches our servers — for example syncing your settings across devices. We collect that information only for the feature you enabled, describe it where you enable it, and stop collecting it when you turn the feature off.
- Technical data. Browser type, device and operating system, and approximate location derived from IP, collected automatically when you visit the website.
- Cookies & local storage. A session cookie to keep you signed in, and local storage for preferences such as your theme. We do not use third-party advertising cookies.
We do not sell your personal information.
Credentials you enter for third-party ticketing sites stay on your device unless you switch on a feature that explicitly requires them to be synced, such as syncing your settings across devices. Where that happens, they are encrypted before they leave your device, they are never shown in plain text in our interfaces except to staff handling a support request you raised, and each such access is recorded in our audit log. We never use them for anything other than the feature you enabled.
02How We Use Information
- Provide, operate, and secure the Services;
- Activate and validate licenses and enforce device and seat limits;
- Detect, prevent, and investigate fraud, abuse, and security incidents;
- Provide customer support and respond to your requests;
- Improve and develop features, reliability, and performance;
- Comply with legal obligations and enforce our Terms.
03Legal Bases for Processing
Where data-protection laws such as the GDPR apply, we process personal data on the bases of contract performance (delivering the Services you request), legitimate interests (security, abuse prevention, and product improvement), consent (where required), and legal obligation.
04How We Share Information
We share information only as needed:
- Service providers / subprocessors who host and operate the Services on our behalf (e.g., cloud hosting, content delivery, and—if applicable—payment processing), under confidentiality obligations;
- Legal & safety disclosures when required by law or legal process, or to protect the rights, property, or safety of Sharkit, our users, or the public;
- Business transfers in connection with a merger, acquisition, or sale of assets, subject to this Policy.
We do not sell or rent personal information to third parties.
05Third-Party Services
The Services rely on infrastructure providers including Cloudflare (CDN, DNS, and DDoS protection) and our cloud hosting providers. The desktop application interacts with third-party ticketing websites at your direction; those sites are operated by independent parties and are governed by their own privacy policies and terms.
If you link your Discord account, Discord receives the request to add you to our server and to set your role. What Discord does with your account is governed by Discord’s own privacy policy. We never receive your Discord password, and we do not read your messages.
06Data Retention
We retain personal data for as long as your account is active or as needed to provide the Services, and thereafter for the period required to comply with legal obligations, resolve disputes, and enforce our agreements. License and activation records may be retained while a license remains valid plus a reasonable period afterward.
Checkout history. While syncing is on, we also keep a running tally by site, hour and outcome: how many checkouts, how many tickets, and total elapsed time. When you delete your synced checkout history, the individual records are removed, and we keep only the record identifiers needed to reject a later re-upload of the same records. Contributions already counted into the tally are not subtracted. The tally holds no account identifier, but where the data is sparse — or combined with other information — an individual contribution may still be inferable.
07Security
We use technical and organizational measures—including encryption in transit (HTTPS), hashed credentials, access controls, and tamper-resistant client packaging—to protect information. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
08International Transfers
We operate globally and may process and store information in countries other than your own. Where required, we apply appropriate safeguards for cross-border transfers of personal data.
09Your Rights
Depending on your jurisdiction, you may have the right to access, correct, export, or delete your personal data, to object to or restrict certain processing, and to withdraw consent. To exercise these rights, contact us at the address below. You may also have the right to lodge a complaint with your local data-protection authority.
10Children
The Services are not directed to, and may not be used by, individuals under the age of 18. We do not knowingly collect personal data from children.
11Changes to This Policy
We may update this Policy from time to time. Material changes will be posted on this page with a new “Last updated” date. Continued use of the Services after changes take effect constitutes acceptance.
12Contact Us
Questions or requests regarding this Policy can be sent to [email protected].
