Privacy Policy
Last updated: July 2026
Ducket helps event organizers find and reach the right sponsors. This policy explains what personal data we collect, why we collect it, and the choices you have. It is written to be read, not skimmed past. If anything is unclear, email us at hello@ducket.io.
This policy covers our websites and products: ducket.io, argus.ducket.io, app.ducket.io, our API at api.ducket.io, and the emails we send (together, the "Service"). The Service is operated by Ducket Limited, a company incorporated in Hong Kong SAR ("Ducket", "we", "us"). Ducket is the data controller for the personal data described in this policy.
This policy covers two different groups of people, and we describe each separately:
- Customers and users: people who create a Ducket account or use our Service.
- Business contacts in our intelligence data: people whose professional details appear in the sponsorship market data our product is built on. If you have never used Ducket but received an email from us or found yourself mentioned in our data, section 5 is for you.
1. Data we collect from customers and users
Account data. When you sign up we collect your email address and a password. Passwords are handled by our authentication provider (Supabase) and stored only in hashed form; we never see or store your plain password. If you sign in with Google, we receive your email address from Google instead, and no password is created with us.
Organization data. When you create or join an organization we store the organization name, your role in it (for example operator or viewer), and any details you give us when requesting setup, such as your website, country, and a note about the events you organize.
Onboarding preferences. During signup we may ask about the event you care about (an event URL, event name, industry vertical, and region) so your feed is relevant from day one. These answers are held in your browser until your account is active, then used to set up your feed.
Billing data. Payments are processed by Stripe. We send Stripe your email address and name to create your billing record. Your card number goes directly to Stripe and never touches our servers. We store only your subscription status, plan, and billing history references.
Content you provide. This includes sponsor lists you upload for coverage checks, event details, watchlists, saved views, questions you ask in the product, and, for Sponsorship OS customers, outreach settings such as a sender name, title, and email signature.
Communications. If you email us or reply to our emails, we keep the correspondence.
Website forms. If you submit an interest or contact form on our websites (for example the sponsor interest form on ducket.io), we collect what you enter, typically your name, company, and email address, and use it to respond to you.
API usage. If your organization uses API keys, we record usage (which key, which endpoint, when) for metering and security. API keys themselves are stored only as fingerprints (a one-way hash); we cannot recover a lost key.
2. Data we collect automatically
We keep standard server logs (IP address, request path, timestamps, user agent) for security and debugging.
We do not use any third-party analytics or advertising trackers. There is no Google Analytics, no ad pixels, and no session recording on the Service.
The Service stores a small number of items in your browser's local storage: your sign-in session (so you stay logged in) and display preferences such as currency and feed settings. See section 11 for the full list.
3. How we use customer data
We use the data above to:
- provide and operate the Service, including personalizing your feed;
- manage your subscription, payments, and any refund you request;
- send service emails: invitations, a payment confirmation and receipt, reminders before a charge where a trial has been granted, digest emails for watchlists you set up, and security or billing notices;
- keep the Service secure, prevent abuse, and enforce our terms;
- improve the product, using aggregated or de-identified information where possible;
- comply with legal obligations.
We do not sell personal data. We do not use your data for third-party advertising.
4. AI processing
Ducket uses large language models (from Anthropic, including via AWS Bedrock, and OpenAI) to read public web pages and produce structured, cited summaries of sponsorship activity. Text from public pages, company information, and, in limited cases, a contact's name and job title may be processed by these providers to produce those summaries. Questions you ask inside the product are also processed this way to generate answers.
These providers act as our processors under their API terms, which do not permit them to use our API data to train their models. Every factual claim our system makes is tied to a dated source; the models summarize, they do not decide anything about you.
5. Business contacts and companies in our intelligence data
Ducket's product is a live record of conference sponsorship activity. Most of that record is about companies, not people: which company sponsored which event, at what tier, and when, backed by dated captures of public web pages. We collect this by crawling public pages only. Our crawler identifies itself ("Ducket"), honors robots.txt, and rate-limits itself.
Some of our data is about people in their professional capacity:
What we hold. Name, job title, seniority, employer, business email address, LinkedIn profile URL, and region. We do not hold phone numbers, personal (non-work) email addresses, or any sensitive categories of data.
Where it comes from. Business contact details come only from licensed business-data providers (People Data Labs and Apollo.io), which compile professional profile data. We do not scrape personal contact details from the open web. Public pages we archive (for example a conference site) may incidentally name people, such as speakers, exactly as published.
Why we hold it (legal basis). Our customers are event organizers looking for sponsorship partners. We surface a small number of relevant professional contacts (at most a few people per company) so an organizer can reach the right person about a business partnership. We rely on legitimate interests as the legal basis for this business-to-business processing, and we limit it accordingly: business contact details only, small shortlists, no consumer profiling, and no automated decisions with legal effects.
Outreach. Where our customers use Ducket to contact sponsors, every message is reviewed and sent by a human; nothing is auto-sent. If you receive an email and ask to stop hearing from us, we add you to a suppression list that is checked before every send, and you will not be contacted through Ducket again.
Your choices. Email hello@ducket.io to ask what we hold about you, correct it, object to the processing, or have it deleted. If you ask for deletion, we delete your contact record and keep only a minimal suppression entry (your email address) so that your opt-out sticks. We honor these requests regardless of where you live.
6. When we share data
We share personal data only with service providers that help us run Ducket, under contracts that limit their use of it:
| Provider | What they do for us | Location |
|---|---|---|
| Supabase | Database and authentication | Tokyo, Japan (AWS ap-northeast-1) |
| Fly.io | Application hosting | Tokyo, Japan |
| Tigris Data | Object storage (page captures, screenshots) | Co-located with our application hosting |
| Vercel | Website hosting | Global CDN (US provider) |
| Cloudflare | DNS and network services | Global (US provider) |
| Stripe | Payment processing | United States / global |
| Resend | Transactional email delivery | United States |
| Anthropic (incl. AWS Bedrock) | AI text processing | United States / global |
| OpenAI | AI text processing (secondary) | United States |
| People Data Labs | Licensed business-contact data | United States |
| Apollo.io | Licensed business-contact data | United States |
| Exa | Web search | United States |
| Serper | Web search | United States |
| Sign-in (only if you choose Google sign-in) | Global |
We may also disclose data if required by law, to protect our rights or users' safety, or as part of a corporate transaction (in which case this policy continues to apply to the transferred data). We will update this table when providers change.
7. International transfers
Our primary data infrastructure is in Tokyo, Japan. Some providers above process data in the United States or globally. Where required, we rely on appropriate safeguards for these transfers, such as contractual protections with each provider. Because our customers are mostly in Asia-Pacific, we deliberately keep the system of record in the region.
8. How long we keep data
- Account and organization data: for as long as your account is active. If your organization is deleted, its data (members, invites, API keys, billing state, usage records) is permanently removed.
- Billing records: kept for 7 years, as required by Hong Kong tax law.
- The sponsorship record: our archive of public sponsorship activity (company-level signals, dated page captures) is a historical market record and is retained as such.
- Business contact records: kept while relevant to the purpose above, and deleted on request.
- Suppression entries: kept indefinitely, because they exist to enforce opt-outs.
- Email logs: records of what we sent and to whom are kept for audit purposes.
9. Security
Data is encrypted in transit (TLS). Passwords are hashed by our authentication provider. API keys are stored only as one-way fingerprints. Card details are handled entirely by Stripe. Access to production data is restricted, and each organization's data is isolated at the database level. No system is perfectly secure; if we learn of a breach affecting your personal data, we will notify you as required by law.
10. Your rights
Depending on where you live, you may have rights under laws such as Singapore's PDPA, Hong Kong's PDPO, Japan's APPI, Australia's Privacy Act, or the EU/UK GDPR. In practice we offer the same core rights to everyone:
- Access: ask for a copy of the personal data we hold about you.
- Correction: ask us to fix inaccurate data.
- Deletion: ask us to delete your data (see section 5 for how deletion interacts with suppression, and section 8 for what we must retain).
- Objection and restriction: object to processing based on legitimate interests.
- Portability: receive data you provided in a usable format.
- Withdraw consent: where processing is based on consent.
To exercise any of these, email hello@ducket.io. We will verify your identity (usually by confirming control of the relevant email address) and respond within the time required by applicable law. If you are unsatisfied, you may complain to your local data protection authority (in Hong Kong, the PCPD).
11. Cookies and local storage
We do not use advertising or analytics cookies. The Service stores the following in your browser:
| Item | Purpose |
|---|---|
| Sign-in session (Supabase) | Keeps you logged in |
| Display preferences | Currency, feed and display settings |
| Signup state | Your email and onboarding answers, held during signup only |
Third parties set their own cookies on their own pages: Stripe on its checkout and billing pages, and Google if you use Google sign-in. Those are governed by their policies.
12. Children
The Service is for business use and is not directed to anyone under 18. We do not knowingly collect data from children.
13. Changes to this policy
If we make material changes, we will notify account holders by email or in the product before the changes take effect, and update the date at the top. Earlier versions are available on request.
14. Contact
Ducket Limited
Incorporated in Hong Kong SAR
Email: hello@ducket.io
If your question is specifically about privacy or a data request, put "Privacy" in the subject line so we route it quickly.