Privacy Policy

This policy covers our websites and products: ducket.io, argus.ducket.io, app.ducket.io, our API at api.ducket.io, and the emails we send (together, the "Service"). The Service is operated by Ducket Limited, a company incorporated in Hong Kong SAR ("Ducket", "we", "us"). Ducket is the data controller for the personal data described in this policy.

This policy covers two different groups of people, and we describe each separately:

1. Data we collect from customers and users

Account data. When you sign up we collect your email address and a password. Passwords are handled by our authentication provider (Supabase) and stored only in hashed form; we never see or store your plain password. If you sign in with Google, we receive your email address from Google instead, and no password is created with us.

Organization data. When you create or join an organization we store the organization name, your role in it (for example operator or viewer), and any details you give us when requesting setup, such as your website, country, and a note about the events you organize.

Onboarding preferences. During signup we may ask about the event you care about (an event URL, event name, industry vertical, and region) so your feed is relevant from day one. These answers are held in your browser until your account is active, then used to set up your feed.

Billing data. Payments are processed by Stripe. We send Stripe your email address and name to create your billing record. Your card number goes directly to Stripe and never touches our servers. We store only your subscription status, plan, and billing history references.

Content you provide. This includes sponsor lists you upload for coverage checks, event details, watchlists, saved views, questions you ask in the product, and, for Sponsorship OS customers, outreach settings such as a sender name, title, and email signature.

Communications. If you email us or reply to our emails, we keep the correspondence.

Website forms. If you submit an interest or contact form on our websites (for example the sponsor interest form on ducket.io), we collect what you enter, typically your name, company, and email address, and use it to respond to you.

API usage. If your organization uses API keys, we record usage (which key, which endpoint, when) for metering and security. API keys themselves are stored only as fingerprints (a one-way hash); we cannot recover a lost key.

2. Data we collect automatically

We keep standard server logs (IP address, request path, timestamps, user agent) for security and debugging.

We do not use any third-party analytics or advertising trackers. There is no Google Analytics, no ad pixels, and no session recording on the Service.

The Service stores a small number of items in your browser's local storage: your sign-in session (so you stay logged in) and display preferences such as currency and feed settings. See section 11 for the full list.

3. How we use customer data

We use the data above to:

We do not sell personal data. We do not use your data for third-party advertising.

4. AI processing

Ducket uses large language models (from Anthropic, including via AWS Bedrock, and OpenAI) to read public web pages and produce structured, cited summaries of sponsorship activity. Text from public pages, company information, and, in limited cases, a contact's name and job title may be processed by these providers to produce those summaries. Questions you ask inside the product are also processed this way to generate answers.

These providers act as our processors under their API terms, which do not permit them to use our API data to train their models. Every factual claim our system makes is tied to a dated source; the models summarize, they do not decide anything about you.

5. Business contacts and companies in our intelligence data

Ducket's product is a live record of conference sponsorship activity. Most of that record is about companies, not people: which company sponsored which event, at what tier, and when, backed by dated captures of public web pages. We collect this by crawling public pages only. Our crawler identifies itself ("Ducket"), honors robots.txt, and rate-limits itself.

Some of our data is about people in their professional capacity:

What we hold. Name, job title, seniority, employer, business email address, LinkedIn profile URL, and region. We do not hold phone numbers, personal (non-work) email addresses, or any sensitive categories of data.

Where it comes from. Business contact details come only from licensed business-data providers (People Data Labs and Apollo.io), which compile professional profile data. We do not scrape personal contact details from the open web. Public pages we archive (for example a conference site) may incidentally name people, such as speakers, exactly as published.

Why we hold it (legal basis). Our customers are event organizers looking for sponsorship partners. We surface a small number of relevant professional contacts (at most a few people per company) so an organizer can reach the right person about a business partnership. We rely on legitimate interests as the legal basis for this business-to-business processing, and we limit it accordingly: business contact details only, small shortlists, no consumer profiling, and no automated decisions with legal effects.

Outreach. Where our customers use Ducket to contact sponsors, every message is reviewed and sent by a human; nothing is auto-sent. If you receive an email and ask to stop hearing from us, we add you to a suppression list that is checked before every send, and you will not be contacted through Ducket again.

Your choices. Email hello@ducket.io to ask what we hold about you, correct it, object to the processing, or have it deleted. If you ask for deletion, we delete your contact record and keep only a minimal suppression entry (your email address) so that your opt-out sticks. We honor these requests regardless of where you live.

6. When we share data

We share personal data only with service providers that help us run Ducket, under contracts that limit their use of it:

We may also disclose data if required by law, to protect our rights or users' safety, or as part of a corporate transaction (in which case this policy continues to apply to the transferred data). We will update this table when providers change.

7. International transfers

Our primary data infrastructure is in Tokyo, Japan. Some providers above process data in the United States or globally. Where required, we rely on appropriate safeguards for these transfers, such as contractual protections with each provider. Because our customers are mostly in Asia-Pacific, we deliberately keep the system of record in the region.

8. How long we keep data

9. Security

Data is encrypted in transit (TLS). Passwords are hashed by our authentication provider. API keys are stored only as one-way fingerprints. Card details are handled entirely by Stripe. Access to production data is restricted, and each organization's data is isolated at the database level. No system is perfectly secure; if we learn of a breach affecting your personal data, we will notify you as required by law.

10. Your rights

Depending on where you live, you may have rights under laws such as Singapore's PDPA, Hong Kong's PDPO, Japan's APPI, Australia's Privacy Act, or the EU/UK GDPR. In practice we offer the same core rights to everyone:

To exercise any of these, email hello@ducket.io. We will verify your identity (usually by confirming control of the relevant email address) and respond within the time required by applicable law. If you are unsatisfied, you may complain to your local data protection authority (in Hong Kong, the PCPD).

11. Cookies and local storage

We do not use advertising or analytics cookies. The Service stores the following in your browser:

Third parties set their own cookies on their own pages: Stripe on its checkout and billing pages, and Google if you use Google sign-in. Those are governed by their policies.

12. Children

The Service is for business use and is not directed to anyone under 18. We do not knowingly collect data from children.

13. Changes to this policy

If we make material changes, we will notify account holders by email or in the product before the changes take effect, and update the date at the top. Earlier versions are available on request.

14. Contact

Ducket Limited
Incorporated in Hong Kong SAR
Email: hello@ducket.io

If your question is specifically about privacy or a data request, put "Privacy" in the subject line so we route it quickly.