Last updated: September 3, 2026
Privacy Policy
Introduction
Epic Design Labs operates Dispatch Tickets. This policy explains how we collect, use, disclose, and safeguard your information when you use our service.
Information We Collect
We collect information that you provide directly to us, including:
- Email addresses from sign-ups and account creation
- Name and company details (optional)
- Ticket content, comments, and attachments via API
- Usage data and API request logs
- Email content from connected Gmail/Google Workspace accounts
- Authentication identifiers (user id, organization id, session and OAuth tokens)
- Order and customer context from connected e-commerce stores, when you connect one
Google API Services - Limited Use Disclosure
What Google Data We Access
When you authorize a Gmail connection, Dispatch Tickets requests permission to:
- Read emails for importing incoming messages
- Send emails for customer replies
- Modify emails for marking processed messages as read
How Google Data Is Used
We use Gmail data to import emails as tickets, match replies using threading headers, send customer responses, and mark processed emails as read. We do not use your Gmail data for advertising purposes, and we do not sell or share your Gmail data with third parties for their own purposes.
Data Storage and Retention
Imported email content becomes ticket data stored in our secure databases. OAuth tokens are encrypted and retained while your connection remains active.
Revoking Access
You can disconnect Gmail anytime through your dashboard settings or Google Account permissions. Upon revocation, we stop accessing Gmail and delete OAuth tokens, but retain previously imported tickets.
Compliance
Our use of Google data adheres to the Google API Services User Data Policy and Limited Use requirements.
AI Assistants and Connectors
Dispatch Tickets can be connected to AI assistants and automation platforms — including Claude, ChatGPT, n8n, Make, and Zapier — through our Model Context Protocol (MCP) server and our public API. These connections are optional and are made by you.
What Is Shared, and With Whom
When you connect one of these platforms and it makes a request on your behalf, the data returned by that request — which may include ticket subjects and bodies, comments, contact names and email addresses, and ticket metadata — is sent to that platform's operator so it can be shown to you or acted on. We share only the data the specific request asks for, scoped to the brands your credential can reach.
Their Handling Is Governed by Their Policy
Once data reaches a connected platform, it is processed under that platform's own privacy policy and terms, not this one. Some operators use submitted content to generate responses and may retain it according to their own retention rules. We do not control that handling, and we do not receive the contents of your conversations with those assistants. Review the operator's policy before connecting.
Your Control
Connections are authorized either with a Dispatch Tickets API key that you create and can revoke at any time, or through OAuth consent that names the organization being shared. You can revoke an API key from your dashboard, and disconnect an OAuth connection from your dashboard or from the connected platform. Revoking stops all further access immediately; it does not recall data already sent to that platform.
No Training on Your Data
We do not use your ticket content, contact data, or email content to train machine-learning models, and we do not sell it or share it with third parties for their own independent purposes.
How We Use Your Information
We use collected data to:
- Provide and maintain our services
- Process transactions and send related information
- Send technical notices and support messages
- Respond to your requests and questions
- Monitor usage patterns to improve our services
Data Storage and Security
Your information is protected through technical and organizational measures on secure servers using encryption. However, no method of transmission over the Internet is 100% secure, and we cannot guarantee absolute security.
Data Retention
We retain information for as long as your account is active, and thereafter as follows:
- Tickets, comments, contacts, and attachments — deleted within 30 days of account closure, unless you delete them sooner from the dashboard or API.
- Deleted tickets — soft-deleted immediately and purged within 30 days.
- OAuth tokens and API keys — deleted immediately on revocation or disconnection.
- API request logs and usage records — retained for 90 days for security, debugging, and abuse investigation.
- Audit logs — retained for 12 months so you can review who changed what.
- Billing records — retained for 7 years where tax and accounting law requires it.
We may retain information longer where necessary to comply with a legal obligation, resolve a dispute, or enforce our agreements.
Third-Party Services We Share Data With
We share information with the service providers below, only to the extent each needs it to perform its function for us. We do not sell personal information, and we do not share it with third parties for their own independent purposes.
- Render — application hosting, PostgreSQL database, and Redis queue (stores ticket and account data)
- Cloudflare — content delivery, edge compute, and R2 object storage for attachments
- Clerk — user authentication, sessions, and organization management
- Stackbe — account provisioning, subscription entitlements, and billing
- Stripe — payment processing (card details go to Stripe directly; we never receive them)
- Resend — outbound email delivery and custom sending-domain verification
- Postmark — inbound email processing
- Google — Gmail and Google Workspace, when you connect a mailbox
- Sentry — error monitoring and application performance data
- AI assistants and automation platforms you choose to connect — see “AI Assistants and Connectors” above
We may also disclose information where required by law, or in connection with a merger, acquisition, or sale of assets, in which case we will give notice before your information becomes subject to a different policy.
Your Rights
You have the right to:
- Access your personal data
- Update or correct your information
- Request deletion of your data
- Request portability of your data
- Withdraw consent at any time
Contact Us
If you have any questions about this Privacy Policy, please contact us.