Docs

Privacy Policy

Privacy Policy

Last updated: June 30, 2026 Effective: June 30, 2026

Welcome to TixMemo (“we”, “us” or “the App”). We respect your personal data and privacy. This policy explains what information we collect, how we use it, which third-party services may process it, and how you can manage your data.

If you do not agree with this policy, please stop using features that require network access, an account, cloud sync, AI recognition, membership or payment.

1. Scope

This policy applies to the TixMemo app, website and related services. Third-party services such as app stores, payment platforms, cloud storage, AI platforms and map/location providers have their own privacy policies. We only provide them with information necessary for the relevant feature.

2. Information we collect

We follow a data minimization approach and process information only for product functionality, security, compliance and support.

Account and sign-in

When you register, sign in or manage your account, we may process:

  • phone number, email, username, nickname and avatar;
  • encrypted password hashes;
  • SMS/email verification requests and captcha verification;
  • sign-in time, IP address, User-Agent and refresh sessions;
  • device ID, brand/model, OS name/version, app version and distribution channel.

When signing in with a verification code, an unregistered phone number or email may create an account after you accept the Terms and Privacy Policy.

Ticket records and cloud sync

When you create, edit, import, upload or sync records, we may process:

  • show title, time, venue, city/address, seat, price, currency, rating, mood and notes;
  • tags, tag groups, record preferences and badges;
  • ticket stubs, order screenshots, live photos and share images;
  • file hash, size, type, dimensions, file time and necessary EXIF information;
  • local OCR text, AI results, cover images and captions;
  • sync version, deletion markers and update timestamps.

Some data is stored locally on your device. When you sign in and use sync, upload, AI recognition or cloud backup, relevant data is uploaded to our servers and cloud storage.

AI recognition

When you choose AI ticket recognition, we may process:

  • the image or image URL to be recognized;
  • prompts, request parameters and common tag candidates;
  • extracted fields such as title, date, venue, seat, price, ticket platform, category and suggested tags.

The current project calls partner AI capabilities through our server. The configured ticket-recognition provider in the code is Xiaomi MiMo AI. AI recognition runs only when you trigger it. Please do not upload ID documents, bank cards, medical records, children’s personal information or illegal/infringing content.

Location and venue data

When you use nearby venues, venue search, suggestions or geocoding, we may process:

  • coarse or precise location after your permission;
  • search keyword, city, address and coordinates;
  • approximate city/region inferred from server-side IP lookup;
  • venues you create or select, including name, address, city and coordinates.

You can disable location permission in system settings. Nearby venue features may stop working, but other features remain available.

Membership, orders and payments

When you purchase, restore, redeem or claim PRO benefits, we may process:

  • user ID, device ID, membership level and expiry time;
  • product ID, order ID, payment channel, amount, currency and order status;
  • App Store/Google Play purchase sessions, accountToken, transaction ID, StoreKit JWS, Google Play purchaseToken and related receipt-verification data;
  • for non-store builds using Afdian or manual payment assistance, the payment platform and any contact details you provide may process payment-related information under their own rules.

Membership entitlement is based on backend receipt verification and membership status. Refunds, cancellations, billing and subscription management may be handled by Apple, Google, Afdian or the actual payment platform.

Calendar subscriptions

When you enable ICS calendar subscription, we generate a subscription token and may record access count, access time, User-Agent and client type. Anyone with the subscription link may access the calendar feed, so please do not share it publicly.

Support, feedback and deletion feedback

When you contact us, submit feedback or start account deletion, we may process your reason, source, free-text feedback, contact preference, record count and registration age. After account deletion succeeds, free-text deletion feedback is anonymized and disconnected from your user ID, leaving only aggregated fields for product improvement.

Security and logs

To keep the service stable, secure and compliant, we may process request logs, error logs, operation logs, access time, IP address, User-Agent, device data, API status and COS callback events. We try to avoid logging passwords, verification codes, tokens and other sensitive fields.

3. How we use information

We use information to:

  • provide sign-in, account security, profile management, cloud sync and recovery;
  • save, manage, search and display your show records;
  • upload, store, compress, access and clean up files;
  • provide AI recognition, local OCR, venue search, location, calendar subscription and currency display;
  • provide PRO membership, orders, receipt verification, activation codes and entitlement restore;
  • handle support, feedback, deletion requests, disputes and complaints;
  • prevent abuse, attacks, fraud, illegal content and other security risks;
  • meet legal, regulatory, audit and tax requirements.

If we need to use information for a purpose not described here, we will provide notice and obtain consent where required by law.

4. Third-party services and processors

We use our own and associated-project server capabilities, and may integrate the following third-party services or processors. We do not sell your personal data and do not share it for advertising tracking. The current app configuration does not enable uni statistics and does not integrate ad SDKs.

Service/platform Purpose Possible data involved
Own and associated-project server capabilities Verification codes, captcha, AI forwarding, membership, orders, activation codes, location/maps, currency, email/server notices and active statistics User ID, device ID, phone/email, profile snapshot, AI image URL and prompts, order/membership data, location/search data, IP, User-Agent
Tencent Cloud COS, STS and CDN File upload, storage, access, temporary upload credentials and object callbacks Images/files, file metadata, object key, hash, access URL and upload events
Xiaomi MiMo AI via our server Ticket image recognition and field extraction Image content or URL, prompts, tag candidates and request parameters
Apple App Store StoreKit iOS in-app purchases, subscriptions, restore and receipt verification Product ID, transaction ID, StoreKit receipt/JWS, accountToken and subscription/order status
Google Play Billing Google Play in-app purchases, subscriptions, restore and receipt verification Product ID, purchaseToken, order ID, accountToken and subscription/order status
Afdian and other payment platforms Non-store PRO purchase or manual activation Payment order, payment status and contact/account details you submit
Map/location providers via our server Venue search, nearby venues, geocoding and IP location Search keyword, city, address, coordinates and IP
SMS/email providers via our server Verification code delivery for sign-in, binding and deletion Phone number, email, verification scene and delivery status
Operating systems and app stores Camera, photo library, location, file access, app updates and payments Permission state, selected files/location returned by the system and store transaction data

These providers may process necessary logs for service security, fraud prevention, billing or compliance. We require them to process data only within the agreed purpose and scope.

5. Permissions

Permissions are requested when needed, with an in-app scene explanation before the system prompt.

Permission or capability Trigger and data scope Purpose Can be denied / impact Upload or sharing How to revoke
Camera When you choose to take ticket, order, or show photos; reads the camera preview for that action. Create ticket images, OCR/AI recognition material, or show memories. Yes. The camera flow stops; you can enter details manually or choose an existing image. Only images you confirm to save or upload are processed. The camera is not used in the background. Revoke camera access in system settings.
Photo/image read access Selecting images, batch importing images, or uploading ticket photos; reads selected images and necessary metadata. Store ticket photos, AI/OCR recognition, batch organization, and cloud sync. Yes. Image selection, batch import, and image upload stop working. Images you confirm to upload or sync may be sent to cloud storage or AI services. Unselected album content is not uploaded. Revoke photo/media permission in system settings or delete uploaded images.
Photo library write access Saving generated stats, share images, or similar exports. Save generated images to your system photo library. Yes. Saving to photos stops; in-app viewing or system sharing may still work. Written locally and not uploaded just because it is saved. Revoke photo write/photo library access in system settings.
Android storage or media access Reading, caching, uploading, or saving image files on Android. Compatibility for image reads, cache, uploads, and saves across Android versions. Yes. Related image features stop working. Only selected or generated image files are processed. Revoke photo/media access in Android settings.
Android media location access Only when you batch import album images; reads location metadata that may be embedded in EXIF. Help group imported images by place. Yes. Import still works, but location-based grouping is disabled. Used only for import grouping and not separately shared with unrelated third parties. Revoke media-location/photo-location access in system settings.
Location Nearby venues, address completion, and location-related search. Find nearby venues and complete city/address information. Yes. You can enter venue, city, or address manually. Location queries may be processed by our server or map/location providers with minimum necessary data. Revoke location access in system settings.
Install unknown apps on Android Non-Google Play builds when you choose to download and install an official APK update. Install official APK updates. The Google Play flavor removes this permission and uses store updates. Yes. You can update manually from the website or app store. Only opens the system installer or unknown-app settings; no personal data is uploaded. Disable “install unknown apps” for the app in Android settings.

6. Storage, security and retention

We keep information only as long as necessary for the relevant purpose:

  • account, ticket, image, tag and membership data is generally kept while the account exists;
  • orders, transactions, invoices, audit and security logs may be retained as required by law, platform rules or dispute handling;
  • cloud images are deleted or archived based on business references, cleanup policies and backup cycles;
  • after deletion, phone/email identities are held for a 15-day cooldown.

We use reasonable safeguards such as access control, encrypted transmission, token checks, log masking and least-privilege upload credentials. No internet service is completely secure; please protect your account, password and calendar subscription links.

7. Account deletion

You can delete your account in the app via My → Settings → Delete Account. See Account Deletion for details.

After successful deletion:

  • the account is disabled and sessions are removed;
  • you can no longer access cloud records, images, membership benefits or sync for that account;
  • the linked phone/email cannot be used to register again for 15 days;
  • we delete or anonymize account-related personal data according to law, platform rules, backup and cleanup cycles;
  • minimum necessary information may be retained for transactions, security, disputes, compliance or the cooldown period.

Please back up anything you want to keep before deletion. Account deletion is usually irreversible.

8. Your rights

Subject to applicable law, you may:

  • access, correct or supplement account information;
  • delete or modify records, tags and images you created;
  • revoke camera, photo, location and other system permissions;
  • disable or reset calendar subscriptions;
  • delete your account;
  • contact us with privacy questions, complaints or requests.

If an action is not available in the app, contact us using the details below.

9. Children and minors

Users under 18 should use the app under guardian guidance. Children under 14 should use it only with guardian consent and supervision. Please do not upload children’s identity information, contact details or precise addresses in ticket images, notes or feedback. If we discover children’s personal information was processed without proper consent, we will handle it promptly according to law.

10. Illegal or unsafe content

If you upload or distribute illegal, infringing, fraudulent, pornographic, violent, security-harming or otherwise improper content, we may delete content, restrict features, suspend or terminate the account, preserve evidence or report to authorities as required by law.

11. Changes

We may update this policy due to feature changes, third-party service changes or legal requirements. We will post updates on the website, in the app or through other reasonable means. If a change materially affects how personal information is processed, we will provide notice or request consent where required.

12. Contact

For privacy questions, requests or complaints, contact:

  • Email: ticket@hteamwork.com
  • WeChat: hexiyangwxh