tickin.pro
Data governance

Data retention & deletion

This page describes how long Tickin keeps customer data and how deletion works today. It reflects the current implementation; where a step is manual rather than automatic, we say so.

What we collect

To run attendance, leave, and payroll, Tickin stores: employee names and emails, department and role, attendance and time entries, leave and overtime records, payroll and salary figures, notification preferences, audit logs, and — when you connect them — Slack and Microsoft Teams user IDs. Passwords are stored only as bcrypt hashes; Slack bot tokens and SMTP credentials are encrypted at rest (AES-256-GCM). See the privacy policy and security overview.

How long active data is retained

While your workspace is active, your data is retained for as long as you keep your account, so the product works. You can edit or remove records (employees, leave, attendance) from within the app at any time.

Tenant retention after suspension (60 days)

If a workspace is suspended (for example, after a lapsed subscription), it enters a 60-day retention window. During that time the data is preserved so you can reactivate without loss, and we send reminder emails as the window progresses. This 60-day period is configurable by us but defaults to 60 days.

Soft deletion

When a workspace or an employee is removed, Tickin first performs a soft delete: the record is marked deleted (a workspace's status becomes deleted with a deletion timestamp; an employee is marked revoked/inactive) and is no longer accessible in the product. Related session, break, and idle records are removed immediately via database cascade.

Permanent deletion

Permanent removal of a workspace's underlying data occurs after the 60-day retention window. When a workspace is closed by its owner, that window is scheduled at the moment of closure and the permanent deletion then runs automatically: the workspace database is dropped, uploaded files (avatars, screenshots, attachments) are deleted from object storage, and chat integration records — including the stored Slack bot token — are removed.

For a workspace suspended for non-payment rather than closed by its owner, the retention window and soft-delete are automated; the final hard-delete of the underlying database is performed as an operational step. If you need a guaranteed, expedited permanent deletion in that case, contact support and we will carry it out.

Records we are required to keep for tax and accounting — invoices, payment records — and our internal audit log are retained after permanent deletion. These identify the account and its transactions, not your employees' HR data.

Backups

Our database (Amazon RDS) is backed up daily with a 7-day retention window. Because backups exist, a copy of your data may persist in a backup for up to that window after deletion, then ages out automatically. We do not represent that data is instantly purged from all backups at the moment of deletion.

When you uninstall Slack

Removing Tickin from your Slack workspace stops all messages and notifications immediately and marks the integration disconnected; the stored bot token is invalidated. Your HR data in Tickin (attendance, leave, payroll) is unaffected. Full detail: Slack data & uninstall.

Requesting deletion

The workspace owner — the person who signed the workspace up — can close the workspace themselves from Settings. Closure is confirmed by typing the workspace name, and takes effect immediately: everyone is signed out at once, no one can sign in again, scheduled reports and payroll emails stop, and the subscription is cancelled so there are no further charges. Any period you have already paid for is not refunded and not cut short.

The underlying data is then retained for the 60-day window described above and permanently deleted at the end of it. During that window the closure can still be reversed — contact support@tickin.pro. After it, the data cannot be recovered.

Individual employees should route deletion requests through their organization's admin (the data controller). Admins who are not the owner, and anyone who prefers not to use the self-service route, can email support@tickin.pro.

Questions? Contact us.