Legal
Privacy Policy
How Emei Pty Ltd (ABN 63 686 497 469), trading as “tickOver” collects, uses, discloses, and protects personal information across the tickOver platform.
Last updated: 12 September 2026
1. Who we are
This Privacy Policy explains how Emei Pty Ltd (ABN 63 686 497 469), trading as “tickOver” handles personal information in connection with the tickOver platform, available at tickover.com.au (the “Service”). In this policy, “tickOver”, “we”, “us” and “our” refer to Emei Pty Ltd (ABN 63 686 497 469 · ACN 686 497 469), whose registered office is at Burnside Heights VIC 3023, Australia.
tickOver is an all-in-one lead-to-booking growth platform for local service businesses. Our customers are businesses (each a “Customer” or “organisation”) that use tickOver to capture leads, run automated follow-ups, place AI-assisted voice calls, and take bookings.
If you have any questions about this policy or how we handle your personal information, contact us at info@emei.com.au.
2. Information we collect
We collect the following categories of personal information:
- Account & user data. When someone creates or is invited to an account, we collect their name, email address, and authentication details needed to sign in.
- Organisation data. Details about the Customer business, its settings, team members, and configuration within the Service.
- Contacts & leads.Information about the Customer’s contacts and leads — including name, phone number, email address, and custom fields. For trial bookings this can include a child’s name and age where a parent or guardian has provided them (see Children’s data).
- Bookings. Details of bookings made through the Service, such as the session, venue, date/time, and the person the booking is for.
- Call recordings, transcripts & metadata. When AI voice calls are placed or received through Telnyx, we may process call recordings, transcripts, and call metadata (such as phone numbers, timestamps, duration, and outcome).
- Messages. The content and metadata of messages sent or received through the Service, including SMS, WhatsApp, and email.
- Facebook & Instagram Lead Ads data. Where a Customer connects a Meta account and grants permission, we import lead data submitted through Facebook/Instagram Lead Ads (for example, the name and contact details a person entered into a lead form).
- Usage & technical data. Logs and technical information generated when the Service is used (such as IP address, device/browser information, and actions taken), plus cookies used only for authentication and session management (see Cookies).
3. How we use information
We use personal information to:
- provide and operate the Service — lead management, automations, AI-assisted calling, messaging, and online booking;
- act on the instructions and configuration of the Customer business whose account the data belongs to;
- authenticate users, secure accounts, and maintain the integrity of the Service;
- provide support, communicate about the Service, and respond to enquiries;
- monitor, troubleshoot, and improve the reliability and performance of the Service; and
- comply with our legal obligations.
For contacts, leads, bookings, calls, and messages, we process the data on behalf of, and as directed by, the Customer business that collected it.
4. Our roles (processor vs controller)
Our role depends on the type of data:
- Customer CRM data — we act as a processor. For the contacts, leads, bookings, call recordings/transcripts, and messages that a Customer manages in tickOver, the Customer business is responsible for that data (the controller) and we process it on their behalf and under their instructions. If you are a contact or lead of a business that uses tickOver and want to access, correct, or delete your information, please contact that business directly; we will assist them as their processor.
- Account data — we act as controller.For the account and user data used to run the tickOver Service itself (such as account holders’ names, emails, and login details), we act as the controller.
5. Disclosure & sub-processors
We do not sell personal information. We share personal information only with service providers (sub-processors) that help us run the Service, and only as needed to provide it:
- Supabase — database, storage, and authentication.
- Telnyx — voice calling and messaging (including call recordings, transcripts, and SMS).
- Meta Platforms — Facebook/Instagram Lead Ads integration.
- Resend — transactional and outbound email delivery.
- Google — Google Calendar integration, where you choose to connect a calendar: reading your calendar events and appointment bookings, and holding the authorisation that lets us do so.
- Our hosting provider — the virtual private server (VPS) infrastructure the Service runs on.
We may also disclose personal information where required by law, to protect our rights or the safety of others, or in connection with a business transfer (such as a merger or acquisition), subject to appropriate protections.
6. Facebook / Meta data
Where a Customer chooses to connect a Meta (Facebook) account to import Facebook Lead Ads, we request only the permissions needed to import leads. We disclose each one and why we ask for it:
pages_show_list— to identify which Facebook Pages you manage and their lead forms.pages_read_engagement— to read your Page and lead-form metadata needed to import leads.pages_manage_metadata— to subscribe your Page to lead notifications so new leads arrive in real time.leads_retrieval— to retrieve the lead information submitted through your Lead Ad forms.ads_management— to attribute each imported lead to the ad/campaign that generated it.pages_manage_ads— to manage and read the lead-gen forms on the ads associated with your Page.business_management— to list the Pages owned by your Meta Business Portfolio, so you can choose which Page’s lead forms to import. Without it, Meta does not return business-owned Pages at all. We read only the Page list needed for that choice; we do not modify your business settings.
Where a Customer instead connects an Instagram account to import Instagram Lead Ads, we request the same lead-reading permissions above (pages_show_list and leads_retrieval, because the lead form lives on the linked Facebook Page) plus two Instagram-specific permissions:
instagram_basic— to identify the Instagram professional account linked to your Page.instagram_manage_leads— to read the leads submitted through your Instagram Lead Ad forms.
We use these permissions solely to import your own leads into your tickOver account with your permission. You can disconnectthe Meta integration at any time from your tickOver settings, and you may also remove tickOver’s access from your Facebook account’s Business Integrations settings. Once disconnected, we stop retrieving new leads from Meta.
Data deletion. To request deletion of data associated with the Facebook/Meta integration, or of your data generally, see our Data Deletion page.
7. Children's data
tickOver is a business tool and is not directed to children. However, because our Customers include businesses that run trial sessions for children (for example, junior sports or activity classes), a trial booking may include a child’s name and age, provided by a parent or guardian.
Where this information is provided, it is processed only to arrange and manage the trial booking on behalf of the Customer business, and is handled as part of that Customer’s CRM data (for which we act as a processor). We do not use children’s information for marketing.
8. Retention & deletion
We retain personal information for as long as it is needed to provide the Service, for as long as the relevant Customer account remains active, and thereafter as required to meet our legal, accounting, or reporting obligations, or to resolve disputes.
Customer CRM data is retained and deleted according to the instructions of the Customer business. When an account is closed, or on a valid deletion request, we delete or de-identify the associated personal information within a reasonable period, except where we are required to retain it by law. See also our Data Deletion page.
9. Your rights & how to exercise them
Subject to applicable law, you may request to access, correct, or delete the personal information we hold about you. You can exercise these rights by:
- emailing us at info@emei.com.au; or
- using our Data Deletion page.
If you are a contact or lead of a business that uses tickOver, that business controls your information; where we act as a processor we will refer your request to them or assist them in responding. We may need to verify your identity before acting on a request.
10. Australian Privacy Principles & complaints
We handle personal information in accordance with the Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth). If you believe we have mishandled your personal information, please contact us first at info@emei.com.au so we can try to resolve the matter.
If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.
11. Cross-border storage
We tell you where each of our sub-processors (see Disclosure & sub-processors) operates, rather than describing it in general terms:
- Supabase — Australia. Your customer database, uploaded files, authentication records and backups.
- Telnyx — Australia. Call recordings and transcripts, SMS, and voice traffic.
- Resend — Tokyo, Japan. Outbound and transactional email. The message content and delivery records are held there, so any personal information contained in an email we send on your behalf — a name, an appointment time, a venue — is processed and stored outside Australia.
- Our hosting provider — Jakarta, Indonesia. The application server. It processes requests in memory and does not store your data; nothing is written to disk on it.
- Google — outside Australia. Where you connect a Google Calendar, calendar and booking details are read from Google and the connection is authorised there.
- Meta Platforms— outside Australia. Where you connect a Facebook or Instagram account, lead data originates on Meta’s systems before it reaches us.
Where personal information is held or processed overseas, we take reasonable steps to ensure it is handled consistently with the Australian Privacy Principles, including APP 8. If this list changes, this page changes with it.
13. Changes to this policy
We may update this Privacy Policy from time to time. When we do, we will revise the “Last updated” date at the top of this page. Material changes will be communicated through the Service or by other appropriate means.
14. Contact us
For any privacy questions or requests, contact Emei Pty Ltd (ABN 63 686 497 469), trading as “tickOver” at info@emei.com.au.