Privacy policy
Last updated 25 August 2026. Tickaboo is operated by Goober Marketing Pty Ltd (ABN 34 694 706 619), Gold Coast, Queensland.
Effective date: 25 August 2026
Issued by: Goober Marketing Pty Ltd (ABN 34 694 706 619), trading as Tickaboo ("Tickaboo", "we", "us")
Privacy contact: privacy@tickaboo.com.au, Clayton Hackett, Privacy Officer
1. The short version
Tickaboo is a photo-safety platform for childcare centres and schools. Everything we store is stored in Australia. There are two upload paths for photos that may contain children. In Photo Library, you blur children's faces yourself on your own device before the photo uploads, and the original photo never leaves your device. In Photo Studio, the original photo is uploaded so it can be edited with our AI tools, and it is automatically deleted by a daily process once it no longer needs to be kept, in practice within roughly a day (section 10). What we do store: your account details, cleared images, and AI-generated synthetic images, all in Australia. Our consent register is not yet available to customers (section 3). AI edits are sent to an offshore processing provider to be performed (section 5); we do not use anything you give us to train AI models, and we are seeking the same written commitment from our provider, which we do not yet have.
2. Who we are and our role
We provide the Tickaboo platform to early childhood services, schools and similar organisations ("Customers"). Customers decide what personal information to enter and which images to process; we handle that information to provide the service, on the Customer's instructions, under our Data Processing Schedule. For our own account, billing and website data, we act in our own right. We apply the Australian Privacy Principles to all personal information we handle, regardless of any small business exemption.
3. What we collect and hold
Account information: name, email, role, organisation details, login records, support correspondence.
Consent register information: the register is designed to hold each child's name, room or class, guardian name and contact details, consent tier and effective dates, and an audit trail of changes, entered by your organisation. The consent register is not yet available. The register screens show a preview only, and no child personal information can be entered or is being collected today. This paragraph describes how the register is designed to work once it launches, and we will review this wording again before then.
Images:
- Cleared images (children removed, blurred, turned away, or no children present) and synthetic AI-generated images: stored in your organisation's media library, in Australia.
- Photo Library (reference photos): if a photo contains children, you circle and blur their faces yourself on your device before it uploads. Only the blurred image is sent to us, and the original never leaves your device. If you instead declare that a photo has no children in it, it uploads as taken.
- Photo Studio: the original photo is uploaded, because the AI treatments on offer there need full-resolution source. The original is held only until it is de-identified and saved as a cleared image, or until it is removed by our automated retention process, whichever happens first. That process runs once a day, so in practice an original can be held for up to roughly 24 to 30 hours before deletion, not instantly. See section 10 for detail. Where you use AI editing on a Photo Studio image, see section 5 for what leaves Australia.
- Every save is checked: images cannot be saved to your library until detected faces are resolved (de-identified, or confirmed as a consenting adult), and the person saving confirms this. That confirmation is recorded in the audit trail.
Usage and analytics: we use Google Analytics on the customer app to understand how the product is used, with identifiers removed from page paths before they are sent (section 7). PostHog product analytics is built into the app but is currently switched off in production, so no data flows to PostHog today. If we switch it on we will update this policy and the subprocessor list first.
Billing: payments run through Stripe. Your card details are entered on Stripe's own secure checkout page and are never collected, transmitted or stored by Tickaboo. We hold only a Stripe customer reference, your subscription plan and status, and billing period dates.
4. Where data lives
All stored data is hosted in Australia (Supabase, Sydney region). Our website and application are delivered through Vercel's global content network. Beyond storage, some data is also sent to service providers outside Australia so parts of the service can run: images are sent to our AI processing provider during AI edits (section 5), and account, support and usage data may be sent to our email and analytics providers (section 7). The content you store with us, however, is held in Australia at all times.
5. AI processing overseas (the part that leaves Australia)
When you choose an AI editing treatment in Photo Studio (for example remove, turn away, illustrate, or adding synthetic children to a scene), we send the whole photo to our AI processing provider, Replicate, Inc. (USA), to perform the edit. The edit regenerates the image as a whole, so this applies however many people you have marked. Where your organisation has added reference photos, a brand logo, or a crest or mascot, those may also be sent alongside the prompt so the output matches your brand. Because the whole image is regenerated, detail outside the people you marked can also change in the result; you review and accept every output before it is saved. This is offshore processing. It is not processing in Australia, and any earlier claim that all processing happens in Australia was wrong and has been withdrawn.
Replicate's published documentation states that predictions made through its API, which is the only way Tickaboo calls Replicate, are automatically deleted after around an hour by default. We have not yet had that retention behaviour, Replicate's processing location, or a no-training commitment confirmed to us in writing, so we do not present those as guaranteed facts. We are seeking a signed data processing agreement covering them, and we will update this policy when we have it.
We do not use anything you send us to train any AI model. That is a commitment about our own conduct and does not depend on the confirmation above. On-device blur, used in Photo Library, involves no transmission of the original photo at all. If we change providers or bring this processing onshore, we will update this policy and our public subprocessor list before the change takes effect.
By using AI editing treatments on a photo that includes a child, your organisation confirms it holds guardian consent that covers this offshore processing (our consent form templates include it).
6. Purposes
We use personal information to: provide and secure the service; once the consent register is live, run publish checks against it and generate audit reports for your organisation; process payments through Stripe; provide support; send service and (with consent) marketing communications; measure and improve the product; and meet legal obligations. We do not sell personal information, do not use it for advertising to children, and never use Customer content to train AI models on our side of the pipeline (see section 5 for the position on our provider's side, which is pending written confirmation).
7. Disclosure and subprocessors
We disclose personal information only to the service providers needed to run Tickaboo, listed with locations and purposes in our public Subprocessor List: Supabase (hosting and storage, Sydney, Australia), Vercel (application and website delivery, global network), Replicate (AI image processing, USA, see section 5), Resend (transactional email, USA), Stripe (payments, card details are entered on Stripe's own checkout page and never reach us), and Google Analytics (usage analytics on the customer app, with account, centre and photo identifiers removed from page paths before anything is sent; a Meta advertising pixel also runs on the customer app and is suppressed entirely on any page whose address contains an identifier). PostHog product analytics is integrated but switched off in production; if enabled it would be hosted in the United States, and we will update this list before enabling it. Each provider is bound by contract to handle data only for the stated purpose, and we also disclose information where the law requires it.
8. Automated processes
Once the consent register is live (it is not yet, see section 3), the publish check will automatically compare tagged content against it and can block an export. A human at your organisation always makes the final call; the check is a gate, not a decision-maker about any child. Face detection runs on your device to find faces so they can be de-identified. It only detects that a face is present in an image. It does not identify who the face belongs to, it does not match a face against any other face or against any record, no biometric template is created, stored or transmitted, and no image data leaves your device for this step. Tickaboo has no facial recognition or face-matching capability in the product today; nothing in the system links a detected face to a named child.
9. Security
Current technical measures include encryption in transit and at rest via our infrastructure providers; database-level row-level security that keeps each organisation's data isolated from every other organisation (verified in our own testing); private, non-public storage buckets; optional two-factor authentication on customer accounts, enforced for our own administrative access once enrolled; bot detection on sign-up and sign-in; rate limiting on authentication and spend-sensitive actions; location metadata (EXIF and GPS) stripped from every uploaded photo; and an append-only audit trail that cannot be edited, even by us. If a breach is likely to result in serious harm we will notify affected organisations and individuals and the OAIC as required.
10. Retention and deletion
Photo Library originals blurred on-device: never uploaded, so never held by us at all. Photo Studio originals: held only until they are de-identified and saved as a cleared image, or removed by our automated daily retention process, whichever comes first. Because that process runs once a day, the practical worst case today is roughly 24 to 30 hours, not immediate deletion, and we do not publish a shorter specific window than that until it is true. Consent register records: once the register is live (section 3), retained while your organisation uses the service, and destroyed or de-identified within 30 days of a child's record being deleted, or within 30 days of account closure. Cleared and synthetic images: retained until you delete them or close your account. Deleting a photo removes its database record, its versions, its stored files and its thumbnail. Account and billing records: retained as required by tax and corporate law (generally 7 years). Deletion includes storage objects.
11. Access, correction and complaints
Once the consent register is live (section 3), guardians will be able to access or correct their child's register information through their centre or school, or by contacting us directly so we can coordinate with the organisation. You can contact our Privacy Officer at privacy@tickaboo.com.au. If you are unsatisfied with our response you can complain to the Office of the Australian Information Commissioner (oaic.gov.au, 1300 363 992).
12. Cookies and analytics
The app uses strictly necessary cookies, Google Analytics (with identifiers removed from page paths before they are sent) and a Meta advertising pixel that is suppressed on any page whose address contains an account, centre or photo identifier. Neither runs on our admin systems.
13. Children
Tickaboo is a tool for organisations and their staff; children do not use it. Information about children reaches us only from Customer organisations, which are responsible for obtaining guardian consents. We apply heightened protection to all children's information, consistent with the Australian Privacy Principles and, once registered, the Children's Online Privacy Code.
14. Changes
We will post changes here and notify account holders of material changes before they take effect.