Your Privacy Matters

Privacy Policy

At PatchDesk, we believe your data belongs to you. We are committed to protecting your privacy and maintaining your trust.

Last updated: August 25, 2026

No Third-Party Data Sharing

We do not sell your data. We use a few processors (payments and marketing-site analytics) as described below. Ticket content stays in PatchDesk.

We Do Not View Your Data

Your tickets, bugs, customer conversations, and business data are yours alone. PatchDesk staff will never access or view your content.

Encrypted Storage

All data is stored in encrypted databases. Sensitive information is encrypted at rest using industry-standard encryption algorithms.

Identity Verification Only

Any personal information we collect — such as your name and email address — is used solely to verify your identity and provide you access to your account.

1. Information We Collect

We collect only the minimum information necessary to provide our services and verify your identity:

  • Account information: Your name, email address, and company name, used to create and manage your account.
  • Authentication data: Passwords (stored as irreversible hashes) and multi-factor authentication credentials, used solely to secure your account.
  • Usage data: Basic server logs (IP addresses, browser type, access times) necessary for security monitoring and service reliability. On public marketing pages we also use Google Analytics 4 (see Cookies).

All personal information collected is used exclusively to ensure your true identity and provide you with secure access to PatchDesk.

2. How We Use Your Information

Your information is used strictly for the following purposes:

  • To verify your identity and authenticate your access to PatchDesk.
  • To provide, maintain, and improve our services.
  • To send essential account-related communications (e.g., password resets, security alerts).
  • To process payments through our secure payment processor, Stripe.
  • To understand how people use the public marketing site (Google Analytics 4).

We do not sell your information or use ticket contents for advertising.

3. No Third-Party Sharing

We do not sell, rent, or trade your data.

We use processors only to run the product: Stripe for payments, and Google Analytics 4 on public marketing pages (not the signed-in dashboard or support tickets). Those companies process data under their own policies. Stripe is PCI DSS Level 1 certified.

We will only disclose information if required by law, such as in response to a valid court order or legal process. In such cases, we will notify you unless legally prohibited from doing so.

4. We Do Not Access Your Data

PatchDesk staff will not view, access, or read your customer data. This includes your bug reports, support tickets, customer conversations, internal notes, team communications, and any other content you create within PatchDesk.

Your data is yours. We provide the platform — we do not inspect what you put on it.

5. Data Security & Encryption

We take the security of your data seriously. All data is protected using multiple layers of security:

  • Encryption at rest: All databases are encrypted. Sensitive fields such as personal information are additionally encrypted at the application level.
  • Encryption in transit: All connections to PatchDesk are secured with TLS/SSL encryption.
  • Password security: Passwords are hashed using bcrypt with salt rounds, making them irreversible.
  • Multi-tenant isolation: Row-level security policies ensure that each organization's data is strictly isolated from all others.
  • Multi-factor authentication: Optional MFA via TOTP, email, or SMS adds an additional layer of account protection.

6. Your Rights

You have the right to:

  • Access the personal information we hold about you.
  • Correct any inaccurate information in your account.
  • Delete your account and all associated data.
  • Export your data at any time using our built-in export tools.

To exercise any of these rights, contact us at [email protected].

7. Cookies

PatchDesk uses essential cookies for authentication and session management. On public marketing pages we also load Google Analytics 4 (measurement ID G-1FP4SRPXD0) to see which pages people visit. We do not load Analytics on the signed-in dashboard or customer ticket views, and we do not use advertising cookies.

8. Changes to This Policy

If we make changes to this privacy policy, we will notify you by updating the date at the top of this page. For significant changes, we will provide additional notice via email.

9. Contact Us

If you have any questions about this privacy policy or our data practices, please contact us at:

[email protected]