Ticket Sync

Privacy Policy

Last updated: 21 August 2026

Ticket Sync is a Figma plugin that displays tickets from Jira, ClickUp, monday.com, Notion, Linear, GitHub, Asana and GitLab inside Figma files. This policy explains what the plugin and this website do with personal data, and what they deliberately do not do.

The short version

1. Who is responsible

The controller within the meaning of the GDPR is:
Lukas Bittner
Oststraße 7
48465 Schüttorf
Germany
lukas.ticketsync@gmail.com

A data protection officer is not required under Art. 37 GDPR and has not been appointed. Please send any privacy request to the address above.

2. What the plugin processes

2.1 Connecting your ticket tool

To read your tickets, the plugin needs your permission for the tool you use. You grant it in that tool's own consent screen (Atlassian, ClickUp, monday.com, Notion, Linear, GitHub, Asana or GitLab), or by entering an API token you created there yourself.

During the connection the resulting access token is briefly held in our database so the plugin can pick it up. It is deleted as soon as the plugin retrieves it, and in any case after five minutes - a scheduled job removes anything left over from an interrupted connection. After that the token lives only on your device, in Figma's plugin storage (clientStorage), which is tied to your Figma account and is not part of the design file. Sharing a Figma file therefore never shares your token. Disconnecting in the plugin's settings deletes it.

2.2 Displaying and syncing tickets

Figma plugins cannot call external APIs directly, so every request runs through our proxy server. For each request we process:

None of this is written to a database. The proxy holds it in memory for the duration of the request, forwards it to Figma and forgets it. Requests go only to the ticket tool you connected, always over an encrypted HTTPS connection, and only a fixed list of headers is passed on. If a request fails, the error message returned by your ticket tool may appear in our server logs (see section 6).

Your Figma user ID is used for one purpose: checking whether a Pro license applies to you. It is a pseudonymous identifier assigned by Figma; we cannot derive your name or email from it.

2.3 No third-party content

The plugin's interface loads nothing from third parties. Fonts and icons are bundled into the plugin itself, and the only address the plugin is permitted to contact is our own proxy server, declared in the plugin manifest that Figma enforces.

3. Buying a license

Payments are handled by Paddle.com Market Limited, which acts as merchant of record and is the seller of the license. Paddle collects your name, billing address, payment details and tax information; we never receive or store your payment details. See Paddle's privacy policy.

From Paddle we receive and store: your email address, the subscription ID and Paddle customer ID, the plan, its status, the next billing date and the cancellation date if you cancel. We generate a license key and email it to you. When a license is activated we additionally store the Figma user ID it was activated for - or, for a domain license, the identifier of your ticket tool workspace - so that the plugin can recognise the license later.

4. This website

The site is hosted on Firebase Hosting. The hosting provider records standard server log data, including your IP address, the page requested, the time and your browser's user agent. This is necessary to deliver and secure the site.

Paddle's checkout script is loaded only when you actually open the checkout, and it may then set cookies that are necessary to process the purchase. If you never start a purchase, no such script runs and no cookies are set. The site uses no analytics, no advertising and no tracking cookies.

5. Legal bases

Processing Legal basis
Connecting your ticket tool, fetching and displaying tickets Art. 6(1)(b) GDPR - performing the contract you enter into by using the plugin
Handling your subscription, sending your license key Art. 6(1)(b) GDPR - performing the contract
Checking whether a license applies to you Art. 6(1)(f) GDPR - our legitimate interest in only providing paid features to paying customers
Server logs, protecting the service against abuse Art. 6(1)(f) GDPR - our legitimate interest in a secure, functioning service
Keeping accounting records Art. 6(1)(c) GDPR together with German tax and commercial law

6. Who we work with

We use the following processors and service providers. We do not sell personal data, and we do not pass it to anyone else unless we are legally obliged to.

Provider Purpose Location
Google (Firebase) Hosting of this website, the proxy server and the license database; server logs Database in the EU (Belgium); proxy servers and hosting in the USA
Google (Gmail) Sending license keys and replying to support requests EU / USA
Paddle.com Market Limited Payment processing, invoicing, tax United Kingdom
Figma, Inc. The platform the plugin runs in. Your use of Figma is governed by Figma's own privacy policy. USA

Your ticket tool - Atlassian, ClickUp, monday.com, Notion, Linear, GitHub, Asana or GitLab - is not our processor. You have your own relationship with them, and their privacy policy governs the data you keep there.

7. Transfers outside the EU

Our proxy server and the website's hosting run on Google infrastructure in the United States; the license database is located in the EU. For transfers to the USA we rely on the EU Commission's Standard Contractual Clauses and, where the provider is certified, on the EU-US Data Privacy Framework. The United Kingdom, where Paddle is based, is covered by an adequacy decision of the EU Commission.

8. How long we keep things

Data Retention
Ticket content Not stored - held in memory for the length of a request
Access token on our server (during connection only) Until the plugin collects it, at most 5 minutes
Access token on your device Until you disconnect in the plugin settings or remove the plugin
Server logs Roughly 30 days, then deleted by the hosting provider
Subscription and license records For as long as the subscription exists, and afterwards for as long as German tax and commercial law require us to keep the related records (generally 6 to 10 years)
Support emails Until the matter is settled, then deleted periodically

9. Ticket data and who is responsible for it

When you sync a ticket, the content may contain personal data about other people - the assignee, the reporter, people mentioned in a description. For that content your employer or client is the controller and we act only on your instructions, as a processor. We do not store it, we do not analyse it and we never use it for our own purposes.

If your organisation needs a data processing agreement under Art. 28 GDPR before using the plugin, write to lukas.ticketsync@gmail.com and we will provide one.

10. Your rights

Under the GDPR you have the right to:

Email lukas.ticketsync@gmail.com and we will answer within one month.

You also have the right to complain to a supervisory authority. The authority responsible for us is Die Landesbeauftragte für den Datenschutz Niedersachsen, Prinzenstraße 5, 30159 Hannover, Germany. You may also complain to the authority where you live or work.

11. Children

Ticket Sync is a professional tool and is not directed at children. We do not knowingly process data of people under 16.

12. Changes to this policy

We update this policy when the plugin or the services behind it change. The date at the top always shows the current version. If a change materially affects how we handle your data, we will point it out in the plugin or by email to license holders.

13. Contact

Lukas Bittner, Oststraße 7, 48465 Schüttorf, Germany
lukas.ticketsync@gmail.com