Privacy Policy
Last updated: February 3, 2026
1. Data controller
Publisher: Individual (France) is the data controller for personal data processing.
2. Scope and international compliance
We apply GDPR requirements (EU/EEA/UK/CH) and, where applicable, US privacy laws (e.g., CCPA/CPRA in California). Specific rules may apply depending on your country or state.
3. Data collected
| Catégorie | Détails |
|---|---|
| Identity and account | Discord OAuth identifiers, user ID. |
| Usage | technical logs, metrics, usage statistics, events. |
| Addons & plugins (FiveM, Garry’s Mod, Minecraft) | heartbeats, player counts, events and logs sent by the bridge, player identifiers (e.g., Steam/Discord/license) and nicknames. |
| Servers | configuration and telemetry related to managed servers. |
| Technical data | bridge/server IP, heartbeat IP, IP enrichment if enabled (country, country code, ISP, VPN detection). |
| Edge SDK (if enabled) | registration and instance state (instance ID, public key, instance name, version, platform, last heartbeat timestamp, heartbeat IP, declared URL/port) to route requests and ensure monitoring. |
| Payments | billing information via our providers (no card storage). |
| Support | tickets, messages and attachments. |
| API & integrations | API keys, webhook endpoints, usage logs and rate limits. |
4. Stored data overview
This overview lists the data we store, including data sent by addons (Bridge). Fields marked as variable payload depend on the enabled addon module.
| Catégorie | Détails |
|---|---|
| Account & profile | Discord ID, username, avatar, role, premium, 2FA status, setup, created/updated dates. |
| Security & sessions | encrypted 2FA secret, session/refresh tokens, revocations. |
| Servers (config) | owner, game, IP, port, domain, name, description, language, public/verified status, social links. |
| Server media | banner/logo files, MIME type, update dates. |
| Server API key | hashed API key, creation/rotation dates. |
| API & webhooks | user API keys, webhook endpoints, secrets, usage logs. |
| Billing | Stripe customer ID, subscription ID, status, periods, invoices and payments. |
| Shared access | server ↔ user relationships, VIEWER role, added date. |
| Bridge (addon presence) | last seen, bridge IP, addon, players/max, map, version. |
| Edge SDK (instance) | instance ID, public key, instance name, version, platform, ONLINE/OFFLINE status, last heartbeat timestamp, last heartbeat IP, declared URL/port, storage capacity, uptime (if provided). |
| Uptime | source (TCP/ADDON), UP/DOWN status, latency, timestamp. |
| Player count | count, source, timestamp. |
| Players (global) | external identifier, known nickname, VPN, country, country code, ISP, seen dates. |
| Sessions per server | join/leave, current session, duration, total playtime. |
| Server events | title, description, creator, dates (start/created/updated). |
| Reviews & reports | ratings, comments, owner replies, reports and reasons. |
| Tags & reputation | tags, helpful votes, score/reputation, dates. |
| Support & messaging | tickets, messages, statuses, dates, assigned agents. |
| Technical caches | online presence, aggregated stats, tag caches (short TTL). |
5. Purposes and legal bases
Service delivery and improvement (contract performance).
Security, fraud prevention and compliance (legitimate interest / legal obligation).
Support and communications (contract or legitimate interest).
Marketing, where applicable (consent when required).
6. Retention
Data is retained for the time necessary for the purposes, then deleted or anonymized. Specific retention periods may apply (billing, legal obligations).
Edge SDK: registration codes are valid for 48 hours. Instance metadata (status, last heartbeat, last heartbeat IP) is kept while the instance is associated with your account (or until deregistration), for security, diagnostics and routing.
Edge SDK local storage: activity data (players/logs/samples) hosted on your Edge SDK instance is stored locally per your configuration. You are responsible for its security, backup and retention on the instance.
7. Sharing and processors
We share data only with necessary providers (hosting, payments, support, email, OAuth) and contractual partners. Examples: Stripe for billing, Discord for OAuth, hosting/CDN providers, email/support vendors.
These providers are bound by confidentiality and security obligations.
8. International transfers
Data transfers outside the EU may occur (e.g., United States). We implement appropriate safeguards (standard contractual clauses, security measures).
9. Security
We apply appropriate technical and organizational measures (access control, encryption, logging, backups). No system is entirely risk-free.
10. Your rights
Depending on your location, you have rights of access, rectification, erasure, restriction, objection, portability, and withdrawal of consent. California users have specific CCPA/CPRA rights (access, deletion, non-discrimination).
11. Cookies and trackers
We use essential cookies for operation and, where applicable, analytics/marketing cookies with your consent. A consent manager may be offered depending on local regulations.
Edge SDK: the software may contact our endpoints for heartbeats and update checks. Auto-update requests include technical parameters (OS/ARCH and current version) and may download a signed binary from our servers.
Plugins/Addons: send API requests from your server to transmit status, logs and player events.
12. Minors
The Services are not intended for persons under 13 years old (or the locally required minimum age). We do not knowingly collect data from minors.
13. Contact and complaints
For any questions, please contact support. EU residents may lodge a complaint with their data protection authority.