1. In short
This policy explains what data the Discord bot Patron and its web panel (together, the “Service”) collect, why, how long they are kept, and how to exercise your rights.
The essentials:
- the Service collects only what is needed to run your RP business;
- your data is never sold and never used for advertising;
- you can ask for access to, correction of or deletion of your data at any time;
- the retention periods stated in section 6 are applied automatically, with no manual step.
Processing is carried out in accordance with the General Data Protection Regulation (GDPR) and the French “Informatique et Libertés” Act.
2. Data collected
The Service processes only data relating to Discord and to your server's activity. No civil-status or location data is collected, and no banking data is stored by the Service (see section 3).
The Service never has access to your Discord password or to your private messages.
If you appear in our prospecting records
We identify Discord servers that may be interested in Patron and, to keep track of them, we record the server name, its game platform, a public means of contact and sales notes. This information comes from public sources (open servers, directories, social media): it is not collected from you, which is why we are required to inform you (GDPR art. 14).
No civil-status data, no sensitive data and no browsing data is recorded here. The processing relies on our legitimate interest in making the Service known (art. 6.1.f).
You can ask to be removed at any time, with no need to explain why: contact us (section 11) and your record will be deleted. We then keep only the minimum needed to avoid contacting you again.
3. Payment data
Premium subscription payments are processed by Stripe, a third-party payment provider. Your card details are entered directly in Stripe's secure interface: they never pass through our servers, and Patron stores no banking data.
For each subscription the Service keeps only: the Stripe order identifier, the Discord account holding it, the server or servers it is activated on, and the subscription period. This information is used to switch on paid features, to handle renewal and cancellation, and to deal with support requests.
The processing carried out by Stripe is governed by its own privacy policy.
4. Purposes
This data is processed solely in order to:
- run the bot's features: staff management, hiring, payroll, the till, tickets, time off, discipline, status and messages;
- generate the activity logs requested by the server's administrators;
- produce the HTML transcripts of tickets;
- detect fraud in job submissions (duplicate proof images);
- authenticate web panel users and show them their servers;
- manage Premium subscriptions: activation, renewal, cancellation;
- answer support requests opened from this site;
- record the team's actions in the internal console, for security purposes;
- make the Service known to Discord servers that may be interested;
- keep the Service secure and technically sound.
The legal basis for this processing is performance of the service you requested (GDPR art. 6.1.b) and the publisher's legitimate interest in securing the Service and making it known (GDPR art. 6.1.f). No profiling and no automated decision producing legal effects is carried out.
Where processing relies on legitimate interest — which is the case for sales prospecting and the administration log — you have a right to object which you can exercise at any time (section 8).
5. Storage and security
Data is stored in a SQLite database hosted on a private server, access to which is restricted to the Service's technical team. It passes through no third-party analytics or advertising service.
Reasonable security measures are in place: authenticated server access, permissions re-checked on every panel request (only a server's authorised members can reach its data), an encrypted session cookie, and request rate limiting.
No system is infallible, so we recommend never submitting sensitive or out-of-game personal information through the Service (tickets, job proofs).
6. Retention periods
- RP business data (members, jobs, duty hours, till, configuration): kept for as long as the bot is on the server. Once the bot is removed they are deleted within 90 days at the latest, the delay being there so that a reinstall loses nothing.
- Ticket contents and transcripts : kept until the server deletes them, and no later than 90 days after the bot is removed.
- Panel sign-in session : deleted on sign-out or when the session expires.
- Technical logs and administration log (including IP addresses): kept for a maximum of 12 months for security and diagnostic purposes.
- Product support tickets : kept for 12 months after the ticket is closed, then deleted together with every message attached to it.
- Prospecting records : 3 years from the last contact, in line with the CNIL's recommendation on prospecting. Deleted immediately on request.
- Premium subscription data (Stripe order identifier, period): kept for the duration of the subscription, then for the statutory periods applicable to evidence and accounting.
These periods are not just a statement of intent: they are applied automatically by the Service, which runs a daily purge of data that has reached its limit.
You can request early deletion at any time (see section 8).
7. Data sharing
Your data is not sold. It is not rented, exchanged or passed on to anyone for commercial or advertising purposes.
It is visible only to:
- the authorised members of your Discord server, according to the permissions configured (for example, management can see member profiles and the till);
- the Service's technical team, only where necessary for maintenance or support;
- Stripe, the payment provider, solely as required to process Premium subscriptions (see section 3);
- the competent authorities, only upon a valid legal request.
The Service is built on the Discord Inc. API: your interactions with Discord remain governed by Discord's privacy policy.
8. Your rights (GDPR)
Under the GDPR you have the following rights over your personal data:
- Right of access : obtain a copy of the data concerning you;
- Right to rectification : have inaccurate data corrected;
- Right to erasure : have your data deleted;
- Right to restriction of processing and right to object, under the conditions set out in the Regulation;
- Right to portability of the data you have provided.
To exercise these rights, contact the team through the support Discord server stating your Discord ID and your request. You will receive a reply within one month at the latest.
If, after contacting us, you consider that your rights are not being respected, you can lodge a complaint with the French data protection authority, the CNIL (cnil.fr).
10. Changes
This policy may change, in particular when a new feature is released or the regulations evolve. The last-updated date at the top of the page is then amended, and substantial changes are announced on the support Discord server before they take effect.
If you disagree with the new version, you can stop using the Service and request the deletion of your data.
11. Contact
For any question about this policy or your personal data, contact the team through the support Discord server, linked in the site footer.
For questions about the terms of use of the Service, see the Terms of Use.