CD Creator Bot Deck Legal and policy center
Home Privacy Terms Cookies Discord Login
DATA AND DISCORD API NOTICE

Privacy Policy

How Creator Bot Deck and its Discord bot use dashboard, Discord, store, support, and security data for connected creator servers.

Last updated 15 Jun 2026

Review this page when new dashboard features add new data types, processors, permissions, or retention behavior.

CONTENTS
01Who Controls The Data 02Data We Process 03Why We Process It 04Legal Bases 05Who Can See Data 06Retention 07User Rights And Deletion Requests 08Security 09Children And Sensitive Data 10Changes

Creator Bot Deck is a Discord OAuth dashboard and bot control surface for connected creator servers. It is operated by the bot owner for Starkims VFX / Starkim1999 and by server owners who connect their own storefronts through the dashboard.

This policy explains what data is processed, why it is processed, who can see it, and how users can ask for access, correction, or deletion.

01

Who Controls The Data

For the global bot and dashboard service, the bot owner is the controller. For per-server creator setup, the server owner may also control their own store credentials, webhook routes, product mappings, support configuration, and server-specific bot settings.

Privacy or data deletion requests can be made through the connected Discord server's support channel, the dashboard support panel when available, or by contacting the bot owner account Starkim1999 on Discord.

02

Data We Process

  • Discord account data: user IDs, usernames, global display names, avatar hashes/URLs, owned or visible servers, and OAuth session state.
  • Discord server data: server IDs, names, icons, owner IDs, member counts, role IDs, channel IDs, permissions, and member lists for selected server audits.
  • Storefront data: Gumroad, Jinxxy, and Payhip product records, order or license identifiers, purchase status, mapped Discord user IDs, masked buyer email where needed for support, and entitlement history.
  • Manual upload-order data: Upload Studio product names, thumbnails, customer Discord IDs, receipt IDs, customer-visible timeline entries, internal notes, and manually entered PayPal invoice IDs or links.
  • Bot configuration: welcome, leave-log, daily ping, calendar, product mapping, support, protection, storefront, webhook, and permission settings for each connected server.
  • Support and safety data: support ticket IDs, linked Discord channel IDs, ticket status, action reasons, audit records, blocked invite events, and security warnings.
  • Dashboard security data: signed session cookies, OAuth state cookies, owner-unlock cookies, selected-server browser storage, audit logs, request timestamps, and service logs that may include IP address, path, and user agent.
  • Secrets: per-server store API keys and webhook secrets are stored through the encrypted vault and are not shown back in the dashboard after saving.
03

Why We Process It

  • To sign users in with Discord and show only the servers and tools they are allowed to use.
  • To verify purchases, assign or repair Discord roles, and prevent duplicate or abusive license claims.
  • To operate support tickets, store operations, upload-only avatar receipts, product mappings, welcome messages, daily pings, patch notes, calendar reminders, and invite protection.
  • To keep an audit trail for security-sensitive actions such as role repair, support changes, webhook setup, owner unlocks, and bot-service controls.
  • To detect errors, secure the VPS-hosted service, troubleshoot incidents, and keep the bot available.
04

Legal Bases

Where GDPR or similar privacy law applies, the likely legal bases are performance of the requested service, legitimate interests in operating and securing the bot, consent where a user chooses to sign in or verify a purchase, and legal obligations where records must be retained.

The dashboard does not sell Discord API data, does not build advertising profiles, and does not use Discord API data for unrelated marketing.

05

Who Can See Data

  • The bot owner can access global operational data needed to run and secure the service.
  • A server owner can access data for their own connected server.
  • Configured Store Admins and Support Staff can see limited server-scoped customer or support context according to the permission rules.
  • Discord, Netcup, Gumroad, Jinxxy, Payhip, PayPal when invoice links are used, and related infrastructure providers process data as needed to provide their own services.
  • Data may be disclosed if required to investigate abuse, security incidents, legal requests, or platform-policy violations.
06

Retention

  • Session and OAuth cookies expire automatically and can be removed by signing out or clearing browser cookies.
  • Store entitlements, manual upload-order receipts, product mappings, support records, and audit logs are kept while needed to provide the bot service, prove role grants or upload delivery, resolve support, prevent fraud, or protect the system.
  • Server-specific configuration can be deleted or disconnected when the bot is removed and the server owner requests cleanup.
  • Some minimal records may be retained when needed for security, dispute handling, fraud prevention, accounting, or legal compliance.
07

User Rights And Deletion Requests

Users may request access, correction, export, or deletion of personal data associated with their Discord ID. Requests should include the relevant Discord user ID and server name so the correct records can be located.

If Discord API data was received in error, the bot owner will delete it and, when required, provide proof of deletion. Some records may be retained where deletion would break security logs, fraud prevention, transaction history, or legal obligations.

08

Security

  • Dashboard access uses Discord OAuth instead of a separate password account.
  • Sessions, owner unlocks, and state-changing actions use signed tokens with expiry.
  • Owner-only VPS actions require an extra owner unlock and are audited.
  • Store credentials and webhook secrets use the encrypted vault rather than plaintext database storage.
  • Permissions are scoped by bot owner, server owner, store admin, support staff, moderator, and mass-mention roles.
09

Children And Sensitive Data

The service is not intended for children under Discord's minimum age rules. Users should not submit government IDs, payment card numbers, health data, private passwords, 2FA codes, recovery codes, or other sensitive data into support tickets, patch notes, dashboard fields, or Discord bot commands.

10

Changes

This policy should be updated whenever new dashboard features collect new categories of data, expose data to new permission groups, add new processors, or change retention behavior.

REF

Related Platform Documents

These pages help explain the platform rules this dashboard is designed around.

  • Discord Developer Terms of Service
  • Discord Developer Policy
  • Netcup Data Processing Agreement documentation
Creator Bot Deck
Privacy Terms Cookies