Discfront

Privacy Policy

Effective date: 2026-06-06

1. Overview

This Privacy Policy explains how Discfront processes personal data when you use the Discfront website, Discord bot, checkout pages, email flows, payment-provider integrations, dashboards, support channels, webhooks, accounting exports, and related services.

Discfront is a Discord-native commerce platform. Server owners use Discfront to manage shops, products, subscriptions, license keys, role-based access, payment providers, customer notifications, webhooks, support workflows, and accounting exports.

This Policy is intended to be read with the Terms of Service. It does not replace privacy notices that a server owner must provide for its own shop, customers, community, products, or support operations.

2. Controller/operator and contact

For processing described in this Policy as Discfront-controlled processing, the controller is the Discfront operator identified in the applicable order, invoice, account dashboard, signed agreement, public legal-notice page, or other written contracting record for the service.

Privacy contact: contact@discfront.com.

Discfront has not appointed a data protection officer unless a separate legal notice says otherwise. If a data protection officer, EU/EEA representative, or additional privacy contact becomes legally required, Discfront will publish those details and update this Policy.

3. Roles

Discfront may act as:

Where a server owner acts as controller and Discfront acts as processor, Discfront processes that data to provide the service, follow documented configuration and operational instructions, maintain security, and comply with law. The Data Processing Terms in the Terms of Service apply unless a separate signed data processing agreement controls.

Server owners are responsible for their own shop, customers, products, support, legal basis, privacy notices, refunds, disputes, tax/accounting duties, and compliance obligations where they decide how and why customer data is processed for their own shop.

4. Personal data we process

Depending on how you use Discfront, we may process:

Discfront does not intentionally store full card numbers, card security codes, wallet private keys, seed phrases, or payment-card authentication credentials. Payment-card data is handled by Stripe or another payment provider. Crypto payments are handled through the configured BTCPay Server or wallet/payment infrastructure.

5. Sensitive data, children, and unsupported data

Discfront is not designed for children and is not intended to knowingly process children's personal data as a direct service. Server owners are responsible for age restrictions and legal compliance for their own communities, products, and buyers.

Discfront does not intentionally request special-category data, health data, biometric data, criminal-offence data, government identity documents, private keys, seed phrases, or other highly sensitive data unless a specific feature expressly supports it and lawful safeguards are in place. Do not submit unsupported sensitive data to Discfront.

If a server owner submits sensitive data or children's data through product descriptions, support messages, webhooks, files, metadata, or other configuration, the server owner is responsible for ensuring the processing is lawful, necessary, properly disclosed, and authorized.

6. Sources of data

We may receive data from:

7. Purposes and legal bases

We process personal data to:

Legal bases may include performance of a contract, legitimate interests in operating and securing Discfront, compliance with legal obligations, consent where required, and establishment, exercise, or defense of legal claims.

Where we rely on legitimate interests, the interests may include platform operation, service reliability, fraud prevention, abuse prevention, information security, provider reconciliation, product improvement, support, business administration, and protecting Discfront, users, sellers, buyers, and third parties.

8. Required data

Some data is required to use Discfront. For example, Discord identifiers are needed to connect a server, contact email is needed for account notices, payment-provider identifiers are needed for checkout and reconciliation, and buyer email may be needed for receipts, renewals, access notices, or license-key delivery.

If required data is not provided, certain features may not work, purchases may not complete, access may not be delivered, provider reconciliation may fail, or support may be limited.

9. Sharing and service providers

We may share data with:

Providers process data under their own terms and privacy notices where they act as independent controllers, and under service-provider, processor, or subprocessor arrangements where applicable.

Discfront may publish or provide a subprocessor list, security summary, or data-processing documentation separately where required or reasonably requested.

10. International transfers

Some providers or infrastructure services may process data outside Norway, the EEA, or your country. Where required, we rely on appropriate safeguards such as adequacy decisions, standard contractual clauses, provider transfer mechanisms, supplementary measures, or other lawful transfer bases.

Server owners using third-party providers through Discfront are responsible for assessing whether their own use of those providers and transfers is lawful for their shop and customers.

11. Retention

We keep personal data only as long as reasonably needed for the purposes described above, including service operation, accounting, tax, audit, dispute handling, fraud prevention, security, support, provider reconciliation, backup rotation, and legal compliance.

Typical retention depends on the record type:

Backups may retain data for a limited additional period before rotation or deletion. Deletion requests may be limited where retention is required or permitted for law, tax, accounting, security, provider reconciliation, dispute handling, fraud prevention, or legal claims.

12. Security and incidents

We use technical and organizational measures intended to protect personal data, including access controls, request signing, webhook signing, provider signature checks, duplicate-event protection controls, least-privilege access, operational logging, backup/security procedures, and incident review.

No service can guarantee perfect security. You are responsible for protecting your Discord account, provider accounts, email accounts, wallets, API keys, webhook secrets, admin permissions, devices, local exports, and backup records.

If Discfront becomes aware of a personal-data breach that requires notification, Discfront will handle notification according to applicable law and the role Discfront has for the affected data.

13. Your rights

Depending on your location and relationship to Discfront, you may have rights to:

In Norway, the supervisory authority is Datatilsynet. You may also have the right to complain to a supervisory authority in your country or EEA member state.

To make a request, contact contact@discfront.com. We may need information to verify your identity, protect other users, and locate the relevant server, purchase, account, provider record, or support record. Where required, we will respond without undue delay and within the time required by applicable law.

Some requests may need to be handled by the Discord server owner if they are the controller for the shop/customer relationship. If we cannot act directly because we process the data on behalf of a server owner, we may direct the request to that server owner or assist them as appropriate.

14. Customer and buyer requests

If you bought something from a Discord server using Discfront, the server owner is usually responsible for the product sale and customer relationship. Contact the server owner for product support, refunds, access questions, shop-specific privacy requests, cancellation requests, and consumer-rights questions.

Discfront may still process certain buyer data as needed for platform security, provider reconciliation, legal compliance, tax/accounting records, email delivery, dispute handling, abuse prevention, and technical operation.

15. Automated checks

Discfront may use automated checks to help prevent duplicate trials, abuse, fraud, unauthorized access, unsafe configurations, failed provider states, sanctions or provider-risk issues, invalid checkout states, or suspicious activity.

These checks may affect trial eligibility, checkout availability, access delivery, provider availability, admin-panel warnings, product review, or account restrictions. You can contact contact@discfront.com if you believe an automated check is wrong.

Discfront does not intentionally use automated processing to make decisions that produce legal or similarly significant effects about individuals unless disclosed separately or required for security, provider compliance, or legal compliance.

16. Cookies, local storage, and marketing

Discfront public pages may use strictly necessary technical storage for security, routing, login, checkout redirects, fraud prevention, load balancing, preferences, or service operation.

If optional analytics, marketing cookies, advertising pixels, cross-site tracking, or similar tracking technologies are added later, this Policy and any required consent or opt-out flow should be updated before use.

Discfront may send service and transactional communications needed for the service. Marketing communications, if used, should include any legally required consent or unsubscribe mechanism.

17. No sale of personal data

Discfront does not sell personal data. Discfront does not use buyer data for third-party advertising unless this Policy is updated and any required consent or opt-out mechanism is provided.

18. Changes

We may update this Privacy Policy at any time. The updated version applies when posted unless a later effective date is stated.

Material privacy changes will be communicated where required by law or where reasonably practical.

19. Contact

For privacy questions, security reports, or data-protection requests, contact contact@discfront.com.