Privacy Policy
Effective date: 2026-06-06
1. Overview
This Privacy Policy explains how Discfront processes personal data when you use the Discfront website, Discord bot, checkout pages, email flows, payment-provider integrations, dashboards, support channels, webhooks, accounting exports, and related services.
Discfront is a Discord-native commerce platform. Server owners use Discfront to manage shops, products, subscriptions, license keys, role-based access, payment providers, customer notifications, webhooks, support workflows, and accounting exports.
This Policy is intended to be read with the Terms of Service. It does not replace privacy notices that a server owner must provide for its own shop, customers, community, products, or support operations.
2. Controller/operator and contact
For processing described in this Policy as Discfront-controlled processing, the controller is the Discfront operator identified in the applicable order, invoice, account dashboard, signed agreement, public legal-notice page, or other written contracting record for the service.
Privacy contact: contact@discfront.com.
Discfront has not appointed a data protection officer unless a separate legal notice says otherwise. If a data protection officer, EU/EEA representative, or additional privacy contact becomes legally required, Discfront will publish those details and update this Policy.
3. Roles
Discfront may act as:
- a controller for data needed to operate Discfront accounts, platform subscriptions, support, security, fraud prevention, billing, legal compliance, provider reconciliation, service analytics, and service administration;
- a processor or service provider for certain customer/shop data processed on behalf of a Discord server owner;
- an independent controller where Discfront must process data for legal obligations, payment/accounting records, tax documentation, security, abuse prevention, provider reconciliation, dispute handling, or platform operations.
Where a server owner acts as controller and Discfront acts as processor, Discfront processes that data to provide the service, follow documented configuration and operational instructions, maintain security, and comply with law. The Data Processing Terms in the Terms of Service apply unless a separate signed data processing agreement controls.
Server owners are responsible for their own shop, customers, products, support, legal basis, privacy notices, refunds, disputes, tax/accounting duties, and compliance obligations where they decide how and why customer data is processed for their own shop.
4. Personal data we process
Depending on how you use Discfront, we may process:
- Discord identifiers: user id, server id, role ids, channel ids, message ids, interaction ids, usernames, handles, avatars, or mentions where Discord provides them;
- contact data: email address, verification status, support messages, support request references, and service-notice preferences;
- shop and purchase data: product names, product ids, purchase references, subscription status, access status, delivery status, license-key delivery status, renewal status, refund/dispute status, timestamps, currency, amount, customer email where needed for receipts or delivery, and seller/customer support notes;
- payment-provider data: Stripe customer ids, Checkout Session ids, PaymentIntent ids, invoice ids, subscription ids, connected account ids, BTCPay store/payment-request/invoice ids, provider statuses, provider event references, tax totals, provider fees, and provider-returned billing details where available;
- platform subscription and accounting data: plan, billing period, payment status, collected tax, fees, net amounts, country, customer type, buyer name, business name, address, tax id, VAT number, or organization number where collected by the provider;
- configuration data: product settings, policy settings, webhook endpoint metadata, provider connection state, branding package metadata, public URLs, audit settings, API state, and admin-panel state;
- technical and security data: IP addresses where captured by infrastructure, device and browser metadata, request metadata, signatures, timestamps, logs, error details, event ids, retry state, authentication state, and security/audit records;
- email delivery data: email address, template type, send status, provider message id, timestamps, and bounce, delivery, suppression, or complaint status where returned by the email provider.
Discfront does not intentionally store full card numbers, card security codes, wallet private keys, seed phrases, or payment-card authentication credentials. Payment-card data is handled by Stripe or another payment provider. Crypto payments are handled through the configured BTCPay Server or wallet/payment infrastructure.
5. Sensitive data, children, and unsupported data
Discfront is not designed for children and is not intended to knowingly process children's personal data as a direct service. Server owners are responsible for age restrictions and legal compliance for their own communities, products, and buyers.
Discfront does not intentionally request special-category data, health data, biometric data, criminal-offence data, government identity documents, private keys, seed phrases, or other highly sensitive data unless a specific feature expressly supports it and lawful safeguards are in place. Do not submit unsupported sensitive data to Discfront.
If a server owner submits sensitive data or children's data through product descriptions, support messages, webhooks, files, metadata, or other configuration, the server owner is responsible for ensuring the processing is lawful, necessary, properly disclosed, and authorized.
6. Sources of data
We may receive data from:
- you or your Discord interactions;
- the Discord server owner or administrators;
- Discord;
- Stripe, BTCPay Server, banks, card networks, wallets, blockchain infrastructure, or other payment providers;
- Postmark or another email provider;
- support communications;
- configured webhook endpoints, APIs, and integrations;
- hosting, logging, monitoring, security, backup, abuse-prevention, and infrastructure systems.
7. Purposes and legal bases
We process personal data to:
- provide, operate, secure, maintain, and improve Discfront;
- create and manage server setup, products, policies, providers, subscriptions, purchases, access, roles, license-key delivery, renewals, cancellations, webhooks, branding, support workflows, and accounting exports;
- verify contact emails and send service emails, receipts, renewal notices, access notices, support replies, security alerts, and account notices;
- process platform billing, provider events, provider reconciliation, refunds, disputes, and chargeback records;
- calculate, collect, document, reconcile, and report taxes on Discfront platform fees where required;
- prevent fraud, duplicate trials, abuse, unsafe configurations, unauthorized access, provider misuse, security incidents, and illegal activity;
- keep audit logs, event logs, operational records, security records, accounting records, and legal records;
- comply with tax, accounting, legal, provider, dispute, sanctions, regulatory, and enforcement obligations;
- establish, exercise, or defend legal claims.
Legal bases may include performance of a contract, legitimate interests in operating and securing Discfront, compliance with legal obligations, consent where required, and establishment, exercise, or defense of legal claims.
Where we rely on legitimate interests, the interests may include platform operation, service reliability, fraud prevention, abuse prevention, information security, provider reconciliation, product improvement, support, business administration, and protecting Discfront, users, sellers, buyers, and third parties.
8. Required data
Some data is required to use Discfront. For example, Discord identifiers are needed to connect a server, contact email is needed for account notices, payment-provider identifiers are needed for checkout and reconciliation, and buyer email may be needed for receipts, renewals, access notices, or license-key delivery.
If required data is not provided, certain features may not work, purchases may not complete, access may not be delivered, provider reconciliation may fail, or support may be limited.
9. Sharing and service providers
We may share data with:
- payment providers such as Stripe and BTCPay Server;
- Discord;
- email providers such as Postmark;
- hosting, infrastructure, monitoring, logging, security, backup, analytics, and support providers;
- server owners and administrators where needed to operate their shop, provide access, resolve support issues, manage orders, handle refunds or disputes, or satisfy their own customer obligations;
- authorities, courts, lawyers, accountants, auditors, advisers, providers, counterparties, or other parties where required or reasonably necessary for law, provider rules, security, fraud prevention, dispute handling, accounting, tax, enforcement, or legal claims;
- successors or transaction parties in connection with a merger, acquisition, financing, reorganization, sale of assets, change of control, insolvency, or similar transaction, subject to appropriate safeguards.
Providers process data under their own terms and privacy notices where they act as independent controllers, and under service-provider, processor, or subprocessor arrangements where applicable.
Discfront may publish or provide a subprocessor list, security summary, or data-processing documentation separately where required or reasonably requested.
10. International transfers
Some providers or infrastructure services may process data outside Norway, the EEA, or your country. Where required, we rely on appropriate safeguards such as adequacy decisions, standard contractual clauses, provider transfer mechanisms, supplementary measures, or other lawful transfer bases.
Server owners using third-party providers through Discfront are responsible for assessing whether their own use of those providers and transfers is lawful for their shop and customers.
11. Retention
We keep personal data only as long as reasonably needed for the purposes described above, including service operation, accounting, tax, audit, dispute handling, fraud prevention, security, support, provider reconciliation, backup rotation, and legal compliance.
Typical retention depends on the record type:
- account, server, product, purchase, subscription, and provider records: kept while the service relationship is active and for a reasonable period after;
- accounting, tax, invoice, payment, refund, and dispute records: kept for the period required by law or legitimate business needs;
- security, webhook, provider event, provider payload, delivery, access, and audit logs: kept as needed for integrity, duplicate-event protection, replay protection, reconciliation, troubleshooting, support, abuse prevention, accounting exports, tax documentation, dispute handling, provider compliance, and legal claims;
- support records: kept as needed to resolve the request, maintain support history, protect rights, and improve support quality;
- failed, stale, or redundant operational events: deleted, aggregated, or reduced when no longer needed.
Backups may retain data for a limited additional period before rotation or deletion. Deletion requests may be limited where retention is required or permitted for law, tax, accounting, security, provider reconciliation, dispute handling, fraud prevention, or legal claims.
12. Security and incidents
We use technical and organizational measures intended to protect personal data, including access controls, request signing, webhook signing, provider signature checks, duplicate-event protection controls, least-privilege access, operational logging, backup/security procedures, and incident review.
No service can guarantee perfect security. You are responsible for protecting your Discord account, provider accounts, email accounts, wallets, API keys, webhook secrets, admin permissions, devices, local exports, and backup records.
If Discfront becomes aware of a personal-data breach that requires notification, Discfront will handle notification according to applicable law and the role Discfront has for the affected data.
13. Your rights
Depending on your location and relationship to Discfront, you may have rights to:
- access your personal data;
- correct inaccurate data;
- request deletion;
- restrict processing;
- object to processing;
- request data portability;
- withdraw consent where processing is based on consent;
- complain to a data protection authority.
In Norway, the supervisory authority is Datatilsynet. You may also have the right to complain to a supervisory authority in your country or EEA member state.
To make a request, contact contact@discfront.com. We may need information to verify your identity, protect other users, and locate the relevant server, purchase, account, provider record, or support record. Where required, we will respond without undue delay and within the time required by applicable law.
Some requests may need to be handled by the Discord server owner if they are the controller for the shop/customer relationship. If we cannot act directly because we process the data on behalf of a server owner, we may direct the request to that server owner or assist them as appropriate.
14. Customer and buyer requests
If you bought something from a Discord server using Discfront, the server owner is usually responsible for the product sale and customer relationship. Contact the server owner for product support, refunds, access questions, shop-specific privacy requests, cancellation requests, and consumer-rights questions.
Discfront may still process certain buyer data as needed for platform security, provider reconciliation, legal compliance, tax/accounting records, email delivery, dispute handling, abuse prevention, and technical operation.
15. Automated checks
Discfront may use automated checks to help prevent duplicate trials, abuse, fraud, unauthorized access, unsafe configurations, failed provider states, sanctions or provider-risk issues, invalid checkout states, or suspicious activity.
These checks may affect trial eligibility, checkout availability, access delivery, provider availability, admin-panel warnings, product review, or account restrictions. You can contact contact@discfront.com if you believe an automated check is wrong.
Discfront does not intentionally use automated processing to make decisions that produce legal or similarly significant effects about individuals unless disclosed separately or required for security, provider compliance, or legal compliance.
16. Cookies, local storage, and marketing
Discfront public pages may use strictly necessary technical storage for security, routing, login, checkout redirects, fraud prevention, load balancing, preferences, or service operation.
If optional analytics, marketing cookies, advertising pixels, cross-site tracking, or similar tracking technologies are added later, this Policy and any required consent or opt-out flow should be updated before use.
Discfront may send service and transactional communications needed for the service. Marketing communications, if used, should include any legally required consent or unsubscribe mechanism.
17. No sale of personal data
Discfront does not sell personal data. Discfront does not use buyer data for third-party advertising unless this Policy is updated and any required consent or opt-out mechanism is provided.
18. Changes
We may update this Privacy Policy at any time. The updated version applies when posted unless a later effective date is stated.
Material privacy changes will be communicated where required by law or where reasonably practical.
19. Contact
For privacy questions, security reports, or data-protection requests, contact contact@discfront.com.