01Who is responsible for your information
Andrew Cook (sole trader), trading as GuildPay, operates this service from the United Kingdom.
Privacy requests and complaints: [email protected].
The operator is responsible as a controller for GuildPay’s own account administration, marketplace operations, security and business records. Sellers, developers, Discord and payment providers also make decisions about information for their own services. Their privacy notices apply to those uses.
Developer-supplied data can involve different responsibilities depending on the integration and its purposes. Where we handle information solely on another controller’s instructions, the relevant processing contract and that controller’s notice apply alongside this explanation. Contact us if you need to identify who is responsible for a particular record.
This notice applies to website visitors, buyers, administrators, developers and people whose information is supplied to GuildPay through an integration. It does not authorise a seller or developer to use your information for unrelated purposes.
02Information we collect
| Information | Examples and source |
|---|---|
| Discord account and sign-in | Discord ID, username/display name, avatar and other profile fields returned by the permissions you authorise, locale, OAuth access and refresh tokens, session information. Discord supplies this information when you sign in. |
| Server and workspace information | Server IDs, names, images, ownership and management permissions, server features and counts, GuildPay bot membership, channel and role metadata, and your pinned servers. This comes from Discord, the bot and your workspace choices. |
| Seller payout connections | Administrator and server IDs, account or merchant identifiers, selected business country, contact details returned by the provider, onboarding and capability status, referral/consent references and relevant timestamps. Stripe or PayPal supplies verification status. |
| Customers, checkouts and payments | Customer references, server/plan/price IDs, amount, currency, provider references, checkout and return URLs, payment/refund/dispute status, subscription periods and cancellation or collection-pause status. These come from checkout, payment providers and integrations. Provider notifications can also contain payer contact or billing information. |
| Developer tools | API key names, prefixes, permission scopes and hashes, creator and usage timestamps, webhook URLs and event selections, encrypted signing secrets, request history, event payloads, delivery attempts and outcomes. |
| Content and uploads | Storefront, plan and group descriptions, benefits, public images and URLs, and settings you supply. Uploaded files may include embedded metadata; do not upload information you do not intend to publish. |
| Technical information and communications | Request identifiers, API paths and status, timestamps, network/browser information received by infrastructure, analytics statistics, and the contents and contact details of support or privacy correspondence. |
For a GuildPay storefront purchase, the customer identifier is linked to your authenticated Discord account. A third-party bot or website can instead supply its own customer identifier, order reference and metadata. Those identifiers may relate to you even when they are not your Discord ID.
Payment details are entered through the payment provider’s checkout. GuildPay does not ask you to send card security codes and does not store full card numbers in its application databases. We do receive payment records and provider notifications; payment-related personal information is not limited to a transaction ID.
The bot uses server information for access and administration. The current service does not read Discord message content or message history to operate memberships.
03Why we use it and our lawful bases
| Purpose | Lawful basis |
|---|---|
| Provide your sign-in, workspace, storefront and requested platform features | Contract where you are personally party to our service agreement; legitimate interests in administering services for an organisation where you act on its behalf. |
| Coordinate checkout and maintain payment/subscription records | Contract where needed for services requested directly by you; legitimate interests in recording and reconciling seller-customer transactions, including where a developer supplies your identifier; legal obligation where applicable financial or tax duties require records. |
| Deliver authorised APIs and webhooks and troubleshoot integrations | Contract for the administrator’s or developer’s service; legitimate interests in reliable delivery, reconciliation and supporting the relevant customer relationship for other affected individuals. |
| Protect accounts, prevent misuse and resolve payment or legal disputes | Legitimate interests in protecting users, the service and lawful transactions; legal obligation where disclosure or retention is legally required. |
| Respond to support requests, privacy requests and complaints | Contract or legitimate interests for service support; legal obligation for applicable data protection duties. |
| Understand basic public-site usage through analytics | Legitimate interests in understanding and improving the public website, subject to your objection and any storage/access rules that apply. Consent will be sought before any non-exempt tracking is introduced. |
Our legitimate interests are providing reliable marketplace tools, maintaining accurate records, preventing fraud and misuse, responding to enquiries and improving the public site. We must balance these interests against your rights, including the needs of younger users. Consent is used only where actually requested; Discord authorisation and payment authorisation are not general consent to all processing.
You can browse public pages without supplying a Discord account. Sign-in information is needed to authenticate a workspace or a storefront purchase. Payment and relevant customer references are needed to reconcile a purchase. If the necessary information is not supplied, the corresponding service cannot be provided.
05Public storefronts and images
A seller’s published storefront, plan/group details, prices and images are visible to visitors. Do not include private customer information in these fields. Uploaded images are public resources and can be cached by browsers and content delivery services. Upload processing does not automatically remove embedded image metadata.
Removing an image URL from a listing stops that listing referring to it; it does not necessarily erase the stored file or copies already cached. Contact us for an image-removal or privacy request. External image hosts control their own copies and logs.
07Basic analytics and your choice
We use Rybbit on public information pages to understand visits and improve the website. Analytics requests go to rybbit.rankcord.com, on infrastructure located in the United Kingdom. It is configured for basic cookieless statistics, without session recordings, named-user identification or optional raw-IP tracking.
Statistics can include the page visited, time, referral source, browser/device information and approximate location. Rybbit can derive pseudonymous visitor or session identifiers from network and browser information. Cookieless does not mean that no information is processed. We do not use these statistics to target advertising or decide who may buy a plan.
Analytics is excluded from workspace, sign-in and storefront checkout pages. We respect this browser’s opt-out preference and supported Do Not Track or Global Privacy Control signals. You can object to analytics using the control below without losing platform access.
This choice is saved only in this browser for this website. Changing it reloads the page. It does not affect essential sign-in or security cookies.
Checking your browser preference…
Analytics retention depends on the continuing need to understand public-site usage, compare trends and improve the service. These records are separate from your sign-in session. Contact us to request information about retained statistics or to exercise your rights.
For the software’s operation, see Rybbit’s privacy information. GuildPay’s own deployment settings and retention determine how our statistics are handled.
08How long records are kept
Information is kept for the purposes described above, taking into account the account or customer relationship, ongoing subscriptions, support needs, applicable legal and accounting duties, dispute periods and proportionate security needs. Closing a session or deleting a listing is not the same as deleting all related records.
| Record | Current retention and deletion behaviour |
|---|---|
| Sign-in records and cache | The session cookie lasts up to 24 hours. Logging out removes the stored Discord sign-in profile, OAuth token records and current user-server cache. Other records linked to your account are separate. |
| Payment, checkout, subscription and customer history | Retained for ongoing memberships, reconciliation and necessary legal/dispute records. These records do not currently have automatic expiry. A deletion request is assessed against the continuing purpose and legal duties. |
| Developer API request history | Kept as the project’s request history while the integration is operated. It currently has no automatic expiry. It remains after key revocation; a request to close the project or erase personal data requires a separate review. |
| Webhook event payloads and delivery attempts | Outgoing developer events and delivery records, and incoming PayPal event payloads, are normally eligible for automatic deletion after 30 days. Database expiry processing is asynchronous. Separate transaction ledgers remain. |
| Stripe event receipts and configuration history | Event identifiers/status, API-key revocation records and related operational history currently have no automatic expiry. Retention depends on reconciliation, preventing duplicate processing, account administration and justified security needs. |
| Uploaded media and cached copies | Files remain until separately removed; removing a listing URL does not delete an upload. Public cache directives can allow copies for up to one year. Backup and cache deletion need separate handling. |
| Correspondence and infrastructure logs | Kept according to the support, security, legal or operational purpose. Retention depends on the time needed to handle the enquiry or incident, resolve any related dispute and meet applicable legal duties. Log and backup rotation is managed separately from the application. |
Where information no longer has a justified purpose, it should be deleted or anonymised. A request may require retaining a limited record to demonstrate compliance, handle a dispute or meet a legal duty. We will explain any applicable reason for retaining data when responding.
The table distinguishes automatic expiry from records that need separate review and removal. Contact us for information about a particular record or a deletion request.
09UK hosting and international transfers
GuildPay’s core application, database, cache and analytics infrastructure is located in the United Kingdom. This does not mean that every recipient processes information only in the UK. Payment providers, Cloudflare, Google and browser resource hosts can operate internationally. A seller’s external integration or webhook destination may also process information outside the UK.
Where GuildPay is responsible for a restricted international transfer, a lawful transfer route is required, such as a relevant adequacy decision or appropriate contractual safeguards and the required assessment. Each provider’s role and contract determine the arrangements. You can request information about applicable destinations and safeguards by contacting [email protected].
10Security and automated checks
GuildPay uses permission checks, scoped API keys, signed webhook verification, request limits and other controls to protect its service. API key values are stored as hashes, and stored webhook signing secrets are encrypted. This does not mean that every record is encrypted at application level or that any service is risk-free. Protect your own credentials and report suspected misuse promptly.
The service automatically checks plan availability, inventory, prerequisites, duplicate purchases, server permissions and rate limits. Provider-confirmed payment status affects recorded access. These checks can prevent or delay checkout. They do not assess your creditworthiness, and GuildPay does not use analytics to make eligibility decisions. Providers may run their own fraud and financial checks under their notices. Contact support if you believe a check has produced an incorrect result.
11Younger users
Administrators and developers must be at least 18. Buyers must be at least 13, meet any higher applicable Discord or provider age requirement, and obtain parent or guardian permission where required. We do not knowingly offer the service to children below that minimum.
We do not use basic analytics to target advertising to younger users. Sellers and developers must provide age-appropriate explanations and collect only information needed for their plans. If you are a parent or guardian and believe a child’s information has been handled improperly, contact [email protected]. The minimum age is a service rule, not a claim that every person of that age can enter every contract without permission.
12Your rights and privacy requests
Depending on the circumstances and lawful basis, you can request access to your personal information, correction, deletion, restriction of use and a portable copy of information covered by the portability right. You can withdraw consent where a use actually relies on consent, without affecting lawful use before withdrawal.
Your right to object: you can object to processing based on legitimate interests, including basic website analytics. We will consider the reason and stop that processing unless the law permits a compelling justification or processing is needed for legal claims. You can disable analytics here immediately for this browser.
Send a request to [email protected]. Include enough information to find the relevant account or transaction, such as your Discord ID and server or order reference. We may need proportionate verification before disclosing or changing records. Do not send identity documents unless specifically requested through an appropriate channel.
We normally respond within one month of a valid request, subject to lawful extensions or pauses. We will explain any extension, refusal or restriction. These rights are not absolute: legal duties, other people’s rights and justified retention of transaction records can affect what can be erased. There is no automatic account-wide erasure simply from logging out.
For copies held by a seller, developer or payment provider for its own purposes, contact that organisation too. We can help identify the relevant recipient but cannot automatically erase another controller’s records.
13Privacy complaints and the ICO
You can make a data protection complaint to [email protected]. We will acknowledge it within 30 days, investigate without undue delay, keep you informed and communicate the outcome. That acknowledgement period is not a promise that every complaint will be resolved in 30 days.
You may also complain to the UK Information Commissioner’s Office. See ico.org.uk/make-a-complaint or call 0303 123 1113. Your ability to complain to the ICO is not conditional on waiving other rights.
14Updates to this notice
We will update this notice when the service or its data handling changes. The version and update date are shown above. Material changes will be brought to your attention through the service or an appropriate contact route. New purposes must have an appropriate lawful basis; publishing a revised notice is not a substitute for obtaining consent where consent is required.
For privacy questions, contact [email protected]. For general service terms, read the Terms of service.
Keep a copy for your records. You can print or save this page using your browser.