Last updated: 2026-07-25
Privacy Policy
This Privacy Policy describes how GuildMaster (“we”, “the platform”) collects, uses, shares, and protects the personal data of visitors to the institutional site and users of the guild management system, in compliance with Brazil’s General Data Protection Law (Lei nº 13.709/2018 — LGPD).
If this version conflicts with the Portuguese version, the Portuguese version prevails.
1. Who is the data controller
Controller: Hendy Rodrigues - (contact@syslogg.net)
2. What data we collect
| Category | Data | Collected when |
|---|---|---|
| Account | Email, password (stored as a hash), timezone | Registration |
| Discord (optional) | Discord ID, email, avatar, servers where you have manage permissions (via Discord login/link) | Signing in with or linking Discord |
| Character | Character name, class, free-text description | Joining a guild |
| Guild activity | Event attendance, RSVPs, auction bids, DKP (Dragon Kill Points) balance and transaction history | Normal use of the system |
| Billing | Stripe customer identifier, subscription status | Subscribing to a paid plan |
| Technical | IP address, user agent, session cookies | Every request to the site and the system |
We do not intentionally collect sensitive data (health, biometrics, sexual orientation, etc.) or data from users under 18.
3. Why we use your data and the legal basis
| Purpose | Legal basis (LGPD Art. 7) |
|---|---|
| Creating and maintaining your account, your guild, and your DKP/auction/event history | Contract performance (Art. 7, V) |
| Discord authentication and RSVP messages sent by the bot | Contract performance (Art. 7, V) |
| Processing payments for paid plans | Contract performance (Art. 7, V) |
| Sending registration confirmation and guild invite emails | Contract performance (Art. 7, V) |
| Preventing fraud, abuse, and attacks (e.g. login attempt limits) | Legitimate interest (Art. 7, IX) |
| Complying with tax obligations on payments received | Legal obligation (Art. 7, II) |
4. Who we share your data with
We use the following processors to operate the service. All of them process data outside Brazil (international transfer, LGPD Art. 33):
| Processor | Purpose | Data sent | Country |
|---|---|---|---|
| Stripe | Payment processing | Email, internal account identifier | United States |
| Resend | Transactional email delivery (registration confirmation, guild invite) | Recipient’s email | United States |
| Google Cloud Storage | Avatar/guild logo storage and database backups | Avatar/logo image; full database backup (encrypted) | United States |
| Discord | Social login, RSVP/attendance bot | Discord ID, email, avatar, access tokens, list of manageable servers | United States |
| Cloudflare | Edge protection (proxy/CDN) for all traffic | IP address, HTTP headers | Global (edge network) |
| Google Analytics | Website traffic/audience measurement — only if you accept analytics cookies | Pseudonymous client identifier, pages viewed, device/browser type — no account data | United States |
| CookieYes | Manages your cookie consent choice | Your consent choice; technical data needed to remember it | See CookieYes’s own privacy policy |
We do not sell your personal data and do not use it for third-party advertising.
5. Cookies
We use cookies that are strictly necessary for the system to work, plus optional Google Analytics cookies you can accept or decline through the consent banner (powered by CookieYes, using Google Consent Mode — the Analytics tag doesn’t load or set a cookie until you accept).
| Cookie | Purpose | Duration |
|---|---|---|
access_token | Keeps your session authenticated (HttpOnly, not readable from JavaScript) | 7 days |
selected_guild_id | Remembers which guild you last viewed | 90 days |
_ga, _ga_* | Google Analytics — opt-in only | Up to 2 years |
See the Cookie Policy for details.
6. How long we keep your data
- Active account: for as long as you keep your account.
- Expired or used guild invites: up to 90 days.
- Rejected join requests: up to 180 days.
- Read notifications: up to 90 days.
- DKP, attendance, and auction history: kept as part of the guild’s history even after a member leaves or an account is deleted, but anonymized (your character name is replaced with “Deleted user”). This is necessary to preserve the integrity of every other guild member’s ledger (LGPD Art. 16, II).
- Database backups: retained for 7 days.
7. Your rights as a data subject (LGPD Art. 18)
You can, at any time:
- Confirm and access the data we hold about you;
- Download a copy of all your data (portability), at
/app/profile, under “Your data”; - Correct incomplete or outdated data by editing your profile at
/app/profile; - Delete your account, at
/app/profile, under “Danger zone” — your identifying data (email, password, avatar, Discord link) is erased; your guild participation history is anonymized as described in section 6; - Withdraw consent — for analytics cookies, anytime via the “Cookie preferences” link in the footer; for anything else based on legitimate interest, by contacting the DPO;
- Ask who we share your data with (see section 4 above).
To exercise any right not available directly in the system, contact [DPO CONTACT EMAIL].
8. Security
Passwords are stored as hashes (bcrypt), never in plain text. Sessions are protected by an HttpOnly cookie. Access to the admin panel is restricted and audited. Database backups are encrypted before leaving our server.
9. Changes to this policy
We may update this policy from time to time. The last-updated date is shown at the top of this page. Material changes will be communicated by email or an in-app notice.
10. Contact
Questions about this policy or how your data is processed: [DPO CONTACT EMAIL].