Privacy policy
How Tyr Scripts collects, uses, and protects your data under GDPR.
Last updated: [PLACEHOLDER: set the effective date when this policy is finalised]
We operate from the Netherlands, so your data is processed under the EU General Data Protection Regulation (GDPR). This page explains what we collect, why, and what rights you have over it.
Placeholder — real policy text needed
Insert the data controller's registered legal name, address, company registration number, and (if required) a Data Protection Officer contact.
1. Data we collect
- Discord account info from OAuth sign-in — your Discord ID, username, and avatar.
- Order and payment metadata — what you bought, when, the price charged, and a reference from our payment provider (not your full card details).
- Licence data — the key issued to you, its expiry, and the hardware ID (HWID) it's bound to.
- Basic technical logs — IP address and request metadata, kept for security and abuse prevention.
Placeholder — real policy text needed
Confirm this list against what's actually collected once payments, analytics, and support tooling are wired up, and correct/extend it before publishing.
2. Legal basis for processing
Placeholder — real policy text needed
Insert the GDPR Article 6 legal basis for each processing purpose — typically contract performance (delivering your licence), legal obligation (tax records), legitimate interest (fraud/security), and consent (non-essential cookies, marketing).
3. How we use your data
- To create your account and authenticate you via Discord.
- To process payment and provision, renew, or extend your licence key.
- To show you your active keys and their expiry.
- To investigate fraud, abuse, or breaches of our terms of service.
Placeholder — real policy text needed
Add anything else data is actually used for (e.g. product analytics, marketing emails) once those exist — don't leave silent uses out of this list.
5. International data transfers
Placeholder — real policy text needed
If any processor stores or processes data outside the EU/EEA, insert the transfer mechanism relied on (e.g. Standard Contractual Clauses, adequacy decision).
6. How long we keep your data
Placeholder — real policy text needed
Insert concrete retention periods per data category (account data, order records, logs) and the legal/business reason for each — e.g. Dutch tax law generally requires financial records to be kept for 7 years.
7. Your rights
Under GDPR you have the right to access, correct, delete, restrict, or export your personal data, and to object to certain processing. You can also lodge a complaint with the Dutch data protection authority, the Autoriteit Persoonsgegevens.
Placeholder — real policy text needed
Insert exactly how a user exercises these rights in practice (which email, expected response time, any identity-verification step).
9. Children's privacy
Placeholder — real policy text needed
Insert a minimum-age statement consistent with the terms of service and Discord's own age requirements.
10. Changes to this policy
Placeholder — real policy text needed
Insert how material changes are communicated to users before they take effect.
11. Contact
Placeholder — real policy text needed
Insert a contact email for privacy requests and complaints, distinct from general support if applicable.