RP-Servers does not sell personal information and does not use personal information for cross-context behavioral advertising. We collect only the information needed to operate, secure, moderate, and improve the platform.
1. Information received from Discord
Discord OAuth is the account sign-in method. We request the identify and email scopes. Discord only supplies an email address when it is available and authorized for the application. We do not receive or store your Discord password.
- Discord user ID
- Username and display name
- Avatar identifier and avatar image URL
- Email address, when Discord supplies it
- Registration time, last login time, language preference, account role, and suspension status
2. Server listings and content
When you create or manage a listing, we process the information and files you submit. Approved listing information is public. Drafts, rejected revisions, and pending revisions are available only to the owner and authorized administrators.
- Server name, slug, short and long descriptions
- Logo, banner, tags, language, region, roleplay type, minimum age, and whitelist status
- Website, Discord invite, FiveM connection details, and optional social links
- Revision history, moderation status, rejection reasons, and administrator actions
- View totals and active or historical boost information
3. Technical, cookie, and security data
The platform uses essential cookies and technical records to keep accounts signed in, preserve language choices, prevent request forgery, enforce rate limits, investigate errors, and protect the service.
- A session cookie and CSRF security token; inactive sessions expire after approximately two hours
- A language cookie stored for up to one year
- IP address and browser user-agent while requests are processed
- A keyed one-way visitor hash for daily server-view deduplication; the raw IP address is not stored in the server-view table
- Hashed rate-limit keys and expiry times
- Server logs, security events, and administrator audit records; administrator audit entries may contain an IP address
4. Notifications, email, and activity records
We create internal notifications and may send transactional email for registration, moderation, payments, and boost events. Delivery is attempted only when an email address is available.
- Notification title, message, status, link, and creation/read time
- Email recipient, message content, delivery attempt, and successful-delivery marker
- Platform activity events sent to the private RP-Servers Discord administration channel, including account identifiers and relevant server, moderation, payment, or boost metadata
- Discord activity events do not include email addresses, raw IP addresses, OAuth tokens, passwords, or full form contents
5. Payment and boost data
Customer checkout is currently disabled. If payments are enabled later, Stripe Checkout will process payment details. RP-Servers will not store full card numbers or card security codes.
- Selected server and boost plan
- Amount, currency, purchased duration, status, and timestamps
- Stripe Checkout and payment identifiers
- Webhook event identifier and payload hash for duplicate-event protection
- Refund status and boost start/end information
6. How information is used
- Create and authenticate accounts
- Publish, search, moderate, and manage server listings
- Send service messages and transactional email
- Prevent abuse, count non-duplicated views, troubleshoot errors, and enforce platform security
- Process and document boosts, payments, refunds, and administrator actions
- Comply with applicable law and protect users, RP-Servers, and third parties
7. When information is shared
Information is shared only as needed to provide the service, process user-requested actions, secure the platform, or comply with law.
- Discord for account authentication and the private administration activity channel
- The configured SMTP provider for transactional email
- Stripe if customer payments are enabled
- Hosting, database, and infrastructure providers that operate the service
- Authorities or other parties when disclosure is legally required or necessary to prevent fraud, abuse, or harm
- The public, for approved server listings and information you intentionally publish
8. Cookies and online tracking
RP-Servers uses essential session, security, and language cookies. It does not currently use advertising cookies or third-party behavioral analytics. Browser Do Not Track signals do not change platform behavior because RP-Servers does not track users across unrelated websites. Fonts are hosted on our own server; loading them does not send a request to Google Fonts.
9. Retention
Account and listing information is retained while an account or listing is active and as needed for moderation, security, dispute resolution, and service integrity. Payment, refund, and audit records may be kept longer when required for accounting, fraud prevention, or legal compliance. Session, rate-limit, log, email-delivery, and outbox data is retained only as long as reasonably needed for its operational purpose. Deleted public listings are removed from public display, although limited records or backups may remain for a lawful operational period.
10. Your privacy choices
You may update or delete your own server listings from the dashboard, change your language preference, disconnect the Discord authorization through Discord, and clear cookies through your browser. You may contact RP-Servers to request access, correction, or deletion of account information. Requests may require identity verification and may be limited where retention is required by law, security, fraud prevention, or the rights of others. RP-Servers does not discriminate against users for making a privacy request.
11. Security
RP-Servers uses access controls, prepared database statements, CSRF protection, secure session handling, output encoding, upload validation, server-side authorization, webhook verification, and restricted administrative access. No online service can guarantee absolute security.
12. Children
RP-Servers is not intended for children under 13 and does not knowingly collect personal information from children under 13. Contact us if you believe a child has submitted such information.
13. Privacy contact
For privacy questions or a request to access, correct, or delete personal information, contact:
[email protected]