Skip to main content

In effect from 09.09.2026

Privacy Policy

Explains what Discord Tickets collects on the website, in the dashboard and through the bot, why it is needed, how long it is kept, who can access it and how to delete it.

Contents
  1. 1General provisions
  2. 2What data we collect
  3. 3Purposes of processing
  4. 4Legal bases and roles
  5. 5Cookies
  6. 6Who can access the data
  7. 7Retention periods
  8. 8Security
  9. 9Your rights
  10. 10Children
  11. 11International transfers
  12. 12Limitation of liability
  13. 13Changes to the Policy
  14. 14Contact information

1.General provisions

  1. 1.1.
    This Privacy Policy (the “Policy”) describes the processing of personal data when using the website discord-tickets.com, the dashboard and the Discord Tickets bot (together, the “Service”) provided by the RootCore team (the “Administration”).
  2. 1.2.
    The Policy forms an integral part of the Terms of Service. By using the Service, the User confirms having read the Policy and agrees to the processing described in it.
  3. 1.3.
    The Administration is not Discord. The Service is not affiliated with or connected to Discord Inc. Your Discord account and all messages on the Discord platform are processed by Discord Inc. under its own privacy policy, over which the Administration has no control.
  4. 1.4.
    The Administration also runs discord-webhook.com. The projects share a team but keep separate data and separate policies.
  5. 1.5.
    The Policy may be updated as the Service evolves, including when new bot features launch. The current version is always published on this page; its date is shown at the top of the document.

2.What data we collect

  1. 2.1.
    When you sign in with Discord (OAuth2, scopes identify and guilds): your Discord user ID, username, display name and avatar hash; the list of servers you belong to — their IDs, names, icons and your permission bits; OAuth access and refresh tokens. We do not request your e-mail, direct messages, friends list, connections or the ability to act on your behalf.
  2. 2.2.
    When a Server Administrator configures the Service: server ID and name; IDs and names of the selected channels, categories and roles; panel and topic settings — titles, texts, button labels, intake-form questions, welcome messages, close rules, auto-close windows, limits, log channel, language; who changed what and when.
  3. 2.3.
    When tickets run (bot): ticket metadata — number, topic, opening and closing times, who opened, claimed and closed it, the close reason; intake-form answers; messages inside ticket channels and threads — author ID and username, text, timestamps, links to attachments hosted by Discord. The data is stored to build Transcripts and statistics.
  4. 2.4.
    The bot reads messages only in the channels and threads it created for tickets. It does not read, store or analyse messages anywhere else on the server.
  5. 2.5.
    Automatically: web-server logs (IP address, user agent, requested URL, referrer, timestamp) and technical error reports (stack trace, request ID) — without message content.
  6. 2.6.
    We do not use advertising trackers, analytics pixels or fingerprinting, and we do not combine data with external advertising networks.

3.Purposes of processing

  1. 3.1.
    Signing you in and keeping the session between page loads.
  2. 3.2.
    Showing the servers the User can manage and letting the User configure them.
  3. 3.3.
    Running tickets: creating private channels and threads, pinging staff, applying close rules, archiving Transcripts.
  4. 3.4.
    Producing statistics for the server’s staff (response times, ticket counts and similar).
  5. 3.5.
    Keeping the Service secure, preventing abuse, diagnosing problems, protecting the rights of the Administration and third parties.
  6. 3.6.
    Complying with applicable law and lawful requests from competent authorities.

5.Cookies

  1. 5.1.
    The site uses strictly necessary cookies only. No consent banner is required because nothing is tracked.
  2. 5.2.
    dt_session — the encrypted sign-in session; valid for 7 days or until you sign out.
  3. 5.3.
    dt_oauth — a one-time anti-forgery token used during the Discord sign-in; valid for 10 minutes.
  4. 5.4.
    Dashboard settings in preview mode may be kept in the browser’s local storage (localStorage) on the User’s device; they are not sent to the Administration and are removed by clearing the site data in the browser.

6.Who can access the data

  1. 6.1.
    The server’s staff: administrators and the roles assigned to a topic can see that topic’s tickets and Transcripts.
  2. 6.2.
    Anyone with the link — only for Transcripts that a server administrator or staff member has explicitly made public. Sharing can be switched off at any time; the link stops working immediately.
  3. 6.3.
    Discord Inc. — as the platform every message passes through.
  4. 6.4.
    Hosting providers that store and process data on the Administration’s behalf under a data-processing agreement.
  5. 6.5.
    Competent authorities — where disclosure is required by law or court order, or to protect the rights and safety of the Administration, Users and third parties.
  6. 6.6.
    The Administration does not sell personal data and does not share it for advertising.

7.Retention periods

  1. 7.1.
    Sign-in session — 7 days or until sign-out. On sign-out the Administration asks Discord to revoke the tokens.
  2. 7.2.
    Server configuration — while the bot is installed on the server, then up to 30 days after its removal.
  3. 7.3.
    Tickets and Transcripts — until the Server Administrator deletes them, or up to 90 days after the bot is removed from the server.
  4. 7.4.
    Server logs and error reports — up to 30 days.
  5. 7.5.
    Backups may contain data for a limited time after deletion from the primary system and are overwritten in the normal course.
  6. 7.6.
    The Administration may keep data longer than the stated periods where necessary to comply with the law, resolve disputes and protect its rights.

8.Security

  1. 8.1.
    All traffic is encrypted in transit (TLS). The session cookie is sealed with authenticated encryption and cannot be read or altered without the server key.
  2. 8.2.
    Everything Users write — transcript messages, intake-form answers and close reasons — is encrypted at rest in our database with AES-256-GCM. Reading the database files alone does not reveal the content of the conversations.
  3. 8.3.
    The bot requests the minimum Discord permissions its features need; access to production systems is limited to the people who operate them; backups are stored encrypted.
  4. 8.4.
    No system is perfectly secure. The Administration does not guarantee that unauthorised access is impossible and is not liable for incidents caused by third parties, vulnerabilities of platforms and providers, or the User’s negligence (including compromise of their Discord account).
  5. 8.5.
    If a breach affecting the User is discovered, the Administration will notify them within a reasonable time through the channels available to it.

9.Your rights

  1. 9.1.
    Depending on jurisdiction, the User may have the right to access, rectify, delete, restrict or export their data and to object to certain processing.
  2. 9.2.
    Signing out deletes the session cookie and revokes the tokens. The application’s access can also be revoked in Discord under User Settings → Authorized Apps.
  3. 9.3.
    Server Administrators can delete panels, individual tickets and Transcripts in the dashboard, or remove the bot — after which the periods in section 7 apply.
  4. 9.4.
    Members who want a ticket they took part in removed contact the Server Administrator or the Administration with the server ID and ticket number.
  5. 9.5.
    Requests concerning these rights are submitted on the Administration’s official Discord server (section 14). The Administration may ask for proof of identity and responds within 30 days.
  6. 9.6.
    Users in the EEA, the UK and Switzerland may also lodge a complaint with their local data-protection authority.

10.Children

  1. 10.1.
    The Service is intended for people who meet Discord’s minimum age (13, higher in some countries). The Administration does not knowingly collect data from anyone below that age.
  2. 10.2.
    If you learn that a child has provided us with data, let us know and it will be deleted.

11.International transfers

  1. 11.1.
    Data is processed on servers located in the European Union.
  2. 11.2.
    If processing moves to another region, the Administration will put recognised safeguards in place (such as standard contractual clauses) and update the Policy.
  3. 11.3.
    Discord Inc. processes platform data under its own rules and in its own regions, which the Administration does not control.

12.Limitation of liability

  1. 12.1.
    The Administration is not responsible for the content of tickets, Transcripts or other Content submitted by Users, nor for the distribution of Transcripts through links enabled by server administrators and staff.
  2. 12.2.
    The Administration is not responsible for processing carried out by Discord Inc., hosting providers or other third parties, nor for the consequences of a compromise of the User’s Discord account.
  3. 12.3.
    To the fullest extent permitted by law, the Administration’s liability connected with data processing is limited as set out in section 11 of the Terms of Service.

13.Changes to the Policy

  1. 13.1.
    The Administration may change the Policy unilaterally. A new version takes effect upon publication on this page; material changes are announced on the official Discord server.
  2. 13.2.
    Continued use of the Service after changes are published constitutes acceptance of the new version. If the User does not agree, the User must stop using the Service.

14.Contact information

  1. 14.1.
    For questions about data processing, contact the official Discord Tickets Discord server. Please include the server ID and, for ticket matters, the ticket number.
  2. 14.2.
    Requests received through other channels may be left unanswered.