1.General provisions
- 1.1.This Privacy Policy (the “Policy”) describes the processing of personal data when using the website discord-tickets.com, the dashboard and the Discord Tickets bot (together, the “Service”) provided by the RootCore team (the “Administration”).
- 1.2.The Policy forms an integral part of the Terms of Service. By using the Service, the User confirms having read the Policy and agrees to the processing described in it.
- 1.3.The Administration is not Discord. The Service is not affiliated with or connected to Discord Inc. Your Discord account and all messages on the Discord platform are processed by Discord Inc. under its own privacy policy, over which the Administration has no control.
- 1.4.The Administration also runs discord-webhook.com. The projects share a team but keep separate data and separate policies.
- 1.5.The Policy may be updated as the Service evolves, including when new bot features launch. The current version is always published on this page; its date is shown at the top of the document.
2.What data we collect
- 2.1.When you sign in with Discord (OAuth2, scopes
identifyandguilds): your Discord user ID, username, display name and avatar hash; the list of servers you belong to — their IDs, names, icons and your permission bits; OAuth access and refresh tokens. We do not request your e-mail, direct messages, friends list, connections or the ability to act on your behalf. - 2.2.When a Server Administrator configures the Service: server ID and name; IDs and names of the selected channels, categories and roles; panel and topic settings — titles, texts, button labels, intake-form questions, welcome messages, close rules, auto-close windows, limits, log channel, language; who changed what and when.
- 2.3.When tickets run (bot): ticket metadata — number, topic, opening and closing times, who opened, claimed and closed it, the close reason; intake-form answers; messages inside ticket channels and threads — author ID and username, text, timestamps, links to attachments hosted by Discord. The data is stored to build Transcripts and statistics.
- 2.4.The bot reads messages only in the channels and threads it created for tickets. It does not read, store or analyse messages anywhere else on the server.
- 2.5.Automatically: web-server logs (IP address, user agent, requested URL, referrer, timestamp) and technical error reports (stack trace, request ID) — without message content.
- 2.6.We do not use advertising trackers, analytics pixels or fingerprinting, and we do not combine data with external advertising networks.
3.Purposes of processing
- 3.1.Signing you in and keeping the session between page loads.
- 3.2.Showing the servers the User can manage and letting the User configure them.
- 3.3.Running tickets: creating private channels and threads, pinging staff, applying close rules, archiving Transcripts.
- 3.4.Producing statistics for the server’s staff (response times, ticket counts and similar).
- 3.5.Keeping the Service secure, preventing abuse, diagnosing problems, protecting the rights of the Administration and third parties.
- 3.6.Complying with applicable law and lawful requests from competent authorities.
4.Legal bases and roles
- 4.1.Where the GDPR or UK GDPR applies, the legal bases are: performance of the service requested by the User (Art. 6(1)(b)); the Administration’s legitimate interest in a secure and working service (Art. 6(1)(f)); the User’s consent where it is requested separately.
- 4.2.For the User’s account data and technical logs, the Administration acts as an independent controller.
- 4.3.For Members’ data submitted in tickets of a specific server, the purposes and means of processing are determined by that server’s Administrator; the Administration processes such data on the Administrator’s instructions solely to operate the Service. The duty to inform Members and to ensure lawful processing rests with the Server Administrator.
- 4.4.Members’ claims regarding the content, use and distribution of Transcripts are addressed to the Administrator of the relevant server. The Administration assists with deletion as described in section 9.
7.Retention periods
- 7.1.Sign-in session — 7 days or until sign-out. On sign-out the Administration asks Discord to revoke the tokens.
- 7.2.Server configuration — while the bot is installed on the server, then up to 30 days after its removal.
- 7.3.Tickets and Transcripts — until the Server Administrator deletes them, or up to 90 days after the bot is removed from the server.
- 7.4.Server logs and error reports — up to 30 days.
- 7.5.Backups may contain data for a limited time after deletion from the primary system and are overwritten in the normal course.
- 7.6.The Administration may keep data longer than the stated periods where necessary to comply with the law, resolve disputes and protect its rights.
8.Security
- 8.1.All traffic is encrypted in transit (TLS). The session cookie is sealed with authenticated encryption and cannot be read or altered without the server key.
- 8.2.Everything Users write — transcript messages, intake-form answers and close reasons — is encrypted at rest in our database with AES-256-GCM. Reading the database files alone does not reveal the content of the conversations.
- 8.3.The bot requests the minimum Discord permissions its features need; access to production systems is limited to the people who operate them; backups are stored encrypted.
- 8.4.No system is perfectly secure. The Administration does not guarantee that unauthorised access is impossible and is not liable for incidents caused by third parties, vulnerabilities of platforms and providers, or the User’s negligence (including compromise of their Discord account).
- 8.5.If a breach affecting the User is discovered, the Administration will notify them within a reasonable time through the channels available to it.
9.Your rights
- 9.1.Depending on jurisdiction, the User may have the right to access, rectify, delete, restrict or export their data and to object to certain processing.
- 9.2.Signing out deletes the session cookie and revokes the tokens. The application’s access can also be revoked in Discord under User Settings → Authorized Apps.
- 9.3.Server Administrators can delete panels, individual tickets and Transcripts in the dashboard, or remove the bot — after which the periods in section 7 apply.
- 9.4.Members who want a ticket they took part in removed contact the Server Administrator or the Administration with the server ID and ticket number.
- 9.5.Requests concerning these rights are submitted on the Administration’s official Discord server (section 14). The Administration may ask for proof of identity and responds within 30 days.
- 9.6.Users in the EEA, the UK and Switzerland may also lodge a complaint with their local data-protection authority.
10.Children
- 10.1.The Service is intended for people who meet Discord’s minimum age (13, higher in some countries). The Administration does not knowingly collect data from anyone below that age.
- 10.2.If you learn that a child has provided us with data, let us know and it will be deleted.
11.International transfers
- 11.1.Data is processed on servers located in the European Union.
- 11.2.If processing moves to another region, the Administration will put recognised safeguards in place (such as standard contractual clauses) and update the Policy.
- 11.3.Discord Inc. processes platform data under its own rules and in its own regions, which the Administration does not control.
12.Limitation of liability
- 12.1.The Administration is not responsible for the content of tickets, Transcripts or other Content submitted by Users, nor for the distribution of Transcripts through links enabled by server administrators and staff.
- 12.2.The Administration is not responsible for processing carried out by Discord Inc., hosting providers or other third parties, nor for the consequences of a compromise of the User’s Discord account.
- 12.3.To the fullest extent permitted by law, the Administration’s liability connected with data processing is limited as set out in section 11 of the Terms of Service.
13.Changes to the Policy
- 13.1.The Administration may change the Policy unilaterally. A new version takes effect upon publication on this page; material changes are announced on the official Discord server.
- 13.2.Continued use of the Service after changes are published constitutes acceptance of the new version. If the User does not agree, the User must stop using the Service.
14.Contact information
- 14.1.For questions about data processing, contact the official Discord Tickets Discord server. Please include the server ID and, for ticket matters, the ticket number.
- 14.2.Requests received through other channels may be left unanswered.