Skip to content
Tyr Scripts

Privacy policy

How Tyr Scripts collects, uses, and protects your data under GDPR.

Last updated: [PLACEHOLDER: set the effective date when this policy is finalised]

We operate from the Netherlands, so your data is processed under the EU General Data Protection Regulation (GDPR). This page explains what we collect, why, and what rights you have over it.

Placeholder — real policy text needed

Insert the data controller's registered legal name, address, company registration number, and (if required) a Data Protection Officer contact.

1. Data we collect

  • Discord account info from OAuth sign-in — your Discord ID, username, and avatar.
  • Order and payment metadata — what you bought, when, the price charged, and a reference from our payment provider (not your full card details).
  • Licence data — the key issued to you, its expiry, and the hardware ID (HWID) it's bound to.
  • Basic technical logs — IP address and request metadata, kept for security and abuse prevention.

Placeholder — real policy text needed

Confirm this list against what's actually collected once payments, analytics, and support tooling are wired up, and correct/extend it before publishing.

3. How we use your data

  • To create your account and authenticate you via Discord.
  • To process payment and provision, renew, or extend your licence key.
  • To show you your active keys and their expiry.
  • To investigate fraud, abuse, or breaches of our terms of service.

Placeholder — real policy text needed

Add anything else data is actually used for (e.g. product analytics, marketing emails) once those exist — don't leave silent uses out of this list.

4. Who we share data with

We share the minimum data necessary with a small number of processors to run the store — for example, our payment provider (to charge you) and our key-management provider (to issue and bind your licence key).

Placeholder — real policy text needed

Insert the named list of sub-processors (payment provider, key-management provider, hosting provider, Discord), what each receives, and links to their own privacy policies / data processing agreements.

5. International data transfers

Placeholder — real policy text needed

If any processor stores or processes data outside the EU/EEA, insert the transfer mechanism relied on (e.g. Standard Contractual Clauses, adequacy decision).

6. How long we keep your data

Placeholder — real policy text needed

Insert concrete retention periods per data category (account data, order records, logs) and the legal/business reason for each — e.g. Dutch tax law generally requires financial records to be kept for 7 years.

7. Your rights

Under GDPR you have the right to access, correct, delete, restrict, or export your personal data, and to object to certain processing. You can also lodge a complaint with the Dutch data protection authority, the Autoriteit Persoonsgegevens.

Placeholder — real policy text needed

Insert exactly how a user exercises these rights in practice (which email, expected response time, any identity-verification step).

8. Cookies

We use cookies for essential site functions like staying signed in. Anything non-essential is off until you opt in — see our cookie policy for the full breakdown and how to change your choice.

9. Children's privacy

Placeholder — real policy text needed

Insert a minimum-age statement consistent with the terms of service and Discord's own age requirements.

10. Changes to this policy

Placeholder — real policy text needed

Insert how material changes are communicated to users before they take effect.

11. Contact

Placeholder — real policy text needed

Insert a contact email for privacy requests and complaints, distinct from general support if applicable.