Privacy Policy
This Policy explains how Cordlytic handles personal data when you use our website, account system, Discord app, analytics, alerts, scheduled reports and support services.
1. Who controls your data
Cordlytic is the controller of personal data processed for Cordlytic accounts and service operation. Privacy enquiries and data requests can be sent to admin@cordlytic.com.
A Discord server owner or administrator may separately be responsible for how they use Cordlytic analytics in their community.
2. Data we collect
Account and contact data
- email address, username, encrypted password hash and email-verification status;
- account role, workspace role, subscription and billing status;
- security sessions, timestamps and transactional-email delivery status;
- support messages and information you choose to provide.
Discord account and server data
- Discord user ID, username, display name and avatar;
- server IDs, names, icons and whether you can manage a server;
- member IDs, usernames, display names, avatars, roles, bot status and join/leave timestamps where available;
- channel IDs, channel names and channel types;
- message-event metadata used for analytics, such as server, channel, member and timestamp identifiers;
- voice-state durations, member counts, role counts and server snapshots;
- bot installation, permissions and service-health information.
Usage and technical data
- pages and product features used, onboarding progress and configuration choices;
- IP-derived security information, request metadata, browser/device details and diagnostic logs where generated by our infrastructure;
- cookies required for authentication, security, currency preferences and service operation.
Payment data
Stripe processes card and payment details. Cordlytic receives billing identifiers, plan, currency, payment and subscription status, but does not store full card numbers.
3. How we use data
- create and secure Cordlytic accounts;
- connect Discord accounts and install the bot with permission;
- collect server snapshots and calculate aggregate analytics, reports and health indicators;
- deliver alerts, scheduled reports, verification and password-reset emails;
- process subscriptions, enforce plan limits and provide billing support;
- detect abuse, investigate faults, maintain backups and protect the service;
- comply with legal obligations and enforce our Terms.
4. Legal bases
Where UK or European data-protection law applies, we rely on:
- Contract: to create your account and provide requested Cordlytic features.
- Legitimate interests: to secure, maintain, diagnose and improve the service, prevent abuse and provide useful aggregate analytics.
- Consent: where you choose optional communications or grant Discord authorization that can be revoked.
- Legal obligation: for tax, accounting, fraud prevention, law-enforcement and regulatory requirements.
5. Sharing and service providers
We share data only as needed with providers that help operate Cordlytic, including:
- Discord: OAuth, bot installation, API and Gateway event delivery;
- Stripe: subscription Checkout, billing portal, payments, fraud prevention and tax-related functions;
- Resend: account, invitation, alert and scheduled-report email delivery;
- hosting and infrastructure providers: web hosting, VPS operation, databases, caching, backups, DNS and security;
- professional and legal advisers: where reasonably necessary;
- authorities or other parties: where required by law, to protect rights and safety, or during a legitimate business transfer.
We do not sell personal data. We do not share Discord API data for advertising or unrelated profiling.
6. Retention
We keep data only while reasonably needed for the purposes described above, service security, dispute resolution and legal compliance. Retention depends on the data type and plan history allowance.
- active account and workspace data is retained while the account or connection remains active;
- analytics history is retained according to the applicable product plan and operational backup cycle;
- security, audit, delivery and billing records may be retained longer where necessary for fraud prevention, accounting or legal claims;
- expired one-time verification and reset tokens are deleted or rendered unusable;
- when Discord access is removed or deletion is requested, we delete or anonymise API data that is no longer needed for the approved service function, subject to legal and backup limitations.
7. Your choices and rights
Depending on your location, you may have rights to:
- access and receive a copy of your personal data;
- correct inaccurate or incomplete data;
- request deletion or restriction;
- object to processing based on legitimate interests;
- receive portable data you provided to us;
- withdraw consent without affecting earlier lawful processing;
- complain to a data-protection authority, including the UK Information Commissioner’s Office where applicable.
Send requests to admin@cordlytic.com. We may need to verify your identity and authority over the relevant account or Discord server.
8. Discord data controls
You can stop new Discord data collection by:
- disconnecting Discord from your Cordlytic account;
- removing the Cordlytic bot from the Discord server;
- revoking the application through Discord’s authorised-app settings;
- contacting us to request deletion of associated Cordlytic data.
Server administrators should only use Cordlytic where they have authority and should respond appropriately to community-member privacy requests.
9. International transfers
Some service providers may process data outside the United Kingdom or European Economic Area. Where required, we rely on adequacy regulations, approved contractual protections or another valid transfer mechanism.
10. Security
We use safeguards including HTTPS, password hashing, restricted administrative access, hashed one-time tokens, environment-secret separation, database backups and service-health monitoring. No online service can guarantee absolute security, so please use a unique password and tell us promptly about suspected compromise.
11. Children
Cordlytic is intended for people permitted to use Discord and able to manage a community or account. We do not knowingly create Cordlytic accounts for children below the applicable digital-consent age. Contact us if you believe a child has provided account data improperly.
12. Policy changes
We may update this Policy when the service, providers or legal requirements change. We will publish the revised date and provide additional notice for material changes where appropriate.
13. Contact
Privacy enquiries and requests: admin@cordlytic.com.