Last updated: September 14, 2026
Privacy Policy
This Privacy Policy explains how Esports Hub collects, uses, and protects your information across both the Discord server and the web portal.
About This Policy
Esports Hub is operated from Australia. This Privacy Policy is governed by the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs) set out in Schedule 1 to that Act. The data-handling commitments in this policy reflect APP requirements and apply to every user.
Where you are located outside Australia, additional rights and disclosures apply under the privacy laws of your jurisdiction. See the Region-Specific Rights section below for details on rights available to users in the European Union, the United Kingdom, California, and other regions.
Information We Collect
When you sign in to the web portal, we receive and store the following information from your linked account:
- User ID: used to identify your account.
- Username and avatar: used to personalise your experience.
- Verified email address: with your Discord authorization, saved to your account and used to prefill checkout and Settings. A billing email you enter takes priority, and the email you submit at checkout is shared with the payment processor.
- Server membership: used to verify that you are a member of the Esports Hub Discord server.
Discord authorization also provides a basic list of your servers for membership and bot setup checks. It does not grant access to your friend list, direct messages, or messages in those other servers.
Discord Bot Data
In servers where the bot operates, Discord may send it message content and files, reactions, message and channel IDs, usernames, avatars, nicknames, member roles, join and leave events, boost status, and voice channel participation. The bot does not record voice audio or monitor your direct messages.
We use this data for moderation, scam and spam detection, forum duplicate checks, tickets and private transcripts, role and boost features, games, rewards, activity statistics, and other bot features requested by members or staff. We do not sell Discord API data, use it for advertising, scrape Discord, or use Discord message content to train AI models.
Some message text, images, or files may be sent to a contracted AI inference provider when needed to classify a moderation or support issue or generate a requested response. The provider retention rules are explained under AI Processing below. The bot may also send service, safety, and transaction notices by Discord direct message. Optional bot messages can be turned off in Settings, but essential security or moderation notices may still be sent.
Server Verification
To access the Discord server, you must complete verification through our website. During this process, we collect the following information to maintain server safety:
- Browser and device fingerprint: hashes generated from browser and device characteristics. These hashes can change or collide and are treated as supporting signals rather than proof of identity.
- Device details: browser, operating system, device type, model when the browser reports one, architecture, approximate memory, logical processor availability, and touch capability. Browser-reported details are advisory.
- Device continuity tokens: a random browser token and a separate signed HttpOnly cookie help recognise a returning browser. The browser token is HMAC-protected before database storage.
- IP address, country, and internet service provider: your network address, approximate city or country, and ISP / ASN. Our self-hosted network service evaluates the address locally against public relay, cloud, proxy, and VPN data.
- User-agent string: the browser-provided user-agent header, used as supporting context for suspicious verification attempts.
- Discord account ID: used to link the verification to your Discord account.
- Account age: the age of your Discord account at the time of verification.
This data is used to enforce bans, detect alternate accounts, and identify suspicious verification attempts. We do not sell verification data or share it with third parties for marketing or analytics. Network classification runs in our own service; public data feeds are downloaded without sending them member IP addresses. Our hosting provider supplies approximate IP geolocation headers as part of serving the request.
90-day PII redaction: Once a verification is more than 90 days old, your IP address, city, region, location provenance, user-agent string, browser-reported device details, and internet service provider are automatically wiped from the record. The hashed device fingerprint, country, and your Discord account ID stay so we can keep banned alt accounts blocked, but the raw identifiers that aren't needed for ongoing anti-abuse are removed on schedule.
Verification record retention: The redacted verification record (fingerprint hash, Discord ID, country, account age) is retained for as long as you continue to use the Esports Hub Discord server, so we can recognise your device on future verifications and detect alt accounts. It is removed when you request deletion via either of the methods below.
Banned-fingerprint records: If you are banned from the server, a separate banned-fingerprint record is created so the same device cannot rejoin under a new Discord account. When you ask us to delete your verification data, this row is pseudonymised rather than deleted: your raw Discord ID is removed, but a keyed account identifier, hashed fingerprint, and IP stay on file so the ban still applies to the same account and prevents device-based evasion. This processing rests on our legitimate interest in preventing ban evasion (GDPR Article 6(1)(f) for users in the EU/UK; APP 11.2 read together with APP 6.2(a) for Australian users), with retention limited to what is proportional to that purpose.
Data deletion: You can delete your verification data at any time using either of the following options:
- Run the /privacy command in the Esports Hub Discord server and confirm the prompt.
- Open Settings on the web portal, go to the Privacy tab, and click Delete data under the verification card.
Either path promptly deletes the verification records associated with your Discord account, pseudonymises any banned-fingerprint rows tied to your account, and revokes your verified role. Deleting through web settings also clears the verification cookie and browser token available to the site. You will need to re-verify to regain access to the server.
How We Use Your Information
The table below sets out the purposes for which we process your personal data, the categories of data involved, and the legal basis we rely on under the Australian Privacy Principles and equivalent privacy laws (such as the GDPR for users in the European Union).
| Purpose | Data | Legal Basis |
|---|---|---|
| Authenticate you and link your Esports Hub account to your Discord identity | User ID, username, avatar, authorized verified email address, server membership | Contract (necessary to provide the service) |
| Verify you during sign-up and stop banned members from rejoining on alt accounts | Browser and device fingerprint, IP address, country, Discord ID, and Discord account age | Legitimate interests (community safety and abuse prevention) |
| Operate and moderate Discord bot features | Message content and files, reactions, member profile and role data, join and leave events, boost status, and voice channel participation | Contract and legitimate interests (providing bot features, community safety, and abuse prevention) |
| Run AI chat features and persist conversations between sessions | Chat messages, uploaded images, conversation history, model preferences | Contract |
| Process payments, subscriptions, and gift transactions | Payment details (handled directly by external payment processors), gifter and recipient identifiers, transaction history, and a checkout consent record (agreement timestamp, IP address, browser user agent, and the policy versions agreed to) | Contract |
| Track rewards activity and tier progression | Discord activity (messages, voice minutes, reactions), point balance, redemption history | Contract |
| Create and manage Discord roles on your behalf | Role configuration, uploaded logos and icons, Discord account ID | Contract |
| Detect and respond to errors, performance issues, and security events | Error reports, session replay on checkout errors only, anonymised usage telemetry | Legitimate interests (operating a reliable service) |
Gift Purchases
When you purchase a gift subscription for another member, the recipient will be notified that they received premium and will be shown your display name as the gifter. Similarly, when searching for a recipient, you may see other members' usernames, avatars, and Discord IDs. Gift transaction records (gifter, recipient, duration, and payment details) are stored in our database to manage the gift subscription lifecycle.
Data Storage & Retention
Your data is stored securely using cloud infrastructure. Web chat conversations, Discord ticket records, role requests, and activity records are stored in our database. Ticket transcripts and uploaded files are stored in private or access-controlled cloud storage. We retain each category of data only for as long as needed for the purpose it was collected, after which it is deleted or anonymised.
When you delete your account, access is disabled immediately and recurring billing is canceled. Account-linked Discord activity, ticket and appeal identities and content, private transcripts, copied ticket attachments, and bot-generated transcript log messages are erased or queued for deletion immediately and are not restored if you recover the account. You can sign in with the same Discord account within 30 days and confirm that you want to recover the remaining account data. If you do not recover it, the remaining account and account-owned content are permanently deleted or anonymized after that period. Limited transaction, dispute, moderation, ban-evasion, shared-conversation, and de-identified ticket lifecycle records may remain while they are still needed for the purposes described in this policy. Canceled subscriptions, removed Discord roles, and verification are not restored by account recovery.
| Data category | Retention period |
|---|---|
| Account profile (User ID, username, avatar) | For as long as your account is active. Held in a disabled state for up to 30 days after account deletion so you can recover it, then permanently deleted if you do not recover it. |
| Verification record (raw IP, user-agent, ISP) | 90 days from the verification, then automatically wiped from the record. Removed sooner on request. |
| Verification record (fingerprint hash, Discord ID, country, account age) | For as long as you continue to use the Esports Hub Discord server, so we can recognise your device on future verifications. Removed when you request deletion via /privacy or in Settings. |
| Banned-fingerprint records | Retained for ongoing ban-evasion prevention. Pseudonymised (Discord ID dropped) on a deletion request, but the fingerprint hash and IP stay on file. |
| Discord bot activity and temporary safety records | Forum duplicate-detection records expire after 24 hours. Recent Discord name history is kept for 30 days. Hourly activity and aggregate word-frequency records are kept for 35 days while the account remains active. Account-linked activity is erased as soon as account deletion is confirmed. A secret-keyed marker that does not contain the raw Discord ID prevents buffered activity from recreating erased records, and is removed if the account is recovered or the member later creates a new account through Discord. |
| Discord ticket transcripts and attachments | A private transcript may be kept after a ticket closes or its Discord channel is deleted for support, safety, and dispute handling. Access is limited to the ticket owner, authorized staff, and administrators. When account deletion is confirmed, private transcripts, copied attachments, and bot-generated transcript log messages and previews are queued for deletion immediately, and the linked ticket and appeal identity and content are anonymized. De-identified ticket lifecycle statistics may remain. Erased transcript data is not restored if the account is recovered. |
| AI chat conversations | For as long as your account is active, until you delete the conversation, or until the 30-day account recovery period ends without recovery. |
| Uploaded images and assets | For as long as the linked role, post, or service is active. Owned files are queued for deletion after the 30-day account recovery period ends without recovery. Storage failures are retried; file removal may finish after your account and saved content have been deleted. Copies already cached or downloaded by others may remain. |
| Payment and transaction records (including checkout consent records) | 7 years to comply with tax, accounting, refund, and dispute requirements. If the 30-day recovery period ends without recovery, the account link, free-form checkout metadata, consent IP address, and browser user agent are removed. Limited payment-provider transaction references remain so refunds, disputes, and accounting records can still be reconciled. |
| Error reports and analytics events | 90 days, after which they are aggregated or deleted. |
| Cookies and browser local storage | The verification cookie and verification browser token are cleared when you delete verification data or your account. Other preferences remain until you clear them or change them through Cookie settings. |
Third-Party Services
Esports Hub relies on third-party services to operate the platform. The categories below describe what each kind of provider does and what data it receives. Each provider operates under its own privacy policy and only receives the data needed to perform its role.
- Authentication: Discord OAuth, used to sign you in and read your username, avatar, authorized email and its verification status, and basic server membership information.
- Payments: card-on-file and one-off charges for subscriptions, contracts, websites, and other paid services. Card details are handled directly by the payment processor and never reach our servers.
- Hosting and infrastructure: serverless hosting, managed Postgres (encrypted at rest), object storage for uploaded images, and an ephemeral cache used for rate-limiting and deduplication.
- Anti-abuse: bot detection on the verification flow and other forms; a third-party VPN and proxy risk service that receives only your IP address and returns a risk score, country, and ISP.
- Transactional email: account verification, receipts, and similar service notifications.
- Monitoring: error tracking and a checkout-only session replay that activates when a payment error occurs. Replays mask all text and block images; payment fields render in third-party iframes we cannot see into.
- AI inference: web chat content and Discord content selected for moderation or support classification may be sent to an AI provider. We do not use this content to train models. Provider data use and retention depend on the applicable service terms and features, as explained below.
Data Sharing
We do not sell, trade, or share your personal information with third parties for marketing purposes. Your data is only shared with third-party service providers as necessary to operate the platform.
AI Processing
Messages you send through the web portal's AI chat, and Discord messages or files selected for moderation or ticket-support classification, may be processed by a third-party AI provider. We do not use this content to train models. The provider's use of the data is governed by its privacy policy and data processing terms.
Our current provider documents a standard 55-day retention period for prompts, context, and responses used for abuse monitoring. Search-grounded requests have a separate 30-day retention period. Approved retention arrangements and other features may have different rules, so we do not promise immediate deletion or zero retention by the provider. Deleting a chat or your Esports Hub account does not itself delete the provider's retained records. See the provider's abuse-monitoring policy and retention guidance.
Cookies & Local Storage
We use cookies and browser local storage in three categories. You can review and change your choices at any time by opening Cookie settings in the site footer.
Strictly necessary
Always active. These are required for the site to work and cannot be turned off. They cover authentication sessions, security checks (CSRF and bot-protection challenges), and saving your UI preferences such as theme and font choice in local storage.
Analytics
Helps us understand how the site is used so we can fix bugs and improve performance. This bucket includes error tracking and, on the checkout flow only, a short session replay that activates if an error happens during a payment. Replays mask all text and block images so personal details are not captured, and payment fields render in third-party iframes we cannot see into.
Marketing
Helps us measure the effectiveness of our marketing campaigns. We do not currently load any third-party advertising or retargeting pixels, but this category exists so we can ask before we ever do.
Where your choice is stored
Your cookie preferences are saved in your browser's local storage under the key esports-hub-cookie-prefs. The value is a small JSON object with your analytics and marketing choices and the timestamp of when you last saved them. Clearing your browser storage will reset the choice and reopen the consent question on your next visit.
What we do not do
We do not sell your data. We do not load third-party advertising trackers. We do not record session replays anywhere outside the checkout flow, and even there only when an error occurs and you have left analytics enabled.
Your Rights
Under the Australian Privacy Principles, you have the following rights in relation to the personal information we hold about you:
- Access (APP 12): request a copy of the personal information we hold about you.
- Correction (APP 13): request correction of personal information you believe is inaccurate, out of date, incomplete, irrelevant, or misleading.
- Use limitation (APP 6): have your information used only for the primary purpose for which it was collected, unless you consent to a secondary use or one of the exceptions in the APPs applies.
- Security (APP 11): have your information held securely and protected from misuse, interference, loss, and unauthorised access.
- Complaint: make a complaint about how we handle your personal information.
To exercise any of these rights, email us at privacy@esportshub.io, contact us through our contact page, or the Esports Hub Discord server. We will respond within a reasonable period and provide reasons in writing for any refusal. If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.
Region-Specific Rights
If you are located outside Australia, the following additional rights may apply under your local privacy law. These rights operate alongside the rights under the Australian Privacy Principles described above.
European Union and United Kingdom
Under the GDPR and UK GDPR, in addition to the APP rights above, you have the right to:
- Erasure: request deletion of your account and associated data, subject to exceptions for ban-evasion records and legal retention obligations. Retained payment, transaction, and checkout consent records are de-identified and unlinked from your account. Limited provider transaction references remain for refunds, disputes, and accounting for the period described in Data Storage & Retention.
- Restriction: request that we limit how we process your data while a complaint is being resolved.
- Objection: object to processing that relies on our legitimate interests.
- Portability: request a machine-readable export of the data you provided to us.
- Withdraw consent: revoke any consent you previously gave, including the web portal's OAuth access through your Discord authorized-apps settings.
- Lodge a complaint: file a complaint with your local data protection authority.
California
If you are a California resident, you have rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA), including the right to know what personal information we collect, the right to delete personal information, the right to correct inaccurate personal information, and the right to opt out of the sale or sharing of personal information. We do not sell or share personal information for cross-context behavioural advertising.
Other regions
If you are located in a region with its own privacy law (such as Brazil under the LGPD, Canada under PIPEDA, or other regimes), the rights granted by that law apply to you and are not limited by this policy.
Security
We take reasonable measures to protect your data, including encrypted connections (HTTPS), secure authentication tokens, and access controls on our infrastructure. However, no method of transmission or storage is 100% secure, and we cannot guarantee absolute security.
Data Breach Notification
Esports Hub complies with the Notifiable Data Breaches scheme under Part IIIC of the Privacy Act 1988 (Cth). If a data breach is likely to result in serious harm to affected individuals, we will notify the affected individuals and the Office of the Australian Information Commissioner as soon as practicable in accordance with the scheme. Where you are located outside Australia, we will additionally comply with the breach-notification obligations of your local privacy law (such as Article 33 GDPR for EU users, which sets a 72-hour notification window to the supervisory authority).
Where a breach involves data we received from Discord under the Discord Developer Terms of Service (your Discord ID, username, avatar, server membership, or any other API data), we will additionally notify Discord without undue delay in accordance with Section 5(c) of those terms. Our internal target is to acknowledge the incident within 24 hours of detection and to issue formal notifications within the timelines required by each applicable regime (72 hours for GDPR, "as soon as practicable" for the Australian NDB scheme, and Discord's "without undue delay").
Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by updating the "Last updated" date at the top of this page and, where reasonable, by posting an in-app notice or sending a notification to your Discord direct messages. Continued use of the service after the effective date of an update constitutes acceptance of the revised policy.
Contact
For privacy questions, data-rights requests, or breach notifications, email privacy@esportshub.io. For anything else, our contact page and the Esports Hub Discord server are the fastest channels.
Document versions