1. Plain-language summary
- The website uses Discord to identify members and may keep Discord profile details, OAuth tokens, guild membership, and role information so sign-in, role synchronization, and approved automation can work.
- Information you intentionally submit—such as applications, interview answers, custom forms, onboarding replies, forum content, reports, and RSVP choices—is stored so the community can provide the requested feature.
- The website records technical and security information, including IP addresses or hashes, masked IPs, browser/user-agent information, request identifiers, audit events, and failed or successful security actions to prevent abuse and investigate incidents.
- Some information is visible publicly, some is visible only to signed-in members, and some is restricted to staff with the specific permission needed for their duties.
- Selected events may be sent to configured Discord channels or webhooks. Incident embeds mask IP addresses; access to the full internal incident record remains restricted.
- Vice Valley Roleplay does not use the website to sell personal information or operate behaviorally targeted advertising. Operational providers may process data only to provide hosting, authentication, email, security, backups, or integrations.
- S. Poon has access to the development side only: maintenance, deployment, debugging, database and log diagnostics, backups, security response, and repair. This is technical access—not routine authority to review applications, conduct ordinary moderation, or use member information for unrelated purposes.
- You can download a limited profile-data export from Account Settings. Full deletion and broader privacy requests are handled manually through staff because automated full-account deletion is not currently available.
2. Scope, operator, and responsibility
This policy applies to the Vice Valley Roleplay website, its member accounts, public pages, applications, forums, forms, calendar, staff and department features, administrative tools, developer console, Discord integrations, website-generated email, and the databases, logs, file storage, and backups supporting those features.
“Vice Valley Roleplay,” “VVRP,” “the community,” “we,” and “us” mean the Vice Valley Roleplay community operating this website. The community determines why operational member data is used. Questions and privacy requests may be submitted through the contact page.
Discord, email providers, infrastructure providers, Cloudflare where enabled, and other connected services operate under their own privacy notices for processing they independently control. This policy does not replace those notices.
3. Information the website collects, stores, or creates
The precise fields collected by an application or configurable form may change over time. The following inventory describes the categories supported by the current platform.
A. Core account and Discord identity
- Internal website user ID, profile number, account creation and update timestamps.
- Website username, display name, avatar reference, account lock/suspension state, review flags, and assigned website roles and permissions.
- The version of this Privacy Policy accepted by the account and the server-recorded acceptance date and time.
- Discord user ID, username, global display name, avatar hash or avatar URL, main-guild nickname where available, Discord guild membership, and Discord role IDs.
- Discord OAuth access token, refresh token, and token expiration time when required for connected-account features, membership checks, guild joining, or role synchronization.
- Department tags, department membership, rank, division or command status, joined date, roster order, and department portrait where configured.
B. Profile and staff-directory information
- Biography, “about me” text, title, department, banner image URL, avatar, signature settings, profile appearance and accessibility preferences.
- Birthday, whether the birthday is shown publicly, profile badges, badge notes, award/revocation history, and public activity shown by enabled profile features.
- Staff-directory status, staff role/rank, department placement, featured status, command position, roster portrait, and ordering.
C. Authentication, sessions, and two-factor security
- Session identifier and session data, sign-in state, OAuth state values, intended return URL, step-up authorization time, CSRF state, and temporary authentication challenges.
- Optional email address used for email two-factor authentication, email verification state, pending email, challenge timestamps, attempt counts, hashed verification codes, hashed backup codes, and trusted-device records.
- Trusted-device cookie token, device label or metadata where available, issue/use/expiration timestamps, and security reauthentication state.
- Account-recovery request, Discord ID at request, Discord reauthentication time, IP hash, masked IP, user agent, review status, reviewer, review time, and review note.
- Administrator security-code hash and developer unlock state. Raw administrator security codes and raw two-factor codes are not intended to be stored.
D. Applications and interviews
- Application type, submission ID, applicant account, submission and update dates, status, accepted/denied dates, canonical display name, and configured department choice.
- Every answer entered into application questions, including text, selections, checkbox data, dates, uploaded files, and any age, date-of-birth, contact, character, experience, availability, or department information requested by the form.
- Interview answers, interview start/end/submission times, staff review notes, internal review metadata, reviewer identity, and application timeline entries.
- Discord delivery status, last delivery attempt, limited failure reason, forum thread relationship, and Discord automation records associated with the application.
Do not place passwords, government identifiers, financial information, medical records, or other highly sensitive information in an application unless a field specifically and lawfully requires it.
E. Onboarding and configurable forms
- Onboarding case, linked application, participant identities and roles, case status, activity times, messages, system messages, requested forms, answers, and submission times.
- Custom-form answers, images, optional account association, approval metadata, forum-post relationship, and configured delivery state.
- Public-page form submissions, including the entered field names and values, page/form identifier, submission time, and a one-way hash of the submitting IP address.
- The public contact page provides an email address rather than storing a contact-form submission in the website database. Messages sent to that address are handled by the sender’s and community’s email services.
F. Forums and community interaction
- Forum post title, body, author, section, creation/update dates, linked application, public slug, lock/deletion state, and moderation reason.
- Comments or timeline entries, staff-only moderation notes, reactions, watched threads, section watch preferences, last-read time, and thread view history.
- Post reports, reporter, report category, report explanation, report status, and moderation actions.
- Notification title, body, type, destination link, read time, delivery metadata, and user notification preferences.
G. Calendar and events
- Event creator, title, description, times, location, address, Discord channel, banner, tags, event links, publication/cancellation details, and custom event fields.
- RSVP status, changes, waitlist position, approval/lock information, plus-one count, assisting-member assignment, and staff RSVP override history showing the acting and affected users.
H. Moderation, bans, audit records, and security incidents
- Account flags, suspension/lock state, user or Discord ban, reason, source, related metadata, staff member who acted, and action time.
- IP-ban HMAC hash, masked IP, reason, source, expiration time, and creator. The hash is used to compare requests without displaying the complete address in normal ban-management views.
- General audit events: actor, action, target, result, category, severity, incident relationship, request IP address, browser/user-agent, before/after state, metadata, request ID, and Discord-log delivery status.
- Security audit events: actor, action, target, success, IP hash, masked IP, user agent, request ID, before/after state, and metadata.
- Security incidents: signal/cause, event count, time, source hash and masked source, attempted path, possible matched accounts, timeline, resolution, resolver, lockdown state, and permission snapshots needed to restore access after lockdown.
- Error and diagnostic logs: service, event, message, HTTP method/path/status, affected user ID, request ID, and technical details required to diagnose failures.
- Rate-limit or abuse-detection information, such as repeated requests, failed authentication attempts, denied privileged-page access, scanning patterns, and automated risk thresholds.
I. Discord automation and integrations
- Guild IDs, role IDs, department mappings, nickname/display-name values, automation rules, event type, target account, and requested role or membership changes.
- Automation-run ID, idempotency key, submission/user/Discord identifiers, dry-run state, summary, individual steps, guild, action, HTTP status, and error code.
- Discord direct-message and webhook delivery attempts and limited delivery outcomes.
J. Files, images, technical requests, and configuration
- Uploaded file storage key, original filename, file type, size, checksum, public/private marker, and relationship to an application, profile, theme, or custom page.
- Request IP, proxy-provided client IP where trusted, user agent, method, path, response status, time, referrer, request identifier, and server logs generated by normal web requests.
- Site preferences saved in the browser, such as cookie-notice acknowledgement, first-visit acknowledgement, interface state, accessibility choices, or draft/editor preferences.
- Administrative settings and revision history, including the acting user where recorded. Secret settings may include webhook URLs, API credentials, or service configuration and are restricted as credentials rather than member profile data.
- Database backups and file backups that may contain copies of the records described above.
4. How each major feature uses information
Discord sign-in and account linking
Discord identity verifies that a member controls the Discord account being linked. The website uses Discord IDs as a durable account link, displays current names and avatars, checks configured guild membership, synchronizes approved website roles, and may refresh OAuth access when a feature requires it.
Profiles, staff directory, departments, and badges
Profile information supports community identity and optional self-expression. Role, department, rank, staff title, roster, badge, and Discord nickname information supports the public staff directory, department pages, permissions, recognition, and organizational records. Privacy controls determine whether supported fields such as birthday are publicly displayed.
Applications, interviews, and acceptance automation
Application answers allow authorized reviewers to assess eligibility and communicate a decision. The site may create a restricted forum thread, request interview answers, notify the applicant, send a configured Discord embed, join the applicant to approved Discord guilds using OAuth, adjust Discord roles or nicknames, add department tags, and preserve an action history. Application status is intentionally excluded from public social-preview metadata.
Onboarding and custom workflows
Onboarding cases and custom forms coordinate follow-up questions, participant messages, approvals, department transfers, internal-affairs workflows, and other configured community processes. Visibility and approval permissions depend on the form or forum section.
Forums, reports, reactions, views, and notifications
Forum data publishes conversations to the audience allowed for each section, records reactions and watches, marks content read, shows permitted viewer activity, routes reports to moderators, and creates in-site notifications. Staff-only notes remain restricted to authorized users.
Calendar and events
Event details publish community activities. RSVP and waitlist information manages attendance, capacity, approvals, assistance, reminders, and staff overrides. Visibility depends on event and module access settings.
Page builder, uploads, forms, short links, and changelog
Custom pages and saved blocks publish site content; revision history permits restoration. Page forms store submitted answers and an IP hash for abuse prevention. Concurrent authorized editors may briefly share presence details such as display name, avatar, and cursor position with each other while editing. Uploaded files support applications, profiles, pages, and branding. Short links store their creator and destination. Changelog entries may show their staff author.
Moderation and community safety
Flags, reports, suspensions, bans, IP blocks, audit logs, recovery reviews, and incident records protect members and the platform, enforce community rules, investigate misuse, preserve evidence, prevent accidental or unauthorized staff actions, and support accountability. Automated detection can group suspicious behavior into a reviewable incident but does not by itself establish that a person acted maliciously.
Lockdown and privileged areas
During security events, lockdown can temporarily suspend elevated access while preserving permission snapshots for restoration. The developer and admin areas record denials and require additional authentication for sensitive actions. These records are used to detect probing and investigate potential compromise.
FiveM server panel
The home page may retrieve and display configured FiveM server status, join information, player count, and related server metadata. The website does not use that panel by itself to create a permanent website record of an individual player unless another configured integration or log expressly does so.
5. Why information is processed
Depending on applicable law and the context, processing is based on one or more of the following purposes and grounds:
- Provide the community service: create accounts, authenticate members, show profiles, operate forums, process forms and applications, manage events, send requested notices, and provide staff tools.
- Member request or consent: connect Discord, enable optional email 2FA, publish optional profile details, upload content, submit a form, RSVP, watch a thread, or join a configured Discord guild.
- Legitimate community interests: organize departments, enforce permissions, moderate content, prevent fraud and abuse, investigate incidents, maintain reliable services, troubleshoot errors, and document decisions.
- Security and legal obligations: preserve relevant evidence, respond to lawful requests, protect accounts, enforce bans, maintain audit trails, and address threats to members or systems.
- Establish or defend claims: retain records reasonably needed to explain moderation, application, access, safety, or security decisions.
6. Who can access information
Access is intended to follow role-based permissions and need-to-know duties. Holding a staff title does not automatically grant access to every record.
You
You can view information shown in your account, your permitted submissions and threads, notifications, profile, security settings, and a limited downloadable profile-data export. The export does not currently include every application, forum, audit, or security record associated with you.
Public visitors and signed-in members
They may view information intentionally published to public or member-visible profiles, staff directories, department rosters, forums, calendar pages, leaderboards, badges, and custom pages. Restricted content remains subject to section, role, ownership, or permission checks.
Application, onboarding, and department staff
Staff with the relevant application-set, form, department, forum-section, or onboarding permission may access the submissions, answers, files, interview responses, applicant identity, internal notes, and decision tools needed for that assignment. Department staff should not use application data outside the review or onboarding purpose.
Forum moderators, event staff, and content editors
Authorized personnel may access reports, staff notes, deleted or locked content, viewer or watch data where displayed, RSVP administration, page revisions, submitted page forms, and other content within their granted area.
Administrators and security reviewers
Administrators with specific permissions may manage users, roles, bans, settings, backups, Discord mappings, audit logs, recovery requests, and integrations. Authorized developer-console reviewers may inspect security incidents, possible account matches, masked network data, and—only after additional authentication where implemented—more sensitive diagnostic information or actions.
S. Poon — development access only
S. Poon has technical development-side access required to build, deploy, maintain, diagnose, secure, back up, restore, and repair the website and its integrations. Because those duties can require database, server, source-code, configuration, diagnostic-log, backup, and developer-console access, S. Poon may technically encounter member records when necessary to investigate a defect, security incident, failed automation, data corruption, or support issue.
This access is limited in purpose to development and platform operations. S. Poon does not use development access for routine application decisions, ordinary department review, routine forum moderation, or unrelated inspection of member information. Technical access does not grant permission to disclose or use information for personal or unrelated purposes.
Automated systems and service providers
The website, database, hosting platform, Discord integration, email provider, security proxy, rate-limit store, file storage, and backup provider may process data automatically to deliver their function. Access by provider personnel is governed by their systems, contracts, policies, and security controls.
8. Public, member-visible, staff-only, and secret information
- Potentially public: chosen display name, Discord-derived avatar, public profile number and URL, profile biography/about text, visible birthday choice, banner, roles, department, rank, staff-directory placement, badges, public forum content, reactions, published events and attendee/RSVP lists where the calendar page shows them, birthday broadcasts to community notification audiences when enabled, public custom pages, and content you intentionally submit to a public form or thread.
- Member or permission restricted: non-public forums, application threads, onboarding cases, custom forms, event RSVP details, staff notes, reports, internal review data, notifications, and role-restricted custom pages.
- Administrative or security restricted: audit logs, IP data, bans, recovery requests, security incidents, permission snapshots, error logs, automation diagnostics, backups, secrets, OAuth tokens, webhook URLs, and provider credentials.
- Social previews: crawlers may receive limited metadata for protected links so Discord can show a useful embed. For application threads, the preview may show application type, applicant display name, department, and submission date, but not application status or full answers.
Public information can be copied, cached, indexed, screenshotted, or reposted by others. Removing it from this website may not remove copies held elsewhere.
10. Security and privacy controls
The platform includes controls intended to reduce unauthorized use, including:
- Role- and permission-based access checks for staff modules, applications, forums, forms, page editing, moderation, administration, and developer tools.
- Discord OAuth authentication, optional email 2FA, step-up verification for high-risk actions, session rotation, CSRF protection, secure/HTTP-only cookies, trusted-device controls, and recovery review.
- Rate limiting, abuse-signal detection, privileged-area monitoring, account/IP bans, lockdown controls, request IDs, security alerts, and audit trails.
- HMAC hashing for IP matching in bans and many security records; masking for routine IP display and incident Discord embeds. General internal audit logs may retain the full request IP for authorized diagnostics and investigations.
- Hashing of administrator codes, two-factor verification codes, backup codes, and trusted-device validation material. Raw OAuth tokens are operational secrets stored for connected Discord functions and restricted to backend use.
- Sanitization and validation of user content, file limits, secret-setting flags, noindex controls for privileged pages, and confirmation prompts for destructive actions.
- Rotating backups when enabled, diagnostic error records, and revision histories used to recover from operational mistakes or corruption.
No internet service can guarantee absolute security. Members should protect their Discord and email accounts, avoid sharing codes, use unique credentials, report suspicious behavior, and avoid placing unnecessary sensitive information in free-text fields.
11. Retention, archival, and deletion
The platform does not currently apply one universal automatic deletion deadline to every record. Data is generally kept for as long as the account or feature remains active, the record is needed for community operations, or security, moderation, dispute, recovery, or legal reasons justify retention.
- Sessions: normally expire within seven days; temporary OAuth, CSRF, step-up, and challenge state expires sooner according to the relevant security flow.
- Trusted devices: normally expire after approximately 30 days unless revoked earlier.
- Accounts and Discord links: remain while the account exists or until manually disconnected, removed, or anonymized where technically and operationally appropriate. Privacy-policy acceptance version and history remain with the account for compliance evidence.
- In-site notifications: are ordinarily pruned after about 90 days.
- Applications, interviews, onboarding, forms, forums, reports, reviews, calendar records, and moderation history: may remain as community operational history until staff archives, deletes, or anonymizes them. Soft-deleted forum content may remain stored for restoration or moderation history even after it is hidden from ordinary viewers.
- Security and audit records: may be retained longer because they document access, incidents, bans, recovery, administrative changes, and abuse patterns. Security audit records are intentionally write-once through the application and have no ordinary update/delete interface. Hot general audit-log rows may later be moved into restricted archives (currently after about one year when that archive process is run), which can retain the archived copy beyond hot-database deletion.
- Uploads: may remain while linked content or a recovery need exists. A publicly cached copy may persist temporarily after removal.
- Backups: when automatic backups are enabled, the configured system rotates a limited number of archives (currently up to eight by default). Local backup archives are compressed and access-restricted, not application-encrypted. Deleted information can therefore remain in a restricted backup—and in any configured Google Drive backup copy—until that archive rotates out or is removed by operators.
- Discord, email, and operator-configured webhook copies: messages, embeds, direct messages, and delivery records sent to Discord, Resend, or custom webhook destinations follow those recipients’ retention controls, not solely this website’s deletion process.
If a deletion request conflicts with active security, moderation, fraud-prevention, dispute, backup, or legal needs, the community may restrict processing, retain a limited record, or deny part of the request where permitted, while explaining the reason when appropriate.
12. Member choices and privacy rights
Depending on location and applicable law, a member may have rights to request access, correction, deletion, restriction, objection, portability, or withdrawal of consent. The following controls are available or may be requested:
- Edit supported profile, appearance, birthday-visibility, notification, connection, and security settings.
- Download the current profile JSON export from Account Settings → Data & account. This is a limited profile export, not a complete copy of every record.
- Withdraw or modify an application where the relevant application workflow allows it.
- Delete or edit your content where the interface and permissions allow, or ask authorized staff for help.
- Disable email 2FA, revoke trusted devices, or request help with an account-recovery issue, subject to identity and security checks.
- Ask staff to correct inaccurate account, application, department, or moderation information.
- Request a fuller access review, account deletion, or anonymization through the contact page. Because full workflows are not automated, staff must verify identity and review linked applications, forum records, Discord automation, security history, and backup implications manually.
- Complain to a relevant privacy regulator where that right applies.
Requests may require proof that the requester controls the linked Discord account or other reasonable identity verification. The community will not disclose another person’s data in response to a request and may redact staff, security, confidential, or third-party content.
13. Age, minors, and sensitive information
The website relies on Discord authentication and is not intended for anyone below the minimum age permitted by Discord or applicable law. Application forms may ask age or date of birth to evaluate community eligibility. Members should provide only what the form requests and should not submit highly sensitive personal information in open text.
If a parent, guardian, or member believes information was collected from someone who was not permitted to use the service, contact the community so the account and records can be reviewed. Verification may be required before action is taken.
14. Locations and international processing
Vice Valley Roleplay members and service providers may be located in different countries. Discord, hosting, database, email, backup, security, and infrastructure providers may process information in the United States or other locations where they operate. Those locations may have privacy laws different from the member’s home jurisdiction. Where required, the community and its providers should use appropriate safeguards for those transfers.
15. Changes to this policy
This policy may be updated when website features, providers, data practices, community operations, or legal requirements change. The effective date and version at the top will be updated. Material changes may also be announced through a site-wide notice, changelog, Discord announcement, or other reasonable channel.
16. Questions, corrections, exports, and deletion requests
Use the contact details on the Vice Valley Roleplay contact page for privacy questions or requests. Include:
- your website display name and Discord username or Discord user ID;
- the type of request (access, correction, deletion, restriction, objection, or another concern);
- the specific account, submission, post, or record involved; and
- enough information to verify account control without sending a password or 2FA code.
Never send a Discord password, email password, OAuth token, backup code, administrator code, or active two-factor code in a privacy request.