Skip to content

Privacy Policy — Discord Sign-In and Discord-Backed Support

**Last updated: 21 August 2026**

This Privacy Policy explains how **Quasar Store** ("we", "us", "the Service"), available at **https://www.quasar-store.com**, handles personal data **in connection with Discord only**:

1. signing in to the Service with your Discord account ("Discord Sign-In"), and
2. the support ticket system, whose conversations are mirrored into our Discord server ("Support Tickets").

Any other processing carried out by the Service is outside the scope of this document.

The data controller is **[Legal entity name, address]**. You can reach us at **[email protected]**.

---

## 1. Discord Sign-In

### 1.1 What we receive

When you choose to sign in with Discord, you are redirected to Discord and asked to authorize our application. Discord then sends us only the data covered by the scopes you approve, which are:

- `identify` — your Discord user ID (snowflake), username, global display name, discriminator (if any) and avatar image reference;
- `email` — the email address associated with your Discord account and whether Discord has verified it.

We do **not** request access to your servers, your direct messages, your friends list, your connections, or your Discord password. We never see your Discord credentials: the sign-in happens entirely on Discord's own pages.

### 1.2 What we store

- Your Discord user ID, username, display name and avatar reference, used as your account identity on the Service.
- Your email address, used to identify your account and to send transactional messages about it.
- The OAuth **access token** and, where issued, the **refresh token** and their expiry times, plus the granted scopes. These are stored so your session can be re-established without asking you to re-authorize on every visit.
- Our own account record: internal user ID, creation and update timestamps, and session records (including IP address and user agent, as is standard for session security).

### 1.3 Why we do it

- To create and authenticate your account, keep you signed in, and secure your session.
- To display your identity (name and avatar) inside the Service and to staff handling your tickets.
- To detect and prevent abuse, account takeover, ban evasion and fraud.

**Legal basis (GDPR):** performance of a contract (Art. 6(1)(b)) for authentication and account management; legitimate interests (Art. 6(1)(f)) for security and abuse prevention. Discord Sign-In itself is initiated by your explicit action of authorizing the application.

---

## 2. Support Tickets

Our support widget creates a ticket on the Service and a matching private channel in our Discord server, so that our staff can reply from Discord while you stay on the website. Messages are mirrored in both directions.

### 2.1 What is processed

- **Message content** you write in the support widget, and the replies our staff write in Discord.
- **Attachments** you or our staff upload (images, files), together with their file name, type and size.
- **Discord identity of the ticket owner** — your Discord user ID and username, stored on the ticket so staff can see who they are talking to.
- **Discord identity of responding staff** — their Discord user ID, display name and avatar, stored on each message so the conversation renders correctly.
- **Discord metadata** — the ID of the private ticket channel, our server (guild) ID, and any user, role or channel mentions contained in a message, resolved to readable names at the time the message is received.
- **Technical context captured once when the ticket is opened** — your IP address and browser user agent, used to help staff diagnose issues and to detect abuse.
- **Timestamps and read receipts** for each message.

### 2.2 Why we do it

- To receive, answer and track your support requests.
- To keep a transcript of the conversation, so both you and our staff can consult what was said.
- To prevent abuse of the support channel (spam, harassment, repeated fraudulent claims).

**Legal basis (GDPR):** performance of a contract or pre-contractual steps taken at your request (Art. 6(1)(b)); legitimate interests (Art. 6(1)(f)) for record-keeping and abuse prevention.

### 2.3 Please note

A support ticket is mirrored into a **private channel inside our Discord server**. Content you send through the widget therefore becomes visible to our support staff on Discord and is processed by Discord as described in Discord's own Privacy Policy. **Do not send passwords, full payment card numbers, government identity documents, or any other sensitive data through a support ticket.**

---

## 3. Who your data is shared with

- **Discord Inc.** — inherently, since both features run on Discord's platform. Discord's handling of your data is governed by the [Discord Privacy Policy](https://discord.com/privacy).
- **Our infrastructure providers** — hosting, database and object storage suppliers acting as processors on our instructions, solely to run the Service.
- **Authorities**, where we are legally required to disclose data.

We do **not** sell your personal data and we do not use Discord-derived data for advertising or profiling.

Where data is transferred outside the EEA/UK (including to Discord, a US company), the transfer relies on the safeguards published by the relevant provider, such as the EU Standard Contractual Clauses.

---

## 4. Retention

- **Account and Discord Sign-In data:** kept while your account exists. If you delete your account, the account record, the linked Discord identity and the stored OAuth tokens are deleted.
- **OAuth tokens:** deleted when you unlink Discord, when you delete your account, or when they expire and are not renewed.
- **Support tickets and transcripts:** kept for **[e.g. 24 months]** after the ticket is closed, for evidence and dispute-handling purposes, then deleted. The private Discord channel is deleted when the ticket is closed; the transcript stored on the Service survives it.
- **Attachments:** kept for the same period as the ticket they belong to, in a private, non-public storage bucket reachable only by the ticket owner and our staff.
- **Session records (IP, user agent):** kept for **[e.g. 12 months]** for security purposes.

---

## 5. Your rights

Subject to applicable law, you may request: access to your data, rectification, erasure, restriction of processing, objection to processing based on legitimate interests, and data portability. You may also lodge a complaint with your local supervisory authority.

To exercise any of these rights, contact **[email protected]**. We answer within one month.

**You can also act directly:**

- Revoke our access to your Discord account at any time in Discord under **User Settings → Authorized Apps**. Doing so prevents further sign-ins with Discord and invalidates the stored tokens.
- Unlink Discord or delete your account from your account settings on the Service.

Revoking access does not by itself delete existing support transcripts; request their deletion using the contact address above.

---

## 6. Security

Access tokens and refresh tokens are stored in our database and are never exposed to the browser. Ticket attachments are stored in a private bucket and served only through an authenticated proxy that checks that the requester is the ticket owner or a staff member. Ticket channels on Discord are restricted to the support staff role.

No system is perfectly secure; we cannot guarantee absolute security, but we notify affected users and the competent authority where a breach legally requires it.

---

## 7. Children

The Service follows Discord's own age requirement: you must be at least **13 years old**, or the minimum age of digital consent in your country if it is higher, to use Discord Sign-In or to open a support ticket. We do not knowingly process data of children below that age; if you believe we have, contact us and we will delete it.

---

## 8. Changes

We may update this policy. The "Last updated" date at the top reflects the current version, and material changes will be announced on the Service before they take effect.

---

## 9. Contact

**[Legal entity name]**
**[Postal address]**
Email: **[email protected]**