Privacy Notice
This Notice explains how CoreRP Systems processes personal data when operating the Role Link Discord bot, website, dashboard, and public API.
Effective and last updated: 24 July 2026
1. Controller and contact
CoreRP Systems, Slovakia, is the operator of Role Link and the controller for processing where we determine the purposes and means. Contact us about privacy at privacy@corerp.systems. Legal notices may be sent to legal@corerp.systems.
A Discord server owner or organization may separately determine why its server uses Role Link and which configurations are enabled. For processing performed solely on that server's documented instructions, that owner or organization may be the controller and CoreRP Systems may act as its processor or service provider.
2. Scope
This Notice applies to Role Link's website, Discord OAuth sign-in, dashboard, bot operations, configuration synchronization, public API, security systems, support, and operational logging. Discord and our infrastructure providers process some information under their own notices.
3. Data we process
- Discord identity: Discord user ID, username, global display name, avatar reference, bot/system status, OAuth provider identity, and authentication timestamps.
- Guild and authorization data: guild ID, name, icon, owner ID, availability, membership, Discord permissions, dashboard eligibility, and the time access was matched.
- Synchronized Discord metadata: roles, role IDs, role colors, hierarchy positions, managed status, permissions, channels, channel types and positions, categories, members, and member-role relationships.
- Configuration: Role Links, join roles, delegated role grants, reaction-role messages and options, log destinations and events, selected channels, enabled settings, and configuration revisions.
- Operational records: bulk jobs, role mutations, audit events, actors, affected members and roles, outcomes, error categories, correlation IDs, synchronization status, and timestamps.
- Public API data: key name, prefix and one-way key hash, creator, scopes, allowed roles, expiration/revocation, rate-limit state, idempotency key, command member and role IDs, operation, status, attempts, and bounded Discord response status. A newly generated secret is displayed once and is not stored in recoverable plaintext.
- Technical and security data: IP address, request time, route, method, user agent, essential session cookies, origin, rate-limit counters, request fingerprints, security events, server logs, and correlation IDs.
- Communications: information you provide when requesting support, reporting abuse, exercising privacy rights, or disclosing a security issue.
Do not provide passwords, Discord tokens, webhook tokens, payment-card data, health data, government identifiers, or other sensitive personal data. Role Link does not request Discord message content for its core role-management functionality.
4. Sources of data
- you, when you sign in, configure a guild, create an API key, call the API, or contact us;
- Discord, through OAuth, Gateway events, REST APIs, interactions, and data available to the installed bot;
- guild owners and authorized administrators who configure Role Link for their communities;
- our systems and providers, which generate authentication, security, delivery, and operational records; and
- API clients acting with a valid Role Link API key.
5. Purposes and legal bases
- Contract and requested service (GDPR Article 6(1)(b)): authenticate users, display manageable guilds, apply configurations, perform authorized role changes, deliver reaction-role messages, process API commands, and provide requested dashboard functions.
- Legitimate interests (Article 6(1)(f)): secure accounts and infrastructure, enforce hierarchy and authorization, prevent abuse, rate-limit requests, maintain auditability, troubleshoot failures, protect legal rights, and improve reliability. We balance these interests against the rights and reasonable expectations of Discord users.
- Legal obligations (Article 6(1)(c)): respond to lawful requests, protect data, preserve required evidence, and comply with applicable regulatory or court obligations.
- Consent (Article 6(1)(a)): only when we specifically request consent for an optional purpose. Consent can be withdrawn without affecting earlier lawful processing.
6. Discord OAuth and cookies
Dashboard sign-in redirects directly to Discord and requests the identify OAuth scope. Guild-management access is not accepted from the browser; it is determined from bot-maintained eligibility data and revalidated on the server.
We use essential, secure authentication cookies created through Supabase Auth. They maintain your signed-in session and protect authenticated requests. We do not currently use advertising cookies, cross-site behavioral tracking, or optional web analytics. Because these cookies are strictly necessary to provide the service you request, they do not require an optional cookie banner under applicable ePrivacy rules.
7. How we share data
We disclose only the information reasonably necessary to:
- Discord: authenticate users and read or make authorized guild, channel, message, member, and role changes. Discord acts under its Privacy Policy.
- Supabase:provide authentication, PostgreSQL database hosting, and related infrastructure under Supabase's privacy terms.
- Vercel: host and deliver the website and server-side dashboard under Vercel's Privacy Notice.
- Upstash:provide server-side Redis rate limits, transient coordination, and configuration invalidation under Upstash's Privacy Policy.
- Professional advisers and authorities: when reasonably necessary to obtain advice, establish or defend claims, comply with law, or protect users and the Service.
- Business transfer: as part of a merger, reorganization, financing, or transfer of the Service, subject to confidentiality and applicable notice requirements.
We do not sell personal data, share it for cross-context behavioral advertising, or use Discord API data to train artificial-intelligence or machine-learning models.
8. International transfers
Provider regions and subprocessors may involve processing outside Slovakia or the European Economic Area. Where required, transfers are protected by an adequacy decision, the European Commission's Standard Contractual Clauses, the EU-U.S. Data Privacy Framework where applicable, or another lawful transfer mechanism. Provider-specific details are available in their privacy notices and data-processing addenda.
9. Retention
We retain personal data only for as long as reasonably necessary for the relevant purpose:
- authentication and identity links are kept while needed to provide account access, resolve security issues, or comply with deletion and legal obligations;
- synchronized guild metadata and configuration are kept while the bot and dashboard serve the guild; when the bot leaves, dashboard eligibility is removed and the guild is marked as left, after which remaining data is deleted or anonymized when no longer needed for restoration, security, disputes, or legal obligations;
- rate-limit and idempotency records are short-lived and expire automatically according to their technical time limits; Redis coordination and invalidation messages are transient;
- API keys remain until expiration, revocation, or deletion is appropriate; key secrets are stored only as one-way hashes after their one-time display;
- audit, security, command, and operational records are retained as needed to investigate incidents, demonstrate authorization, maintain reliability, resolve disputes, and comply with law; and
- provider logs and encrypted backups remain until their configured rotation or deletion cycle completes.
Retention decisions consider the amount and sensitivity of data, risk of harm, feature needs, user requests, Discord requirements, limitation periods, and legal duties. Data may be anonymized instead of deleted where it can no longer identify a person.
10. Security
We use measures designed to protect data, including HTTPS, secure and HTTP-only session cookies, server-side authorization, Discord hierarchy validation, PostgreSQL row-level security, restricted service credentials, one-way API-key hashing, rate limits, origin checks, idempotency controls, security headers, correlation IDs, audit logs, secret redaction, and bounded retries.
No service can guarantee absolute security. If you suspect an exposed API key, unauthorized dashboard access, or a data incident, revoke affected credentials and contact privacy@corerp.systems promptly. We will assess and notify affected people and authorities where applicable law requires it.
11. Your rights
Subject to applicable law, you may request access, correction, erasure, restriction, portability, or a copy of your personal data; object to processing based on legitimate interests; withdraw consent; and receive information about relevant safeguards for international transfers.
Send requests to privacy@corerp.systems. Describe the Discord account and guild involved. We may request proportionate proof of identity and guild authority, particularly where disclosure or deletion could affect other members or a server's records. We normally respond within one month, subject to lawful extensions.
You may complain to the Office for Personal Data Protection of the Slovak Republic or another competent supervisory authority, and you may seek a judicial remedy.
12. Server members and administrator responsibilities
Guild owners and administrators must configure Role Link transparently, limit access to authorized personnel, choose lawful logging and automation settings, and provide any additional notice required to their members. They must not use Role Link to make unlawful eligibility, employment, housing, insurance, credit, or similarly significant decisions.
If you are a server member who does not control the guild, you may contact the guild owner about its use of Role Link and may also contact us. We may coordinate with the guild owner when necessary to verify and fulfill a request without exposing other users' information.
13. Automated processing
Role Link automatically evaluates permissions, hierarchy, cycles, configured mappings, rate limits, and safety rules before role operations. These checks protect users and enforce administrator instructions. We do not use personal data for profiling or solely automated decisions that produce legal or similarly significant effects within the meaning of GDPR Article 22.
14. Children
The dashboard is intended for people authorized to manage Discord servers. You must meet Discord's minimum age and applicable local requirements. We do not knowingly solicit personal data directly from children who cannot lawfully use the Service. Contact us if you believe such data is being processed improperly.
15. Third-party links
Links to Discord, provider documentation, or other websites are provided for convenience. Their operators independently control their websites and privacy practices. Review their current notices before providing information to them.
16. Changes to this Notice
We may update this Notice to reflect legal, technical, vendor, or service changes. The current version will be posted here with its effective date. We will provide additional notice for material changes where required or reasonably practicable.
17. Contact
Privacy questions and rights requests: privacy@corerp.systems. Legal notices: legal@corerp.systems. Service operator: CoreRP Systems, Slovakia.
The legal rules governing use of Role Link are available in our Terms of Service.