Privacy

Privacy Policy

How Ro-Link collects, uses, stores, and protects information across its website, Discord bot, Roblox integration, and related services.

Effective date: July 27, 2026
01

Who We Are and Scope

Ro-Link Management Services (“Ro-Link,” “we,” “us,” or “our”) operates the Ro-Link website, Discord bot, dashboard, Roblox integration, APIs, plugins, and module marketplace (collectively, the “Services”).

This notice explains how we handle personal information when you use the Services. It does not govern Discord, Roblox, Vercel, or Supabase's independent processing; their own notices apply to their platforms.

02

Information We Collect

  • Discord account and server information: Discord user ID, username, avatar hash, OAuth access and refresh tokens, guild IDs, role IDs, channel IDs, and server configuration provided by administrators.
  • Roblox information: Roblox user ID, username, display name, place and universe IDs, server/job IDs, and account-linking information.
  • Service and moderation data: commands, action logs, reports, reasons, dashboard configuration, player-presence events, runtime diagnostics, and related metadata needed to run, secure, support, or moderate the Services.
  • Module and application content: module source code, configuration, descriptions, creator identifiers, review records, and answers submitted for a job application.
  • Technical information: IP address used temporarily for rate limiting, and authentication-session cookies. We do not use analytics, advertising, tracking, error-monitoring, or non-essential cookies.
03

How We Use Information

We use information to authenticate users; link Discord and Roblox accounts; provide role synchronisation, server management, moderation, module marketplace, and support features; maintain security and rate limits; investigate misuse; enforce our Terms and DGSU Policy; communicate service matters; and meet legal obligations.

We do not sell personal information or use it for targeted advertising.

04

Legal Bases

Where a law requires a legal basis for processing, we rely on the performance of our contract with you, our legitimate interests in operating, securing, improving, and enforcing the Services, your consent where we request it, and compliance with legal obligations. We only process information for purposes consistent with the purpose for which it was collected or as otherwise permitted by applicable law.

05

Cookies, IP Addresses, and Device Information

We use essential, HTTP-only authentication cookies to keep users signed in and help protect sessions. These cookies are not used for advertising or analytics. We temporarily use IP addresses to apply rate limits and protect our endpoints; IP/rate-limit records are not retained. We do not collect device fingerprints or device information for analytics or advertising.

06

Sharing and Subprocessors

We share information only as needed to provide the Services, including with these service providers and platforms:

  • Discord, for sign-in, bot operation, messages, server administration, and support.
  • Roblox, for account linking, game integration, and commands or data needed by the connected experience.
  • Supabase, for database and related backend services. Our production database is hosted in Singapore.
  • Vercel, for website and application hosting. Our production deployment is hosted in Sydney, Australia.

These providers may use their own subprocessors and may process information under their own terms and privacy notices. We may also disclose information where reasonably necessary to protect users, investigate abuse, enforce our policies, comply with law, or respond to a valid legal process.

07

International Transfers and Hosting

Your information may be processed in New Zealand, Australia, Singapore, the United States, and other countries where Discord, Roblox, Vercel, Supabase, or their subprocessors operate. Those countries may have privacy laws that differ from the laws where you live. By using the Services, you acknowledge these international transfers. We take reasonable steps to use providers that apply appropriate security protections to the information they process for us.

08

Retention

  • Account and account-link data are retained unless you request deletion.
  • Discord OAuth tokens are retained locally as part of the authenticated service session until the associated user data is deleted.
  • Moderation and action logs are deleted with the associated user data.
  • Runtime logs are deleted after 48 hours.
  • Support requests are retained in Discord.
  • Job applications are deleted after the relevant application closes.
  • Module content is deleted when its creator uses the delete function.
  • We do not maintain separate backups or retained IP/rate-limit records.

We may retain limited information longer where necessary to comply with law, resolve disputes, or protect the security and integrity of the Services.

09

Your Privacy Rights

Depending on where you live, you may have rights to ask for access to, correction of, deletion of, or restriction of the processing of your personal information; to object to certain processing; to withdraw consent; or to complain to a privacy regulator. New Zealand users may make requests under the Privacy Act 2020. United States residents, including California residents, may have additional rights under applicable state law.

Ro-Link does not provide a self-service data export. You can request access, correction, deletion, or other privacy assistance through our Support Server. We may need to verify your identity before acting on a request. You may also complain to the Office of the Privacy Commissioner in New Zealand or your local privacy regulator.

10

Children and Minors

The Services are not intended for children under 13. You must be at least 13 years old to use them. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided us personal information, contact support so we can take appropriate action.

11

Security and Breach Response

We use reasonable technical and organisational measures designed to protect information, including secure authentication flows and access controls. No system is completely secure. We assess suspected privacy breaches and will notify affected people and relevant regulators where required by applicable law, using email, dashboard notices, Discord, or another reasonable method.

12

Changes and Contact

We may update this notice to reflect changes to our Services or legal obligations. We will post the revised version here and update the effective date.

For privacy requests, questions, or formal privacy notices, contact Ro-Link through the Ro-Link Support Server.