YOUR INFORMATION

Privacy Policy

Operated by Intelliquinte L.L.C. (Raleigh, North Carolina, United States). Contact: support@onavey.com.

Last updated October 9, 2026

Your community belongs in public. Your account information needs clear boundaries.

1. Who handles your information

Intelliquinte L.L.C. (Raleigh, North Carolina, United States) handles information for this website. This policy covers the public directory, accounts, reports, events, subscriptions, ad campaigns, cosmetics, analytics and opt-in storefronts. It describes the implemented website, rather than private Discord game data. Privacy requests use support@onavey.com.

2. Information we collect

  • Account: Discord user identity, name, email supplied through sign-in, and authentication/session information handled by Supabase.
  • Permission checks: your Discord server list and management permissions when you submit or edit a listing. The server checks that Discord access belongs to the signed-in identity.
  • Your submissions: listing descriptions, server IDs, invites, image URLs and uploaded images, rules, events, and review records.
  • Public network: aggregate economy snapshots and explicitly opted-in company identity, completed facilities, project progress and public market offers. Company ownership is linked by verified Discord identity. Vaults, wages, private inventories and individual balances are excluded.
  • Analytics: daily counts and temporary rotating deduplication signatures for public page views, links and sponsored impressions.
  • Your activity: saved listing IDs and reports you send. Guest saves stay on your device.
  • Billing: Stripe customer and subscription identifiers, plan, status, and billing period. One-time purchases include the product, amount, currency, target page, payment identifiers and refund state. Card details are entered directly on Stripe’s hosted pages.
  • Technical data: IP addresses, requests, and device information that hosting and service providers may process to deliver and protect the service.

3. Why we use it

We use account and permission information to authenticate you, verify server management access, operate saved places, and protect ownership. We use submissions to publish reviewed pages and events, reports to investigate directory problems, and subscription records to apply website benefits and manage cancellation.

Where applicable, processing relies on performing the requested service, legitimate interests in security and moderation, legal obligations for financial records, and consent when legally required. We do not sell your personal information. Sponsored campaigns use page categories rather than behavioral profiling. We do not use third-party advertising pixels. Optional first-party engagement analytics record deduplicated views, outbound clicks and sponsored impressions.

4. Public and private information

Approved page names, descriptions, rules, invitations, owner-supplied images, language/category, events, and Onavey participation are public. Optional member counts are labeled owner-reported. Account email, saves, reports, review notes, and billing identifiers are not included in public directory responses. The website does not connect to private bot balances or inventories.

5. Providers and external links

Cloudflare hosts the site and API functions. Supabase handles authentication and website records. Discord supplies identity and permission checks. Stripe provides checkout, billing management, and payment records. GitHub stores website source code; it is not the account database. Providers may process data in countries outside your own under their contractual and legal safeguards.

Viewing owner-hosted images can contact the image host and share your IP address; the site suppresses the image request’s referrer. Opening external links shares information with their operators under their own policies.

6. Cookies and device storage

Guest saved places use local storage. Supabase uses browser storage for the authentication session, including access/refresh information; Discord provider access may be included in the session used to check server permissions. Fonts and scripts are hosted with the website. Optional engagement analytics use a short-lived signed token and a daily rotating device/network signature; no marketing cookie or raw IP address is stored by the analytics database. See cookies and storage for controls.

7. How long information remains

Account, listing, event, saved-place, and report records remain while needed to provide or moderate the service. Account deletion removes associated website records through database relationships. Guest saves remain until you clear them, clear browser storage, or remove individual saves. Signing out clears the authentication session but does not erase guest saves.

Stripe may retain transaction information to meet legal requirements. Provider security logs and backups follow the provider’s configured retention; deleted records can remain in protected backups until they rotate out. Website deletion removes uploaded listing images from their storage prefixes and withdraws public storefronts and removes their website story, images and selected design; bot publication remains blocked until you explicitly opt in again. Private order records and an account reference remain for financial reconciliation and legal obligations; they do not retain your profile, email or private game data. We will publish specific operational retention periods when production logging and backup settings are configured, and retain exceptional records only when necessary for legal or security obligations.

8. Your choices and rights

You can edit your submitted content, unsave places, sign out, clear guest saves, manage subscriptions, and delete your website account. Depending on your location, you may have rights to access, correct, export, delete, restrict, or object to use of your information, or withdraw consent where it is the basis for processing. Contact the privacy address for a request; we may verify your identity to protect your information. You can also complain to your local data protection authority.

9. Security

Server-side authentication and Discord permission checks protect edits; database row-level security and limited public fields separate private records from discovery. Billing changes are processed through verified Stripe events. No system can guarantee complete security. Never send passwords, API keys, tokens, card details, or private identity documents in a directory report.

10. Age requirements

The website is intended for people at least 13 and old enough to use Discord in their country. We do not knowingly create accounts for younger children. Contact support@onavey.com if you believe a child below the required age has provided personal information so we can investigate and remove it where appropriate.

11. Policy updates

The date at the top identifies this version. We will update this policy when data practices change and provide additional notice where required for material changes. New optional tracking or public game-data features require a corresponding policy and product-control update before they are enabled.

ONAVEY