The·Cantina·Network ©

Skip to policy content

The Cantina Network

Privacy Policy

Websites, community services, chat, events and management tools

Effective
Last updated
Privacy contact
info@the-cantina.net

1.Who we are

The Cantina Network ("TCN", "we", "us") is an informal, non-commercial online gaming community operated from the Netherlands. People from around the world may join and use our community services.

The controller responsible for the processing described in this policy is the community operating under the name The Cantina Network:

The Cantina Network community
Operated from: The Netherlands
Privacy contact: info@the-cantina.net
Back to top

2.Services covered by this policy

This policy covers TCN-operated services, including:

  • the-cantina.net and related TCN websites;
  • the TCN Anniversary website and its contact and contribution flows;
  • The Cantina Chat at chat.the-cantina.net;
  • TCN-managed Discord and TeamSpeak spaces;
  • TCN email and community-administration systems;
  • moderation and safety tools, including Sentinel; and
  • the Discord-The Cantina Chat synchronization and management bot, when that service is enabled.

Third-party services such as Discord, Stripe and Cloudflare also process data under their own privacy notices. This policy describes TCN's role and does not replace those third-party notices.

Back to top

3.Personal data we process

The data depends on the service you use.

Accounts, profiles and community membership

We may process platform account identifiers, usernames, display names, nicknames, avatars, email addresses used for registration or verification, community and channel memberships, roles, permissions, account-link status, status information and recent activity.

The main website has a small number of administrator and editor accounts. If WordPress comments are used, a comment can include the name and email address supplied by the commenter, the comment, IP address, browser information and an optional comment cookie.

The website's World of Warcraft roster feature receives public or pseudonymous character information from Raider.IO, including character and realm names, class, race, specialization, role, faction, achievement and honour information, item level and a Raider.IO profile link.

Content and communications

We process messages, edits, deletions, replies, reactions, attachments and attachment metadata, voice-session participation, moderation reports, contact-form messages, support and privacy requests, and other content you choose to submit to a TCN service or community space.

TCN does not record TeamSpeak voice. The current TeamSpeak service is a temporary community setup. The Discord-The Cantina Chat bot's cross-platform voice relay is also disabled.

Community administration and safety

We may process role and permission changes, bans and timeouts, exempt-user settings, security and moderation events, review decisions, consent choices, administrative audit metadata and service-health information.

Sentinel receives Discord guild, member, message and AutoMod events needed to detect configured trap-role mentions and enforce the guild's anti-spam rules. It stores identifiers, timestamps, policy/configuration state, evidence state and enforcement outcomes. It does not persist message bodies as detection evidence. Its operational logs may contain guild, user and resource identifiers, account age, enforcement reason and delivery outcome. Relevant events may also be posted to a configured Discord moderation-log channel.

Automated tools can flag or enforce clear configured rules. You may ask for human review of a moderation decision by contacting us.

Technical and security data

Ordinary operation may produce IP addresses, request times, requested hosts and paths, browser or client information, session identifiers, gateway and connection metadata, rate-limit information, error codes, mail-routing metadata and security logs.

Our self-hosted mail system processes mailbox contents and delivery metadata. Mail logs may include sender and recipient addresses, connection IP and client details, authenticated account name, queue identifiers, delivery status and anti-abuse results such as SPF, DKIM or policy checks.

The synchronization bot removes query strings from request logs and redacts OAuth codes, state values, authorization headers and cookies.

Anniversary contact and contribution data

The Anniversary contact form asks for a name, email address and message. Its normal JavaScript flow sends the message to our server, which delivers it directly to a TCN mailbox. We do not use contact submissions for advertising, profiling or a CRM.

For a contribution, our server sends the selected amount to Stripe to create a Stripe-hosted Checkout session. Stripe collects the payment details. TCN may receive the contribution amount, transaction or Checkout identifier and status, and information needed for event reconciliation, refunds, disputes, fraud prevention or legally required records. TCN does not receive full payment-card details through the ordinary Checkout integration. The public participant statistic is an aggregate count.

Sensitive information in free-form content

TCN does not ask you to include special-category or otherwise sensitive personal data in messages, uploads or contact forms. If you include it, the people who can access that community space or mailbox may see it. Do not share information you do not want those recipients to receive.

Back to top

4.How we obtain data

We obtain data:

  • directly from you when you create an account, post content, contact us, contribute, link accounts or change a consent choice;
  • from Discord, The Cantina Chat, TeamSpeak, Stripe or another service when you use an integration or TCN-managed community space;
  • from Raider.IO for the public guild-roster display; and
  • automatically through ordinary website, application, mail, security and network operation.

For the synchronization bot, source data comes from the Discord and The Cantina Chat communities in which the bot is installed and configured.

Back to top

5.Why we process personal data

We process personal data to:

  • provide, secure, maintain and troubleshoot TCN services;
  • administer accounts, memberships, roles, community content and events;
  • deliver contact messages to the TCN mailbox and respond to them;
  • provide the Stripe-hosted contribution flow and reconcile contributions;
  • display public guild information from Raider.IO;
  • operate optional account linking and cross-platform synchronization;
  • synchronize configured channels, roles, permissions, moderation state and informational presence where those features are enabled;
  • prevent abuse, enforce community rules, protect users and infrastructure, and keep proportionate accountability records;
  • respond to support, privacy and lawful requests; and
  • keep records where Dutch or other applicable law requires them.

We do not sell personal data. We do not use personal data for advertising or a CRM. The synchronization bot contains no advertising, product analytics, third-party telemetry or crash-reporting destination. Our live-observed public websites did not load advertising or analytics trackers at the date above.

Back to top

6.Discord-The Cantina Chat synchronization bot

The synchronization bot is not currently active. The following terms apply if it is enabled.

Text synchronization and identity labels

The bot receives configured Discord and The Cantina Chat gateway events so it can decide whether they are eligible for synchronization. Normalized events may be held temporarily in an encrypted queue before the consent decision is applied. Consent controls delivery to the other platform; it does not prevent the limited initial processing needed to receive the event, enforce your choice, prevent loops, and discard or deliver it safely.

Text is sent to the other platform only after the required text-relay consent exists. A synchronized message may show your display name, avatar and a source label such as "Discord" or "TCN Chat". Members who could not see the source channel may therefore receive the synchronized copy if they can access the mapped destination channel.

Message identifiers, channel mappings, revisions, timestamps and a one-way content fingerprint may be retained to synchronize edits and deletions and to prevent duplicate or looping messages. Deleting a mapped message is intended to delete its mapped copies too, subject to platform availability and API behaviour.

Attachments

Attachment metadata and source links may be synchronized. Byte transfer is disabled unless TCN configures an exact approved HTTPS source-host allowlist and size limit. When enabled, bounded attachment bytes are held transiently in process memory for transfer and are not written to a durable local bot file. Discord and The Cantina Chat then store the delivered copy under their respective service behaviour.

Account linking, roles and presence

Account linking is optional. The bot stores a one-way digest of each short-lived link code rather than the displayed code. Once verified, it stores the paired platform account identifiers. Unlinking stops use of the pairing but is not by itself a request to erase every historical record.

Configured role, permission, membership, ban, nickname or informational presence data may be synchronized only when the corresponding feature is enabled. Role-derived administrative access fails closed when membership data is stale or unavailable.

Voice

Cross-platform voice relay is disabled. It will not be enabled without a separate acceptance review, prominent disclosure and voice-specific consent. If introduced, the bot is designed for live-only audio: it will not record, durably store, transcribe, analyse, clone or use audio for training. A relay would terminate each platform's transport-encryption boundary and could not reproduce every listener's native cross-platform block or mute relationship. These limitations would be shown to participants before activation.

Back to top

7.Legal bases

Where the GDPR applies, we rely on one or more of these legal bases:

  • Consent: for optional cross-platform text relay, optional account linking, any future voice relay, and non-essential cookies or similar technologies where required. You may withdraw consent at any time.
  • Steps requested by you or performance of an agreement: where processing is necessary to provide an account, contribution flow or other service you specifically request.
  • Legitimate interests: to operate this informal community, publish and maintain community information, deliver requested contact messages, secure services, prevent abuse, investigate faults, enforce rules and keep narrowly scoped accountability records. We balance those interests against your rights and interests.
  • Legal obligation: where we must keep financial records or respond to a legally binding request.
  • Legal claims: where data is necessary to establish, exercise or defend a legal claim.

Withdrawal of consent does not affect processing that was lawful before the withdrawal. A different legal basis may still permit limited processing, for example to keep a suppression record or handle a dispute.

Back to top

8.Recipients and service providers

Personal data may be received by:

  • members and administrators of the community space in which content is posted or synchronized;
  • Discord when you use Discord, Sentinel processes a Discord event, or content is synchronized to Discord;
  • TCN's self-hosted The Cantina Chat, WordPress, TeamSpeak, mail and infrastructure systems where needed to provide those services;
  • Stripe when you use the Stripe-hosted contribution flow. Stripe processes payment data under its applicable processor and independent-controller roles, including its own security, fraud-prevention and legal-compliance purposes;
  • Cloudflare when it provides DNS, reverse-proxy, security or Turnstile services;
  • Raider.IO, as the source of the public guild data displayed by the website;
  • Google Fonts, jsDelivr, Figma and Unsplash when a page loads an asset directly from those services; those services receive ordinary request data such as your IP address and browser request details;
  • TCN's infrastructure-hosting and backup providers where needed to operate or protect a service; and
  • authorities or other recipients where disclosure is legally required or necessary to protect legal rights.

TCN administrators receive access only where needed for operations, moderation, security, support or legal compliance.

Relevant third-party notices include:

TCN remains responsible for deciding to offer the contribution flow, what TCN asks Stripe to process and how TCN uses the transaction information it receives. Stripe's precise role depends on the activity and its terms.

Back to top

9.International transfers

TCN is operated from the Netherlands, but our community is worldwide and some providers process data outside the European Economic Area. This can include Discord, Stripe, Cloudflare and external asset providers.

Their privacy notices describe their processing locations and transfer mechanisms. Where TCN is responsible for a restricted international transfer, we use an applicable safeguard, such as an adequacy decision or approved contractual clauses, and assess additional safeguards where required.

When you deliberately post in a worldwide community space, other community members may view that content from their own countries. Do not post content that you do not want those members to receive.

Back to top

10.Retention

We keep personal data only as long as needed for the purpose described below, security, disputes and applicable legal obligations. We delete or anonymize it when it is no longer needed, subject to technical dependencies and protected backups.

Websites, roster, contact and contributions

  • WordPress administrator and editor accounts are kept while access is needed and removed or disabled when that access ends.
  • Published website or event content remains while it is relevant to the community or until it is removed. If comments are used, a comment and its associated metadata remain with the comment until removal, anonymization or a valid erasure request, unless a security or legal reason requires more.
  • Raider.IO guild-roster cache data remains while used for the roster and is replaced or removed when the roster is refreshed or the feature is removed.
  • Contact-form and support correspondence is normally deleted 12 months after the last substantive contact, unless it is still needed for an open request, safety matter or legal claim.
  • TCN-held operational contribution data is kept until event reconciliation and any refund or dispute period is complete. Records required by Dutch law are kept for the applicable statutory period. Stripe applies its own retention to data in its service.

The Cantina Chat

The Cantina Chat uses Fluxer's default self-hosted lifecycle settings at the date above:

  • a user-requested account deletion is scheduled after a 72-hour grace period and can be cancelled by signing back in during that period;
  • the deletion process removes or anonymizes profile and authentication data, sessions, relationships, notes, saved items, IP authorizations, guild membership and user avatar/banner files;
  • existing messages are anonymized to a generic deleted user rather than automatically erased, so the conversation remains understandable; message content and its attachments remain until separately deleted or removed;
  • inactive ordinary accounts become eligible after at least two years without activity, followed by a 30-day warning period and the deletion grace period; and
  • eligible attachments can expire under the instance's enabled attachment- decay rules. Their exact lifetime depends on size, renewal and the effective instance media configuration shown by the service.

Sentinel

  • Open detection evidence and message-detection state expire with the configured detection window. The upstream defaults are 30 seconds for message-mode detection and 1 hour for AutoMod detection.
  • Expired data is purged on startup and by a daily cleanup task, with lazy cleanup during new detections.
  • Closed, cancelled, superseded or manual enforcement claims and related evidence, and enforcement-attempt records, are deleted after 30 days.
  • A departed guild's configuration and exempt-user records are deleted 30 days after the bot leaves. Active-guild configuration remains until changed or the guild is removed.
  • Discord retains copies posted to a Discord moderation-log channel according to that channel's settings and Discord's service behaviour.

Synchronization bot

When its maintenance service is running, the synchronization bot uses this schedule:

  • successful or discarded encrypted queue payloads are scrubbed immediately;
  • consent-held message copies are normally resolved or scrubbed within 10 minutes;
  • encrypted dead-letter payloads are scrubbed within 7 days;
  • expired or consumed link challenges are deleted after a 1-day grace period;
  • mappings for already-deleted messages, account-link records after unlinking, and resolved or superseded consent history are deleted within 30 days when no dependent event remains;
  • the latest relevant consent decision remains while the account profile remains, so deleting a revocation cannot reactivate an older permission;
  • eligible inactive non-bot platform profiles are deleted after at least 30 days without activity once no link, session, grant, fresh membership, challenge or consent dependency remains;
  • browser sessions last up to 12 hours, and expired or revoked session records are deleted within a further 30 days; and
  • metadata-only bot audit events are deleted within 365 days.

Active bot identity, mapping, role, moderation and consent records remain while needed for the enabled service or its integrity. Bot application logs are size-bounded and rotated; incident extracts may be kept while an investigation or claim remains open.

TeamSpeak, email, service logs and backups

The temporary TeamSpeak service keeps client, permission, ban and connection information only while needed to operate the service, enforce an active sanction or investigate a fault. TCN does not retain TeamSpeak voice recordings. Data that is not needed for a continuing sanction or incident will be removed when the temporary service is retired.

Mailbox contents remain until the mailbox user deletes them or until the applicable correspondence period above ends. Routine website, mail, proxy, application and infrastructure logs are kept for the shortest period needed for delivery, security, troubleshooting and abuse prevention. Incident extracts may be kept while the incident or related claim remains open.

Protected backup and rollback copies are not used for ordinary access. Some current operational backups are manual rollback sets rather than a uniform rolling schedule, so TCN does not promise a universal backup-deletion period. Copies are removed when they are no longer needed for safe recovery. If a backup is restored, applicable deletions must be reapplied where practicable.

Back to top

11.Cookies and similar technologies

TCN services use necessary cookies or equivalent storage for login sessions, security, preferences and OAuth state. WordPress can set login cookies for administrators and, if a commenter selects the option, a convenience cookie for comment details. Cloudflare Turnstile may process data needed to distinguish legitimate users from automated abuse.

The synchronization bot dashboard does not use product analytics or advertising trackers. Our live-observed public WordPress and Anniversary pages did not load analytics or advertising trackers at the date above. If we add non-essential analytics, marketing or similar technology, we will identify it and obtain consent where required before enabling it.

Directly loaded fonts, scripts and images from the external providers listed in section 8 are not advertising, but they cause the visitor's browser to make a request to those providers.

Back to top

12.Security

Depending on the service, safeguards include HTTPS, network isolation, access controls, protected secret storage, encrypted sensitive bot payloads, hashed link and session values, restricted administrative permissions, security logging, rate limiting and hardened containers. No online service can guarantee absolute security.

If you believe TCN data or an account has been compromised, contact us promptly at info@the-cantina.net.

Back to top

13.Your choices and rights

Depending on applicable law, you may have rights to:

  • receive information about processing;
  • access and receive a copy of your personal data;
  • correct inaccurate or incomplete data;
  • request deletion;
  • restrict processing;
  • object to processing based on legitimate interests;
  • receive portable data where the right applies;
  • withdraw consent; and
  • request human review of a moderation decision.

WordPress includes export and erasure tools for data associated with an email address. The synchronization bot provides commands to link or unlink accounts, view consent status, and allow, decline or revoke text consent. Unlinking or revoking consent is not the same as requesting complete erasure.

To exercise a right, email info@the-cantina.net. We may ask for enough information to verify that you control the relevant account. We respond without undue delay and normally within one month where the GDPR applies, subject to a lawful extension or exception.

You may complain to the Dutch supervisory authority, the Autoriteit Persoonsgegevens.

Back to top

14.Children

TCN services are not intended for anyone below the minimum age required by the service they use or the law that applies to them. A person below the age at which they may give valid consent must not use a consent-based TCN feature without the required parent or guardian authorization. Contact info@the-cantina.net if you believe a child has provided personal data contrary to these requirements.

Back to top

15.Changes to this policy

We may update this policy when our services, providers or legal requirements change. We will update the date above and provide a prominent notice where a change materially affects how personal data is used or where the law requires additional notice or consent.

Back to top

16.Contact

Questions, complaints and privacy requests may be sent to:

The Cantina Network community
Operated from: The Netherlands
Email: info@the-cantina.net
Back to top

bECOME PART OF OUR cOMMUNITY!

The·Cantina·Network ©
linkedin facebook pinterest youtube rss twitter instagram facebook-blank rss-blank linkedin-blank pinterest youtube twitter instagram