SafeGuardBeta

Privacy Policy

Version of 2026-09-24. The Portuguese version prevails in case of doubt.

1. Controller

SafeGuard, tax ID [to be completed], [to be completed]. Privacy contact: equipa@safeguardac.online.

SafeGuard processes data in two roles:

  • Controller of account, billing and website/dashboard usage data (this policy).
  • Processor of the data of the players of our customers' servers. There, the server owner is the controller; we process that data only on their behalf, under the Data Processing Agreement. If you are a player, talk to the server you play on first.

2. Data we process as controller

DataWhyLegal basis
Name, e-mail and password (stored hashed)Create and protect the accountPerformance of contract
Organization, members and rolesProvide the Service to the teamPerformance of contract
Audit log, IP and browser of sessionsSecurity, abuse preventionLegitimate interest
Plan, subscription and invoices; Stripe customer referenceBillingContract and legal obligation
MB WAY phone number given in a payment orderFind the transferPerformance of contract; deleted once the payment is decided
Support messages (e-mail, Discord)Answer youContract / legitimate interest

We do not sell data, advertise or build marketing profiles.

3. Cookies

We only use necessary cookies: safeguard_session (signed-in session, 7 days) and sg_lang (chosen language, 1 year). The dashboard also keeps interface preferences in your browser (for example a collapsed sidebar). We use no analytics or advertising cookies, so we do not ask for consent.

4. Who receives data (subprocessors)

CompanyWhy
Vercel Inc.Hosting of the website and dashboard
Supabase Inc.Database and file storage (screenshots)
RenderAPI hosting
Stripe Payments Europe, Ltd.Card payments (card data is only processed by Stripe)
Resend, Inc.Transactional e-mail
Discord Inc.Only if you set up alerts or the bot in your Discord

Some of these providers are in the USA. Transfers rely on the European Commission's standard contractual clauses and/or the EU-US Data Privacy Framework.

5. How long

  • Account and organization: while active; when you delete the account, personal data is deleted or anonymised within 30 days.
  • Invoices and billing data: 10 years (tax obligation).
  • Audit log: per the organization's retention setting (365 days by default).
  • Player data: per each customer's retention settings (see the Data Processing Agreement).

6. Your rights

You have the rights of access, rectification, erasure, restriction, portability and objection, and to withdraw consent. Write to equipa@safeguardac.online; we answer within one month. You can also complain to the Portuguese supervisory authority, CNPD (www.cnpd.pt).

7. Security

Argon2 password hashing, revocable sessions, license and API keys stored only as hashes, encrypted webhooks, signed server requests, player identifiers pseudonymised by default, and role-based access with an audit log.

8. Changes

If we change this policy in a relevant way, we tell you by e-mail or in the dashboard.