Privacy Policy

Last updated: August 15, 2026

Introduction

Welcome to Giveaway-Bot | System ("the Bot", "we", "our", "us"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Discord bot and web dashboard services. Please read this privacy policy carefully. If you do not agree with the terms of this privacy policy, please do not access the service.

What Data We Collect

Discord Data

When you use Giveaway-Bot, we collect and store the following data from Discord's API:

  • User IDs – To identify giveaway participants and winners
  • Server (Guild) IDs – To associate giveaways with specific servers
  • Channel IDs – To know where to post giveaway messages
  • Message IDs – To track and manage giveaway messages
  • Role IDs – To enable bonus entry features for specific roles
  • Username and discriminator – Displayed in giveaway winner announcements

Dashboard Data

When you access our web dashboard via Discord OAuth2, we additionally collect:

  • Discord Access Token – Temporarily stored to authenticate your dashboard session (expires when you log out)
  • Discord User Profile – Your username, avatar, and email address (if you grant email scope permission) for dashboard login purposes
  • Session Data – Temporary session cookies to maintain your dashboard login state
  • Server List – The list of servers where you have administrative permissions, to allow you to manage bot settings

Giveaway Data

  • Giveaway settings (duration, prize, winner count, channel)
  • List of entry participant User IDs
  • Winner User IDs and timestamps
  • Giveaway history and statistics

Admin Activity Logs

The admin dashboard records internal operational events for security and stability purposes. The following data is logged and stored in our database:

  • Action type – e.g. restart initiated, restart successful, restart failed
  • Timestamp – Date and time of the action
  • Username – The Discord username of the admin who triggered the action (owner account only)
  • Message / Status – A short description of the logged event

These logs are only accessible to the bot owner via the admin dashboard and are not shared with any third party.

Dashboard Ban Records

If a user is banned from accessing the dashboard by the bot owner, the following data is stored:

  • Discord User ID – To identify the banned account
  • Discord Username – For display in the admin panel
  • Ban reason – The reason provided by the admin
  • Ban date – Timestamp of when the ban was issued

This data is deleted automatically if the user is unbanned via the admin dashboard.

Public Statistics

The website homepage fetches aggregated, non-personal statistics from our public API endpoint (https://giveaway-bot.de/api/stats) to display global server count, user count, and channel count. This endpoint returns only anonymized aggregate numbers and does not process or expose any personal data.

IP Address Processing & Rate Limiting

Our web server and dashboard API process your IP address as a standard part of handling HTTP requests. Your IP address is used exclusively for:

  • Rate limiting – The dashboard API enforces request limits (100 requests per minute) to prevent abuse and ensure service availability for all users
  • Security logging – Failed authentication attempts or suspicious access patterns may be logged temporarily for security purposes
  • Server infrastructure – Nginx web server access logs may retain IP addresses for up to 7 days as part of standard server operation

IP addresses are not linked to your Discord account or stored in our application database beyond the purposes listed above.

How We Use Your Data

We use the collected data exclusively to:

  • Create, manage, and track giveaways on Discord servers
  • Randomly select winners from eligible participants
  • Send DM notifications to winners
  • Provide the web dashboard functionality
  • Prevent abuse and ensure fair giveaway participation
  • Generate giveaway statistics and history
  • Authenticate users via Discord OAuth2 for dashboard access
  • Record admin operational events for security and audit purposes
  • Enforce dashboard access restrictions (bans) where necessary

We do not sell, rent, or share your data with third parties for marketing purposes.

Data Sharing

We do not sell or rent your data. Data may be shared only in the following limited circumstances:

  • Discord API: Necessary interactions with Discord's API to operate the bot
  • Hosting Provider: Our server infrastructure provider (AVORO / dataforest GmbH) processes data as a data processor under a Data Processing Agreement (DPA)
  • Legal Requirements: If required by law, court order, or to protect against fraud or abuse

Data Retention

  • Active giveaway data: Retained while the giveaway is running and for 90 days after completion
  • Winner data: Retained for 1 year for dispute resolution purposes
  • Server configuration: Retained as long as the bot is active on your server; deleted within 30 days of bot removal
  • Dashboard session data: Deleted immediately upon logout; automatically expires after 6 hours
  • OAuth tokens: Deleted immediately upon logout
  • Admin activity logs: Retained for up to 90 days, then automatically purged
  • Dashboard ban records: Retained until the ban is lifted by the administrator; deleted immediately upon unban
  • Nginx / server access logs (IP addresses): Retained for up to 7 days as part of standard server infrastructure operation

Cookies

Our dashboard uses a single, strictly necessary session cookie to maintain your login state after authenticating via Discord OAuth2. We do not use tracking, analytics, or advertising cookies of any kind.

Session Cookie Details

Technical Properties

  • HttpOnly: Yes — the cookie cannot be accessed via JavaScript, protecting against XSS attacks
  • Secure: Yes (in production) — transmitted over HTTPS only
  • SameSite: Lax — provides protection against cross-site request forgery (CSRF)
  • Storage: The session data referenced by this cookie is stored server-side in our MongoDB database, not in the cookie itself

Because this cookie is strictly necessary for the core functionality of the dashboard (login/authentication), it does not require your explicit consent under the GDPR / ePrivacy Directive. You can delete it at any time by logging out or clearing your browser cookies.

Security

We implement appropriate technical and organizational security measures to protect your data against unauthorized access, alteration, disclosure, or destruction. The admin dashboard is restricted to the bot owner account only — access by any other Discord account is automatically blocked and redirected. However, no internet transmission is completely secure, and we cannot guarantee absolute security.

Your Rights (GDPR)

If you are in the EEA, you have the right to:

  • Access the data we hold about you
  • Request correction of inaccurate data
  • Request deletion of your data
  • Object to or restrict data processing
  • Data portability
  • Withdraw consent at any time

To exercise these rights, contact us at [email protected] with the subject line "GDPR Request".

Children's Privacy

Our service is not directed to children under 13. We do not knowingly collect data from children under 13. If you believe a child under 13 has provided us with data, please contact us immediately at [email protected].

Changes to This Policy

We may update this Privacy Policy from time to time. Significant changes will be announced in our Discord support server. Continued use of the service after updates constitutes acceptance of the revised policy.

Contact

For any privacy-related questions or to exercise your rights, contact us at [email protected].

Data Controller: Tim Hofeditz (Giveaway-Bot | System)
Address: Waldstraße, 59846 Sundern, Germany