1. Our approach
CBBOT aims to process only data needed to provide the service, manage licences and orders, support users and protect the system. Processing is limited to actual product workflows.
2. Account and password
The account stores username, email and a one-way password hash. Plain-text passwords are not stored in the database. Users are responsible for protecting their accounts and signed-in devices.
3. Payment and billing
CBBOT stores order/billing and payment-result records. Card numbers and CVV are not entered into CBBOT forms or stored in its order table; the active payment provider supplies the payment screen and processes data under its own policy and legal duties.
4. Licence, device and diagnostics
Hashed device identifiers, sessions, client build and connection times are retained to prevent unauthorised use and operate licence time. If the client submits a crash report, an encrypted diagnostic package and technical error details may be made available for administrator review.
5. Sharing and external links
Data is shared only with providers needed for the relevant transaction and legally authorised bodies. When Discord, Facebook, OpenStreetMap or corporate-site links are visited, those external sites’ privacy terms apply.
6. Choices and contact
Cookie choices can be changed from the footer and commercial-message choice can be withdrawn in the dashboard. The Personal Data Processing Notice provides the full data categories, legal bases, retention criteria and rights.