Privacy Policy

How FXEZ handles personal data. See also the terms of sale and the legal notice.

1. Who is responsible

The controller is the operator of fxez.eu, identified on the Legal notice page. Support and every data request go through our Discord server, which is currently the only support channel.

2. Data we actually process

Only what the site technically needs to sell and deliver a licence:

  • Discord account data received through Discord OAuth: your Discord user ID, username, avatar URL, and the e-mail address attached to your Discord account (used to link your orders and deliver your licence).
  • Order data: product purchased, quantity, amount, currency, order date, payment status, delivery status, Stripe Checkout session ID and Stripe payment intent ID, plus the date and version of the terms you accepted.
  • Authentication data: the session issued after your Discord login, stored by your browser so you stay logged in.
  • Cart data: the items you add to the cart, stored locally in your own browser. It never leaves your device until you check out.
  • Technical logs generated by our hosting and payment providers (IP address, request time, user agent) for security and fraud prevention.

3. What we do NOT process

We never receive or store your card number, expiry date or CVC: the payment form is served and handled by Stripe. We do not run advertising or analytics trackers, and we do not build profiles or sell data.

4. Purposes and legal bases

  • Creating your account and logging you in — performance of the contract (Art. 6(1)(b) GDPR).
  • Processing payments, issuing licences and delivering them to your Discord account — performance of the contract.
  • Keeping proof of your order and of your consent to immediate performance — legal obligation and legitimate interest in defending our rights.
  • Preventing fraud, abuse and chargebacks — legitimate interest.
  • Accounting and tax records — legal obligation.

5. Processors and recipients

Data is shared only with the providers the site genuinely uses to operate:

  • Discord (authentication of your account and delivery of your licence/roles/messages).
  • Stripe (payment processing, fraud prevention, invoicing).
  • Supabase (database and authentication backend, hosting your account and order records).
  • Hosting and content delivery: Lovable (Cloudflare edge network).
  • Google Fonts (the site loads its webfonts from Google's font CDN, which receives your IP address when the fonts are fetched).

6. Transfers outside the EU

Some of these providers are established in or transfer data to the United States. Those transfers rely on the providers' own contractual safeguards (EU standard contractual clauses and, where applicable, the EU-US Data Privacy Framework). Their own privacy policies describe those safeguards.

7. Retention

  • Account and Discord identifiers: for as long as your account exists, then deleted on request.
  • Order and payment records: kept for the legal accounting retention period applicable to the seller (in France, 10 years), even after your account is deleted.
  • Delivery queue entries: deleted or archived once the delivery has been completed.
  • Sessions: until you log out or the session expires.
  • Cart: until you clear it or your browser storage is cleared.

8. Your rights

You can request access, rectification, erasure, restriction, portability of your data, and object to processing based on legitimate interest. You can also lodge a complaint with your national supervisory authority (in France, the CNIL).

Erasure does not apply to order and accounting records we are legally required to keep. When that is the case, we delete or anonymise everything else.

9. How to exercise them

Open a ticket on our Discord server and state what you want (export, correction or deletion). We answer through the same ticket and act within one month.

10. Cookies and local storage

The site only uses strictly necessary storage: your login session and your shopping cart. It does not load advertising, analytics or profiling trackers, so no consent banner is required. Stripe may set its own strictly necessary cookies inside the payment form for fraud prevention.

Contact support on Discord →