LEGAL
Privacy Policy
Snugglez — Discord RPG bot, website and store
Last updated: 12 September 2026
This Privacy Policy explains what information Snugglez collects when you use the Snugglez Discord bot, the website at https://www.snugglestripezzz.com, the game and the Store (together, the Service), why we collect it, where it goes, who can see it and when it is deleted. Snugglez is operated by:
- Operator
- Snugglez
- Privacy requests
- Open a ticket in our Discord server: https://discord.gg/URCcpUMRUz
- Website
- https://www.snugglestripezzz.com
1. Does the Privacy Act apply to Snugglez?
Snugglez is a small business run by a single operator. As at the date of this policy, it has an annual turnover below $3 million and does not fall within any of the categories to which the Privacy Act 1988 (Cth) applies regardless of turnover, so we understand that the Australian Privacy Principles (APPs) do not currently bind us.
We have nonetheless chosen to handle personal information in line with the APPs as a matter of good practice, and this policy describes what we actually do. If the Privacy Act comes to apply to us, for example because our turnover grows, we will review this policy and comply with it as required.
2. What we collect
The information we hold depends on how you use Snugglez. We do not collect payment card numbers, passwords, government identifiers, health information or other sensitive information, and you should not send them to us.
| Category | What it includes | Where it comes from |
|---|---|---|
| Discord identity | Discord user ID, username, display name, avatar, and the email address on your Discord account (when you sign in to the website with Discord) | Discord, when you use the bot or sign in with Discord OAuth |
| Website account | Account ID, email address, display name if you enter one, sign-in and session tokens, account creation date | Created by Supabase Auth when you sign in; name entered by you on the Account page |
| Game profile | Level, XP, tier, stats and ability points, coins and gems, inventory, boosters and their remaining charges, cooldowns, statistics (hunts, fishes, battles, faints, robberies), achievements, collection, Daily Drop streak and claim times, reminder preference | Generated by the bot and the website as you play |
| Server rank | Per server: your server-rank XP, a count of your messages and the time of your last XP award. We never store message content. | Generated by the bot when you send messages in a server that has server ranks enabled |
| Purchases | Stripe customer ID, product bought, price, currency, date, payment and delivery status, refund status, subscription status and renewal dates, and the reward credited to your profile | Stripe (via webhook) and our own delivery log |
| Billing details held by Stripe | Name, billing address, card details and receipt email | Entered by you at Stripe Checkout. Stripe holds these; we can see name and billing address in Stripe but do not copy them into our database |
| Support | Your messages, screenshots and files, and the purchase or technical details you give us | You, when you open a support ticket in our Discord server |
| Technical | IP address, browser and device type, pages requested, timestamps, error and security logs | Automatically, from the website's hosting provider (Vercel) and, for bot interactions, from Discord |
3. How your information flows through Snugglez
Snugglez is built from a small number of services that work together. The table below sets out, for each kind of information, where it goes, why we keep it, who can access it and when it is deleted.
| Information | Where it goes | Why we keep it | Who can access it | When it is deleted |
|---|---|---|---|---|
| Discord identity | Supabase database (US) | To link your game profile and website account to you, and to deliver purchases to the right profile | The bot, the website, and the operator | When your profile is deleted (section 12) |
| Website account and sessions | Supabase Auth (US); session cookie in your browser | To sign you in and keep you signed in | The website and the operator | Sessions expire automatically; the account is deleted with your profile |
| Game profile | Supabase database (US) | To run the game and save your progress | The bot, the website, other players (see section 13 for what is public) and the operator | When you ask us to delete it, or after 24 months of inactivity |
| Server rank | Supabase database (US) | To show your rank, run the server leaderboard and grant the roles that server's admins attach to levels | The bot, members of that server (leaderboard and rank card), that server's admins and the operator | When that server's admins reset it, when you ask us to delete it, or with your profile |
| Purchase records | Stripe (US/Australia) and Supabase database (US); a summary is posted to a private operator-only Discord channel when a payment succeeds or fails | To deliver what you paid for, prevent double delivery, handle refunds and disputes, and meet tax and accounting obligations | The operator; Stripe | Kept for 7 years after the transaction, as Australian tax law requires, then deleted |
| Billing details | Stripe (US/Australia) | Stripe uses them to process payments and prevent fraud | Stripe; the operator can view name and billing address in the Stripe dashboard | Under Stripe's retention rules; see Stripe's privacy policy |
| Support messages | Discord (US) | To resolve your issue and to recognise repeat problems or abuse | The operator and any moderators we appoint | 12 months after the ticket is closed |
| Technical logs | Vercel (US); Discord (US) | To keep the website and bot running, diagnose errors and detect abuse | The operator; Vercel | Vercel keeps runtime logs for a short period (currently days, not months) unless we export them for a security investigation |
4. Why we use your information
We use the information above to:
- run the bot and the website and save your game progress;
- sign you in and keep your account secure;
- process payments, deliver purchases, manage Premium renewals and handle refunds;
- answer support requests and investigate delivery problems;
- detect cheating, exploits, fraud, payment abuse and unauthorised access;
- send you the service messages described in section 8;
- fix bugs, balance the game and improve the Service; and
- comply with law, respond to lawful requests and protect our legal rights.
We do not use your information for behavioural advertising, and we do not sell it.
5. Who we share information with
We share information only with the providers that make Snugglez work, and only what each one needs:
| Provider | What they do for Snugglez | Location |
|---|---|---|
| Discord Inc. | Runs the platform the bot operates on, provides sign-in (OAuth) and delivers bot messages and DMs | United States |
| Supabase Inc. | Hosts our PostgreSQL database and authentication service | United States (AWS, us-east-1) |
| Stripe, Inc. and Stripe Payments Australia Pty Ltd | Checkout, payment processing, subscription billing and refunds | United States and Australia |
| Vercel Inc. | Hosts the website and its server functions and produces technical logs | United States |
Each provider handles information under its own privacy policy: Discord (discord.com/privacy), Supabase (supabase.com/privacy), Stripe (stripe.com/au/privacy) and Vercel (vercel.com/legal/privacy-policy).
We may also disclose information where the law requires it, to respond to a lawful request, to investigate fraud or a security incident, to enforce our Terms, or to protect users or the public from serious harm. If Snugglez is transferred to a new operator, your information may be transferred with it; the new operator will be bound by this policy unless you are told otherwise.
6. Overseas storage and disclosure
Our database and authentication service are hosted by Supabase in the United States (AWS region us-east-1). The website is hosted by Vercel, Stripe processes payments in the United States and Australia, and Discord operates from the United States. This means your personal information is stored and processed in the United States, where privacy laws differ from Australia's. By using Snugglez you acknowledge this. We choose providers with recognised security practices and contractual privacy commitments, and where the Privacy Act applies to us we will take the steps it requires in relation to overseas disclosures.
7. Cookies
The website uses only the cookies needed to sign you in and keep you signed in. They are set by Supabase Auth, contain your session token, and are removed when you sign out or when the session expires. We do not use analytics, advertising or tracking cookies, and we do not use any third-party analytics service. If that changes we will update this policy and, where required, ask for your consent first.
8. Messages we send you
8.1 Service messages
The bot replies to your commands in Discord. It can also send you one kind of direct message: a streak reminder, sent at most once per claim cycle, about six hours before a website Daily Drop streak would reset, and only if you have a streak on the line. Streak reminders are on by default for profiles with a website streak. You can turn them off at any time with the /reminders off command or the "Stop these reminders" button in the message, and they stop immediately. Stripe sends payment receipts and, where applicable, renewal notices by email under its own terms.
8.2 Marketing
We do not currently send marketing emails, newsletters or promotional direct messages. If we introduce them, we will only send them to people who have opted in, every message will identify Snugglez as the sender and include a working unsubscribe link or command, and we will honour unsubscribe requests within 5 business days, as required by the Spam Act 2003 (Cth). Announcements posted in our Discord server are not direct messages and are governed by Discord's own notification settings.
9. Children
Discord requires users to be at least 13 (or older in some countries), and so does Snugglez. We do not knowingly collect personal information from anyone under 13. Users aged 13 to 17 may use Snugglez with a parent or guardian's permission, as our Terms of Service require, and purchases must be made or authorised by that parent or guardian. A parent or guardian may contact us through a support ticket in our Discord server (https://discord.gg/URCcpUMRUz) to access, correct or delete their child's information, or to have a profile removed. If we learn that we hold information about a child under 13, we will delete it.
10. Security
We take reasonable steps to protect personal information from misuse, interference, loss, and unauthorised access, modification or disclosure. Those steps include: sign-in through Discord only, with no passwords stored by us; encrypted connections to every service; database access restricted by row-level security and service keys held only by the operator; secrets stored in provider-managed configuration rather than code; Stripe webhook signature verification; and access to the Stripe, Supabase, Vercel and Discord dashboards limited to the operator. No internet service can be completely secure, and we cannot guarantee the security of information you send to us.
10.1 If a data breach happens
If we become aware of a breach involving your personal information, we will contain it, assess within 30 days whether it is likely to cause serious harm, notify affected users through the website and Discord where that is the case, and notify the Office of the Australian Information Commissioner where the law requires it.
11. How long we keep information
We keep personal information only as long as it is needed for the purposes in this policy or as the law requires, then delete or de-identify it. Our standard periods are:
| Information | Retention period |
|---|---|
| Game profile and website account | While you use Snugglez. Profiles with no activity for 24 months are deleted or de-identified after we announce a clean-up in the Discord server |
| Purchase and refund records | 7 years after the transaction (Australian tax and accounting requirements) |
| Support tickets | 12 months after the ticket is closed |
| Records of exploits, fraud or bans | Until the matter is resolved, then 12 months, so we can recognise repeat abuse |
| Technical logs | Per Vercel's and Discord's default retention (days), unless exported for a security investigation, in which case until the investigation is closed |
12. Access, correction and deletion
You can ask us to tell you what personal information we hold about you, to correct it, or to delete it, by opening a support ticket in our Discord server. We will ask you to verify that you control the Discord account concerned, which is usually automatic because you open the ticket from it, and we aim to respond within 30 days.
What deletion means. Deleting your profile permanently removes your game progress, currency, items, achievements, Daily Drop streak and website account. It cannot be undone, and we do not restore progress or re-deliver past purchases to a new profile. We will keep purchase records for as long as tax law requires, and we may keep the minimum information needed to enforce a ban, resolve an open dispute or meet a legal obligation. Deleting your Snugglez data does not delete information held independently by Discord, Stripe, Supabase or Vercel; you can contact those providers directly about the information they hold.
13. Information other players can see
Some game information is visible to other users as part of normal play: your Discord username or display name and avatar, your level, tier, stats, badges and Premium status on your profile card, your position on the leaderboard, your server rank level and XP on that server's rank leaderboard and level-up announcements, the results of hunts, fishes, battles and robberies posted in the channel where you play, and any items you choose to showcase. Discord users in the same server can see when you are robbed and by whom. Please do not put personal information you would not want others to see in your Discord username or display name.
14. Changes to this policy
We will update this policy when our practices, providers, features or legal obligations change, and update the "Last updated" date at the top. Significant changes, such as a new provider, a new category of data, analytics or marketing, will be announced on the website and in our Discord server before they take effect.
15. Complaints
If you think we have mishandled your personal information, contact us first through a support ticket in our Discord server (https://discord.gg/URCcpUMRUz) with a description of your concern and the relevant dates. Snugglez is run by one person; we will acknowledge your complaint within 14 days and aim to resolve it within 30 days. If you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner at oaic.gov.au or 1300 363 992.
16. Contact
- Discord server (support tickets)
- https://discord.gg/URCcpUMRUz
- Website
- https://www.snugglestripezzz.com
This policy should be read together with our Terms of Service (https://www.snugglestripezzz.com/terms) and Refund & Digital Goods Policy (https://www.snugglestripezzz.com/refunds).