SPACEWHLE SPACEWHLE ← Back to spacewhle.org

Privacy Policy

Effective Date: 6 April 2026 · Last revised: 10 September 2026
Service: the SPACEWHLE website (spacewhle.org) and the SPACEWHLE Discord bots

This explains what the SPACEWHLE website and Discord bots may know about you, why, and what you can do about it. It covers spacewhle.org, our bots, and the dashboards connected to them — together, "the Service".

Short version: we hold what we need to run the org, we don't sell any of it, and you can ask us what we've got or ask us to remove it.

1. Who's responsible for this

SPACEWHLE is a Star Citizen player organisation, not a company. The people who run the org decide what the Service holds and why, which makes them the data controller for it. You can reach us through any officer in Discord, or at spacewhle@gmail.com.

2. What we may hold

Depending on which parts of the Service you use, and how you use them, we may hold:

We don't go looking for anything beyond what running the org actually needs.

3. What we use it for

Running the org: tracking participation and attendance, managing ranks and roles, running events, connecting members in the marketplace, attributing referrals, and spotting abuse, bugs and security problems. That's it — we don't sell your data, share it with advertisers, or use it to build a profile of you outside the org.

4. Why we're allowed to hold it

Mostly because we have a genuine interest in it — you can't run a member organisation, award ranks fairly, or organise operations without keeping track of who's in it and who turned up. We keep that to what's actually needed, and you can object (see Your rights below).

Some things are there because you chose to add them: linking your RSI handle, posting a marketplace listing, uploading an image. You can withdraw those at any time by asking us to remove them.

And occasionally we keep something because we have to — for example where a record is needed to deal with a complaint or a security incident.

5. Who else sees it

Officers and staff see what they need through the dashboard. Beyond that, information is shared only with the providers that run the Service for us, or where we're legally required to hand it over, or where it's genuinely needed to protect someone.

The Service runs on Discord (community and sign-in), Supabase (login and database), Cloudflare (hosting, delivery and image storage) and Oracle Cloud (servers). Each handles some data under its own privacy policy, including technical details like IP addresses. We're not responsible for their practices.

6. Images added to the website

This section is only about images added to the website — uploaded through the gallery editor, or attached to an operation write-up. We do not copy or store images you post in Discord. The message log records an attachment's filename, never the image itself. A screenshot you drop in a Discord channel stays there, under Discord's own terms, unless an officer chooses to upload it to the website.

When an image is added to the website — uploaded as a file, or by pasting a link that we then fetch — we take our own copy and store it. It's resized in your browser first, then kept on Cloudflare storage. We copy rather than link because image links from other platforms (Discord ones especially) expire, and a copy is the only way a page keeps its picture.

Stored images sit at a public address. Anyone with the link can view them without logging in. The addresses aren't guessable in practice, but treat anything you upload as capable of being seen outside the org — so nothing private, and nothing you don't have the right to share.

Images added to the website may be shown anywhere on it — the gallery, an operation record, or recruitment material used to promote the org, which may be seen by people who are not members. If you'd rather a particular screenshot wasn't used that way, tell an officer and we'll take it down.

We record which account added what, and how much space it uses, so storage limits can be enforced.

7. What gets published publicly

The public Operations Log shows an operation's name, date, write-up and a chosen image. Anyone can read it and search engines may index it.

Publishing is a deliberate choice by an officer, never automatic, and the public page is built from a fixed list of fields. Participant names, attendance numbers, the internal after-action report, the organiser, and loot or payout figures are never published. A record can be taken down on request, though anything already copied or cached elsewhere may persist.

8. Security records and your browser

If someone repeatedly tries to reach a restricted part of the Service without authorisation, we record it: the Discord account (where identifiable), the time, what was requested, and whether they were signed in. A one-off is not recorded — pages check permissions all the time and that isn't interesting. Only senior staff can see these, and they're kept as a rolling recent history rather than forever.

We also keep small things in your own browser — an unsent event draft, cached lists, interface preferences. That stays on your device and clearing your browser data removes it.

9. How long we keep things

As long as it's useful for running the org, and no longer than that. Participation records, rank history and audit logs are kept longer because the org's history depends on them.

Specifically: images added to the website stay until deliberately deleted, since a page can't be rebuilt without its picture; access-attempt records are a capped rolling history; and copies of Discord messages kept for the message log are deleted automatically after 30 days.

10. Keeping it safe

We take reasonable steps to protect what we hold — access is limited to staff who need it, and sensitive credentials never sit in the website's code. No system is perfectly secure and we can't promise absolute safety, but we'd rather say that plainly than pretend otherwise. If something does go wrong in a way that affects you, we'll tell you.

11. Your rights

You can ask what we hold about you, ask for it to be corrected, ask for it to be deleted, ask us to stop using it for something, or ask for a copy of what you gave us. Just ask — you don't need a form or a reason, and we'll come back to you within a month.

Some records may need to stay for legitimate reasons — an operation's attendance history, for instance, is part of the org's record and affects other members' figures — and we'll tell you if that applies rather than quietly ignoring the request.

Ask any officer, or email spacewhle@gmail.com. Include your Discord username and ID so we can find the right records.

12. If you're not happy with how we handled it

Tell us first and we'll try to sort it out. If you're in the UK and still not satisfied, you can complain to the Information Commissioner's Office at ico.org.uk. If you're elsewhere, your local data protection authority handles the same thing.

13. Age

The Service isn't aimed at anyone below Discord's own minimum age for their region. If we learn we're holding data for someone under that age, we'll remove it.

14. Where data is handled

Our providers operate internationally, so data may be processed outside the UK. Where that happens we rely on the safeguards those providers have in place for international transfers.

15. Changes

We may update this policy. The current version always lives at spacewhle.org/policy, and we'll announce anything significant in Discord.

16. Contact

Questions? Ask an officer in Discord, or email spacewhle@gmail.com.