Pluven Tickets / Pluven

Privacy Policy

This policy explains what data Pluven Tickets processes when operating the Discord bot, web dashboard and public transcripts, and how you can request access, correction or deletion of data.

Last updated: 7 September 2026 Operator: Pluven Tickets / Pluven Project author / maintainer: G0rd0n3k

1. Who operates the service

The service operator is Pluven Tickets / Pluven. The project is developed and maintained by G0rd0n3k.

Privacy and data contact: contact@pluven.nl.

2. Data we may process

Discord identifiers required for the service, including User IDs, Guild IDs, Role IDs and Channel IDs, plus readable snapshots of usernames, server names, channel names and role names where needed.

Ticket data such as ticket number and status, category, author, users and roles with access, claim information, close reason, operation timestamps and other metadata required for the ticket lifecycle.

When an administrator generates a transcript, it may contain Discord message content, mentions, usernames, emoji and links to attachments hosted by Discord.

Server configuration, panels, categories, audit logs, statistics, Premium branding settings, Premium status and promo-code redemption history. Full promo codes are not stored in the database; a hash and the metadata required to operate the code are stored instead.

3. Why we use data

To create and operate tickets, manage channel access, generate transcripts, provide the dashboard, statistics, audit logs, configuration, diagnostics, security protections and Premium functionality.

Processing is primarily necessary to provide requested service functions, based on legitimate interests in service security and reliability, and where applicable to meet legal obligations. We do not use Discord API Data for advertising profiles of users.

4. Sign-in, sessions and cookies

The dashboard uses Discord OAuth2 for account identity and server-list access. The OAuth token is used server-side to determine dashboard access and is not stored in the database as a permanent user profile.

Dashboard sessions use an HttpOnly cookie. A language cookie stores your manual language choice. An IP address may be used temporarily in process memory for rate limiting; IP addresses and User-Agent values are not written to permanent audit logs.

5. Public transcripts

A public transcript receives a unique URL and does not require sign-in. It is a bearer link: anyone who has the URL can open the transcript while the link is active.

A server administrator can revoke the link or generate a new one. After revocation the public file is no longer available at the old address and may remain in the service's private archive until the server data is deleted.

The server administrator is responsible for deciding when to generate and share a public link and who receives it.

6. Who data may be shared with

Discord where necessary to operate the bot and Discord API, and infrastructure providers necessary to host and maintain the service.

Data may be disclosed when required by law or a valid request from an authorized authority. We do not sell personal data to advertisers.

Public transcript content is available to people who receive an active link as described above.

7. Data retention

While the bot is installed on a server, server data is retained for as long as needed to provide the configured Pluven Tickets functionality.

When the bot is removed from a server, a 30-day retention period starts. Re-adding the bot during that period cancels the scheduled deletion and allows the saved configuration to be used again.

After 30 days, that server's data is automatically removed from the database and from public and private transcript storage. The service owner can also perform an earlier controlled deletion of server data.

Some information may be retained longer only where required by applicable law or necessary to establish, exercise or defend legal claims.

8. Access, correction and deletion requests

You can send a request concerning Discord API Data to contact@pluven.nl. Depending on the request, we may ask for a Discord User ID or Server ID (Guild ID) and verification that you are authorized to make the request.

A server administrator can remove the bot, which starts the 30-day data-deletion lifecycle. Where appropriate, you may also request earlier deletion or correction of data.

Fulfilling a request may require deleting or restricting parts of ticket history, transcripts or logs unless a legal requirement requires continued retention.

9. Security

We use HTTPS/TLS, restricted production access, server-side sessions, CSRF protection, rate limiting, security headers and separation between public transcripts and the private transcript archive.

We do not publish application secrets, OAuth tokens or Discord tokens. If a security incident occurs, we will take remediation steps and make notifications required by applicable law.

10. Discord services and international processing

Pluven Tickets operates on Discord and uses the Discord API. Your use of Discord is also governed by Discord's own terms and privacy policy.

Depending on the location of Discord and infrastructure providers, data may be processed outside your country. Where required, appropriate transfer mechanisms under applicable law are used.

11. Changes to this policy

This policy may be updated when functionality, law or Discord platform requirements change. The current version is published on this page with its last-updated date.

Contact

contact@pluven.nl

Contact