Privacy Policy
How GuildMesh collects, uses, shares, retains and protects information across the website, portal and Discord application.
Last updated: 16 August 20261. Scope and controller
This Privacy Policy explains how GuildMesh, operated from the United Kingdom, processes personal data when you use the GuildMesh Discord application, website, portal and connected community features.
GuildMesh acts as controller for data used to operate the platform. A Discord community may also be responsible for how its administrators use information made available through GuildMesh.
2. Information we collect
Discord account information
- Discord user ID, username, display name and avatar;
- the Discord servers returned through the OAuth2 permissions you approve;
- server, role and permission information required to determine access and administrative rights;
- interaction data needed to process commands, buttons, forms and Discord events.
Battle.net and World of Warcraft information
- when you connect Battle.net: Battle.net account identifier, BattleTag, selected region, connection timestamps and the World of Warcraft characters returned for the authorised account;
- for imported characters: character identifier, name, realm, region, level, class and other game/profile data returned by Blizzard or subsequently enriched from supported game-data services;
- for connected community guilds: public guild identity, realm/region, roster, rank, character profile/media and achievement information returned through Blizzard APIs;
- GuildMesh does not store your Battle.net password. OAuth access tokens are used to complete authorised requests and are not stored as a persistent Battle.net credential in the GuildMesh user record.
GuildMesh profile and community information
- community settings, selected channels, roles, enabled modules and connection settings;
- player profiles, including the World of Warcraft region you select to keep realm choices, recruitment and relevant discovery aligned, plus character names, realms, regions, classes, specialisations and imported game information;
- event, raid, Mythic+, group, invite-request and recruitment information, including seasonal raid-interest sheets, roster preferences, availability and recorded raid attendance;
- Warcraft Logs-derived After Action Report data, including report identifiers, encounter/pull information, player performance, deaths, progression and generated or edited feedback;
- raid recording links, POV labels and their association with an entire report or a specific encounter pull; GuildMesh stores the external link and metadata, not the external video itself;
- messages, notes, applications, availability, signup status, community website custom pages, branding/theme settings and other content you choose to submit;
- support messages and bug reports you send to us.
Premium and payment information
- the GuildMesh user and Discord community associated with a Premium purchase or contribution;
- plan or duration purchased, amount, currency, payment status, contribution status and relevant timestamps;
- payment-provider customer, payment and subscription references where needed to reconcile billing, renewals, refunds or disputes;
- GuildMesh does not need to store full payment-card details when payments are handled by an external payment provider.
Technical information
- session identifiers, timestamps, request information, security logs and error records;
- basic browser/device information and referrer information where supplied by the browser;
- first-party website analytics including page views, page category, country where supplied by hosting infrastructure, and a salted one-way visitor fingerprint used to estimate unique visitors. Raw visitor IP addresses are not retained in the analytics database.
3. Cookies and local storage
GuildMesh uses only cookies/local storage needed to provide the service and remember that you have seen the cookie notice. Website analytics are collected server-side and do not create an analytics cookie.
- guildmesh_session, a strictly necessary, HTTP-only session cookie used to authenticate your portal session and maintain secure access. In production it is sent over HTTPS, uses SameSite=Lax and expires after up to 12 hours;
- guildmesh_cookie_notice_seen_v1, a local-storage preference used only to remember that you dismissed the cookie information notice. It is not used for advertising, analytics or cross-site tracking.
GuildMesh does not use advertising or analytics cookies. Limited first-party server-side analytics are used to understand visits, feature discovery and signup conversion. Analytics records are retained for up to 180 days. If optional cookies or similar tracking technologies are introduced later, this policy and the consent controls will be updated before they are used where consent is required.
4. How we use information
We process information to:
- authenticate users through Discord and maintain secure sessions;
- show the communities, permissions and features available to you;
- operate signups, profiles, applications, Community Connections and Discord synchronisation, and use your selected World of Warcraft region to keep relevant realm choices, recruitment and discovery aligned;
- verify optional Battle.net account/character relationships, synchronise connected guild data and refresh game data so profiles do not rely indefinitely on stale third-party records;
- enrich supported character and guild records with Raider.IO progression data and provide attribution/profile links where applicable;
- provide support, investigate faults and improve reliability;
- administer Premium access, stack community Premium time, keep payer contribution history, reconcile payments, renewals, refunds and billing disputes;
- measure first-party website usage, understand feature discovery and improve Open Beta adoption;
- prevent abuse, protect users and maintain security;
- comply with legal obligations and Discord's developer requirements.
5. Lawful bases
Under UK data-protection law, GuildMesh generally relies on:
- contract, where processing is necessary to provide features you request;
- legitimate interests, including platform security, service improvement, abuse prevention and community administration;
- consent, where you actively authorise an optional connection or feature that requires it;
- legal obligation, where information must be processed or retained to comply with law.
6. How information is shared
Information may be shared:
- with Discord, where required to authenticate users or operate Discord-based features;
- with members or administrators of a community according to the feature and visibility settings selected;
- across connected communities where a user or organiser chooses community or public visibility;
- with service providers used for hosting, databases, security or technical operation, under appropriate safeguards;
- with Stripe, our payment processor, where required to create and manage Premium checkout, subscriptions, renewals, refunds, tax calculation, fraud prevention and payment disputes. Stripe processes payment details under its own privacy terms; GuildMesh receives identifiers and billing status needed to administer Premium but does not store full card numbers or CVC values;
- with Blizzard/Battle.net when you authorise a Battle.net connection or when GuildMesh requests public World of Warcraft guild/profile data needed for a configured integration;
- with Raider.IO when GuildMesh requests supported character or guild enrichment; Raider.IO receives the game identifiers needed to resolve the requested record, such as character/guild name, realm and region;
- with Warcraft Logs when an authorised community user imports or synchronises supported combat-log data, and through links back to Warcraft Logs where GuildMesh displays report analysis;
- where required by law, court order, platform enforcement or to protect rights and safety.
GuildMesh does not sell personal data.
7. Community, public and game-data visibility
GuildMesh includes private, community and public visibility options. Information you deliberately publish as community or public content may be visible outside your own Discord server. This includes public Community Profiles and content such as news, roster information, recruitment, events and other material a community chooses to publish. Review the selected visibility before submitting an event, profile, recruitment listing or group activity.
After Action Reports and raid recording links are visible according to GuildMesh community access and publishing controls. Where an authorised organiser publishes an AAR to Discord, approved feedback and external recording links may be included in that Discord message. Following an external recording link leaves GuildMesh and is subject to the destination provider's privacy terms.
Connecting Battle.net does not automatically publish every character discovered on the authorised account. GuildMesh lets you choose which characters to import and which imported characters appear publicly. Some World of Warcraft and Raider.IO information may already be publicly available from the source provider independently of GuildMesh; changing visibility in GuildMesh does not change the privacy settings held by Blizzard or Raider.IO.
8. Retention
Information is retained only for as long as reasonably necessary to provide GuildMesh, maintain security, resolve disputes and meet legal obligations. Retention varies by record:
- account and community configuration is normally retained while the account or community remains active;
- Battle.net connection identifiers and imported character records are retained while needed for the linked GuildMesh profile or until they are disconnected/removed or a valid deletion request is completed; cached third-party game data is refreshed periodically so GuildMesh does not rely indefinitely on stale records;
- event, signup, attendance, progression and After Action Report records may be retained to support history, analysis and administration;
- external raid recording URLs and associated POV/report/pull metadata may be retained with the related After Action Report until removed or the related report/data is deleted according to applicable controls;
- security and error logs are retained for a limited period appropriate to investigation and service protection;
- Premium contribution, Stripe customer/subscription/payment identifiers, transaction status and billing records may be retained for account history, payment reconciliation, fraud prevention, disputes, accounting and legal obligations even after a payer leaves the funded community;
- Premium customisation settings may remain stored after a subscription ends so a community can restore its configuration if it later resubscribes; while Premium is inactive, Premium-only presentation can revert to GuildMesh defaults;
- deleted information may remain temporarily in restricted backups until those backups rotate or expire.
9. Security
GuildMesh uses reasonable technical and organisational measures to protect information, including encrypted HTTPS connections, controlled access, Discord OAuth2 authentication, permission checks and protected infrastructure. No online service can guarantee absolute security.
10. International transfers
Discord and other service providers may process information outside the United Kingdom. Where required, transfers are handled using recognised safeguards or another lawful transfer mechanism provided by the relevant service.
11. Your rights
Depending on the circumstances, UK data-protection law may give you rights to:
- access your personal data;
- correct inaccurate or incomplete information;
- request deletion or restriction;
- object to processing based on legitimate interests;
- receive certain information in a portable format;
- withdraw consent where processing relies on consent;
- complain to the UK Information Commissioner's Office.
We may need to verify your Discord identity before completing a request.
12. Data deletion requests
To request deletion, join the GuildMesh Support Discord and raise a private support request. Include your Discord user ID and identify any GuildMesh communities involved. Community owners may also request removal of their community configuration and associated operational data.
13. Children
GuildMesh is not intended for anyone below Discord's minimum age requirement in their country. We do not knowingly seek to collect personal data from children who are not permitted to use Discord.
14. Changes to this policy
We may update this policy when GuildMesh features, legal requirements or platform rules change. The current version will remain publicly available here with its effective date.
15. Payment data and Stripe
When you choose to fund GuildMesh Premium, checkout and recurring billing are provided by Stripe. Depending on the payment method and location, Stripe may collect your name, email address, billing address, payment credentials, tax information and transaction-risk information. GuildMesh receives payment and subscription identifiers, payment status, amounts, currency, tax totals and limited customer information required to match the subscription to the correct GuildMesh community and payer.
GuildMesh uses this information to perform the subscription contract, maintain Premium entitlement, provide billing-management links, reconcile payments and refunds, prevent abuse and meet accounting or legal obligations. Full payment-card credentials are handled by Stripe rather than stored in the GuildMesh database.
16. Contact
Privacy questions and rights requests can be raised through the official GuildMesh Support Discord.