Privacy Policy
Effective and last updated: 13 August 2026
Privacy at a glance
- We use Discord identity and linked Tibia character data to provide the service.
- We do not sell personal information or use advertising trackers.
- Optional first-party audience measurement is off until you allow it.
- You can request access, correction, deletion, restriction, objection or portability as applicable.
1. Controller and contact
Software Deck Pty Ltd, trading as Dominando, determines why and how Dominando processes personal data and is the data controller (also called the administrator under RODO/GDPR or controlador under LGPD). Dominando operates from Australia.
Privacy requests and complaints: [email protected]. Include the Discord account ID or linked Tibia character needed to locate your account, the right you want to exercise, and a safe way to reply. We may ask you to authenticate with the linked Discord account before releasing or deleting data.
2. Data we collect and its sources
- Discord identity: user ID, username, legacy discriminator where supplied, avatar, server IDs, server names, permissions, channel IDs and channel names received through Discord OAuth, the Discord Activity, installations and commands. We never receive your Discord password.
- Tibia information: linked character name, world, vocation, level and ownership-verification state, plus public character/world information received from Tibia-compatible data services.
- Guild operations: groups, membership and roles, spawn claims and queues, events and availability, transfer records, hunting-list cases, notification settings, audit records and related in-game payment notes.
- Security and support: session identifiers, authentication events, request metadata, error/runtime logs and messages you send through email, Discord or GitHub.
- Optional audience measurement: a random first-party visitor ID, month, page-view count and monthly unique-visitor count. It is not joined to your Discord or Tibia identity.
Information may come from you, group administrators, Discord, public Tibia sources and TibiaData-compatible APIs. A public character name can still be personal data when it can be linked to a person.
Hunting-list information: a group administrator may create a case about a character who has not supplied the information directly. Administrators must keep entries factual, proportionate and limited to legitimate group coordination. If an entry relates to you, contact us for a copy, correction, objection or removal review. We may consult the relevant group administrator, preserve the request and outcome for accountability, and provide any notice required by applicable law.
3. Purposes and lawful bases
| Purpose | Data | GDPR/RODO and LGPD basis |
|---|---|---|
| Authenticate, link characters and provide requested group features | Identity, character, membership and operational records | Performance of a contract or steps requested before it; LGPD contract execution |
| Secure the service, enforce permissions, prevent abuse and keep auditable group operations | Sessions, request/security records, roles and audit events | Legitimate interests in security, integrity and service administration, balanced against user rights |
| Send configured Discord notices and respond to support | Discord destinations, operational content and support messages | Contract performance and legitimate interests in delivering requested support |
| Optional monthly audience measurement | Random visitor ID and aggregate counts | Consent where required; consent may be withdrawn at any time |
| Meet legal, regulatory and dispute obligations | Only records reasonably necessary for the obligation or claim | Legal obligation and establishment, exercise or defence of legal claims |
Dominando does not use solely automated decisions that produce legal or similarly significant effects. Spawn suggestions and configurable transfer/hunting rules support game coordination; administrators can review and change operational outcomes.
4. Cookies and device storage
Strictly necessary storage supports Discord OAuth, secure sessions, language, selected character and interface preferences. The optional visitor cookie is created only after consent. Rejecting analytics does not block sign-in or product features. See the Cookie Policy for names, purposes, durations and withdrawal controls.
5. Sharing and processors
We do not sell or share personal information for cross-context behavioural advertising. We disclose only what is needed to operate Dominando:
- DigitalOcean: application and managed PostgreSQL hosting, backups, security and platform logs.
- Discord: authentication, bot commands, Activities, installations, configured channels, support messages you choose to send there, and dormant legacy webhook destinations retained temporarily for rollback but no longer used for delivery.
- TibiaData-compatible services and public Tibia sources: character/world validation and game information; searches may include a character name.
- GitHub: only when you choose to open or participate in a support issue.
- Authorities or professional advisers: only where legally required or reasonably necessary to protect rights and investigate abuse.
Dominando is not currently listed as a supported or promoted Tibia fansite. We do not currently share audience totals or visitor identifiers with CipSoft. If an official programme relationship changes the recipients or purpose of this processing, we will update this notice before recurring reporting begins.
6. International transfers
Dominando is operated from Australia and its production application and PostgreSQL database are configured in DigitalOcean's Singapore region. Discord is based in the United States and may process data in the United States and other countries. These countries may provide different privacy protections from your home country.
Where European transfer rules apply, provider data-processing terms and approved safeguards such as the European Commission's Standard Contractual Clauses are used where applicable. DigitalOcean's DPA incorporates SCCs for customer data, and Discord's developer terms address EEA controller-to-controller transfers. You may request information about the applicable safeguard through our privacy contact.
7. Retention
- Application sessions: up to 7 days after last use; logout removes the active application session.
- Discord Activity sessions and setup grants: expire after their short authentication/setup window and are deleted by scheduled cleanup.
- Claims: deleted one week after the claim ends. Related security/audit entries may remain where needed for integrity or disputes.
- Optional visitor identifiers: cookie up to 12 months; monthly identifier rows up to 14 months. Anonymous aggregate reports may be retained for fansite history.
- Accounts, characters, groups, events and operations: while the account/group remains active, then until deletion is requested or the record is no longer needed. Some group records may be retained or pseudonymised to protect other members, resolve disputes or meet legal obligations.
- Support: only as long as needed for the request and reasonable follow-up, subject to the independent retention rules of email, Discord or GitHub.
- Platform logs and backups: under DigitalOcean's configured platform retention and backup schedules. Deleted data may remain in restricted disaster-recovery copies until those copies expire and is not restored except for recovery.
8. Your rights
Depending on location and circumstances, you may request confirmation and access, correction, deletion, restriction, objection, portability, consent withdrawal, information about sharing, or review of an automated decision. Rights are not absolute; for example, deletion can be limited by legal obligations, other people's rights or legal claims.
Send a request to our privacy contact. We will verify identity proportionately, acknowledge the request, and respond within the legally applicable period. For GDPR/RODO requests this is normally one month, extendable where the law permits. LGPD provides immediate simplified access or a complete response within the applicable statutory period. Australian users may request access/correction and lodge a privacy complaint. We do not discriminate for exercising applicable rights.
You may also complain to your local authority, including Poland's UODO, Brazil's ANPD, or Australia's OAIC. Please contact us first when practical so we can investigate.
9. Security and incidents
We use HTTPS, encrypted database connections, HTTP-only session cookies, strict authorization checks, rate limiting, scoped Discord permissions, secret management, expiration/cleanup jobs and restricted administrative access. No system is completely secure.
We assess suspected personal-data incidents, document decisions and notify authorities and affected people when required by applicable law. Notifications will explain the affected data, likely consequences, mitigation and contact channel where known.
10. Children
Dominando is not directed to children under 13. You must meet Discord's minimum age and any higher age or parental-authorization rule that applies where you live. If we learn that a child used the service contrary to these requirements, contact us so we can investigate and remove data where appropriate.
11. Changes
We will update the date above when this notice changes. Material changes will be announced through the app or Discord before they take effect where required. A previous legal basis cannot be replaced retroactively merely by changing this notice.