VanillaMonster Back to website

Privacy

Privacy Notice.

How VanillaMonster handles website, server, Discord and moderation data during Public Beta Phase I.

Version 1.0 Published 4 August 2026 · Revised 4 September 2026

1. Controller and contact

VanillaMonster is a privately operated project, not a registered company. The data controller is:

Jakub Antoniuk
Netherlands

Privacy questions and data-subject rights requests can be sent directly by email, or submitted through the official private Discord ticket system:

kolopop94@gmail.com
discord.gg/EKJ5gcmMbW

2. Scope

This notice applies to the VanillaMonster website, Minecraft Java server, Discord community, account linking, private support tickets, player reports, appeals, testing programmes and official events. External services such as Discord, Microsoft, Mojang, Netlify and PrismNodes also process data under their own privacy information.

3. Website data

The current website is a static Netlify deployment. VanillaMonster does not currently run its own analytics, advertising trackers, newsletter form or account system on the website.

When you visit, the hosting provider and internet infrastructure may process technical request information such as IP address, date and time, requested files, browser information, security signals and error data. The website also loads fonts from Google Fonts, which causes your browser to contact Google’s font servers.

4. Data categories

CategoryExamples
Account identifiersMinecraft username, UUID, Discord user ID and linked-account status.
Connection and securityIP address, login time, session records, anti-abuse and authentication signals.
Gameplay recordsClaims, shops, inventories where technically logged, votes, rewards, locations, punishments and achievements.
CommunicationsChat, commands, signs, books, tickets, reports, appeals and attachments.
Technical dataServer/client version, latency, plugin logs, errors and performance diagnostics.
Moderation evidenceScreenshots, video, CoreProtect records, witness statements and investigation notes.
Transaction supportFor Store purchases: transaction reference, product, delivery status and support history.
Creator applicationsChannel/creator name, email, Discord username, Minecraft username, platform links, language, timezone, audience size bracket, content plans and any optional notes submitted through the Creator Program application form.

5. Purposes and legal bases

  • Provide and operate the service: connect players, maintain worlds, deliver configured features and provide support.
  • Security and fair play: detect cheating, abuse, griefing, fraud, ban evasion and technical attacks. This is based on the project’s legitimate interest in operating a safe and fair community.
  • Moderation and disputes: investigate reports, apply rules, restore damage and handle appeals.
  • Technical reliability: diagnose errors, monitor performance, create backups and recover data.
  • Legal obligations: retain or disclose information when required by applicable law, accounting, fraud-prevention or valid legal process.
  • Consent: where optional information, publicity, event participation or future marketing specifically relies on consent.
  • Creator Program applications: to evaluate applications to the Creator Partner Program and to contact applicants about their submission. Application data is not sold, and is used only for this purpose.

6. Providers and recipients

  • Netlify: website hosting and delivery, and processing of Creator Program application form submissions.
  • PrismNodes: current Minecraft server hosting and allocated network services.
  • mcsrvstat.us: aggregate Minecraft server status and player totals used by the live status widget. Only an online/offline state and player counts are requested and displayed — no player username, UUID or location list is rendered.
  • Discord: community, private ticket communication, and — for Supporter, Patron and Founder purchases — account verification via OAuth (see below).
  • Tebex: payment and checkout processing for the Store. Card and payment details are handled directly by Tebex — VanillaMonster does not receive full payment-card details through this website.
  • Microsoft and Mojang: Minecraft account and game services.
  • Google Fonts: font delivery requested by the visitor’s browser.
  • Authorised VanillaMonster staff: only where access is necessary for operation, support, security or moderation.

Supporter, Patron and Founder require Discord authentication because those packages include a Discord role. Authentication uses the VanillaMonster Bridge Discord application and requests only the identify OAuth scope — no email, server list or messaging access. The verified Discord account ID returned by Discord is used only to associate that specific benefit with the correct account. OAuth access tokens are used server-side to complete the authentication step and are not intentionally persisted by the VanillaMonster website. The Minecraft Java username entered at checkout is used to associate a purchase with the correct in-game account.

Providers may process data in countries outside the European Economic Area under their own legal arrangements and safeguards. Their own privacy notices provide additional information.

7. Planned retention

DataOperational target
Routine server logs30–90 days.
Security and anti-cheat logsUp to 180 days.
CoreProtect records90–180 days.
Closed support ticketsUp to 12 months after closure.
Moderation and ban recordsFor the sanction period and as needed for appeals, ban evasion and defence of claims.
BackupsAccording to the documented rotating backup schedule.
Transaction recordsAs required by the store provider, accounting rules and applicable law.
Creator Program applicationsKept while the application is reviewed and, if accepted, for the duration of the creator relationship. Declined or inactive applications may be removed on request.

Data may be kept longer for an active investigation, legal claim, fraud prevention or legal obligation, and may be deleted earlier when no longer necessary.

8. Security

VanillaMonster uses role-based access, restricted staff channels, private tickets, controlled technical permissions, backups and moderation logs. Private reports, payment references, IP addresses and administrative logs are not intended for public disclosure.

No online service can promise absolute security. Users should protect their Minecraft, Microsoft and Discord accounts and never send passwords, Discord tokens, card details or two-factor authentication codes to staff.

9. Your rights

Depending on applicable law, you may request access, correction, erasure, restriction, objection or portability of relevant personal data, and you may withdraw consent where processing is based on consent.

You may also lodge a complaint with the Dutch Data Protection Authority or another competent supervisory authority. Identity verification may be required before fulfilling a request.

10. Children

VanillaMonster does not seek unnecessary information about age, school, home or family. Users who cannot independently consent under their local law must obtain appropriate parental or guardian permission for optional consent-based processing and purchases.

11. Automated tools

Anti-cheat, anti-spam and security tools may generate alerts or risk signals. Significant sanctions are intended to be reviewed by authorised staff rather than imposed solely by automated decision-making.

13. Changes

This notice will be updated when the hosting stack, analytics, forms, store, account linking, retention schedule or operator details materially change. The publication date at the top will be updated.