Privacy Policy
Data Governance & Privacy Disclosure for Team Summit Services
1. Scope & Coverage
This Privacy Policy governs the collection, use, storage, and disclosure of personal data and information through all Team Summit-operated systems and services, including:
- Spectra Bot: Our proprietary Discord automation system, including all commands, moderation tools, logging mechanisms, and background processes
- Team Summit Discord Server: All channels, voice rooms, and server interactions
- Team Summit Website: summitgg.org and all associated web properties
- APIs & Dashboards: Backend services, integrations, and administrative interfaces
- Future Services: Any additional tools, bots, or platforms released under the Team Summit brand
Data Controller
Team Summit acts as the data controller for all personal data collected through our services. We determine the purposes and means of processing your personal information.
By using any Team Summit service, you consent to the data practices described in this Privacy Policy.
2. Data Collected
Team Summit collects and processes the following categories of data through our services:
2.1 Automatically Collected Data
| Data Type | Description | Source |
|---|---|---|
| Discord User ID | Unique identifier assigned by Discord | Discord API |
| Server ID (Guild ID) | Identifier for Discord servers using Spectra Bot | Discord API |
| Role IDs | Server roles assigned to users | Discord API |
| Username & Display Name | Discord username and server nickname | Discord API |
| Interaction Timestamps | Date and time of user actions | System Logs |
| Command Usage | Bot commands executed and parameters used | Spectra Bot |
| Moderation Events | Warnings, mutes, kicks, bans, and appeals | Spectra Bot |
| Message Metadata | Message IDs, channel IDs (content not stored) | Discord API |
2.2 Optionally Provided Data
- Contact Form Submissions: Name, email, inquiry type, and message content
- Billing & Checkout Details: For paid services, transaction metadata and billing contact details are processed through Stripe
- Custom Bot Configurations: User-defined settings and preferences
- Feedback & Reports: Voluntarily submitted feedback, bug reports, or suggestions
2.3 Website Analytics
- IP addresses (anonymized where possible)
- Browser type and version
- Device information and operating system
- Page views and navigation paths
- Referral sources
- Discord CTA event telemetry submitted to /api/discord/event (event name, page label, and user-agent string)
- Session-level ad-block detection state used for analytics and ad diagnostics
Data Not Collected
Team Summit does NOT collect or store:
- Full message content (except flagged moderation cases)
- Private DM conversations
- Voice chat audio recordings
- Payment or financial information
- Passwords or authentication credentials
3. Purpose of Data Processing
Team Summit processes collected data for the following legitimate purposes:
3.1 Core Functionality
- Bot Operations: Enable Spectra Bot commands, automations, and interactions
- User Identification: Recognize and differentiate users across sessions
- Role Management: Assign, track, and enforce role-based permissions
- Feature Delivery: Provide requested services and respond to user commands
3.2 Moderation & Security
- Rule Enforcement: Detect and respond to Terms of Service violations
- Abuse Prevention: Identify spam, harassment, and malicious activity
- Automated Moderation: Process data through automated detection systems
- Security Monitoring: Detect unauthorized access attempts and exploit attempts
- Ban Evasion Detection: Identify users attempting to circumvent enforcement
3.3 Analytics & Optimization
- Usage Analytics: Understand feature popularity and usage patterns
- Performance Optimization: Identify and resolve technical issues
- System Improvements: Enhance bot logic and response quality
- Resource Allocation: Optimize infrastructure and capacity planning
3.4 Legal Compliance
- Dispute Resolution: Investigate user complaints and conflicts
- Legal Obligations: Comply with applicable laws and regulations
- Law Enforcement Cooperation: Respond to valid legal requests
- Terms Enforcement: Document and prosecute Terms of Service violations
Legal Basis for Processing
We process personal data based on:
- Consent: You consent to data processing by using our services
- Legitimate Interests: Necessary for service operation, security, and improvement
- Legal Obligations: Required by applicable laws and regulations
4. Third-Party Integrations
Team Summit uses the following third-party services to operate our platforms:
4.1 Discord Platform
Spectra Bot operates through the Discord API and is subject to:
- Discord Privacy Policy
- Discord Terms of Service
- Discord's data retention and processing policies
4.2 Hosting & Infrastructure
Our services are hosted on third-party infrastructure providers who may process data for:
- Server hosting and data storage
- Network routing and content delivery
- Backup and disaster recovery
- DDoS protection and security services
4.3 Analytics Services
We may use analytics tools to understand service usage, including:
- Website traffic analysis
- User behavior tracking (anonymized)
- Performance monitoring
Data Sharing Policy
Team Summit will NEVER sell your personal data to third parties.
We only share data with third-party processors necessary for service operation, and require them to maintain equivalent privacy and security standards.
4.4 Cloudflare & Security Edge Services
Team Summit traffic is proxied through Cloudflare services, including Cloudflare Tunnel and edge security protections. Cloudflare may process standard request metadata (such as IP address, request headers, and TLS/network diagnostics) to provide routing, abuse prevention, and availability controls.
4.5 Data Transfer
By using Team Summit services, you acknowledge that your data may be transferred to and processed in jurisdictions outside your country of residence, subject to applicable data protection laws.
4.6 Stripe Payment Processing
Team Summit uses Stripe to process payments for paid products or services. Payment card data is collected and processed directly by Stripe under Stripe's security and compliance controls. Team Summit does not store full payment card numbers or card verification values (CVV).
- Stripe Privacy Policy
- Stripe Services Agreement
- We may receive limited billing metadata from Stripe, such as payment status, transaction identifiers, and billing contact details needed for support, accounting, and fraud prevention.
5. Data Retention & Security Controls
5.1 Retention Timelines
| Data Category | Retention Period | Rationale |
|---|---|---|
| Active User Data | While account is active | Core functionality |
| Moderation Logs | 12 months | Appeal processing, pattern analysis |
| Permanent Bans | Indefinite | Ban evasion prevention |
| System Logs | 90 days | Security auditing, debugging |
| Analytics Data | 24 months (aggregated) | Long-term trend analysis |
| Contact Forms | 6 months | Response tracking, reference |
| Legal Hold Data | As legally required | Litigation, investigations |
5.2 Security Measures
Team Summit implements industry-standard security controls to protect user data:
Technical Safeguards
- Encryption: Data encrypted in transit (TLS/SSL) and at rest
- Access Controls: Role-based access restrictions for administrative functions
- Authentication: Multi-factor authentication for system administrators
- Logging & Monitoring: Comprehensive audit trails and anomaly detection
- Regular Backups: Automated backup systems with disaster recovery procedures
Administrative Safeguards
- Least-privilege access principles
- Regular security training for administrators
- Incident response and breach notification procedures
- Periodic security audits and vulnerability assessments
Security Limitations
While we implement reasonable security measures, no system is completely secure. Team Summit cannot guarantee absolute security of user data. Users are responsible for maintaining the security of their Discord accounts and credentials.
6. User Rights & Data Requests
Subject to applicable laws and technical limitations, users have the following rights regarding their personal data:
6.1 Right to Access
You may request confirmation of whether we process your personal data and obtain a copy of your data in a structured, machine-readable format.
6.2 Right to Deletion
You may request deletion of your personal data, subject to the following limitations:
- Active Enforcement: Data related to active bans, sanctions, or ongoing investigations may be retained
- Legal Obligations: Data required for legal compliance, dispute resolution, or contractual obligations
- Legitimate Interests: Data necessary for security, fraud prevention, or Terms enforcement
- Aggregated Data: Anonymized analytics data that cannot be linked to individuals
6.3 Right to Rectification
You may request correction of inaccurate personal data. Note that Discord-sourced data (usernames, IDs) are controlled by Discord, not Team Summit.
6.4 Right to Object
You may object to processing of your personal data for specific purposes. However, this may limit or prevent access to Team Summit services.
6.5 How to Exercise Rights
To submit a data request:
- Use the Contact Us form on our website
- Clearly state your request type (access, deletion, rectification, etc.)
- Provide your Discord User ID for verification
- Allow up to 30 days for processing
Identity Verification
To protect user privacy, we may require verification of your identity before processing data requests. We will not fulfill requests that cannot be authenticated.
7. Children's Privacy (COPPA Compliance)
Team Summit services are subject to the Children's Online Privacy Protection Act (COPPA) and similar international regulations.
7.1 Age Requirements
- Users must be 13 years of age or older to use Team Summit services
- This requirement aligns with Discord's Terms of Service
- Users under 18 should obtain parental consent before using our services
7.2 Knowingly Collected Data from Children
Team Summit does not knowingly collect personal information from children under 13. If we discover that we have inadvertently collected such data, we will:
- Delete the data promptly upon discovery
- Terminate access to the account
- Notify parents/guardians if contact information is available
7.3 Parental Rights
Parents or guardians may:
- Request review of data collected from their child
- Request deletion of their child's data
- Refuse further collection of their child's information
Report Underage Users
If you believe a user under 13 is using Team Summit services, please report this immediately through our Contact Us form.
8. Policy Enforcement & Updates
8.1 Enforcement Authority
Team Summit reserves the right to:
- Enforce this Privacy Policy strictly and without exception
- Investigate suspected violations of privacy terms
- Terminate access for users who violate data protection provisions
- Report serious violations to appropriate authorities
8.2 Policy Updates
Team Summit may update this Privacy Policy at any time to reflect:
- Changes in data collection or processing practices
- New features, services, or integrations
- Legal or regulatory requirements
- Security or operational improvements
8.3 Notification of Changes
- Updated policies will be posted with a revised "Last Updated" date
- Material changes may be announced in the Team Summit Discord server
- Continued use of services constitutes acceptance of updated policies
8.4 User Responsibility
Users are responsible for periodically reviewing this Privacy Policy. Team Summit is not obligated to provide individual notification of policy changes.
Version History
Current Version: 1.1
Effective Date: June 20, 2026
Previous Versions: 1.0 (January 3, 2026)
Privacy Inquiries & Data Requests
For privacy-related questions, concerns, or data requests:
General Privacy Inquiries
Use the Contact Us form on our website and select "Privacy & Data Protection" as the inquiry type.
Formal Data Requests
For data access, deletion, or rectification requests:
- Submit a detailed request through our contact form
- Include your Discord User ID for verification
- Specify the type of request (access, deletion, etc.)
- Allow up to 30 days for processing
Security Concerns
To report data breaches, security vulnerabilities, or privacy concerns, contact us immediately through official channels marked as urgent.
Your Privacy Matters
Team Summit is committed to protecting user privacy and maintaining transparency in our data practices. We continuously work to enhance our privacy protections and comply with applicable data protection laws.
Binding Policy
BY USING TEAM SUMMIT SERVICES, YOU ACKNOWLEDGE THAT YOU HAVE READ, UNDERSTOOD, AND AGREE TO THE DATA PRACTICES DESCRIBED IN THIS PRIVACY POLICY.
