Legal
Privacy Policy
Last updated 16 August 2026
DRAFT — before switching Stripe to live mode, fill in the data controller identity in §1 and have a lawyer read this. It is written to match what the system actually does; if the implementation changes, this page has to change with it.
Short version: we collect your email address so we can bill you, and your Discord user ID so we can give you the role you paid for. That is essentially all of it. This site has no analytics, no tracking pixels and no advertising, and it sets exactly one cookie — the one that remembers your payment for the two minutes between paying and connecting Discord.
1. Who is responsible for your data
CONTROLLER IDENTITY REQUIRED — legal name, registered address, and company number. If a Data Protection Officer is appointed, name them here; for an operation this size one is very unlikely to be required.
The data controller for the processing described here is the operator of bmonitors.com. Privacy questions: privacy@bmonitors.com.
2. What we collect, and why
| Data | Where it comes from | Why we have it |
|---|---|---|
| Email address | You, at Stripe checkout | To send you your access link, and to identify your subscription if you contact us |
| Stripe customer and subscription reference, plan, subscription status, renewal date | Stripe | To know whether your access should be on or off |
| Country and VAT treatment of the sale | Stripe | Tax compliance |
| Discord user ID, username, avatar | Discord, when you authorise the connection | To add you to the server and assign the paid role, and to remove it when you stop paying |
| IP address, request metadata | Automatically, in server logs | Security, abuse and rate limiting |
What we deliberately do not have
- Card details. Payment is taken on Stripe's own page. Card numbers never reach our servers, and we could not retrieve them if we wanted to.
- Your Discord password or messages. The connection uses Discord's
identifyandguilds.joinpermissions, which let us read your user ID, username and avatar and add you to one server. Nothing else. We cannot read your DMs, your other servers, or your email address at Discord. - Your Discord access token. It is used once, at the moment you join, and discarded. We never store it.
- Any behavioural data. We do not log which alerts you clicked, which channels you read, or when you were online.
3. Cookies and tracking
The landing page loads no third-party scripts and makes no requests to any other domain — the fonts and logos are served from our own server. There is no analytics package and no advertising network. This is enforced technically by the site's Content-Security-Policy, not offered as a promise.
We set one cookie, and only after you pay:
| Name | Purpose | Lifetime |
|---|---|---|
bm_link | Identifies which completed payment this browser belongs to, so the "Connect Discord" step knows which subscription to attach your account to. It holds a single-use random token and nothing else — no identifier, no email. | Up to 7 days, or until you connect Discord |
It is a strictly necessary cookie under the ePrivacy Directive: without it the thing you just bought cannot be delivered. That is why there is no cookie banner — there is nothing here to consent to or refuse. It is HttpOnly, Secure, SameSite=Lax, and scoped to /api, so it is never sent when you load the landing page or any static asset.
Stripe's checkout page and Discord's login page are operated by those companies on their own domains and set their own cookies under their own policies.
4. Legal bases (GDPR Article 6)
- Performance of a contract — your email, subscription record and Discord ID. Without them we cannot deliver what you paid for.
- Legal obligation — transaction and tax records we are required to keep.
- Legitimate interests — server logs and rate-limiting data, for keeping the service secure and available, and for preventing payment fraud and access sharing. We have balanced this against your rights and consider it proportionate: the data is minimal and short-lived.
We do not process any special category data, and we do not carry out automated decision-making or profiling that produces legal effects for you.
5. Who else processes your data
| Processor | What they handle |
|---|---|
| Stripe | Payments, billing, invoices, tax calculation |
| Cloudflare | Hosting, CDN, DDoS protection, the membership database |
| Discord | Delivery of the service itself, and your account there |
| Resend | Sending your access-link email |
We do not sell your data, and we do not share it for anyone else's marketing.
6. Transfers outside the EEA
The processors above are US-headquartered and may process data outside the EEA. Those transfers rely on the European Commission's Standard Contractual Clauses and, where the provider is certified, the EU–US Data Privacy Framework.
7. How long we keep it
- Membership record (email, Stripe references, Discord ID, status) — for as long as your subscription is active, and up to 12 months afterwards so that you can come back without starting over.
- Invoices and transaction records — for the period tax law requires, which in the EU is commonly up to 10 years. These are held primarily by Stripe.
- Access-link tokens — stored only as a one-way hash, and expired automatically. The raw token exists only in the email we sent you.
- Server and security logs — short-lived, per Cloudflare's retention.
Note that your Discord account, your membership of the server, and any messages you posted there belong to your relationship with Discord. Deleting your data with us removes your role; it does not delete your Discord account.
8. Your rights
Under the GDPR you can ask us to give you a copy of your data, correct it, delete it, restrict or object to how we use it, or provide it in a portable format. Email privacy@bmonitors.com from the address you used at checkout and we will respond within one month.
Asking us to delete your data while you have an active subscription means cancelling it — we cannot keep your access on without knowing who to keep it on for.
You also have the right to complain to your national data protection authority.
9. Security
The site is served over HTTPS only, with HSTS and a strict Content-Security-Policy. Access tokens are stored hashed. Payment webhooks are cryptographically verified before they are acted on. Our published security contact and reporting process are at /.well-known/security.txt.
10. Children
The service is not intended for anyone under 18 and we do not knowingly collect data from children. If you believe a minor has subscribed, email us and we will delete the account and refund it.
11. Changes
If this policy changes materially we will announce it in the Discord server and update the date at the top of this page.