Privacy policy
RZ Development (“we”, “us”, “our”) runs this website. We aim to be transparent about what information is processed, why we use it, and what we do not do. This policy describes our storefront practices; it should be read together with Terms of service and Tebex’s privacy materials for payments.
1. Transparency: tracking and analytics
- No ad profiling or cross-site analytics in the default storefront. As shipped, this site does not load third-party advertising pixels or audience analytics tools (for example Google Analytics, Meta Pixel, or similar) to track you across the web for marketing profiling.
- Server and security logs. Like almost all websites, our hosting stack may create standard technical logs (such as IP address, user agent, URL, and timestamp) when you request pages or call our APIs. We use that information for operating the service, abuse prevention, and security—not for selling personal data or for unrelated advertising.
- Future changes. If we ever add optional first-party or third-party analytics, we will update this policy to name the tool, what data it receives, and the purpose. Where the law requires consent before non-essential tracking, we will ask for it before turning those features on.
2. Who is responsible
The data controller for data processed through this website is RZ Development, except where Tebex acts as an independent controller for checkout and payment flows—see Tebex’s documentation for how they handle payment and account data.
3. What we process and why
We only use personal or technical data for specific, legitimate purposes tied to running the store:
- Shopping cart and checkout. To keep your basket and complete purchases, Tebex processes transaction data. On your device we may store a Tebex basket identifier in
localStorage(rz-tebex-basket-ident) so your session can resume. Purpose: fulfil orders you start on this site. - Optional sign-in (CFX / FiveM and Discord). If you use “Continue with CFX / FiveM”, we use Tebex’s basket authentication to obtain your Tebex
username_idand store a signed session in anrz_authHTTP-only cookie (up to ~90 days). If you then “Link Discord”, we merge your Discord id into that session. If you use “Continue with Discord only”, we receive basic profile identifiers from Discord (user id, username, avatar) in the same cookie. Short-lived cookies (rz_oauth_state,rz_oauth_return,rz_cfx_login_ident,rz_cfx_return,rz_discord_link) protect OAuth / Tebex redirects and are cleared when no longer needed. For a smoother UI, your browser may keep a non-secret copy of display name and ids inlocalStorageunderrz-auth-display-v1until you sign out or it expires (~35 days); it does not contain secrets. Purpose: account features you choose (wishlist, loyalty, Tebex add-to-cart variables). - Wishlist (browser). If the wishlist feature is enabled, selected product ids may be stored in
localStorageunderrz-wishlist-ids(and synced server-side when you are signed in). Purpose: remember items you save. - Guest loyalty demo (browser). For visitors not signed in, a demo loyalty snapshot may be stored in
localStorageunderrz-loyalty-demo. Purpose: local UI only; when you sign in with Discord, server-backed data takes precedence. - Discord server statistics (aggregates). Our server may call Discord’s public APIs to show approximate online or member counts (for example on the homepage). That does not identify individual visitors to our site. Purpose: display non-personal community stats.
4. What we do not sell
We do not sell your personal information to data brokers and we do not use the practices described in this policy to build unrelated advertising profiles. If we relied on “sale” or “sharing” definitions in US state privacy laws, we would describe that here—currently we do not operate such sales from this storefront.
5. Legal bases (EEA / UK visitors)
Where GDPR-style rules apply: we process data necessary to perform a contract with you (checkout and delivery), based on our legitimate interests in securing and operating the site (logs, fraud prevention), and—where required—on your consent (for example optional OAuth or any future non-essential cookies we would disclose separately).
6. Retention
Session cookies expire per their settings. Server logs and any server-stored profile data tied to Discord sign-in are kept only as long as needed for the feature, support, accounting, or legal obligations, then deleted or anonymised where feasible.
7. Sharing
- Tebex — payments, baskets, and entitlement delivery.
- Discord — only when you choose OAuth or when our server requests public stats from Discord.
- Infrastructure providers — hosting or DNS vendors that process technical data strictly to deliver the service.
8. Your rights
Depending on where you live, you may have rights to access, correct, delete, or port your personal data, and to object to or restrict certain processing. To exercise these rights, contact us through the support channels on this site. You may also lodge a complaint with your local supervisory authority.
9. Children
Our storefront is intended for operators and consumers who can lawfully enter contracts. We do not knowingly collect personal information from children under the age required in your region for independent consent.
10. International transfers
Data may be processed in countries where we or our processors operate. We use contractual or standard safeguards where required by law when transferring personal data across borders.
11. Changes
We may update this policy from time to time. We will adjust the “Last updated” date above. Material changes may also be announced through the site or Discord where appropriate.
12. Legal review
This text is written for transparency and operational accuracy for this codebase; it is not a substitute for legal advice. Have a qualified lawyer review this policy for your entity, regions, and Tebex setup.
