Skip to content
The Last Stand

Privacy Policy

What this website collects when you sign in, link Steam, apply, open a support ticket or use the store, why, and how to have it deleted.
Last updated

The Last Stand is an independent gaming community. This policy covers this website. Our game server and Discord server have their own rules.

What we collect

When you sign in with Discord

We use Discord's identify permission only. Discord sends us your:

  • Discord user ID
  • username and display name
  • avatar (we store the image identifier and load the picture from Discord)

We don't receive your email address, your servers or your messages. Discord gives us a short-lived access token, which we use once to read the details above and then revoke. We don't store it.

We also store an internal account ID, whether you are whitelisted, any staff roles you hold, and when your account was created, last updated and last signed in.

If you are in our Discord server, the site's bot reads which Discord roles you have (role IDs only) to keep whitelist and staff roles in step between Discord and the site, and may add or remove the whitelist roles described on our Discord server. We store the role IDs it last saw and when it checked.

When you link Steam (optional)

Steam confirms which Steam account you signed in with. We store its Steam ID. If the site has a Steam Web API key configured, we also store your public Steam display name, avatar and profile link. We never see your Steam password. You can unlink Steam at any time from your account page, which deletes the link straight away.

When you apply

We store your answers, including your timezone and a yes/no confirmation that you meet the minimum age. We don't ask for your birth date or real name. We also store the Steam ID linked at the time (if any), a reference number, the application status, the dates it was submitted and reviewed, messages between you and staff about it, a history of what happened to it, and notes staff write for each other about the application. Staff notes are never shown to you, and staff messages are shown under a team name rather than the staff member's name.

When you open a support ticket

We store the ticket's category, subject, your messages and any screenshots or text files you attach, the replies, its status and history, and internal notes staff write for each other (never shown to you). For a Staff Report, we also store the name you give for the staff member involved. Attachments are stored on our server and only shown to you and to staff allowed to handle the ticket.

Staff records

Actions staff take in the Staff Portal (for example approving an application or replying to a ticket) are recorded in an audit log for accountability, including which account did it and, behind our own proxy, the IP address of the request. If staff take an action about your account, the log names your account.

When you submit, a copy of the application (your Discord ID and username, linked Steam ID and answers) is posted to a private staff channel in our Discord server.

When you use the store

The store is run by Tebex, our payment partner, which processes every purchase. When you first add something to your basket, our server asks Tebex to open a basket for you. If our hosting passes us your real IP address, we send it to Tebex with that request, so Tebex links the basket to you rather than to our server. Signing in with your Cfx.re account, paying, your receipt and your email address are all handled by Tebex; we don't see your payment details. We don't store baskets or orders in our database.

Cookies

We only use cookies needed to run the site:

  • a sign-in cookie holding a random session token, kept for up to 30 days and renewed while you use the site. Our database stores a one-way hash of the token, not the token itself;
  • short-lived cookies (10 minutes) that protect the Discord sign-in and Steam linking steps from forgery;
  • a store basket cookie holding the ID of your Tebex basket, kept for up to 7 days, so the basket survives page loads and the trip to Tebex and back.

We don't use analytics, advertising or tracking cookies.

IP addresses and logs

The site uses your IP address briefly, in memory, to limit how often requests can be made (to stop spam and abuse). It is not saved to our database. Depending on how the site is hosted, the web server or hosting provider may keep standard request logs, which include IP addresses, for security and troubleshooting.

Other services involved

  • Discord handles sign-in, receives application summaries and optional staff log entries through webhooks, and our bot reads and changes Discord roles for whitelist and staff access. The home page shows public information about our Discord server, such as its member count and some online members, which our server reads from Discord's public API.
  • Valve (Steam) confirms Steam accounts when you link one.
  • Tebex runs the store: baskets, Cfx.re sign-in, payment, tax, receipts and delivery of purchases. Our server reads the store's public package list from Tebex.
  • Profile pictures from Discord and Steam are fetched by our server and passed on to you, so your browser doesn't contact those services for them.

Each service handles your data under its own privacy policy.

How long we keep it

We keep your account, applications and tickets while your account exists. Audit log entries are kept after an account is deleted, with the link to the account removed, so staff actions stay accountable. Sessions end when you sign out or after 30 days without use. Linking cookies and their records expire after 10 minutes.

Your choices

  • Unlink Steam from your account page at any time.
  • Sign out from the account menu to end your session.
  • Delete everything: contact a staff member through our Discord server and ask for your account to be deleted. This removes your account, sessions, linked Steam account, applications and tickets (with their attachments' records) from our database. Copies of applications already posted to our staff Discord channel are deleted by staff separately.

Changes

We update this page when the site starts collecting something new or uses it differently. The date at the top shows the last change.