WOSRedeem
Gift Codes Quick Claim Discord Bot FAQ
Select Language
Translated by Google
Deutsch DE English EN Español ES Français FR Italiano IT Nederlands NL Polski PL Русский RU Українська UK
Login Register
Gift Codes Quick Claim Discord Bot FAQ
Login Register

Privacy Policy

Last updated: July 21, 2026

1. Introduction

WOSRedeem (“we”, “us”, “the Service”) respects your privacy and complies with the EU General Data Protection Regulation (GDPR). This policy explains what personal data we collect, why we collect it, how we use and share it, how long we keep it, and the rights you have over your data.

2. Controller & Contact

Data controller: WOSRedeem.

For questions or to exercise your rights, contact us (see Section 14).

3. Personal data we collect

We collect only the data necessary to operate and secure the Service:

  • Account information: username, email address, and password (securely hashed & salted).
  • Activity & security logs: IP addresses, timestamps, device and browser metadata for account creation, login, and security events.
  • In‑game data: Whiteout Survival player IDs, optional manual nicknames, and region numbers. This data may be personal data when usernames, nicknames, or other fields contain real names or otherwise identify a person.
  • Discord bot integration data: Discord server IDs, detected server names and icon URLs, configured alert channel IDs and names, configured bot manager user or role IDs, command runner user IDs and names, role IDs used for authorization, guild and channel IDs, command names, timestamps, submitted gift codes, player IDs, regions, and optional player names submitted through Discord.
  • Automated processing metadata: logs used for automated gift-code processing and anti‑abuse systems.
  • Third‑party service data: limited data collected by integrated services (see Sections 5, 6, and 8).
  • Billing metadata: subscription plan, payment provider, provider transaction and subscription identifiers, payment status, amount, currency, and billing timestamps. PayPal collects and processes payment details directly.

We do not store PayPal account credentials or full card or bank details.

4. Purposes of processing and legal bases

We process your data for the following purposes and legal bases:

  • Account creation & management — performance of a contract with you.
  • Security, fraud prevention, and bot protection (including hCaptcha, Cloudflare) — legitimate interests (to protect the Service and users). We balance this interest against your privacy rights.
  • Automated gift‑code processing — performance of a contract and, when applicable, legitimate interests for automation. Where automated processing produces legal or similarly significant effects, you may request human review (see Section 10).
  • Discord bot operation, alert delivery, access control, audit logs, and abuse prevention — performance of a contract for premium Discord features and legitimate interests in securing the Service, preventing misuse, and keeping tenant activity auditable.
  • Analytics and performance monitoring — consent for non‑essential tracking; legitimate interests for aggregated, anonymized analytics.
  • Translation features (Google Translate) — consent where required; otherwise legitimate interest for usability, with a clear notice about third‑party collection.
  • Legal compliance and security incident handling — legal obligations and legitimate interests.

If we rely on consent, you can withdraw it at any time without affecting processing that relied on consent before withdrawal.

5. Categories of recipients / third‑party processors

We share or allow access to personal data only with parties required to provide or secure the Service:

  • Hosting: Contabo.
  • Security / CDN: Cloudflare.
  • Bot protection: hCaptcha.
  • Translation: Google Translate.
  • Product analytics: PostHog.
  • Payment processing: PayPal and, when selected, CryptAPI.
  • Discord bot interactions: Discord, when you invite or use the WOSRedeem bot in a Discord server. Discord may receive and process bot commands, messages, channel posts, server and channel identifiers, user and role identifiers, and related metadata under Discord's own terms and privacy policy.

6. Discord bot

The WOSRedeem Discord bot is an optional premium integration that connects a Discord server to the WOSRedeem group configured by that group's administrator.

  • Stored integration data: when the integration is configured, we store the Discord server ID. When the bot detects the server, we may also store the server name, server icon URL, alert channel ID and name, and configured bot manager user or role IDs.
  • Command data: when commands are used, we process the command runner's Discord user ID and display name when available, Discord role IDs used to authorize the command, guild and channel IDs, command names, timestamps, submitted gift codes, player IDs, regions, and optional player names.
  • Visibility in Discord: /gift-codes, /gift-codes-full, alert test messages, and gift-code alert deliveries may be visible to members who can access the Discord channel where they are posted. Premium management, history, and player command responses are sent ephemerally to the command runner, but those commands may still create, update, or delete WOSRedeem tenant records and tenant logs.
  • Retention: Discord integration data is kept while the integration is configured. Bot manager entries are removed when deleted by a group administrator or when the configured server ID changes. Discord command, security, and tenant audit logs follow the log retention rules in Section 9 unless a longer period is required for security, fraud prevention, legal obligations, or active investigations.
  • External platform: Discord operates its own service and may process data independently. Review Discord's Privacy Policy and Terms of Service for Discord's own data practices and rules.

7. International transfers

Data hosted in Germany remains in the EU. Some processors (e.g., Cloudflare, Google) may route or process data internationally. Where transfers outside the EEA occur, we rely on appropriate safeguards (EU adequacy decisions, Standard Contractual Clauses) or explicit consent when required. Contact us for details about specific transfers (see Section 14).

8. Cookies

We use a limited number of cookies to ensure the Service functions correctly and to remember your preferences. These are categorized as follows:

Optional analytics (PostHog): If you accept optional cookies via our banner, we load PostHog’s JavaScript SDK, which may set first‑party cookies and use browser storage (e.g. local storage) for product analytics, error reporting configuration, and related features. If you reject optional cookies, PostHog runs in cookieless mode: it does not set PostHog analytics cookies or use that storage for analytics; limited page views may still be counted using a privacy‑preserving server‑side hash (IP address and user agent are inputs to that hash on PostHog’s side, as described in PostHog’s cookieless documentation). That mode requires “cookieless server hash” (or equivalent) to be enabled in our PostHog project settings.

Cookie Category Purpose Duration
auth_token Essential Used for user authentication to keep you logged into your account securely across your session. Session / 24 Hours
googtrans Preference Used by the Google Translate module to remember your language selection when navigating between pages. 2 Years
cf_clearance Essential Set by Cloudflare to distinguish between malicious and legitimate users and to manage bot protection. 1 Year
__cf_bm Essential Used by hCaptcha and Cloudflare bot management to identify automated traffic and support CAPTCHA verification. 30 Minutes
quick_claim_id Essential Used to enforce Quick Claim anti-abuse free limits. 6 Days
ph_* (PostHog) Optional / Analytics First‑party cookies set by the PostHog browser SDK when you accept optional cookies (names typically start with ph_ and relate to your device/session for analytics). Not used for analytics storage when you reject optional cookies (cookieless mode). Up to 1 Year (per PostHog defaults)
cookies_enabled Preference Stores whether you accepted optional (non‑essential) cookies via the consent banner (true or false). 1 Year

9. Data retention

  • Activity, security, and automated processing logs: retained for up to 6 months, except where a longer period is required for active security investigations, legal obligations, or fraud prevention.
  • Account information: retained for the duration your account is active. After deletion, we retain minimal backups for a limited period (typically up to 90 days) for legal and fraud prevention purposes.
  • Inactive accounts without subscription: accounts with no active subscription and no account activity for 6 months will be automatically deleted, together with associated in-game data, subject to any legal retention obligations.
  • Invoices and billing contact details: if you have made a purchase, retained for as long as required to meet legal, accounting, tax, and regulatory obligations; this retention period may be undetermined where required by law.
  • Subscription and payment metadata: retained for the duration needed to administer access, handle refunds or disputes, and meet legal, accounting, tax, and fraud-prevention obligations.
  • In‑game data: retained while the account is active; anonymized aggregates may be kept indefinitely.
  • Discord integration data: retained while the Discord integration is configured. Removing the Discord integration deletes the stored server, channel, icon, and bot manager records, subject to backups, tenant logs, and legal retention obligations.

10. Your rights under the GDPR

You have the following rights, subject to legal limitations:

  • Right of access to your data.
  • Right to rectification.
  • Right to erasure ("forgetting").
  • Right to restriction of processing.
  • Right to data portability.
  • Right to object to processing.
  • Right to withdraw consent.
  • Right to lodge a complaint.

To exercise rights, contact us (see Section 14). We will respond within 30 days after verifying account ownership.

11. Security measures

We implement appropriate technical and organizational measures, including password encryption (hashing & salting), TLS for data in transit, and firewalls via Cloudflare.

12. Children

The Service is not directed to children. We do not knowingly collect personal data from children under the applicable age without parental consent.

13. Changes to this policy

We may update this policy to reflect changes in law or our services. Material changes will be posted with an updated “Last updated” date.

14. How to contact us

For privacy inquiries, requests, or complaints, please verify you are human to reveal our contact email:

Tools Gift Codes Quick Claim Discord Bot Command Guide
Privacy Policy Terms of Service
About Contact FAQ Sitemap

WOSRedeem is not affiliated with Century Games.

© 2026 WOSRedeem.

Cookie preferences

We use optional cookies to better fit your needs and improve the site. You can accept them or continue with essential cookies only. Privacy Policy