Privacy Policy • Last updated: June 1, 2026

Hoorks Privacy Policy

This policy explains what data Hoorks collects, why it is needed, and how it is used to connect Roblox servers with Discord securely.

Part 1: Summary

Hoorks collects only the data required to authenticate administrators, record Roblox purchase events, and send notifications to Discord. We do not collect payment card data, bank details, or player emails.

Part 2: Full privacy policy

1. Information we collect

CategorySpecific dataSourcePurpose
Admin account
usernamepassword hash (bcrypt)admin idcreated_at
Entered by the administratorCreate and authenticate the admin account and secure dashboard access.
Session and cookies
rdb_session cookie (JWT with adminId and username)24h expiration
Generated by the serverMaintain admin sessions and protect restricted routes.
API keys
labelSHA-256 hashcreated_atrevoked statusraw key shown once
Generated in the admin dashboardAuthenticate game server requests and allow key revocation.
Roblox transactions
userIdproductIdgamepassId (optional)isAGiftgifterId (optional)amountuniverseIdplaceIdtransactionIdtimestampitemTypecreated_at
Roblox game servers via APIRecord purchases, display analytics, and send Discord notifications.
Discord webhook
webhook URLtest timestampdelivery status
Entered by the administratorSend real-time purchase notifications to Discord.
Technical data
IP address (rate limiting)request headershosting logs
Collected automaticallySecurity, abuse prevention, and technical troubleshooting.

Note: Hoorks does not request player emails, payment cards, or sensitive personal data.

2. How we collect data

Data comes from three sources: (1) administrator input in the dashboard (setup, login, API keys, webhook), (2) purchase events sent by Roblox game servers through the Hoorks API, and (3) technical data collected automatically by the hosting infrastructure for security and stability.

3. How we use data

Service delivery
Record transactions, display dashboard analytics, and notify Discord.
Security
Protect API routes with hashed keys, JWTs, and rate limiting.
Support and debugging
Resolve technical issues and monitor system health.
Compliance
Meet legal obligations and respond to data requests where required.

5. Sharing and third parties

We share data only with providers required to operate the service:

  • Discord: receives purchase data through webhooks.
  • Turso (libSQL): hosts the database containing accounts, keys, and transactions.
  • Vercel/hosting: runs the infrastructure and may generate technical logs.

We do not sell personal data and do not share data for advertising.

6. International data transfers[⚠️ LEGAL REVIEW REQUIRED]

Data may be processed in regions outside a user location depending on provider infrastructure. Ensure appropriate transfer mechanisms (e.g. SCCs) if GDPR applies.

7. Data retention

Hoorks retains data for as long as it is needed to provide the service:

  • Admin data and API keys: until revoked or removed.
  • Transactions: retained until removed by the administrator.
  • Discord webhook: stored until replaced or removed.
  • Rate-limit IP data: stored in memory for the window duration.

[⚠️ LEGAL REVIEW REQUIRED] Define exact retention periods based on jurisdiction and tax obligations.

8. User rights[⚠️ LEGAL REVIEW REQUIRED]

Depending on jurisdiction, users may have the right to:

  • Access to personal data and a copy of the data
  • Correction of inaccurate information
  • Deletion or restriction of processing
  • Data portability
  • Opt-out of marketing (if enabled)
  • Lodge a complaint with a supervisory authority

Requests can be sent to: devmirkoo@gmail.com or @devmirko on Telegram or Discord.

9. Cookies and tracking

We use only a HTTP-only session cookie (rdb_session) to keep admin sessions active. We do not use advertising or profiling cookies.

10. Security

Data is protected with credential hashing, signed JWTs, SHA-256 API keys, and rate limiting. No system is fully secure, but we apply reasonable safeguards to reduce risk.

11. Children's privacy[⚠️ LEGAL REVIEW REQUIRED]

Hoorks is intended for server operators and is not designed for direct use by children. Confirm any COPPA or local obligations if minors are involved.

12. Contact

Privacy contact: devmirkoo@gmail.com. Telegram or Discord: @devmirko.

13. Policy changes

If we make material changes, we will provide notice in the dashboard or via official project channels.

Part 3: Customization and compliance notes

Operational checklist

[⚠️ LEGAL REVIEW REQUIRED] Complete these items before publishing:

  • Add the legal entity name and address if applicable.
  • Confirm applicable jurisdictions (GDPR, CCPA/CPRA, etc.).
  • Define exact retention periods for each data category.
  • Set a process for access and deletion requests.
  • Sign DPAs with providers (Turso, Vercel, Discord).
  • Update the cookie section if analytics or marketing are added.
This policy is an informational draft and requires legal review before publication.