1. Introduction
Layeh's Market ("we," "us," or "our") respects your privacy. This policy explains what data we collect when you use layehmarket.com, our checkout, and our Discord bot.
2. Data We Collect
2.1 Discord OAuth
When you log in with Discord, we receive your Discord user ID, username, avatar, guild access needed for the service, and email address if Discord provides it under the email OAuth scope.
Email is stored for account and future opt-in marketing use only. Cookie consent does not subscribe you to marketing emails.
2.2 Orders and Payments
- Order details, products, cart lines, selected server, quantity, price, discounts, and status
- Payment method, PayPal reference IDs, and blockchain transaction IDs for crypto payments
- Marketing attribution attached to the order when you consent, such as UTMs, referrer, and ad click IDs
We do not store card numbers, bank details, PayPal login credentials, or crypto private keys. Card and PayPal processing is handled by PayPal. Cryptocurrency is paid directly to our own wallets and confirmed against public blockchain data, so no crypto payment processor receives your information.
2.3 Discord Support and Bot Data
The bot stores data needed for tickets, delivery, rewards, ranks, transactions, scammer checks, moderation, translations, and analytics.
Our bot uses Discord's Message Content privileged intent, so it can read the text of messages. Message content is processed in three situations:
- Support tickets - every message in a ticket channel is recorded, including message content, embeds, attachments and links posted, the message it replies to, timestamps, edits, deletions, and the Discord ID and role of the author. Edits and deletions are recorded as changes; a deleted message is marked deleted rather than erased from our records.
- Moderated and auto-translated public channels - in a small number of clearly identified public channels the bot reads messages as they are posted in order to remove prohibited or offensive wording, or to post a translation. Message content read for these purposes is not retained beyond what is needed to perform the action and to keep a moderation log.
- Commands - text you send to invoke a command, and anything you type into a form or modal the bot shows you.
The bot does not read your direct messages with other people, and it does not read channels it has not been given access to. Outside the cases above, message content in other channels is not stored.
2.4 Website Analytics, Ads, and Improvement Data
On eligible public pages, our own first-party audience measurement records a random visitor identifier, a 30-minute session identifier, pathname without query parameters, referring hostname, UTM campaign fields, country code, device/browser/operating-system family, language, suspected-bot status, foreground active time, maximum scroll depth, and counts and categories of safe interactions such as internal, external, or Discord link clicks. Identifiers are stored only as one-way hashes. We do not store the IP address, raw user-agent string, form values, typed text, full referring URL, or session replay, and we do not link this audience layer to your account or use it across other websites.
Separately, with your consent, we collect browsing and funnel events such as product views, searches, cart actions, checkout steps, purchases, Discord clicks, detailed attribution, ad click IDs, and cookie IDs used by third-party analytics or advertising platforms.
To respect and audit your choices, our first-party systems record that the consent notice was shown, the category choices made, and whether our code blocked, attempted, or received a technical ingestion acknowledgement for an allowlisted provider event. This record uses one-way visitor and session hashes and stores only provider names, event names, outcome classes, coarse page/device/acquisition dimensions, and allowed payload field names. It does not store payload values, full URLs, IP addresses, emails, advertising identifiers, form values, typed text, or secrets. A browser dispatch or provider ingestion acknowledgement does not prove advertising attribution or a completed conversion in that provider.
2.5 Community Building Templates
When you publish a building template, we store the submitted text, declared game requirements, validated file summaries, private template files, normalized public screenshots, publication status, moderation history, and your private rights confirmation. Your public creator profile uses your Discord display name and avatar. We do not display your email address.
Anonymous likes use a functional browser cookie that is transformed with a keyed one-way hash. We do not store an IP address for likes. Reports are linked internally to the reporting Discord account so we can prevent duplicate reports and follow up on misuse.
2.6 Automated Translation
To support customers who do not speak English, the bot can translate messages inside a support ticket and in our translation channel. When it does, the text of the message is sent to Google's translation services (the Gemini API, falling back to Google Translate) to obtain the translation, and the translated text is stored alongside the original message. We do not send your Discord ID, email address, or order details to these services - only the text to be translated.
2.7 Using Support Conversations to Improve and Automate Support
We use our own past support conversations to improve the quality of our support and to build and train an automated support assistant that answers common customer questions. This means the content of ticket conversations, including messages you send, may be used as training and evaluation data for that assistant, together with quality labels our staff assign to a conversation after it closes and signals such as whether the ticket ended in a sale and how quickly it was answered.
Before any conversation data leaves our systems for this purpose it is pseudonymised: we replace Discord IDs and mentions with irreversible keyed hashes, and we strip email addresses, crypto wallet addresses, and payment transaction references from the message text. Your name, Discord ID, email address, and payment details are not part of the training data.
We do not sell this data, we do not share it with third-party AI providers to train their own models, and we do not use it to build a profile of you or to make automated decisions about you. If you would prefer your conversations not to be used for this purpose, you can object by opening a support ticket and we will exclude them.
2.8 Private Atlas Items and Tribe Workspaces
The Island Atlas works without an account and stores pins, saved views, and Paths in your browser. If you sign in with Discord, you may sync those items to your account and create or join private tribe workspaces. We then store item names, notes, coordinates, view settings, Paths, workspace membership and roles, single-use invitation records, version history, tombstones for archived items, and an action audit log.
Workspace content is available only to its invited members according to Owner, Officer, and Member roles. We do not send private Atlas names, notes, coordinates, workspace or invitation identifiers to analytics, error-report context, support-assistant training data, or public Atlas datasets.
3. How We Use Your Data
| Purpose | Legal basis |
|---|---|
| Account login, orders, delivery, ranks, rewards, and support | Contract performance |
| Fraud prevention, audit logs, disputes, chargebacks, and security | Legitimate interests |
| Limited first-party audience measurement used only for aggregate site statistics | Legitimate interests, where permitted under applicable audience-measurement rules |
| Recording the consent notice and technical enforcement outcome so choices can be respected and audited | Legitimate interests and compliance with consent obligations |
| Third-party analytics, ads, retargeting, attribution, and UX/session insight | Consent |
| Legal, tax, and accounting record keeping | Legal obligation and legitimate interests |
| Template publishing, access, moderation, abuse prevention, and creator profiles | Contract performance and legitimate interests |
| Personal Atlas synchronization and private tribe workspace collaboration | Contract performance and legitimate interests |
| Translating support messages so we can serve you in your own language | Contract performance |
| Channel moderation, prohibited-wording removal, and moderation logs | Legitimate interests |
| Improving support quality and training our own automated support assistant on pseudonymised past conversations | Legitimate interests (you may object - see section 7) |
| Error monitoring, crash reporting, and keeping the service running | Legitimate interests |
4. Data Shared with Third Parties
| Provider | Purpose |
|---|---|
| Discord | OAuth login, Discord delivery, tickets, and community support |
| PayPal | Payment processing (PayPal, card, Apple Pay, Google Pay) and payment reference verification |
| Supabase | Database hosting for users, orders, products, private Atlas workspaces, analytics, and bot mirrors |
| Vercel | Website hosting and operational performance |
| Google Analytics and Google Ads | Analytics, consent mode, ad measurement, and purchase conversions |
| Meta | Pixel and server-side purchase conversion measurement when ads consent is granted |
| TikTok | Pixel and server-side purchase conversion measurement when ads consent is granted |
| Microsoft Clarity | UX/session insight when experience-improvement consent is granted |
| Google (Gemini API and Google Translate) | Automated translation of support and translation-channel messages; receives the message text only |
| Sentry | Error and crash reporting; a report may include the Discord or account identifier and the action involved at the time of the error |
We do not sell personal information for money. Advertising pixels may count as data sharing for ads laws; you can reject or withdraw ads consent at any time.
5. Cookies and Consent
We use these categories:
- Essential - required for login, checkout, security, CSRF protection, and site operation.
- Template preferences - a functional cookie remembers an anonymous like without storing your IP address.
- Limited first-party audience measurement - random visitor and session cookies used only by Layeh's Market for aggregate pageview, audience, engagement, and navigation statistics. The visitor cookie is set once for up to 13 months; the session cookie expires after 30 minutes of inactivity.
- Optional analytics - GA4, funnel events, attribution reporting, and product/search insight.
- Ads and retargeting - Meta, TikTok, Google Ads, click IDs, remarketing audiences, and conversion APIs.
- Experience improvement - tools such as Microsoft Clarity to understand UX issues.
Optional analytics, ads, retargeting, and experience-improvement tools stay off until you consent. You can accept all, reject all, or customize those choices. You can change your choice here: .
The first-party consent audit described in section 2.4 records the notice and your choice even when you reject optional categories. It is used to enforce and demonstrate that rejection, not for advertising or cross-site profiling.
6. Data Retention
- Account data - retained until deletion is requested, subject to order/legal retention.
- Order and payment records - retained for tax, accounting, fraud prevention, and dispute handling.
- Ticket messages and transcripts - retained as needed for support quality, delivery evidence, disputes, and the support-assistant training use described in section 2.7. Messages are stored in full while retained; pseudonymisation is applied to data exported for training, not to the stored record.
- Moderation logs - retained as needed to enforce our rules and handle appeals.
- Error and crash reports - retained for a limited period under our monitoring provider's default retention.
- Analytics, consent audit, and attribution - retained while useful for compliance and business reporting unless deletion is required. No automated destructive retention is currently applied.
- Template drafts and quarantine files - temporary uploads expire after 24 hours and are removed by scheduled cleanup; the draft record is retained for audit.
- Published templates and moderation records - retained while published and afterward as reasonably needed for reversibility, rights, safety, abuse prevention, and dispute handling.
- Personal Atlas and tribe workspace data - retained while the account or workspace remains active and afterward as reasonably needed for sync tombstones, reversibility, security, abuse prevention, and audit; you may request deletion subject to those needs.
7. Your Rights
Depending on your location, you may have rights to access, correct, delete, restrict, object to, or receive a copy of your personal data. You can also withdraw consent for non-essential cookies at any time.
You can also object to your support conversations being used to improve and train our automated support assistant, as described in section 2.7. Objecting does not affect the support you receive.
To exercise privacy rights, open a support ticket in our Discord server. We aim to respond within 30 days where legally required.
EU/UK residents may complain to their local supervisory authority. Brazilian residents have rights under LGPD. California residents may request access or deletion and may opt out of advertising data sharing by rejecting ads cookies.
8. Data Security
- HTTPS for all web traffic
- Forced Row-Level Security and service-role-only APIs for private Atlas workspaces
- Server-side validation and rate limiting on API endpoints
- Payment credentials handled by payment providers, not stored by us
9. Children's Privacy
Our services are not directed at children under 13. If you believe a child under 13 provided personal data, contact us through Discord and we will delete it where required.
10. Changes and Contact
We may update this policy from time to time. Material changes will be posted here or announced in Discord.
For privacy questions, contact us through our Discord server by opening a support ticket.