Privacy Policy
Last Updated: 1 October 2026
This Privacy Policy explains how Obsidian Squad ("we", "us", "our") collects, uses, stores, and protects your personal data when you use our website. We are committed to protecting your privacy and complying with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
1. Data Controller
Obsidian Squad is the data controller responsible for your personal data. If you have any questions about this Privacy Policy or our data practices, please contact us at:
- Email: info@obsidiansquad.com
2. Information We Collect
We collect and process the following categories of personal data:
2.1 Account Registration Data
| Data Type | Purpose | Legal Basis |
|---|---|---|
| Username | Account identification and display | Contract performance |
| Password (hashed) | Account security and authentication | Contract performance |
| Discord ID (hashed) | Membership verification and account linking | Contract performance |
2.2 Data Collected During Use
| Data Type | Purpose | Legal Basis |
|---|---|---|
| Last Login Timestamp | Account security monitoring | Legitimate interest |
| Print Request Messages | Fulfilling your 3D print requests | Contract performance |
| Discord Username (for print requests) | Providing custom 3D print files and contacting you about your request | Contract performance |
| Feedback Data - bug reports and suggestions (whether it is a bug or a suggestion, the page it relates to, your description, priority, status, timestamps, and the file names of any screenshots you attach). Screenshots are stored with IONOS HiDrive, not on the Website (see Section 10.4); their file names include the report number and your Website username | Investigating and resolving reported issues with the Website | Contract performance |
| Mining Board Request Data (Website username, ore, quality, SCU amount, notes, status, timestamps). This includes jobs the Supply Chain's "Hold: Request Ore" posts on a crafter's behalf, whose notes name the item being crafted and the Website username of the member who requested it | Creating, displaying, managing, and archiving member mining requests | Contract performance |
| Mining Board Claim and Completion Data (user ID, Website username, claim/completion status and timestamps, and - when a miner marks a job filled - the amount, quality and storage location they enter) | Coordinating fulfilment of mining requests and maintaining completed-job history | Contract performance |
| Mining Statistics (jobs completed and SCU delivered) | Providing Mining Board statistics and member progress information | Contract performance |
| Pledge Rain Member Leaderboard Data (Website username, ships refused, wave reached, wallet total, timestamp) | Recording and displaying your Pledge Rain leaderboard entry; a new run replaces your existing entry rather than adding another one | Contract performance |
| Pledge Rain Guest Leaderboard Data (a randomly generated guest tag, ships refused, wave reached, wallet total, timestamp) | Recording and displaying guest Pledge Rain leaderboard entries; the tag is generated fresh per run and is not linked to any account or identifying information | Legitimate interest |
| Supply Chain Warehouse Data (material/item names, quality, quantity, storage location you enter, private or shared status, timestamps and, for ore stored from a Mining Board job, which job it came from and which member it is being held for) | Tracking your stock and, for lots you choose to share, listing them on the member Distribution board | Contract performance |
| Supply Chain Blueprint, Crafting and Import Data (blueprints you own, crafted-product log entries, counts from log-file scans) | Showing your blueprint library, what you can craft, and your crafting history. Game log files are read in your browser and never uploaded; only the blueprint names found are sent to the Website, and file names are not stored | Contract performance |
| Task List (the items, blueprints, ships and custom tasks you add, amounts, your notes, what you have ticked off, whether a task is public, links to Mining Board jobs you post from it, timestamps) | Keeping your own list of things to get in game and, for tasks you mark public, showing them to other members | Contract performance |
| Meets - Room Choices, Flights and Pickup Requests (linked to your account and shown with your Website username: which of the meet's hotels you are staying at and whether you are booking your own room, want to share or have a spare bed; a flight description such as route and date, an optional link and note; for a pickup you ask for, the airport, when you land and how many seats you need; any note you add; timestamps) | Organising Obsidian Squad in-person meets and helping members coordinate rooms and travel with each other (see Section 4.7) | Legitimate interest |
| Meet Photos (shared by Obsidian Squad administrators: the photo, an optional caption, the Website username of the administrator who shared it, the upload time, and - if anyone asks for a photo to be taken down - who asked, their reason if they gave one, and when). Photos are stored with IONOS HiDrive (Section 10.4) with a small preview copy on the Website. People shown in a photo can be identified from it | Keeping a members-only photo archive of each meet (see Section 4.7) | Legitimate interest |
| Meet, Hotel and Event Details (entered by SuperAdmins, with administrators able to edit events: the meet's dates and place; for each of its hotels the name, address, website and public phone number, a group rate code, costs and hotel photos; airport-to-hotel notes; and for each event during the meet its name, description, address, time, website link and photos) | Telling members about each meet | Legitimate interest |
| Supply Chain Claims, Craft Requests, Ore Orders and Notifications (Website username, item, quantity, quality, notes, status, timestamps, any reason you give when rejecting a craft request, and links between a craft request and the Mining Board jobs posted for it) | Coordinating hand-overs of shared stock and craft requests between members, and notifying the members involved | Contract performance |
| Ship Codex Fleet Data (which ships you record as owning, and how many of each) | Showing your own fleet, and showing other signed-in members who in the organisation owns which ships (the Org Fleet page). Visitors who are not signed in see only the organisation's totals per ship, never member names | Contract performance |
| Competition Entries (the image or video you upload, and a record of your Website username, the competition, the time and the file's name). The file is stored with IONOS HiDrive, not on the Website (see Section 10.4); its file name includes the competition, the upload time and your Website username | Running competitions: administrators review entries and add them to the member vote. By uploading you agree that Obsidian Squad may share your entry on social media | Contract performance |
| Website Activity Logs (user ID, Website username, action, target identifiers, limited action/request details, timestamp) - covers Mining Board, Supply Chain, competition entry, print request, bug report, Meets organising and moderation (meets, hotels and events added, changed or removed; hotel and event photos added; another member's post or photo edited or removed by an administrator; photo removal requests and the decision on them), and administrative account actions | Website administration, moderation, audit, abuse prevention, and resolving operational issues | Legitimate interest |
| Theme Preference | Personalising your experience (stored locally in your browser) | Consent |
Mining Board notes, Supply Chain notes, craft-request rejection reasons, and Meets notes and photo captions are free-form text that other members can see. Please do not include passwords, financial information, booking references, passport details, medical or other sensitive personal data, or unnecessary real-world personal information in them.
2.3 Data NOT Collected
We do NOT collect:
- Your real name or physical address
- Your email address (we do not require email registration)
- Payment or financial information
- Location data or IP addresses for tracking purposes
- Discord messages, friends list, or server content
- Browsing history or activity on other websites
The one exception you choose yourself is the members-only Meets page (Section 4.7): if you post a flight or ask for an airport pickup, other members can see where and when you are travelling for a meet, and meet photos can show people's faces. You decide what to post, only signed-in members can see it, and travel details are deleted automatically 30 days after the meet.
3. Discord OAuth Integration
3.1 What We Access
When you authenticate with Discord, we use the minimal scope (guilds.members.read) to access only:
- Your Discord User ID
- Your membership status in the Obsidian Squad Discord server
- Your roles within the Obsidian Squad Discord server
3.2 How We Process Discord Data
- Your Discord User ID is immediately hashed using HMAC-SHA256
- Only the hashed ID is stored in our database
- We cannot reverse the hash to obtain your original Discord ID
- Membership and role data is checked once during verification and not stored
3.3 Discord's Privacy Policy
Your use of Discord is subject to Discord's Privacy Policy. We are not responsible for Discord's data practices.
4. How We Use Your Data
We use your personal data for the following purposes:
4.1 Account Management
- Creating and maintaining your user account
- Authenticating your login sessions
- Verifying your membership in the Obsidian Squad community
- Processing account updates (username changes, password resets)
- Deciding which features you can use: your role (member, administrator or SuperAdmin) and, if a SuperAdmin has set any, features allowed or blocked for your account personally (for example, a member trusted to edit the Guides). A SuperAdmin sets these on the Admin Dashboard; what is stored is your user ID, the feature, allow or block, and who set it and when
4.2 Service Provision
- Providing access to member-exclusive content
- Processing and fulfilling 3D print requests
- Receiving, investigating, and resolving member-submitted bug reports
- Creating, displaying, claiming, completing, archiving, and managing Mining Board requests
- Calculating Mining Board statistics such as completed jobs and SCU delivered
- Operating the member Supply Chain: your warehouse, blueprint library, crafted-product log, the Distribution board, claims, craft requests, the Marketplace and the Mining Board, including notifying the members involved
- Showing the public Blueprints page (see Section 4.5)
- Running the members-only Meets page for in-person meetups: meet, hotel and event details, room choices, flights, airport pickup requests and meet photos (see Section 4.7)
- Showing you your own figures from around the Website (Supply Chain, Mining Board, Task List, fleet, competitions, feedback, Meets and Pledge Rain) under "Your Stats" on your Account page. They are counted from what we already hold for the features above, are shown only to you, and nothing extra is stored to produce them
- Remembering your display preferences (theme)
4.3 Mining Board Visibility and Website Activity Logging
The Mining Board is available to authenticated members. Other logged-in members may see information needed to coordinate requests, including the requester's Website username, the miner/claimer username where applicable, ore, quality, SCU amount, notes, request status, and relevant dates. Bug reports and print requests are only visible to you and to authorised Website administrators, not to other members.
The Mining Board is part of the Supply Chain. When a miner marks a job as filled, the ore is recorded in the miner's own (private) Supply Chain warehouse at the amount, quality and storage location the miner enters, and the member who requested it is notified with the miner's Website username and those details, including the storage location. The miner can then send the ore to the requesting member's warehouse, and that member is notified again. Jobs posted by a crafter's "Hold: Request Ore" appear under the crafter's Website username, and their notes name the item being crafted and the member who requested it; like all Mining Board jobs, these are visible to every signed-in member.
We also keep a single, site-wide administrator activity log covering actions such as creating, claiming, unclaiming, completing, cancelling, or administratively deleting a mining request, print request, or bug report, an administrator adding, editing, deleting or restoring a guide on the Guides page, adding, editing or deleting a 3D print (its pictures, instructions, files and request box), organising a meet on the Meets page (meets, hotels and events added, changed or removed, and a member's post or photo edited or removed by an administrator), a member asking for a meet photo to be taken down, a SuperAdmin changing who can use which feature (including a feature allowed or blocked for one named member), and an administrator deleting a member's account. Authorised Website administrators can view these logs for moderation, auditing, support, abuse prevention, and maintaining the integrity of the Website. This operational logging is separate from analytics or advertising tracking.
4.4 Pledge Rain Leaderboard Visibility
Pledge Rain keeps two separate leaderboards. The Guest Leaderboard is public and visible to any visitor, signed in or not. The Members Leaderboard, which shows member Website usernames, is only ever included in the data returned to a signed-in member's own request; a signed-out visitor's request never receives it, so member usernames are not disclosed to the public through this feature.
4.5 Supply Chain Visibility
The Supply Chain is only available to signed-in members. Lots you keep in your Warehouse are private. When you own a blueprint, other members viewing that product on the Marketplace can see your Website username and, for each recipe material, only whether your Warehouse holds enough to craft it - never the quantities, qualities or locations of your stock. Lots you share to Distribution, claims, and craft requests show your Website username to the members involved or browsing the board. A reason you give when rejecting a craft request is shown to the member who made the request, and a crafter putting a request on hold notifies that member. If you post a craft request as an Open Request, it is listed on the Open Craft Requests page, where every signed-in member can see your Website username, the item, quantity and quality wanted, your note and any amount you offer, until another member claims it or you cancel it. Members who own that blueprint are notified when it is posted.
Your Task List is private to you. A task you mark "Public" is shown to every signed-in member on the Task List's "All members public tasks" tab, with your Website username, the item and amount, your note and how far along it is, until you finish it, make it private again or remove it. It is never shown to visitors who are not signed in.
The public Blueprints page can be viewed by anyone, signed in or not. It shows the Star Citizen blueprint catalogue and, for each blueprint, only whether at least one Obsidian Squad member has it in their library ("Owned" or "Missing Blueprint"). It never shows which members own a blueprint, how many do, or anything about anyone's stock.
4.6 aUEC Amounts Offered in the Supply Chain
When you request a craft, post a job on the Mining Board, or claim stock from the Distribution board, you may record an amount of aUEC (the in-game currency) that you are offering, and the other member may record a different amount in reply. The Website stores the amount offered, any amount asked for in reply, whether an amount has been agreed, and when.
The Website does not handle money of any kind. It records what members say they will pay and nothing more. No real-world or in-game currency is held, transferred, taken or enforced by the Website, and no payment is ever processed through it. Any actual exchange happens between members inside Star Citizen, and is entirely a matter between them.
Who can see an amount depends on where it was offered. Amounts on the Mining Board and on Distribution claims are shown to members using those boards, because the point of them is to attract someone to the job. An amount on a craft request is shown only to the member who made the request and the member asked to craft it, except on an Open Request, where it is shown to every signed-in member while the request is open. Choosing to offer nothing is not displayed to anyone.
4.7 Meets (In-Person Meetups)
The Meets page is only available to signed-in members. It is never shown to visitors, is not linked from public pages and is kept out of search engines. Only SuperAdmins create meets and enter the meet, hotel, event and airport-to-hotel details; administrators can also edit events and add or remove event photos. Meet photos are shared by administrators and SuperAdmins. Room choices, flights and pickup requests are posted by members about themselves.
What you post, and who sees it. Your room choice (which hotel, and own room, want to share or spare bed), flights you post and pickups you ask for are linked to your account and shown to every signed-in member with your Website username - you cannot post under another name. There is no box for phone numbers or other contact details: members arrange lifts and room shares by messaging each other on the Obsidian Squad Discord. Please post about yourself only, and do not include medical information, booking references, passport or payment details in any note or caption. If you need an accessibility or health-related arrangement, tell an organiser privately rather than posting it. You can change your own room choice, flights and pickup requests while the meet is open, and remove them at any time. SuperAdmins can edit or remove any post or photo, and administrators can remove event photos; when an administrator edits or removes something of yours, that is recorded in the activity log.
Travel details are short-lived. Room choices, flights and pickup requests for a meet are deleted automatically 30 days after the meet ends. The meet itself, the hotel and event details and the photos stay as the meet's members-only archive.
Photos. Meet photos are shared by Obsidian Squad administrators and SuperAdmins, who confirm before uploading that the people in them are happy for them to be shared with members; hotel and event photos are added the same way. Every photo is resized and saved again as a new file when it is uploaded, which removes the hidden information cameras and phones add - including the GPS location where it was taken. Photos are stored in a separate Obsidian Squad folder at IONOS HiDrive (Section 10.4), with a small preview copy on the Website, and they only ever reach your browser through the Website after it has checked you are signed in; no meet photo has a public web address.
Taking a photo down. Anyone signed in - above all anyone who is in a photo - can press "Ask to remove" on it. From that moment only the administrator who shared it and SuperAdmins can see it, and a SuperAdmin then either removes it for good or puts it back. The administrator who shared it is not told who asked. If you are not a member, or cannot sign in, contact us (Section 16) and we will do the same. A photo that is removed - by whoever shared it, a SuperAdmin, an administrator for event photos, or with its hotel, event or meet - is deleted from HiDrive as well; if HiDrive cannot be reached at that moment, the photo is taken off the Website at once and the HiDrive copy is deleted as soon as it can be.
Meet photos stay members-only. Sharing a photo on the Meets page does not allow Obsidian Squad to use it anywhere else. We will not put a meet photo on the public Website or on social media unless the people who can be identified in it have agreed first.
We rely on our legitimate interests (Article 6(1)(f)) in organising our meets and keeping a record of them for members, and have balanced this against your privacy: the page is members-only, it asks for as little as possible, travel details are deleted soon after each meet, photos are cleaned of location data and can be taken down on request, and you can object at any time (Section 8.6). The Meets page keeps nothing in your browser's storage; like any web page, your browser may keep photos you have viewed in its normal cache for up to a day so they load faster, and only on that device.
4.8 Security
- Protecting your account from unauthorised access
- Recording login timestamps to detect suspicious activity
- Maintaining the integrity of our systems and member services
5. Legal Basis for Processing
Under the UK GDPR, we process your data based on the following legal grounds:
5.1 Contract Performance (Article 6(1)(b))
Processing necessary for the performance of a contract with you, including:
- Creating and managing your account
- Providing member services and content
- Processing 3D print requests
- Receiving and resolving bug reports you submit
- Operating Mining Board requests, claims, completed-job archives, and member statistics
- Operating the member Supply Chain (warehouse, blueprints, claims, craft requests, ore orders and notifications)
- Recording and displaying your Pledge Rain Members Leaderboard entry
5.2 Legitimate Interests (Article 6(1)(f))
Processing necessary for our legitimate interests, where those interests are not overridden by your rights and freedoms, including:
- Recording login timestamps for account security
- Recording failed login attempts (as one-way hashes only) to protect accounts from password guessing
- Keeping a site-wide activity log (covering Mining Board, Supply Chain, print request, bug report, and administrative account actions) for administration, moderation, auditing, and abuse prevention
- Showing, on the public Blueprints page, whether the organisation as a whole holds each blueprint (no member is identified)
- Investigating or resolving operational issues and disputes relating to those actions
- Recording and displaying Pledge Rain Guest Leaderboard entries, identified only by a tag generated fresh for that run, for anyone playing the game without an account
- Organising our in-person meets on the members-only Meets page - room choices, flights, airport pickup requests and meet details - and keeping a members-only photo archive of each meet (see Section 4.7)
- Protecting our systems from abuse or unauthorised access
- Improving and maintaining our website
- Counting page views and clicks on our outside links (Discord, RSI, YouTube, Ko-fi) as anonymous daily totals, so we can see which pages and links are used - you can turn this off at any time (see Section 9.4)
5.3 Consent (Article 6(1)(a))
Where you have given consent for specific processing, such as:
- Storing theme preferences in your browser's local storage
- Using a meet photo anywhere other than the members-only Meets page (for example on the public Website or social media) - only with the agreement of the people who can be identified in it (see Section 4.7)
You may withdraw consent at any time by clearing your browser's local storage.
6. Data Storage and Security
6.1 Password Security
- Passwords are hashed using bcrypt (PHP's PASSWORD_DEFAULT algorithm)
- We never store passwords in plain text
- Password hashes are one-way and cannot be reversed
- Repeated failed logins are limited: after 10 failed attempts for one username, or 30 from one connection, within 15 minutes, further logins are paused for up to 15 minutes. To do this we record each failed attempt only as one-way keyed hashes of the username entered and of the connecting IP address, with the time - never the username, IP address or password itself
6.2 Session Security
- Session cookies are marked as HttpOnly (inaccessible to JavaScript)
- Session cookies are marked as Secure (only transmitted over HTTPS)
- Sessions are regenerated after login and password changes
- Sessions expire after a period of inactivity
6.3 Database Security
- All database queries use parameterised statements to prevent SQL injection
- Database access is restricted to authorised systems only
- Discord IDs are stored only as hashed values
6.4 Data Location
Your data is stored on secure servers. We take appropriate technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction.
6.5 Application-Level Security
- State-changing actions (such as submitting a request, updating your account, or an administrative action) require a per-session security token to help prevent forged requests from other websites (cross-site request forgery protection).
- Security-related HTTP headers are applied Website-wide, including a Content Security Policy, to reduce the risk of content injection and clickjacking.
- Third-party gameplay data (see Section 10.3) is cached on our server rather than requested fresh on every page load, reducing unnecessary outbound requests.
7. Data Retention
We retain your personal data as follows:
| Data Type | Retention Period |
|---|---|
| Account Data (username, password hash, Discord ID hash) | Until you delete your account |
| Features allowed or blocked for your account personally (Section 4.1) | Until a SuperAdmin removes the setting, or you delete your account |
| Terms & Privacy review you accepted, and when (Section 14) | Until you delete your account |
| Officer list taken from RSI (handle, display name, country, a copy of the profile picture - see Section 10.5) | Replaced each time the list is refreshed from RSI; an entry is deleted automatically as soon as that person no longer holds an officer rank |
| Failed login attempt records (hashed username entered, hashed IP address, time) | Used for 15 minutes; deleted within 24 hours. Cleared straight away for that username when a login succeeds |
| Print Request Data (including Discord username) | Until you delete your account or request deletion |
| Feedback Data - bug reports and suggestions (record on the Website; any screenshots on IONOS HiDrive) | Until you delete your account, or the report is administratively removed. If you marked another member's report as resolved while an administrator, that report is retained but your admin identity is removed when your account is deleted (see Section 7.1). |
| Mining Board Requests You Create (including notes, status, and timestamps) | Retained while active; completed requests may remain in the archive. Deleted when cancelled, administratively deleted, or when your account is deleted. |
| Your Claims on Other Members' Mining Requests | Retained with the request while your account exists. On account deletion, unfinished claims are released and completed claims are anonymised so your claimant identity is replaced with UNKNOWN. |
| Mining Statistics (jobs completed and SCU delivered) | Until you delete your account |
| Task List | Until you remove a task or delete your account, when your whole list is deleted. |
| Meets - Room Choices, Flights and Pickup Requests | Deleted automatically 30 days after the meet ends, or sooner if you remove them, a SuperAdmin removes them, the hotel a room choice is for is removed from the meet, the meet is deleted, or you delete your account. |
| Meet Photos and Captions (file on IONOS HiDrive, preview and record on the Website) | Kept as the meet's members-only archive until the administrator who shared the photo deletes it, a SuperAdmin removes it (for example after a removal request), an administrator removes an event photo, or the hotel, event or meet it belongs to is removed; the file on HiDrive is deleted at the same time (or as soon as HiDrive can be reached). If you delete your account, photos you shared stay in the archive, no longer linked to you and shown as shared by UNKNOWN - delete them first, or ask us, if you would rather they went too. |
| Photo Removal Requests (who asked, the reason given, when) | Until a SuperAdmin removes the photo or decides to keep it. If you delete your account, a request you made stays in place but no longer records that it was you. |
| Meet, Hotel and Event Details | Kept as the meet's archive until a SuperAdmin removes that hotel or event, or deletes the meet. |
| Supply Chain Warehouse, Blueprint Library, Crafted Log, Import History and Notifications | Until you remove them or delete your account, when they are deleted. |
| Supply Chain Claims, Craft Requests and Ore Orders (including rejection reasons) | Retained as a record of hand-overs and requests while the accounts involved exist. On account deletion, your open claims, requests and ore orders are cancelled, completed ones are anonymised so your identity is replaced with UNKNOWN, and rejection reasons and notification text you wrote are removed. |
| Ore Stored from a Mining Board Job | Kept in the miner's warehouse until the miner sends it to the requesting member or removes it. If the requesting member deletes their account, the ore stays with the miner but is no longer linked to that member. |
| Pledge Rain Members Leaderboard Entry | Until you delete your account. A new run replaces your existing entry rather than adding another one, so at most one entry exists at a time. On account deletion, your user ID is removed and the entry is shown as UNKNOWN (see Section 7.1) rather than deleted, and it is then included only among the public/guest results. |
| Pledge Rain Guest Leaderboard Entries | Not linked to any account, browser, or other identifying information, so there is nothing to delete on request. Retained indefinitely as part of the public leaderboard. |
| Ship Codex Fleet Data | Until you remove those ships or delete your account, when it is deleted. |
| Competition Entries you upload (file on IONOS HiDrive, record on the Website) | The record is kept until you delete your account; uploading again for the same competition replaces it. The file stays on HiDrive until an administrator removes it, which they do once it is no longer needed for the competition, or on request, or after your account is deleted. Entries added to the member vote are shown to members as described on the Competitions page. |
| Website Activity Logs (Mining Board, Supply Chain, competition entry, print request, bug report, and administrative account actions) | Retained for Website administration and audit purposes while linked to active member activity. On account deletion, logs attributable to your account and logs targeting records deleted with your account are removed; known username references in remaining relevant log details are anonymised. A log entry recording only that an administrator carried out an account deletion, and which administrator did so, is retained indefinitely for accountability and never identifies the deleted account. |
| Session Data | Automatically expires after inactivity; cleared on logout |
| Theme Preference, Pledge Rain Personal Best and Counting Opt-Out (localStorage) | Until you clear your browser data |
| Anonymous Page-View and Link-Click Totals (no personal data) | Up to 13 months, then deleted automatically |
Cancelling or administratively deleting a Mining Board request, print request, or bug report removes the request itself, but the fact that the action occurred may remain in the administrator activity log for audit purposes. Such activity-log entries may include limited details such as the action, affected item, usernames involved, and timestamp, but are not used for advertising or cross-site analytics.
7.1 Account Deletion and Anonymisation
When you delete your account, or an administrator deletes it on your behalf, the Website runs a data purge against the active Website database. This process is designed to remove identifying data linked to the deleted account while preserving only non-identifying records that belong to another member.
- Your user account, password hash, hashed Discord ID, and account timestamps are deleted.
- Any feature allowed or blocked for your account personally is deleted. If you were a SuperAdmin who set permissions for others, those settings stay but no longer record that it was you.
- Your print requests, including Discord username and free-form request messages, are deleted.
- Your bug reports, including their free-form description, are deleted.
- All Mining Board requests created by you, including completed/archived requests, are deleted.
- Your Mining Board statistics record is deleted.
- If you currently claim another member's unfinished request, the request is returned to open status and your claimant identity is removed.
- If you completed another member's request, that request may remain in their archive, but your user ID is removed and the claimant username is replaced with UNKNOWN.
- If you marked another member's bug report as resolved while an administrator, that report is retained, but your admin identity is removed and the report is shown as resolved by "an admin".
- If you added, edited or deleted a guide on the Guides page while an administrator, the guide (and any pictures uploaded with it) is retained as organisation content, but your user ID is removed from it and your name on it is replaced with UNKNOWN.
- If you hold a Pledge Rain Members Leaderboard entry, it is retained, but your user ID is removed and it is shown as UNKNOWN; it is then included only among the public/guest results rather than being linked to you.
- Your Supply Chain warehouse, blueprint library, crafted-product log, import history, notifications and ore orders are deleted.
- Your open Supply Chain claims and craft requests (and any material claims and ore orders attached to them) are cancelled; completed claims and requests remain for the other member but your identity is replaced with UNKNOWN, and rejection reasons and notification text you wrote are removed.
- Ore a miner is holding for you stays with the miner but is no longer linked to you; Supply Chain labels that named you (such as "From", "Built by" or "Crafted for" locations and "requested by" notes on Mining Board jobs) are changed to UNKNOWN.
- Your Ship Codex fleet (the ships you recorded as owning) is deleted, so you no longer appear on the Org Fleet page.
- Your Meets room choices, flights and pickup requests are deleted. Meet photos you shared stay in the meet's members-only archive, no longer linked to your account and shown as shared by UNKNOWN. Any photo removal request you made stays in place but no longer records that it was you.
- Your competition entry records and bug report screenshot records are deleted. Entry files and screenshots stored with IONOS HiDrive are not removed automatically; an administrator deletes them from HiDrive after your account is deleted.
- Activity-log rows created by your account, and log rows targeting records removed with your account, are deleted.
- Known Website username references associated with you are replaced with UNKNOWN in remaining relevant activity-log details.
- We do not create a new identifying activity-log entry merely to record that your account was deleted. Where an administrator carries out the deletion on your behalf, a separate entry records only that an administrator performed a deletion and which administrator did so - it does not name, number, or otherwise identify your account.
8. Your Rights Under GDPR
Under the UK GDPR, you have the following rights regarding your personal data:
8.1 Right of Access (Article 15)
You have the right to request a copy of the personal data we hold about you. To exercise this right, contact us at info@obsidiansquad.com.
8.2 Right to Rectification (Article 16)
You have the right to request correction of inaccurate personal data. You can update your username directly through your Account page.
8.3 Right to Erasure (Article 17)
You have the right to request deletion of your personal data. You can delete your account at any time through the Account page. Account deletion removes your identifying data from the active Website database as described in Section 7.1. A completed Mining Board request owned by another member may remain in anonymised form, with your claimant identity removed and replaced with UNKNOWN.
8.4 Right to Restrict Processing (Article 18)
You have the right to request restriction of processing in certain circumstances. Contact us to exercise this right.
8.5 Right to Data Portability (Article 20)
You have the right to receive your personal data in a structured, commonly used, machine-readable format. Contact us to request a data export.
8.6 Right to Object (Article 21)
You have the right to object to processing based on legitimate interests. Contact us to exercise this right.
8.7 Right to Withdraw Consent
Where we process data based on consent, you may withdraw that consent at any time. This does not affect the lawfulness of processing before withdrawal.
8.8 Exercising Your Rights
To exercise any of these rights, please contact us at info@obsidiansquad.com. We will respond to your request within one month.
9. Cookies and Local Storage
9.1 Session Cookies
We use essential session cookies to maintain your login state. These cookies are:
- Strictly necessary for the website to function
- HttpOnly - cannot be accessed by JavaScript
- Secure - only transmitted over HTTPS
If we have asked members to review our Terms and this Privacy Policy (Section 14) and you have not yet done so, we also set a small os_policy_review cookie while you are logged in. It contains only the value "1", tells the page to show the review notice, is removed once you accept (or when you close your browser), and is strictly necessary for that notice to work.
9.2 Local Storage
We use your browser's local storage to remember your theme preference (blue or red theme), if you play Pledge Rain, your personal best score on that device, and, if you turn it off, that your visits should not be counted (Section 9.4). This data:
- Is stored only in your browser, not on our servers
- Contains only the theme value ("alt" or "default"), a single number (your Pledge Rain best) and, if set, an on/off counting choice
- Can be cleared by clearing your browser data
- Is not transmitted to us or any third party
9.3 No Tracking Cookies
We do NOT use:
- Google Analytics or any other third-party analytics
- Advertising or marketing cookies
- Social media tracking pixels
- Third-party tracking cookies of any kind
9.4 Anonymous Page and Link Counts
To see which pages and links are actually used, the Website keeps simple daily totals: how many times each page was viewed, and how many times each of our outside links (Discord, Roberts Space Industries, our referral code, YouTube and Ko-fi) was clicked, split only into "logged in" and "not logged in".
- Only the date, the page or link, logged in or not, and a running total are stored
- No IP address, cookie, device or browser details, or user ID is stored with these counts, so they cannot be linked to you
- No cookie or other data is placed on your device for counting
- The totals are visible only to Website administrators and are kept for up to 13 months
Turning counting off. You don't have to be counted. Nothing is counted when your browser sends a "Do Not Track" or "Global Privacy Control" signal, or you can turn counting off for this browser with the button below. That choice is remembered in your browser's local storage (as a single on/off setting, which is never sent to us) until you turn it back on or clear your browser data. Turning counting off makes no difference to how the Website works.
Counting on this browser: checking...
10. Third-Party Services
10.1 Discord
We use Discord for authentication and membership verification. When you authenticate with Discord, your data is subject to Discord's Privacy Policy.
10.2 CloudFlare CDN
We use CloudFlare's Content Delivery Network to serve Font Awesome icons. This is a static resource that does not involve personal data processing by Obsidian Squad. See CloudFlare's Privacy Policy for more information.
10.3 UEX, FleetYards and Star Citizen Wiki
Several features - the Mining Board, the Supply Chain, the Blueprints page, the Retrofitter, the Ship Codex / Org Fleet pages and the Trade Ledger / Trade Routes pages - retrieve gameplay information such as commodity, refinery, scan-signature, blueprint, material, location and ship data (including ship images) from UEX, FleetYards and the Star Citizen Wiki. These requests are made by our Website server using fixed service requests and are not designed to send your Website username, request content, Supply Chain data, or activity-log data to those services. Their own privacy policies and service practices apply to their systems.
To reduce the number of requests made to these services, responses are cached on our server and refreshed periodically - from every thirty minutes for trade data up to once a day for the blueprint catalogue, and up to seven days for where-to-find-a-blueprint information. This cached data is general gameplay/commodity information only and is not linked to your account or any other member.
10.4 IONOS HiDrive (competition entries, bug report screenshots and meet photos)
Images and videos you upload as competition entries, and screenshots you attach to bug reports and suggestions, are passed straight on by our Website server to Obsidian Squad storage folders at IONOS HiDrive and are not kept on the Website. Only Obsidian Squad administrators can see those folders. IONOS stores the files on our behalf; see IONOS's Privacy Policy.
Meet photos, including hotel and event photos (Section 4.7), are kept in a separate Obsidian Squad folder at IONOS HiDrive that is used for nothing else. Unlike the competition and bug report folders, our Website server also reads photos back from this folder to show them to signed-in members, and deletes a photo from it when the photo is removed. The access key for the folder stays on our server and is never sent to your browser. Only the Website and Obsidian Squad SuperAdmins can reach the folder.
10.5 Roberts Space Industries (Officers page)
The Officers page shows the people holding an officer rank in our organisation on Roberts Space Industries. Once a day - and when an administrator asks for it sooner - our server reads our organisation's public member list on RSI and, for those members only, records their RSI handle, the display name shown beside it, the country listed on their public RSI profile, and a copy of their RSI profile picture (with its web address). Everything stored comes from what that person has chosen to show publicly on RSI, and it is not linked to any Website account: an officer does not need an account here, and having one changes nothing.
We do this on the basis of our legitimate interests (Article 6(1)(f)) - telling members and visitors who to approach for help, without an administrator maintaining the list by hand. Because the list is rebuilt from RSI each time, an entry disappears by itself once the person no longer holds an officer rank, and a detail hidden on their RSI profile stops being shown here at the next refresh. If you are listed and would rather not be, contact us (Section 16) or see your right to object in Section 8.6, and we will remove your entry.
The profile picture is downloaded by our server and shown from this Website, so your browser does not connect to RSI when you view the Officers page. A changed or removed picture is replaced at the next refresh; an officer with no picture on RSI is shown with a default image. Roberts Space Industries is an independent service; their own privacy policy applies to their systems.
11. International Data Transfers
Discord is based in the United States. When you authenticate with Discord, your Discord User ID may be processed in the US. Discord has implemented appropriate safeguards for international data transfers.
12. Children's Privacy
Our website is not intended for children under 18 years of age. We do not knowingly collect personal data from children under 18. If you believe we have collected data from a child under 18, please contact us immediately at info@obsidiansquad.com.
13. Data Breaches
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will:
- Notify the Information Commissioner's Office (ICO) within 72 hours where required
- Notify affected users without undue delay if the breach is likely to result in high risk
- Document the breach and actions taken
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated "Last Updated" date. We encourage you to review this Privacy Policy periodically.
For significant changes that materially affect your rights, we will make reasonable efforts to notify you (e.g., via the website or Discord announcements).
We may also ask every member to review this Privacy Policy and our Terms & Conditions again. You will see a notice the next time you use the Website while logged in, and member features stay unavailable until you confirm you have read and understood both. We record on your account which review you accepted and when, plus an entry in our activity log, so we can show that you were told about the change. This record is kept until you delete your account.
15. Complaints
If you are not satisfied with how we handle your personal data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):
- Website: https://ico.org.uk
- Telephone: 0303 123 1113
We encourage you to contact us first at info@obsidiansquad.com so we can try to resolve your concerns.
16. Contact Us
If you have any questions about this Privacy Policy, your personal data, or wish to exercise your rights, please contact us:
- Email: info@obsidiansquad.com
- Discord: Obsidian Squad Discord Server