Privacy
What we hold, why we hold it, and how to get rid of it
The short version
- No analytics. No Google Analytics, no Plausible, no pixels, no third-party scripts. None.
- One cookie,
mg_sid, which keeps you signed in. That is the only one this site sets. - We do not sell your data and never have.
- No advertising, no profiling, no automated decisions that produce legal effects for you.
- We hold your game server's IP addresses if you have a commissioned licence. That one surprises people, so it is spelled out below.
Who we are
Misschevious Development, trading as Misschevious Marketplace, is the controller of the data on this page. We are a sole trader in the United States, working US Eastern hours. Our customers are FiveM server owners worldwide, so UK and EU data protection law and the California privacy laws apply to us regardless of where we sit.
Contact us about anything on this page at privacy@misscheviousmarketplace.com, or by opening a ticket in our Discord. There is no data protection officer; the person who runs the business handles these requests.
What we hold, and why
Your Discord account
Your Discord user ID, your display name, and the roles you hold. This is how we know who you are — there is no separate password to remember or for us to lose. Held to provide the service you asked for.
Your verified email
If you run /verify, we ask Discord for the email address on your account.
We store it encrypted with AES-256-GCM, alongside a keyed hash that
lets us answer "is this address already taken?" without decrypting anything. We record
which version of this notice you agreed to and when. Held on the basis of your consent,
which you can withdraw at any time with /privacy delete.
We never see your Discord password. The access token Discord issues is used once, to read your ID and your email, and is never written to our database.
Your purchases
For anything bought from our Tebex store: the transaction ID, the package, the price and currency, the checkout email, when it happened, whether it was later refunded or disputed, and the payload Tebex sent us. Held to deliver what you paid for, to grant your customer roles, and as a business and tax record.
Support tickets
The ticket you opened, its type and subject, what you typed into the form, anything you attach, the staff notes on it, and a transcript when it closes. Held to support you, and kept afterwards so the next person picking up your problem can see what was already tried.
Commissions
If you commission custom work: your name, email, Discord tag, your server's name, your brief, and your framework and environment details. Where an agreement binds a company rather than you personally, we also record the legal name, the entity type, and who is authorised to sign. Messages between us are stored here and mirrored into your Discord ticket, so both sides see one conversation rather than two.
Signatures, and the evidence behind them
When you sign a document, we record your name, the email it was sent to, the time, the IP address and browser you signed from, and a hash of exactly what was on screen when you signed. Signed PDFs and DocuSign Certificates of Completion are stored on our server.
This is deliberate and we are not going to apologise for it. A signature with no evidence behind it is not worth much to either of us. It is what lets us show what you agreed to, and lets you show what we agreed to.
Licences and your server's IP addresses
Commissioned resources check in with us to confirm they are licensed. That means we hold the IP addresses of the game servers you run them on — the ones you register, plus the address of every check, successful or failed, and the reason any check was refused. Blocked addresses are kept on a blocklist.
We hold this to enforce the licence you bought and to detect a key being shared. If you do not have a commissioned licence, none of this applies to you. Store products bought through Tebex use FiveM's own escrow instead and do not check in with us.
Using this website
When you sign in we store a session record: a random session ID, your Discord ID, the
IP address and browser user-agent you signed in from, and when the
session expires. The matching cookie mg_sid is HttpOnly, SameSite=Lax, and
marked Secure over HTTPS. Held to keep you signed in and to make a stolen session
noticeable.
Incoming webhooks
Every webhook we receive from Tebex or DocuSign is logged in full, including the sending IP address and the whole payload, whether or not it was valid. Held as the audit trail for payment and signature anomalies.
We hold more about you than this page describes — your legal name, address, entity type and the last four digits of a tax identifier, because a 1099 requires them. We never hold a complete tax number. That is a separate relationship from being a customer, so it has its own notice rather than being buried in this one.
Why we are allowed to hold it
- Because you asked us to. Delivering purchases, licences, commissions and support is performing the contract between us.
- Because you consented. Your verified email, which you can withdraw at any time.
- Because we have a legitimate interest. Enforcing licences, investigating leaks and fraud, keeping the site secure, and keeping signature evidence. We think these are fair and expected; if you disagree, you can object.
- Because the law requires it. Tax and accounting records, and responding to a lawful request.
Who else sees it
These are the only companies that handle your data on our behalf:
- Discord — identity, the bot, your tickets and our community.
- Tebex — store checkout and payment. Tebex is the merchant of record and takes your payment details directly; we never see or store card numbers.
- DocuSign — embedded signing for commission documents.
- Resend — outbound email we send you.
- Fastmail — our own mailbox, where anything you send to support@ lands.
- Cloudflare — DNS and the tunnel that sits in front of this site, so it handles every request to it.
- ZAP Hosting — the server everything runs on.
We do not share your data with anyone for marketing, and we do not sell it. Under California law, we do not sell or share personal information, and we have not in the preceding twelve months. The only other disclosure is a valid legal obligation: a lawful request from law enforcement or a court.
Where it goes
Our server is in the United States and so are most of these companies. If you are in the UK or EU, your data is transferred to the US. We rely on the standard contractual clauses our providers offer, and on the UK and EU adequacy decisions for the US where a provider is certified under the Data Privacy Framework.
How long we keep it
Some of this is deleted automatically, by a job that runs every day. The rest is kept until a person removes it. We would rather tell you which is which than publish a schedule our software does not actually run.
Deleted automatically
- Website sessions, with their IP and browser — within an hour of expiring. Sessions last 14 days, or 12 hours for staff.
- Verification links and email link codes — a day after they expire.
- Successful licence checks — after 90 days.
- Failed licence checks — after 12 months. Kept four times longer on purpose: they are the evidence that a licence key is being shared.
- Webhook records, with their payloads and sender IPs — after 12 months, which outlasts the payment disputes they exist to answer.
- Completed role grants and mirrored messages — 30 days after they finish.
Kept until someone removes it
Your account, purchases, tickets, commissions, signed documents, active licences and blocked addresses. These are business and tax records, the evidence behind a signature, or a licence still in force.
We deliberately do not put these on a timer. A schedule that quietly deletes a signed agreement fails at exactly the moment it matters — a dispute, when the record is the only thing either of us has. They come out when a person decides they should, including when you ask.
Tax and accounting records have to be kept for seven years. Nothing deletes them on its own once that has passed, so if you want yours looked at, ask and we will.
What you can remove yourself
Your verified email, with /privacy delete in Discord. That erases the
encrypted address, the lookup hash, your consent record, and any outstanding
verification link, and takes back the Verified role. Your purchases and package
roles are not affected — you keep everything you bought.
Anything else, ask. Some of it we can delete on request; purchase and tax records we have to keep, and a signature we have to be able to prove.
Your rights
If you are in the UK or EU you have all of the following. If you are in California you have the equivalents under the CCPA and CPRA. We apply them to everyone, wherever you live, because running two standards is how mistakes happen.
- Access — a copy of what we hold about you.
- Rectification — correct anything wrong.
- Erasure — delete it, where we do not have to keep it.
- Restriction — tell us to stop using it while something is disputed.
- Portability — get it in a machine-readable form.
- Objection — object to anything we hold on legitimate interests.
- Withdraw consent — for your verified email, any time.
- No discrimination — asking does not cost you service, support or anything you bought.
How to use them: email privacy@misscheviousmarketplace.com, or open a ticket in our Discord if you would rather. Tell us what you want and enough to identify your account. We will answer within 30 days. If we cannot do what you asked, we will tell you why rather than going quiet.
You can complain to your data protection authority — in the UK the Information Commissioner's Office, in the EU your national authority. We would rather you came to us first, but it is your right either way.
Age
You must be 18 or over to buy from us, commission work, hold a licence or hold an account. Discord's own minimum age is 13, and higher in some countries. We do not knowingly collect data from anyone under 16. If you believe a child's data is here, open a ticket and we will remove it.
How it is protected
- Verified emails are encrypted with AES-256-GCM. The database never holds a readable address.
- The lookup hash is keyed, so a database read alone will not tell anyone which addresses we hold.
- Staff passwords are hashed, and staff accounts require an authenticator app.
- Session cookies are HttpOnly and SameSite=Lax, and Secure over HTTPS. Staff sessions expire in 12 hours, customer sessions in 14 days.
- Webhooks are rejected unless their signature verifies.
- The site is server-rendered and loads no third-party scripts, so there is nothing in the page that can quietly read it.
No claim of certification or audit is made here, because we have not had one.
Changes
When this notice changes materially we will post it in our Discord and update the date below. The version you agreed to when you verified your email is recorded against your account, so we can always tell which text applied to you.
Last updated: 30 August 2026.