Privacy Policy
This policy explains what personal data FiveStatus collects, why we collect it, who we share it with, and what rights you have. It also explains — in section 4 — the categories of data we deliberately refuse to collect, which is unusual enough to be worth reading first.
Who we are
FiveStatus is operated by Hydra Labs, which is the data controller for the personal data described in this policy.
Hydra Labs — registered company details and address to be confirmed before launch.
You can reach us on Discord at discord.gg/hydralabs or by email at privacy@fivestatus.com.
Who this policy covers
This policy applies to three groups of people:
- Account holders — server owners and their team members who sign in to FiveStatus.
- Subscribers — people who ask to be notified about a status page by email or Discord DM.
- Visitors — anyone who views a public status page or this website.
Where an organisation invites team members, that organisation and Hydra Labs each act as controller for different aspects of the data: we control the account data needed to run the service, and the organisation controls the content it publishes.
What we collect
If you have an account
| Data | Where it comes from |
|---|---|
| Discord user ID, username and avatar | Discord, when you sign in |
| Email address | Discord, or from you if you register with a password |
| Password (stored only as a hash) | From you, if you choose that sign-in method |
| Discord access and refresh tokens (encrypted at rest) | Discord, so the bot and role sync can work |
| Which Discord guilds you belong to, and your roles in the guild you connect | Discord, with your consent at sign-in |
| Your organisation, role, and who invited you | Created within the service |
| Audit records of actions you take — incidents, changelog posts, settings and team changes — with your user ID, a timestamp and your IP address | Recorded as you use the dashboard |
About the servers you connect
Server addresses, join codes, hostnames, game types, maps, banner images and other configuration values your server publishes; and for every check, whether it responded, how quickly, the number of connected players, the configured maximum, and any queue length your framework exposes.
Some of this may be personal data if you have named your server after yourself or included personal details in its configuration. That is within your control.
If you subscribe to notifications
Your email address and confirmation status, or your Discord user ID if you subscribe through the bot, together with which page you subscribed to and your preferences.
If you visit a page
Server logs recording the request — IP address, time, page requested, referring page and browser user agent — kept for security and troubleshooting. Public status pages set no cookies at all; see our Cookies Policy.
What we deliberately never collect
We do not store anything identifying the players on your server. A FiveM server's players.json endpoint exposes every connected player's name and their licence, Steam, Discord and IP identifiers. We request that endpoint only to count how many entries it contains. The contents are discarded in memory and never written to our database, our logs, our caches or our backups.
We take this position for three reasons:
- those identifiers are other people's personal data, and the players concerned have no relationship with us and no way to exercise their rights over data they do not know we hold;
- a database of who plays where would be worth stealing, and the safest way to protect data is not to have it;
- publishing who is connected to a server right now is a stalking and harassment vector, whatever the intent behind the feature.
The raw responses we store for troubleshooting are passed through a filter that removes player arrays and identifier fields at every level before anything is written. This is enforced by automated tests, not by convention.
We also strip your server's licence key token from anything we store. It is your credential and has no business in our database.
We do not sell personal data, we do not share it with advertisers, and we do not use third-party advertising or analytics trackers.
Why we use it, and our lawful bases
Where UK and EU data protection law applies, we rely on the following lawful bases:
| What we do | Lawful basis |
|---|---|
| Create and run your account, publish your status page, monitor your servers | Performance of a contract with you |
| Send service emails — confirmations, password resets, notices about the service | Performance of a contract |
| Send incident notifications you asked for | Consent, which you can withdraw at any time |
| Post to your Discord guild and sync roles | Performance of a contract, on the instruction of the organisation |
| Keep audit records of who changed what | Legitimate interests — accountability within a shared account, and security |
| Keep server logs, apply rate limits, prevent abuse | Legitimate interests — keeping the service secure and available |
| Understand aggregate usage to improve the product | Legitimate interests — improving a service you use |
| Respond to legal requests and enforce our terms | Legal obligation, or legitimate interests |
Where we rely on legitimate interests we have considered the impact on you and concluded that our interest does not override your rights. You can object to that processing — see section 11.
Data from Discord
Discord sign-in requests three scopes: identify (your user ID, username and avatar), email, and guilds (the list of servers you are in). We ask for all three at sign-in so that connecting the bot and setting up role sync later do not require a second consent screen.
We use the guild list only to show you which of your Discord servers you can connect. We do not read your messages, and the bot does not request permission to do so.
If your organisation maps Discord roles to FiveStatus roles, we periodically ask Discord which roles a member holds in that one guild, in order to grant or remove access. We record the outcome — that a role was granted or removed, and which mapped role caused it — but not your full role list.
Disconnecting Discord from your account, or removing the bot from your guild, stops this. You can also revoke our access from Discord's own authorised applications settings at any time.
International transfers
Some of our providers are based in the United States or process data there. Where personal data is transferred outside the UK or the European Economic Area, we rely on appropriate safeguards — the UK International Data Transfer Addendum, the EU Standard Contractual Clauses, or an adequacy decision where one applies.
You can ask us for details of the safeguards in place for a particular transfer using the contact details in section 16.
How long we keep it
| Data | Retention |
|---|---|
| Account data | While your account is open, then deleted within 30 days of closure |
| Individual monitoring checks | 400 days, then deleted automatically |
| Daily uptime summaries and status history | While the server exists; deleted when the server is removed |
| Billing records | Kept for as long as tax law requires us to, which in the UK is six years from the end of the accounting period |
| Incidents and changelog entries | Until you delete them, or the organisation is closed |
| Audit records | 12 months |
| Subscriber records | Until you unsubscribe, which deletes the record immediately |
| Unconfirmed subscription requests | Deleted if not confirmed within 30 days |
| Server logs | 30 days |
| Backups | Rolling 30 days, after which deleted data is gone from backups too |
We may keep limited records for longer where we need them to comply with a legal obligation or to establish, exercise or defend a legal claim.
How we protect it
- All traffic is encrypted in transit with TLS.
- Discord access and refresh tokens, and Discord webhook URLs, are encrypted at rest.
- Passwords are stored only as salted hashes and are never recoverable.
- Invitation, subscription confirmation and unsubscribe tokens are stored only as hashes; the usable value exists only in the link we send you.
- Access to production systems is limited to the people who need it.
- Our polling refuses private, loopback and reserved network ranges, so the service cannot be pointed at internal infrastructure.
- Content published through the dashboard is sanitised before it is rendered on a public page.
No system is perfectly secure. If we become aware of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours where required, and tell affected users without undue delay where the risk is high.
Your rights
If you are in the UK or the EEA, you have the following rights over your personal data. We extend the same rights to everyone, wherever you are.
- Access — a copy of the personal data we hold about you.
- Rectification — correction of anything inaccurate or incomplete.
- Erasure — deletion of your data where we no longer need it, or where you withdraw consent we relied on.
- Restriction — to have us pause processing while a dispute is resolved.
- Portability — a machine-readable copy of data you gave us, or its transfer to another provider where technically feasible.
- Objection — to processing based on our legitimate interests, including a right to object at any time to direct marketing.
- Withdraw consent — at any time, where we relied on consent. Withdrawing does not affect processing carried out beforehand.
Most of these you can exercise yourself: your dashboard lets you edit your details, delete servers and their history, delete content, and close your organisation. Every notification email includes a one-click unsubscribe link, and running /subscribe again in Discord removes a DM subscription.
For anything else, contact us at privacy@fivestatus.com. We respond within one month, and will tell you if we need longer because a request is complex. We do not charge for this unless a request is manifestly unfounded or excessive.
Children
FiveStatus is not directed at children. You must be at least 13 to hold an account, or older where local law requires it. We do not knowingly collect personal data from children below that age. If you believe a child has given us personal data, contact us and we will delete it.
Public status pages
A status page is public by design. Anything published on it — the page title, tagline, server names, incident text and changelog posts — can be read by anyone with the link and may be indexed by search engines.
By default we do not show who wrote an incident update. An organisation owner can turn author names on, in which case the display name of the person who posted each update becomes public. If you are a team member and would rather your name were not shown, ask your organisation owner to leave that setting off.
Nothing about the players connected to a monitored server is ever published. Pages show counts only.
Automated decision-making
FiveStatus makes automated decisions about servers — for example, deciding that a server is down and opening an incident, or granting and removing dashboard access based on the Discord roles an organisation has mapped.
Role sync can affect whether you can access an organisation's dashboard. It follows rules the organisation sets, it never removes access that was granted manually, and its outcome can be overridden at any time by the organisation's owner or an admin. We do not carry out profiling or automated decision-making that produces legal effects concerning you.
Changes to this policy
We may update this policy. The version number and date at the top of the page will change, and we will give notice by email or in the dashboard where a change materially affects you. Continuing to use FiveStatus after a change takes effect means you accept the updated policy.
Contact and complaints
For anything about privacy, contact privacy@fivestatus.com, or reach us on Discord at discord.gg/hydralabs.
If you are unhappy with how we have handled your personal data, you can complain to your local data protection authority. In the UK that is the Information Commissioner's Office (ico.org.uk). We would appreciate the chance to put things right first.