FiveStatus
How it works Features Pricing Discord
Start free
How it works Features Pricing Discord Start free

Privacy Policy

Version 1.0 · Last updated 12 August 2026

This policy explains what personal data FiveStatus collects, why we collect it, who we share it with, and what rights you have. It also explains — in section 4 — the categories of data we deliberately refuse to collect, which is unusual enough to be worth reading first.

Contents

  1. Who we are
  2. Who this policy covers
  3. What we collect
  4. What we deliberately never collect
  5. Why we use it, and our lawful bases
  6. Data from Discord
  7. Who we share it with
  8. International transfers
  9. How long we keep it
  10. How we protect it
  11. Your rights
  12. Children
  13. Public status pages
  14. Automated decision-making
  15. Changes to this policy
  16. Contact and complaints

Who we are

FiveStatus is operated by Hydra Labs, which is the data controller for the personal data described in this policy.

Hydra Labs — registered company details and address to be confirmed before launch.

You can reach us on Discord at discord.gg/hydralabs or by email at privacy@fivestatus.com.

Who this policy covers

This policy applies to three groups of people:

  • Account holders — server owners and their team members who sign in to FiveStatus.
  • Subscribers — people who ask to be notified about a status page by email or Discord DM.
  • Visitors — anyone who views a public status page or this website.

Where an organisation invites team members, that organisation and Hydra Labs each act as controller for different aspects of the data: we control the account data needed to run the service, and the organisation controls the content it publishes.

What we collect

If you have an account

Data Where it comes from
Discord user ID, username and avatar Discord, when you sign in
Email address Discord, or from you if you register with a password
Password (stored only as a hash) From you, if you choose that sign-in method
Discord access and refresh tokens (encrypted at rest) Discord, so the bot and role sync can work
Which Discord guilds you belong to, and your roles in the guild you connect Discord, with your consent at sign-in
Your organisation, role, and who invited you Created within the service
Audit records of actions you take — incidents, changelog posts, settings and team changes — with your user ID, a timestamp and your IP address Recorded as you use the dashboard

About the servers you connect

Server addresses, join codes, hostnames, game types, maps, banner images and other configuration values your server publishes; and for every check, whether it responded, how quickly, the number of connected players, the configured maximum, and any queue length your framework exposes.

Some of this may be personal data if you have named your server after yourself or included personal details in its configuration. That is within your control.

If you subscribe to notifications

Your email address and confirmation status, or your Discord user ID if you subscribe through the bot, together with which page you subscribed to and your preferences.

If you visit a page

Server logs recording the request — IP address, time, page requested, referring page and browser user agent — kept for security and troubleshooting. Public status pages set no cookies at all; see our Cookies Policy.

What we deliberately never collect

We do not store anything identifying the players on your server. A FiveM server's players.json endpoint exposes every connected player's name and their licence, Steam, Discord and IP identifiers. We request that endpoint only to count how many entries it contains. The contents are discarded in memory and never written to our database, our logs, our caches or our backups.

We take this position for three reasons:

  1. those identifiers are other people's personal data, and the players concerned have no relationship with us and no way to exercise their rights over data they do not know we hold;
  2. a database of who plays where would be worth stealing, and the safest way to protect data is not to have it;
  3. publishing who is connected to a server right now is a stalking and harassment vector, whatever the intent behind the feature.

The raw responses we store for troubleshooting are passed through a filter that removes player arrays and identifier fields at every level before anything is written. This is enforced by automated tests, not by convention.

We also strip your server's licence key token from anything we store. It is your credential and has no business in our database.

We do not sell personal data, we do not share it with advertisers, and we do not use third-party advertising or analytics trackers.

Why we use it, and our lawful bases

Where UK and EU data protection law applies, we rely on the following lawful bases:

What we do Lawful basis
Create and run your account, publish your status page, monitor your servers Performance of a contract with you
Send service emails — confirmations, password resets, notices about the service Performance of a contract
Send incident notifications you asked for Consent, which you can withdraw at any time
Post to your Discord guild and sync roles Performance of a contract, on the instruction of the organisation
Keep audit records of who changed what Legitimate interests — accountability within a shared account, and security
Keep server logs, apply rate limits, prevent abuse Legitimate interests — keeping the service secure and available
Understand aggregate usage to improve the product Legitimate interests — improving a service you use
Respond to legal requests and enforce our terms Legal obligation, or legitimate interests

Where we rely on legitimate interests we have considered the impact on you and concluded that our interest does not override your rights. You can object to that processing — see section 11.

Data from Discord

Discord sign-in requests three scopes: identify (your user ID, username and avatar), email, and guilds (the list of servers you are in). We ask for all three at sign-in so that connecting the bot and setting up role sync later do not require a second consent screen.

We use the guild list only to show you which of your Discord servers you can connect. We do not read your messages, and the bot does not request permission to do so.

If your organisation maps Discord roles to FiveStatus roles, we periodically ask Discord which roles a member holds in that one guild, in order to grant or remove access. We record the outcome — that a role was granted or removed, and which mapped role caused it — but not your full role list.

Disconnecting Discord from your account, or removing the bot from your guild, stops this. You can also revoke our access from Discord's own authorised applications settings at any time.

Who we share it with

We share personal data only with providers who process it on our behalf, under contract, and only as far as needed to run the service:

Processor Purpose Data involved
Railway Application hosting, database, queues All stored data
Cloudflare Object storage and content delivery Uploaded images; visitor IP addresses in transit
Resend Sending email Email addresses and message contents
Discord Sign-in, bot posts, DMs, role sync Discord user and guild identifiers, message contents
Cfx.re Resolving join codes to server addresses The join code you provide — no personal data of yours
Stripe Taking payment for Pro subscriptions Name, email and billing address you enter at checkout, and your payment details, which go to Stripe directly and are never received or stored by us

We may also disclose personal data where we are required to by law, court order or a valid request from a public authority, or where it is necessary to establish, exercise or defend legal claims. If we are ever involved in a merger, acquisition or sale of assets, personal data may transfer to the buyer, and we will tell you before it does and explain your options.

International transfers

Some of our providers are based in the United States or process data there. Where personal data is transferred outside the UK or the European Economic Area, we rely on appropriate safeguards — the UK International Data Transfer Addendum, the EU Standard Contractual Clauses, or an adequacy decision where one applies.

You can ask us for details of the safeguards in place for a particular transfer using the contact details in section 16.

How long we keep it

Data Retention
Account data While your account is open, then deleted within 30 days of closure
Individual monitoring checks 400 days, then deleted automatically
Daily uptime summaries and status history While the server exists; deleted when the server is removed
Billing records Kept for as long as tax law requires us to, which in the UK is six years from the end of the accounting period
Incidents and changelog entries Until you delete them, or the organisation is closed
Audit records 12 months
Subscriber records Until you unsubscribe, which deletes the record immediately
Unconfirmed subscription requests Deleted if not confirmed within 30 days
Server logs 30 days
Backups Rolling 30 days, after which deleted data is gone from backups too

We may keep limited records for longer where we need them to comply with a legal obligation or to establish, exercise or defend a legal claim.

How we protect it

  • All traffic is encrypted in transit with TLS.
  • Discord access and refresh tokens, and Discord webhook URLs, are encrypted at rest.
  • Passwords are stored only as salted hashes and are never recoverable.
  • Invitation, subscription confirmation and unsubscribe tokens are stored only as hashes; the usable value exists only in the link we send you.
  • Access to production systems is limited to the people who need it.
  • Our polling refuses private, loopback and reserved network ranges, so the service cannot be pointed at internal infrastructure.
  • Content published through the dashboard is sanitised before it is rendered on a public page.

No system is perfectly secure. If we become aware of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours where required, and tell affected users without undue delay where the risk is high.

Your rights

If you are in the UK or the EEA, you have the following rights over your personal data. We extend the same rights to everyone, wherever you are.

  • Access — a copy of the personal data we hold about you.
  • Rectification — correction of anything inaccurate or incomplete.
  • Erasure — deletion of your data where we no longer need it, or where you withdraw consent we relied on.
  • Restriction — to have us pause processing while a dispute is resolved.
  • Portability — a machine-readable copy of data you gave us, or its transfer to another provider where technically feasible.
  • Objection — to processing based on our legitimate interests, including a right to object at any time to direct marketing.
  • Withdraw consent — at any time, where we relied on consent. Withdrawing does not affect processing carried out beforehand.

Most of these you can exercise yourself: your dashboard lets you edit your details, delete servers and their history, delete content, and close your organisation. Every notification email includes a one-click unsubscribe link, and running /subscribe again in Discord removes a DM subscription.

For anything else, contact us at privacy@fivestatus.com. We respond within one month, and will tell you if we need longer because a request is complex. We do not charge for this unless a request is manifestly unfounded or excessive.

Children

FiveStatus is not directed at children. You must be at least 13 to hold an account, or older where local law requires it. We do not knowingly collect personal data from children below that age. If you believe a child has given us personal data, contact us and we will delete it.

Public status pages

A status page is public by design. Anything published on it — the page title, tagline, server names, incident text and changelog posts — can be read by anyone with the link and may be indexed by search engines.

By default we do not show who wrote an incident update. An organisation owner can turn author names on, in which case the display name of the person who posted each update becomes public. If you are a team member and would rather your name were not shown, ask your organisation owner to leave that setting off.

Nothing about the players connected to a monitored server is ever published. Pages show counts only.

Automated decision-making

FiveStatus makes automated decisions about servers — for example, deciding that a server is down and opening an incident, or granting and removing dashboard access based on the Discord roles an organisation has mapped.

Role sync can affect whether you can access an organisation's dashboard. It follows rules the organisation sets, it never removes access that was granted manually, and its outcome can be overridden at any time by the organisation's owner or an admin. We do not carry out profiling or automated decision-making that produces legal effects concerning you.

Changes to this policy

We may update this policy. The version number and date at the top of the page will change, and we will give notice by email or in the dashboard where a change materially affects you. Continuing to use FiveStatus after a change takes effect means you accept the updated policy.

Contact and complaints

For anything about privacy, contact privacy@fivestatus.com, or reach us on Discord at discord.gg/hydralabs.

If you are unhappy with how we have handled your personal data, you can complain to your local data protection authority. In the UK that is the Information Commissioner's Office (ico.org.uk). We would appreciate the chance to put things right first.

FiveStatus

Status pages for FiveM servers. We poll your server directly, so the page stays right without anyone maintaining it.

Made by Hydra Labs

Product

  • How it works
  • Features
  • Pricing
  • Sign in

More from Hydra Labs

  • FiveM Rosters
  • FiveM Applications
  • Advertise your FiveM Server
  • Join our Discord

Legal

  • Terms & Conditions
  • Privacy Policy
  • Cookies Policy

© 2026 Hydra Labs. FiveStatus is not affiliated with Cfx.re, FiveM, Rockstar Games or Take-Two Interactive.