← Back to LW CMS Pro
Privacy Policy
Last Updated: September 12, 2026
This Privacy Policy describes how LW CMS Pro ("the Service", "we", "us", "our") collects, uses, stores, and protects information when you use our web platform, the LW-CMS Discord Bot ("the Bot"), or any associated services.
By using LW CMS Pro, you consent to the data practices described in this policy.
1. Information We Collect
1.1 Information You Provide Directly
- Account information: Commander name/tag, Discord username, alliance name, and server number (provided during license checkout or account setup)
- Bot configuration: Custom bot nicknames, uploaded avatar images, Discord Server IDs, and channel selections
- Announcements: Message content, titles, and image attachments you compose through the broadcaster
- LOA requests: Leave of absence dates, reasons, and member identifiers
1.2 Information Collected Automatically
- Alliance game statistics: Member power levels, kill counts, and Total Hero Power (THP) scores, ingested via user screenshot OCR analysis, CSV roster uploads, or community data APIs
- Discord OAuth2 data: When you log in via Discord, we receive your Discord user ID, username, avatar, and server role memberships (as authorized by Discord's OAuth2 scope)
- Usage analytics: Page views, referrer URLs, browser user-agent, IP addresses, and session timestamps for traffic monitoring and security
1.3 Information the Discord Bot Accesses
When the LW-CMS Bot is invited to your Discord server, it may access:
| Data Type |
Purpose |
Stored? |
| Server member list (usernames, IDs, roles) |
Role-based login authentication, leaderboard display, @ mention autocomplete |
Cached temporarily |
| Server roles |
OAuth2 role-gated portal access |
Cached temporarily |
| Text channel list |
Channel selection for scheduled announcements and roster reports |
Selected channel ID only |
| Server ID and guild metadata |
Multi-tenant portal isolation |
Yes (settings database) |
| Message content in designated channels |
Slash command responses and broadcaster dispatch |
No |
The Bot does NOT:
- Read, log, or store private/direct messages
- Access channels it has not been explicitly granted permission to
- Monitor voice channels or voice activity
- Collect payment information, email addresses, or phone numbers via Discord
2. How We Use Your Information
- Service delivery: To provide alliance tracking, leaderboard generation, roster reports, and scheduled Discord announcements
- Authentication: To verify your identity via Discord OAuth2 and enforce role-based access
- License management: To process license orders, deliver activation keys, and manage subscription status
- Security: To detect abuse, prevent unauthorized access, and enforce rate limits (IP-based)
- Improvement: To analyze aggregate usage patterns and improve the Service
3. Data Storage & Security
- All alliance data is stored in isolated, per-tenant databases. Each alliance portal has its own separate database — your data is never mixed with another alliance's data.
- Data is hosted on secured servers with SSL/TLS encryption (HTTPS enforced via Cloudflare).
- Database access is restricted to authenticated application processes only.
- Uploaded images (bot avatars, announcement attachments) are stored on the web server. One-time announcement images are automatically deleted after 7 days.
- We implement industry-standard security practices including CSRF protection, prepared SQL statements, input sanitization, and IP-based rate limiting.
4. Data Sharing & Third Parties
We do not sell, rent, trade, or share your personal data or alliance data with any third parties, except:
- Discord API: We interact with Discord's API to provide bot functionality (sending messages, fetching roles/members). This interaction is governed by Discord's Privacy Policy.
- Hosting providers: Our servers are hosted by third-party infrastructure providers who may process data on our behalf under strict contractual obligations.
- Legal requirements: We may disclose data if required by law, court order, or governmental authority.
5. Data Retention
- Active accounts: Data is retained for as long as your license is active and the portal is in use.
- Expired licenses: Alliance data is retained for 30 days after license expiration to allow for renewal. After 30 days, data may be permanently deleted.
- Bot removal: If you remove the Bot from your Discord server, cached server data (members, roles, channels) is discarded immediately. Portal data is retained per the license retention policy above.
- Analytics data: Traffic logs and IP-based analytics are retained for up to 90 days for security monitoring purposes.
6. Your Rights
Depending on your jurisdiction (including but not limited to GDPR for EU/EEA residents), you may have the right to:
- Access: Request a copy of the personal data we hold about you
- Rectification: Request correction of inaccurate data
- Erasure: Request deletion of your personal data ("right to be forgotten")
- Portability: Request your data in a structured, machine-readable format
- Objection: Object to processing of your data for certain purposes
- Withdraw consent: Revoke any previously granted consent at any time
To exercise any of these rights, contact us via our Discord support channel.
7. Children's Privacy
LW CMS Pro is not directed to children under the age of 13 (or the applicable minimum age in your jurisdiction). We do not knowingly collect personal information from children. If you believe we have inadvertently collected data from a child, please contact us immediately so we can delete it.
8. Cookies & Local Storage
- The Service uses PHP session cookies for authentication and CSRF protection. These are essential for the platform to function and cannot be disabled.
- We do not use third-party advertising cookies or tracking pixels.
- Analytics are processed server-side; no client-side tracking scripts from third-party providers are used.
9. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via our Discord server or a prominent notice on the platform. Your continued use of the Service after changes constitutes acceptance of the updated policy.
10. Contact
If you have any questions, concerns, or requests regarding this Privacy Policy or your data, please contact us through our official Discord community by opening a support ticket.