1. Who we are
Engagerly is operated by Botorium Ltd, a company incorporated in the United Kingdom ("Botorium", "we", "us" or "our"). For the purposes of the UK General Data Protection Regulation (UK GDPR), the EU General Data Protection Regulation (EU GDPR) where it applies, and similar laws, Botorium is the controller of the personal data described in this policy, except where section 2 says we act on behalf of server admins.
You can contact us about privacy in our official Discord server at https://support.engagerly.bot or by email at support@engagerly.bot.
2. Our role: controller and processor
We are the controller for data we use for our own purposes, including dashboard accounts and sign-in, purchases, billing, invoices and refunds, support, security and fraud prevention, linked wallets and social accounts (which work across all servers), our website, and improving the Service.
When a server's owners and admins use Engagerly to run their community, they decide which features to use and how member data is used in their server, such as which tasks, rewards, shops and giveaways exist and who can see or export results. For that community data we act mainly on behalf of the server's admins, as their processor or service provider, and the server's admins are responsible for their own use of it, including any data they export. If you are a member with questions about how a particular community uses your data, please contact that server's admins first. We will help them respond where needed.
We may also use community data as an independent controller for limited purposes of our own, such as keeping the Service secure, preventing abuse, deciding refund eligibility, meeting legal obligations and producing aggregated statistics that do not identify individuals.
3. Data we collect
The data we process depends on how you use Engagerly. Engagerly does not request Discord's privileged Message Content access and does not store the text of ordinary chat messages. We collect:
- Discord profile data: your Discord user ID, username, display name and avatar, and for servers using Engagerly, server and channel IDs and names, roles and membership details such as when you joined or left.
- Activity data in servers using Engagerly: counts and timings of messages, reactions and voice activity, invites (who invited whom), server boosts, and interactions with the bot such as commands, button clicks and form responses.
- Engagement records: points and currency balances, XP and levels, task and quest completions, check-ins, giveaway entries and winners, drops, games, coupon and code redemptions, leaderboard positions, and shop orders, including any notes you enter at checkout and the files or codes delivered to you.
- Linked accounts: blockchain wallet addresses (EVM, Solana and Bitcoin) that you verify by signing a message; we never ask for private keys or transaction approvals. For X, your account ID, handle, account creation date and the access tokens issued when you connect, which we store encrypted. For Bluesky, your DID, handle and account creation date; the app password you enter is used once to verify the account and is not stored.
- Social activity data: public information from X and Bluesky needed to verify social quests and run post trackers, such as follows, likes, reposts, replies and post metrics.
- Dashboard account data: when you sign in with Discord, your Discord profile, the list of servers you belong to or manage (to show which servers you can manage), and your email address if Discord provides it, which we store encrypted. We also keep records of changes admins make (who changed what and when), notification settings, team permissions and developer API key details (keys are stored in hashed form).
- Purchase data: what was bought, for which server, price, tax, invoice details, order and refund history, and auto-renew or auto-recharge settings and consent records. Card payments are handled by Stripe. We keep Stripe references, such as customer and saved payment method IDs for auto-renew and auto-recharge, but we never see or store your full card number. For USDC payments, the network, transaction hash, sending wallet address and any refund address you give us.
- Brand bot data: if you connect your own Discord bot application, its application ID and token, which we store encrypted and delete when the bot is disconnected.
- Support data: messages and information you share when you contact us in Discord or by email.
- Technical and website data: IP address, browser and device information, and request logs created when you use the dashboard, API or website; and, if you allow analytics cookies, website usage data as described in our Cookie Policy.
4. How we use data
We use personal data to:
- Provide the Service: run bot features, calculate points, levels and rankings, verify tasks and social quests, deliver rewards and shop items, run giveaways and show analytics to server admins.
- Operate your account and the dashboard, including sign-in, permissions and team access.
- Process purchases, sponsorships, redemption codes, auto-renew, invoices, taxes and refunds, including checking whether a plan has been used when you ask for a refund.
- Send service messages, such as plan expiry reminders, billing receipts and security notices, by Discord direct message, in your server's log channel, in the dashboard or by email.
- Keep the Service and communities secure: prevent fraud, spam, reward farming and abuse, enforce our terms, and screen crypto payments against sanctions lists.
- Provide support and respond to your requests.
- Understand and improve the Service, using aggregated or de-identified data where possible.
- Comply with legal, tax and accounting obligations and establish, exercise or defend legal claims.
5. Legal bases
Under UK and EU data protection law we rely on the following legal bases:
- Contract: to provide the Service you or your server signed up for, process purchases and provide support.
- Legitimate interests: to run community features for servers that use Engagerly, keep the Service secure, prevent fraud and abuse, improve the Service and communicate with admins about their servers. We balance these interests against your rights and you can object at any time (see section 12).
- Consent: for optional website analytics cookies, for connecting optional accounts such as wallets, X and Bluesky, for joining our official Discord server at sign-in, and for auto-renew and auto-recharge charges. You can withdraw consent at any time; this does not affect processing that already took place.
- Legal obligation: to keep financial records, meet tax obligations, carry out sanctions screening and respond to lawful requests.
6. What server admins and members can see
Server admins and team members they authorise can see information about members' activity in their server through the dashboard and bot, such as balances, task completions, giveaway entries, shop orders and buyer notes, and analytics. Some features let admins export data, such as giveaway entrants or shop orders, which can include Discord names and IDs and wallet addresses provided for that feature.
Leaderboards, rank cards, giveaway winners, sponsorship announcements and similar features may show your Discord name, avatar and results to other members of the server. Sponsors can choose to sponsor anonymously.
Linked wallets and social accounts are global to your Engagerly account, so communities you take part in can use them for features that require them, such as wallet-gated giveaways, shop items that need a wallet address, or social quests. You can view and unlink them at any time with the /link command.
8. Payments and blockchain data
Card payments are processed by Stripe, which acts as an independent controller for some payment data under its own privacy policy. Stripe may use your data for fraud prevention and to meet its legal obligations.
USDC payments are made on public blockchains. Transaction details, including wallet addresses and amounts, are publicly visible and permanent, and we cannot change or delete them. We match payments to orders by amount, may check sending addresses against sanctions lists, and keep a record of the transaction for accounting and refunds.
9. International transfers
We are based in the UK, and our users and service providers are located around the world. Some providers, including Discord, Stripe, Google and Cloudflare, may process data in the United States and other countries outside the UK and European Economic Area.
When we transfer personal data internationally, we use a lawful transfer mechanism, such as UK or EU adequacy regulations or decisions, the UK International Data Transfer Agreement or Addendum, or the EU Standard Contractual Clauses, together with additional safeguards where appropriate.
10. How long we keep data
We keep personal data only for as long as we need it for the purposes in this policy. In particular:
- Community data is kept while the server uses Engagerly. When the bot is removed from a server, we delete that server's community data about 30 days later, which gives admins time to add the bot back without losing their setup. We keep limited records after that, such as basic server identifiers and the purchase, refund and audit records described below.
- Aggregated analytics are kept for the retention period of the server's plan (90 days on Free and Premium, 365 days on Ultimate) and then deleted.
- Linked wallets and social accounts are kept until you unlink them. When you unlink X, we also revoke the stored access token.
- Brand bot tokens are deleted when the bot is disconnected or the add-on is refunded.
- Download links for shop files expire a few minutes after they are issued.
- Purchase, invoice, refund and related usage records, and records needed for security and audit, are kept for as long as required by tax, accounting and other legal obligations, and to deal with disputes, even after a server stops using Engagerly.
- Support messages and technical logs are kept for as long as needed to resolve the issue and protect the Service, and then deleted or anonymised.
11. Security
We use technical and organisational measures to protect personal data, including encryption in transit, encryption at rest for sensitive data such as linked account tokens, email addresses and brand bot tokens, hashed API keys, signature-only wallet verification, role-based access controls, and audit logs of admin changes.
No method of transmission or storage is completely secure. If we become aware of a personal data breach that affects you, we will notify you and the relevant authorities where the law requires it. If you find a security issue, please report it privately to our team in the official Discord server.
12. Your rights
Depending on where you live, you may have the right to:
- Access the personal data we hold about you and receive a copy.
- Correct inaccurate or incomplete data.
- Ask us to delete your data.
- Restrict or object to our processing, including processing based on legitimate interests.
- Receive data you gave us in a portable format.
- Withdraw consent at any time where we rely on consent.
- Complain to a data protection authority. In the UK, this is the Information Commissioner's Office (ico.org.uk). If you are in the EU, you can contact the authority in your country.
13. How to exercise your rights
You can unlink wallets and social accounts yourself with the /link command, and server admins can delete most community content in the dashboard. For other requests, contact us in our official Discord server or at support@engagerly.bot. We may need to verify your identity, for example by confirming control of your Discord account, before acting on a request.
We will respond within one month, or longer where the law allows. If your request concerns community data that we process for a server's admins, we may pass it to them or ask them to handle it. Some data may need to be kept even after a deletion request, for example purchase records we must keep by law.
14. Children
Engagerly is not intended for anyone below Discord's minimum age, which is at least 13 and higher in some countries. We do not knowingly collect personal data from children below that age. If you believe a child has provided us with personal data in breach of this, contact us and we will delete it.
15. Changes to this policy
We may update this policy from time to time. We will post the updated version on this page and change the "Last updated" date. If the changes are significant, we will give notice through the website, the dashboard or our Discord server.
For information about cookies and similar technologies on our website and dashboard, see our Cookie Policy.
Questions about these policies? Email support@engagerly.bot or ask our team in the official Discord server: support.engagerly.bot