Skip to main content

Privacy Policy

How beeswarm.trade collects, uses, and protects your data.

Last updated 2026-05-19

Privacy Policy

Effective date: 2026-05-19 Site: https://beeswarm.trade (Bee Swarm Trade, "BST") Controller: Revolution Software LLC, 5441 S Macadam Ave Ste R, Portland, OR 97239, USA Contact: [email protected]


What you should know

  • Sign-in: We use Discord. We receive your Discord ID, username, display name, avatar, and email, and we store Discord session tokens securely so you can stay logged in.
  • What you post: Trade listings, profile bio, and chat messages are stored so the site works. Trade listings and a limited public profile are visible without signing in; bio and full profile history require login. Chat is private between participants; staff may read it when handling a report.
  • No ads or analytics trackers: We do not run ad networks or third-party analytics on the site as of this policy date.
  • Cookies: Two essential cookies for login and session. Details: Cookie Policy.
  • Safety: We keep IP addresses and similar signals to rate-limit abuse (see §9 Security), and we keep moderation records (reports, warnings, staff-only notes) to run the community safely.
  • Optional staff notifications: The team may turn on private internal notifications (for example, new sign-ins or error summaries). Those tools are for operations only—not for advertising. When sign-in notifications are enabled, they may include your email so staff can recognize the account; they are not shown on the public site.
  • Age: BST is for users 13 and older. We do not knowingly collect data from children under 13.
  • Your choices: To ask questions, export data, or request deletion, email [email protected].

Table of contents

  1. Who we are
  2. What we collect
  3. Why we process your data
  4. What is public on BST
  5. Who else sees your data
  6. International transfers
  7. How long we keep data
  8. Your rights
  9. Security
  10. Children
  11. Changes to this policy
  12. Contact

1. Who we are

The data controller for Bee Swarm Trade is Revolution Software LLC, 5441 S Macadam Ave Ste R, Portland, OR 97239, USA. Registered agent: Registered Agents Inc (#757883-99). Email: [email protected].

This policy covers the hosted website and APIs at beeswarm.trade. It does not cover Discord, Roblox, or other platforms you use—each has its own policy.


2. What we collect

Account (Discord): When you authorize Discord, we receive the information Discord sends for sign-in (including email), and we store encrypted OAuth tokens to maintain your session.

Sessions: A random session id in a browser cookie, linked to your account and an expiry (about a week). We store a fingerprint of your browser setup (not the raw browser string) to help detect stolen sessions.

Profile: Bio text you add; trust or safety signals derived from account age and warnings; ban status visible to you and staff.

Trades: Items, quantities, optional notes, optional counterparty Discord id, status, and timestamps. Listings are public.

Chat: Message text, who sent it, timestamps, and read receipts so the app works. No file uploads in chat.

Moderation (staff): Reports, warnings, internal notes, and audit logs of staff actions (which may include staff IP for accountability).

Technical: Your IP address (a number that identifies your internet connection) to stop abuse and keep the site fast. We also keep basic server logs (for example which page was requested) for reliability. We apply usage limits per connection per minute—see the Terms of Service for the current numbers. We do not run ad networks or third-party analytics trackers on the site as of this date.

Sign-in IP (Discord OAuth): When you sign up or log in with Discord, we record the client IP address observed at that moment in a staff-only security table (oauth_auth_ip_events). We use this to investigate account abuse, correlate suspicious sign-ins, and support moderation—not for advertising. Access: authorized staff and automated retention jobs only; it is not shown on your public profile. Retention: raw IPs are kept for up to about 90 days by default (configurable server-side via AUDIT_ANONYMIZE_AFTER_DAYS), then cleared in place by a scheduled anonymizer job. If you delete your account, these rows are removed with your account data.

Trade reviews: You cannot submit new reviews on the current version of the site. Older reviews may still show on profiles if they were saved before reviews were turned off.

Cookies and local storage: See the Cookie Policy. Local-only preferences (theme, etc.) stay in your browser.

Images: Your browser may load item images from other sites (for example wikis or Discord’s CDN). Those sites set their own cookies and policies; we do not proxy those images.


3. Why we process your data

We use this information to run BST: sign-in, profiles, listings, chat, moderation, item values edited by staff, and to keep the service secure and reliable.

If you are in the EU or UK, we rely on: contract (features you ask for), legitimate interests (security, fraud prevention, moderation, limited operational diagnostics—using the minimum needed), legal obligation where required, and consent where that applies. We only use strictly necessary cookies today; if we add optional tracking or similar tools later, we will ask where required.

We do not sell your personal data and do not use it for cross-context behavioral advertising.


4. What is public on BST

Without signing in, anyone can view:

  • Trade listings (items, quantities, status, notes, timestamps, and lister Discord id on the listing). When a lister sets an optional counterparty Discord user id on a public listing, that id may appear on the trade board for anyone browsing open trades.
  • A limited public profile at GET /users/{id}: Discord id, username, avatar, and trade_count only (no bio, email, or staff role).

After you sign in, you can view additional profile fields on GET /users/{id}/profile, including your bio, trust/safety readout, and (where applicable) trade history context. Bio is not included on the anonymous public profile endpoint.

Trust and safety visibility: Anyone (including visitors who are not signed in) may call GET /users/{id}/safety and see a numeric account signal and tier label (for example New, Established, Trusted, Warned, or Banned). Signed-in profile views may show the same tier on badges. Ban status on the full profile endpoint is hidden from non-staff viewers even when the public safety endpoint shows Banned; staff and developers may see moderation fields when signed in.

Not public: your email (used for account-related purposes and optional internal sign-in alerts only—not shown on your profile). Chat is between you, the other person, and staff when resolving a report. Internal staff notes are staff-only (moderators/developers may see them when signed in; other users receive an empty field).

Do not put passwords, real names, addresses, phone numbers, or other sensitive information in your bio, trade notes, or chat.


5. Who else sees your data

  • Discord — sign-in and avatar images; optional private staff Discord channels when operators enable webhooks (see below).
  • Hosting — your data is stored in a secure cloud database and on servers we use to run the site (we commonly use managed database hosting such as Supabase). Email us if you need the exact provider name, region, or a data-processing agreement.
  • Cloudflare — we may use Cloudflare (or similar) to protect the site and speed up pages, depending on how we deploy.

Optional staff-only alerts (not public): Our team may send certain events to private Discord channels used for running the site. Depending on settings, those alerts may include:

  • New sign-ins — may include your email, Discord username, and similar account details so staff can recognize you (never shown on your public profile).
  • Moderation and safety — summaries of reports, warnings, and staff actions.
  • Errors and outages — may include your IP address, which page had a problem, and a reference number to help us fix bugs (not shown on the public site).
  • Backup records — if an alert cannot be delivered, a copy may be saved in a server log file until staff review it.

These are for operating and protecting BST, not for ads. Only authorized staff with access to those channels or log files can see them.

We do not integrate dedicated advertising networks, payment processors, or analytics vendors as of this policy date.


6. International transfers

BST is operated from the United States. If you are in the EU or UK, your data may be processed in the U.S. (and elsewhere our host operates) with appropriate safeguards, such as standard contractual clauses with our providers where applicable.


7. How long we keep data

Unless a shorter period is required by law or you successfully request deletion, we keep data as follows:

Sessions: Up to about seven days, or sooner if you log out or are banned.

Account profile: While your account exists. After a deletion request we remove or anonymize personal data where we can; we may keep a minimal record (for example Discord id and that the account was deleted) for fraud prevention for a reasonable time.

Trade listings: Kept while active and for a period after completion or cancellation so disputes and community history can be understood. We do not publish a fixed automatic deletion schedule for old listings; we may delete or anonymize very old listings when storage or policy requires.

Chat messages: By default, messages are retained while the conversation exists and are not automatically purged on a fixed day count. Operators may enable automated deletion of messages older than a configured number of days (for example for legal retention or data-minimization programs). When that feature is enabled, deletion runs on a daily schedule; if it fails repeatedly, our operators are alerted to fix it. After old messages are deleted, the conversation thread may still appear in your inbox as an empty shell until you or we remove it.

Moderation records (reports, warnings, bans, internal staff notes): Kept as long as needed for safety, appeals, and legal compliance. Staff notes are never shown on your public profile; only moderators and developers signed into BST can read them.

Staff activity records: Kept so we can see who changed values or took moderation actions. Retention follows our database backups and housekeeping.

Server action logs (when enabled): Kept on disk until our team rotates them; staff-only access.

App crash reports: If the site breaks in your browser, a short report (page address, error type, and basic details) may be sent to staff to fix bugs. Live production reports do not include full developer stack traces.

Staff Discord alerts and backup log files: Kept according to Discord’s message history and our server log practices. Email us if you need details for the live site at a given time.

Deletion may be limited where law or legitimate safety needs require keeping certain records. Deleted data may persist in backups for a reasonable period before those backups expire.


8. Your rights

Depending on where you live, you may have the right to access, correct, delete, restrict, object to, or port your personal data, and to withdraw consent where processing is based on consent. You may also lodge a complaint with a data protection authority (EU/UK).

California: You can know, delete, and correct personal information, and you have non-discrimination rights for exercising those rights. We do not sell your personal information and do not share it for cross-context behavioral advertising.

To exercise any right, email [email protected].


9. Security

We use reasonable measures including encrypted connections (HTTPS) in production, login cookies that scripts on other sites cannot read, encrypted Discord sign-in tokens in our database, usage limits to reduce abuse (see §2), ending sessions when someone is banned, and staff-only access to moderation tools with a record of staff actions.

No online service is perfectly secure. Report security issues responsibly to [email protected].


10. Children

BST is not directed at children under 13, and we do not knowingly collect their personal data. If you believe someone under 13 has an account, email us and we will close it.


11. Changes to this policy

We may update this policy; the effective date at the top shows the current version. For material changes (for example adding an analytics provider), we will also show a notice on the site when practical so you can review before continuing.


12. Contact

Email [email protected].

Postal mail:

Revolution Software LLC
5441 S Macadam Ave Ste R
Portland, OR 97239, USA