LifeRP Central Privacy Notice
Privacy Policy
This policy explains what information the website may collect while supporting LifeRP server activity, why it is used, when it may be shared, and how records may be retained.
Overview
This Privacy Policy explains how the LifeRP Central website collects, uses, stores, shares, and protects information when players, businesses, and staff use website features for LifeRP server-related activity.
The website exists to support LifeRP server activity through web tools such as accounts, website money records, deposits, withdrawals, transfers, businesses, marketplace listings, orders, fundraisers, chat, tickets, notifications, logs, exports, staff tools, security review, and API integrations.
This policy is written to describe normal website operation as well as moderation, fraud review, scam investigation, staff action, economy review, and security work. Some data may be retained even when it is hidden from normal users, deleted from a public page, or no longer visible in a standard account view.
Information We Collect
The website may collect Steam ID, Steam username or display name, Steam avatar URL, website username, account creation date, login timestamps, session identifiers, theme preference, account status, balance records, bank transactions, transfer reasons, deposit and withdrawal requests, business wallet activity, marketplace listings, orders, fundraiser campaigns, donations, chat messages, ticket content, proof clip URLs, evidence URLs, and settings submitted through the website.
The website may also collect technical and security information such as browser type, device type, user agent, request timestamps, route usage, API usage, business token usage, notification activity, and IP-related metadata.
When a user creates content or performs an action, records may include the actor Steam ID, target Steam ID, business ID, ticket ID, room ID, transaction ID, request code, amount, status, reason, timestamps, proof links, and other metadata needed to understand what happened.
Steam Login Information
The website uses Steam OpenID to verify player identity. Steam login may provide or confirm your Steam ID and basic public Steam profile information such as username, display name, or avatar.
The website does not receive your Steam password, Steam email address, Steam private account information, Steam payment information, or Steam inventory unless a future feature clearly asks for and explains additional access.
Steam profile data may be refreshed from time to time so usernames and avatars stay current. If Steam profile enrichment fails or is unavailable, the website may continue using the last known public profile data or a generated website username.
Information We Do Not Intentionally Collect
LifeRP Central does not intentionally collect Steam passwords, Steam email addresses, real-world payment card data, real bank account data, government ID numbers, real-world financial account balances, or private Steam account credentials.
Users should not put sensitive real-world personal information into tickets, chats, marketplace posts, orders, fundraisers, business pages, proof URLs, or profile content unless it is absolutely necessary for a specific support issue. Staff may remove, hide, or retain such content depending on safety, moderation, or audit needs.
Why We Use Information
Information is used to connect website accounts to LifeRP server players, operate website banking, process deposits and withdrawals, support transfers and frozen holds, manage businesses, provide marketplace and order tools, run fundraisers, provide chat and tickets, send in-app notifications, enforce permissions, prevent abuse, investigate scams, review suspicious activity, provide exports, and maintain audit logs.
Technical and log information may be used to debug errors, secure sessions, detect fraud, investigate API misuse, protect business tokens, review staff actions, enforce bans, and keep the website economy reliable for the LifeRP server community.
Information may also be used to verify whether a user followed a generated command, used the correct request code, submitted believable proof, attempted to move funds in a suspicious way, created misleading content, abused a business API token, or tried to evade a restriction.
Cookies, Sessions, And Browser Storage
The website uses signed session cookies or similar server-side session methods to keep users signed in and protect authenticated actions. Cookies may also help preserve security state and basic preferences.
The website may use browser storage for non-sensitive interface preferences such as light or dark mode and short-lived usability caches such as transfer recipient search data. Business API keys, admin secrets, Supabase service role keys, and other sensitive server secrets must not be stored in browser-accessible code.
Bank, Business, And Economy Records
Bank transactions, deposits, withdrawals, transfer reasons, frozen holds, business payments, business taxes, business wallet records, paychecks, proof clips, and staff actions may be retained as operational records for the LifeRP server companion website.
These records are used for player history, staff review, fraud detection, scam investigation, economy balancing, dispute handling, audit logs, and exports. Deleted or hidden requests may remain stored for safety and review even when normal users cannot see them.
If staff freezes, removes, reverses, adjusts, denies, or wipes roleplay money records, related information may be retained to explain the internal action, prevent repeat abuse, compare future reports, review staff conduct, or defend the website against inaccurate claims.
Chat, Tickets, Proof, And Notifications
Chat messages, ticket content, scam evidence, proof URLs, staff replies, ticket status changes, and notification records may be stored so the website can provide player support and staff review.
Chat messages are encrypted at rest where configured by the application. Authorized room members and permitted staff actions may still access message content or metadata when needed for website operation, moderation, support, or security.
Business API Keys And External Websites
Business API tokens are intended for server-side use by external websites connected to LifeRP server activity. Raw tokens are shown once where applicable, and the website stores only hashes.
Token usage may be logged, including business identity, request time, event delivery, payment data, and security-related metadata. Business owners are responsible for keeping API keys secure on their external websites.
Login With LifeRP Central
Business integrations receive only payment and event information needed for the connected business wallet.
Business integrations do not receive private bank history, personal balances, chat content, tickets, staff roles, staff permissions, private logs, or unrelated business API secrets.
When Information May Be Shared
Information may be shared with authorized LifeRP website staff, service providers used to host or operate the website, database providers, security tools, Steam where needed for login, and business integrations when needed for payment or event flows.
Information may also be preserved or disclosed when reasonably necessary to enforce rules, investigate scams, protect users, respond to abuse, secure the website, prevent fraud, defend the rights and safety of the community, resolve support requests, respond to valid legal obligations, or address allegations made against staff or the website.
Staff may discuss limited account, payment, business, ticket, or marketplace information internally when needed to investigate an issue. Staff should not expose private logs or sensitive metadata to normal users unless disclosure is appropriate for support, moderation, or safety.
No Sale Of Personal Information
The website does not intentionally sell personal information. It does not intentionally trade user account records, private logs, chat content, ticket content, bank history, or Steam IDs for advertising purposes.
External integrations receive only the information needed for approved website features, such as business payment events.
Security Practices
The website uses security measures designed for this type of server companion platform, including server-side handling for sensitive writes, hashed API tokens and secrets, encrypted chat storage where configured, permission checks, staff role controls, audit logs, and restricted IP visibility.
No website can guarantee perfect security. Users and business owners must protect their Steam accounts, browser sessions, business staff access, external website servers, and API tokens.
The website may limit access, rotate sessions, revoke tokens, disable features, or preserve security logs when it detects suspicious behavior, account abuse, token misuse, unusual transfer patterns, or attempts to bypass website permissions.
Data Retention
The website keeps information for as long as reasonably needed to operate LifeRP server-related website features, provide account history, enforce rules, investigate scams, audit staff actions, maintain security, support exports, prevent abuse, and protect economy integrity.
Some information may be retained after account deletion, ban, wipe, or feature removal when needed for fraud prevention, moderation, audit records, dispute handling, security, server economy review, business review, API abuse prevention, or to preserve records of staff actions.
Retention periods may differ by record type. For example, session data may be shorter-lived, while transaction records, audit logs, staff actions, scam evidence, ticket records, business API events, and proof-related records may be kept longer because they help protect the website and the LifeRP server economy.
User Choices And Requests
Users may use available website settings to manage sessions, theme preference, account deletion requests, and other supported controls. Some requests may require ticket review to verify account ownership or prevent abuse.
Privacy questions or requests should be submitted through the LifeRP ticket system. Requests may be limited or denied when retention is needed for scam review, fraud prevention, audit logs, security, dispute handling, or rule enforcement.
Children And Server Rules
The website is intended for users who are allowed to use Steam, the LifeRP server or community, and this website under applicable rules. Users who are not permitted to use the website under applicable law, Steam rules, or LifeRP server rules should not use it.
If a parent, guardian, or authorized person believes a user is using the website improperly, they may contact LifeRP through the ticket system where available.
International Access
The website may be accessed from different regions. By using the website, you understand that information may be processed where the website operator, hosting provider, database provider, or service infrastructure is located.
Privacy rights vary by location. The website will review reasonable privacy requests through the ticket system, subject to security, moderation, fraud prevention, and applicable obligations.
Changes To This Policy
This Privacy Policy may be updated when website features, server-related workflows, data practices, security controls, API behavior, staff processes, or legal notices change. The last updated date shows when the policy was most recently revised.
Continued use of the website after changes means you acknowledge the updated Privacy Policy.
Contact
For privacy questions, account questions, business API concerns, scam evidence concerns, or data requests, use the LifeRP ticket system. Tickets may be reviewed by authorized staff and retained for safety, moderation, security, and audit purposes.