Skip to content

Privacy Policy

Last updated 10 August 2026

This policy covers the RevolutionRP website. It describes what the site stores about you, why, how long for, and what you can do about it.

Who is responsible

RevolutionRP is the data controller for information collected through this site. [Add the operator's legal name, postal address and a contact email here — a privacy policy without a named controller and a working contact route is not compliant.]

What we collect

When you sign in with Steam

Signing in uses Steam OpenID. We never see your Steam password — Steam confirms your identity to us and returns your account ID. We then ask Steam's public API for the profile information already visible on your Steam community page:

Steam does not give us an email address, and we do not ask you for one.

When you use the site

Accounts you choose to link

Linking Discord or Twitch is entirely optional. If you do, we store the account identifier the provider returns, your username there, and the access tokens needed to maintain the link. A Cfx.re link is a URL you type in yourself — we cannot verify it, and it is shown as unverified. You can unlink any of these from Settings, which deletes the stored connection.

Why we are allowed to hold it

DataPurposeLawful basis
Steam ID and profileIdentify your accountContract — you cannot use the site without an account
Session, IP, user-agentKeep you signed in; let you spot unfamiliar sign-insContract, and legitimate interest in account security
Moderation records and staff notesEnforce the rules and keep the community usableLegitimate interest in running a safe community
Linked Discord/Twitch accountsShow your connections; verify who you are elsewhereConsent — you choose to link, and can unlink

Who else sees it

Signing in contacts Steam, and linking an account contacts that provider. Those interactions are covered by their own privacy policies.

How long we keep it

Your rights

Under UK/EU GDPR you can ask for a copy of your data, ask us to correct it, ask us to delete it, object to how we use it, or withdraw consent for anything you consented to.

Getting a copy. You can download everything we hold about your account from Settings, as a JSON file, at any time and without asking. It covers your profile, roles, sessions and linked accounts. Access tokens for linked accounts are left out — they are credentials rather than information about you. Internal moderation notes are also left out, to protect the staff who wrote them; ask staff directly if you want to know what has been recorded.

Deleting your account. Request erasure from Settings. Requests go to a staff queue and are actioned within 30 days, as Article 17 allows. We review rather than delete instantly so we can confirm the request is genuine and check whether anything must be retained. Completing a request permanently deletes your account, sessions, linked accounts, roles and any staff notes about you. We keep a dated record that the deletion happened, with you no longer identified in it.

Anything you published while a member — news articles, for example — stays up with the byline removed, so the server's announcements don't vanish.

For anything else, or to complain, [add a contact email]. If you are unhappy with our response you can complain to your national data protection authority; in the UK that is the ICO.

Cookies

This site sets only strictly necessary cookies — a signed session cookie that keeps you signed in, and a short-lived cookie during Steam sign-in that prevents cross-site request forgery. There are no analytics, advertising or tracking cookies, which is why you are shown a notice rather than asked for consent.

Changes

If this policy changes materially we will say so on the site. The date at the top always reflects the current version.