Privacy Policy
1. Who we are
"SANbox RP," "we," "us," or "our" refers to the community operated by Snippy Studios based in the State of Georgia, United States. This policy covers the SANbox RP website ("the Site") and the FiveM server it serves. Snippy Studios is not a registered legal entity; it operates as a personal-project community.
2. What this policy covers
This policy applies to anyone visiting the SANbox RP website, signing in with Discord, applying to a department, or playing on the FiveM server. The Site may link to external services (Discord, FiveM, gaming platforms). Those services have their own privacy policies — we don't control how they handle your data.
3. What data we collect
We collect the smallest amount we need to run the community. Specifically:
3.1 From Discord (when you sign in)
- Your Discord user ID (a stable numeric identifier)
- Your Discord username and display name
- Your Discord avatar hash (so we can display your profile picture)
- The guild roles you hold in the SANbox Discord server (used to decide who can see staff/admin areas)
3.2 From applications and in-game activity
- Answers you submit on department application forms
- Character information you create in-game (first name, last name, date of birth, appearance, department, rank, level, XP)
- Character activity events — when you join a department, get promoted, withdraw an application, etc. — to power the activity feed
3.3 Technical data
- Server access logs (IP address, browser/operating system, pages visited) — kept briefly for security and abuse prevention
- Session cookies (see Section 7) used to keep you signed in
We do not collect payment information, real-name billing details, location data beyond what's in your IP, or any data brokered from third parties. We don't sell ads. We don't sell your data.
4. How we use your data
- To sign you in and keep you signed in
- To show you your applications, characters, and member information
- To let you submit applications and have department staff review them
- To let staff manage their department roster and operations
- To track in-game progression (levels, XP, dates of service)
- To investigate abuse, rule-breaking, or technical issues
- To improve the site and the community over time
5. How long we keep your data
We keep account-linked data (Discord profile, applications, characters) for as long as you remain part of the community. If you leave the Discord server, withdraw all applications, and ask us to remove your data, we'll delete personally identifying information within 30 days, except where we need to keep records for moderation history (e.g. ban appeals) or where the law requires retention.
Server access logs are typically purged after 30 days.
6. Who we share data with
We share only what's necessary, and only with the platforms that make the community work:
- Discord — for sign-in (we read your profile and roles via OAuth)
- Our hosting provider — the company that runs the server we host on
- Department staff — see applications submitted to their department, and member data for their own department's roster
- Portal admins (currently the Community Director and Community Coordinator) — full view of applications and community-wide tools
We will never sell your data, hand it to advertisers, or share it with people outside the community unless required by a valid legal process (subpoena, court order, etc.).
7. Cookies and local storage
We use a small number of strictly necessary cookies — all set by our own site, none third-party tracking. They keep you signed in and protect against forged requests:
sanbox-site.session-token— your sign-in sessionsanbox-site.callback-url— remembers where to send you after sign-insanbox-site.csrf-token— prevents cross-site request forgerysanbox-site.stateandsanbox-site.pkce.code_verifier— used during the Discord OAuth flow
We don't run analytics or marketing cookies. We may add anonymous usage analytics in the future — if we do, this section will be updated and you'll see a clear notice.
8. Your rights
You can ask us to:
- Show you what data we have on you
- Correct anything that's wrong
- Delete your account and associated data (subject to Section 5)
- Stop using your data for a specific purpose
To exercise any of these rights, contact us at the email below. We'll respond within 30 days. We don't charge for these requests unless they're clearly excessive (e.g. the same request repeated weekly).
9. Security
We take reasonable steps to protect your data — encrypted connections (HTTPS), hashed and cookie-based sessions, restricted database access. No system is bulletproof, so we ask you to keep your Discord account secure and not share access. If you suspect your account is compromised, contact us right away.
10. Children
You must be at least 13 years old to use SANbox RP, in line with Discord's own minimum age. If we learn we've collected data from a child under 13, we'll delete it.
11. Changes to this policy
We may update this policy. Material changes will be announced in Discord and at the top of this page. Continued use of the Site after a change means you accept the updated terms.
12. Contact
Questions, requests, or complaints about your data: contact us through the SANbox RP Discord server or by email at contact@sanboxrp.com. (If that email isn't live yet for you, reach out via the Snippy Studios contact channel in Discord — we'll route it.)
13. Jurisdiction
This policy is governed by the laws of the State of Georgia, United States. Any dispute relating to this policy will be heard in the state or federal courts located in Georgia.
