
Privacy Policy
This policy explains how Gummy Machine processes information when Workspace owners, Collab Managers, and raffle participants use the website and Discord bot.
Information We Process
- Discord account identifiers, usernames, server membership, roles, and permissions needed to operate raffles.
- Participant-provided X handles, email addresses, Telegram handles, and blockchain wallet addresses.
- Workspace, Community, raffle, entry, winner, receipt, support, audit, and billing records.
- Base payment authorization and transaction data. We do not store wallet private keys or seed phrases.
- Security and operational information such as rate-limit events, worker health, errors, and IP-derived request metadata available to our hosting providers.
How We Use Information
If you request access on the landing page, we store your Discord username, role, and Community name or link so our team can respond. These requests are visible only to authorized platform admins and do not automatically grant access.
We use this information to authenticate users, enforce Workspace access, validate raffle requirements, operate entries and draws, deliver prizes or codes, process subscriptions, provide support, prevent abuse, and maintain auditable raffle receipts.
Discord-Native Protection
Discord-native raffle protection uses account age, server membership duration, shared entry identifiers, and a bounded history of entry wallet or X-handle changes. Authorized operators of that raffle can review these signals. A shared identifier is not proof of cheating. This feature does not collect participant IP addresses or device fingerprints through Discord, or require participants to connect accounts on our website. Entry identity history is deleted with the private participant record.
Sharing And Processors
Community owners and admins can view saved-profile completion flags and wallet counts for observed members of their Discord server. Server Stats does not reveal wallet addresses, X or Telegram handles, or email values. Panel usage and profile-save dates are recorded separately for each server.
Information is shared only as needed with service providers that run the platform, including Discord, Supabase, Netlify, Base/CDP infrastructure, Resend, and X-data providers. Workspace operators can export participant and winner data for raffle fulfillment. Public receipts contain public-safe raffle and proof data and do not expose full private participant profiles.
Retention
Completed private participant data is scheduled for deletion after 180 days. Winner and receipt records may be anonymized, while security, audit, payment, refund, and billing-ledger records may be retained longer for fraud prevention, accounting, disputes, and legal obligations. Verification codes expire quickly and are stored only as hashes.
Your Choices
You may update entry-profile information through the Discord Submit Addies panel. You may request access, correction, or deletion through the Help button in a Gummy Machine Discord panel. Some billing, fraud-prevention, raffle-integrity, and legal records cannot be deleted immediately.
Security And Children
We use tenant authorization, least-privilege service access, rate limits, hashed verification data, and auditable operations. No online system is risk-free. Gummy Machine is not directed to children under 13, and server operators are responsible for age and jurisdiction requirements applicable to their Communities.
Changes
We may update this policy as the product or legal requirements change. The effective date above identifies the current version.