SOS Platform ("vrc.club," "we," "us," or "our") is a multi-tenant community management platform for VRChat communities. This Privacy Policy explains what personal data we collect, why we collect it, how we use it, who we share it with, and what rights you have over your data.
We are the data controller for the personal data processed through vrc.club. If you have any questions about this policy or your data, contact us at privacy@vrc.club.
The short version: We collect only what we need to run the platform. We don't sell your data. We don't share it with advertisers. We don't track you across the internet. Your data belongs to you.
We process your personal data under the following legal bases:
When you create an account, join a community, attend events, subscribe to supporter tiers, or purchase merchandise, we process your data to fulfill our contractual obligations to you. This includes managing your account, providing community features, processing payments, and delivering merchandise.
We process certain data based on our legitimate interest in operating a secure and functional platform. This includes rate limiting to prevent abuse (which temporarily processes IP addresses), platform monitoring, fraud prevention, and service improvement. We have assessed that these interests do not override your fundamental rights and freedoms.
We obtain your explicit consent before processing data that requires it. You provide consent when you accept our Terms of Service and this Privacy Policy during registration. You also provide separate consent when you opt into optional features such as the cross-community talent pool, VRChat account linking, or Patreon integration. You may withdraw consent at any time.
We retain certain records (such as merchandise order data and financial transaction records) as required by applicable tax and commercial laws.
The following table describes every category of personal data we collect, what specific data points are included, and why we collect them.
| Category | Data Collected | Purpose |
|---|---|---|
| Discord OAuth | User ID, username, avatar URL, email address, guild memberships | Authentication, identity, community membership verification |
| VRChat (optional) | Username, user ID, group memberships, group roles | Community sync, ownership verification, in-world features |
| Profile | Display name, pronouns, timezone, languages, social links, bio, availability | Community features, talent pool, profile display |
| Stripe | Customer ID, subscription ID, subscription status | Supporter tier management (we never store card numbers) |
| Patreon (optional) | Member ID, full name, email, pledge status, tier entitlements | Supporter management via webhooks |
| Merch orders | Name, email, shipping address (line 1, line 2, city, state, country, ZIP) | Order fulfillment via Printful |
| User content | Posts, comments, photos, media uploads, performance recordings | Platform functionality, community galleries |
| Bot conversations | Messages sent to the Discord bot, bot responses | Community support, moderation review |
| Discord activity | Monthly message counts per user | Community engagement metrics |
| Events | RSVPs, performance schedules, staff assignments | Event management, scheduling |
| Instance monitoring | VRChat world occupancy counts (aggregate only, NOT individual users) | Event analytics (we cannot and do not track individual attendance) |
We share data with the following third-party services only to the extent necessary to provide our platform features. Each service acts as a data processor on our behalf.
We do not share your personal data with any service beyond those listed above. We do not sell or provide your data to any third party for advertising, marketing, or any purpose unrelated to operating this platform.
We retain your data for the following periods:
| Data Type | Retention Period |
|---|---|
| Account & profile data | Until you delete your account |
| Community membership data | Until you leave the community or delete your account |
| Bot conversation logs | Automatically deleted after 12 months |
| Discord activity metrics | Automatically deleted after 12 months |
| Rate limiting counters | Expire automatically within minutes (Redis TTL) |
| Server logs (Vercel/Railway) | 1-3 days (managed by hosting providers) |
| Merchandise order records | 7 years (legal/tax requirement) |
| Supporter subscription records | While subscription is active; deleted with account |
| Event analytics (aggregate) | Retained indefinitely (no individual user data) |
If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, you have the following rights under the General Data Protection Regulation (GDPR):
Response time: We will respond to all data rights requests within 30 days. If we need more time due to the complexity of your request, we will notify you within the initial 30-day period.
We use a minimal number of cookies, all of which are essential for the platform to function or to remember your preferences. We do not use any advertising, analytics, or tracking cookies.
| Cookie | Type | Purpose | Duration |
|---|---|---|---|
| next-auth.session-token | Essential | Authentication session | 30 days |
| next-auth.callback-url | Essential | OAuth redirect handling | Session |
| next-auth.csrf-token | Essential | CSRF protection | Session |
| sos-locale | Functional | Language preference | 1 year |
| OAuth state cookies | Essential | OAuth flow security | Deleted after use |
We also use localStorage to remember whether you have dismissed the cookie information banner. This data never leaves your browser.
IP addresses are processed solely for rate limiting (abuse prevention). When you make requests to our platform, your IP address is used to maintain temporary counters in Redis that automatically expire within minutes. We do not persistently log, store, or analyze IP addresses.
Our hosting providers (Vercel and Railway) retain server logs that include IP addresses for 1-3 days as part of their standard operational infrastructure. We do not access these logs for tracking purposes.
Community managers can see your activity within their community, including your display name, roles, event RSVPs, supporter status, and staff assignments. They cannot see your activity in other communities unless you have opted into cross-community features such as the talent pool.
Platform administrators have access to all data across communities for the purpose of operating, maintaining, and moderating the platform.
Your data is stored on servers located in the United States. If you are located in the EEA, UK, or Switzerland, your personal data is transferred to the United States to provide our services. We rely on the necessity of the transfer for the performance of our contract with you (GDPR Art. 49(1)(b)) and, where applicable, the standard contractual clauses adopted by the European Commission.
We implement appropriate technical and organizational measures to protect your personal data, including:
No system is 100% secure. If we discover a data breach that poses a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours and notify affected users without undue delay, as required by GDPR Articles 33 and 34.
vrc.club is restricted to users aged 18 and older, as stated in our Terms of Service. We do not knowingly collect personal data from anyone under the age of 18. If we become aware that we have collected data from a minor, we will take steps to delete that data promptly. If you believe a minor has provided us with personal data, please contact us at privacy@vrc.club.
We may update this Privacy Policy from time to time to reflect changes in our data practices, legal requirements, or platform features. When we make material changes, we will notify you through the platform and may require you to re-accept the updated policy. The version date at the top of this page indicates the most recent revision.
We encourage you to review this policy periodically. Continued use of vrc.club after changes are posted constitutes acceptance of those changes, except where re-acceptance is required.
For privacy inquiries, data access requests, or any concerns about how we handle your data:
If you are located in the EU/EEA and are not satisfied with our response, you have the right to lodge a complaint with your local data protection supervisory authority.
This policy applies to all users of vrc.club (SOS Platform). For questions, contact privacy@vrc.club.