Privacy Policy

Last updated: August 24, 2026

This Privacy Policy explains how Relyo (the "Platform") collects, uses and protects your personal data in compliance with the General Data Protection Regulation (GDPR) and the EU Digital Services Act (DSA).

1. Data Controller

The data controller for your personal data processed through Relyo is:

Ridoco
KVK: 95439609
BTW: NL005153257B49
De Nieuwe Erven 3-12572, 5431 NV Cuijk, Netherlands
Phone: +31 6 49154776
Email: management@ridoco.com

For support, visit the Support page.

2. Data Collected

2.1 Data provided through authentication

Logging in via Discord or Reddit OAuth2 stores:

  • Discord: User ID, username, discriminator, global display name, avatar URL, email (if authorized)
  • Reddit: User ID, username

OAuth2 access and refresh tokens are stored securely to maintain your session.

2.2 Data generated through platform use

  • Votes: Entity voted for, timestamp, voting streak. A vote never stores the IP address as itself. It is combined with a secret salt held on the server and stored only as an irreversible SHA-256 hash, used to stop the same address voting twice.
  • Reviews: Rating, review text, timestamps
  • Listings: Bot/server details you submit (descriptions, invite links, tags)
  • Reports: Report reason and status
  • Transactions: Relay purchases, amounts, payment provider reference IDs (card numbers are never stored)
  • Withdrawal waiver: When you buy Relay you tick a box asking for the credit immediately and accepting the loss of your right of withdrawal. Relyo stores the exact wording shown, a SHA-256 hash of it, its version, the time, your IP address and your browser user agent, attached to that payment. This is the proof that the waiver was given and it is used for nothing else. See the Refund Policy.
  • API keys: Key names, permissions, usage timestamps (key values are stored as irreversible SHA-256 hashes)

2.3 Automatically collected data

  • IP address hashes: Used for vote fraud detection. Votes never store the address itself, only the salted hash.
  • IP address: Stored as itself in one place only, on the withdrawal waiver attached to a Relay purchase, as evidence that the waiver was given.
  • User-Agent strings: Collected during votes for fraud analysis
  • Essential cookies: Session and authentication cookies (see the Cookie Policy)

3. Legal Basis for Processing

Relyo processes your personal data under the following legal bases (GDPR Art. 6):

  • Contract performance (Art. 6(1)(b)): Processing necessary to provide the Service (account management, listing display, voting)
  • Legitimate interest (Art. 6(1)(f)): Fraud prevention, platform security, service improvement
  • Consent (Art. 6(1)(a)): Non-essential cookies (if applicable), marketing communications
  • Legal obligation (Art. 6(1)(c)): Tax records for purchases, responding to lawful requests

4. How Your Data Is Used

  • Authenticate you and manage your account
  • Display your listings, reviews, and votes on the Platform
  • Detect and prevent vote fraud and abuse
  • Process payments and maintain transaction records
  • Moderate content and enforce the Terms of Service
  • Send service-related notifications (approval/denial of listings, payment confirmations)
  • Generate aggregate, anonymized analytics to improve the Platform

5. Data Sharing

Relyo does not sell your personal data. Data may be shared with:

  • Payment processors (Stripe, PayPal): To process Relay purchases. These providers act as independent data controllers under their own privacy policies. Processed in the EU and the United States.
  • netcup GmbH, and the Anexia group companies it relies on: server hosting, databases and backups, under a data processing agreement. Processed in Germany and Austria (EU).
  • Google: Google Analytics, loaded only if you choose Accept all on the cookie banner. It measures aggregate usage. It is not used for advertising or individual profiling. Processed in the EU and the United States.
  • Sentry: application error and crash reporting. Every event is stripped before it is sent: no IP address, no email address, no request body, no cookies, no account identifier. Processed in the EU and the United States.
  • Bot/server owners: When you vote for or review a bot/server, the owner may receive your user ID and username via webhooks they have configured.
  • Law enforcement: When required by applicable law or valid legal process.

6. Data Retention

  • Account data: Retained while your account is active. Deleted within 30 days of account deletion request.
  • Votes: Retained for as long as the listing and your account both exist. What is retained is the hash, never the address it came from. Deleting your account deletes your votes with it.
  • Reviews: Retained while visible. Deleted reviews are permanently removed within 30 days.
  • Transaction records: Retained for 7 years as required by Dutch tax law. The withdrawal waiver attached to a purchase, including the IP address and user agent it recorded, is the evidence that the purchase was made on those terms. It is kept with that record for the same period.
  • Webhook logs: Retained for 90 days. A job runs daily and deletes every log older than that. Deleting your account also redacts the delivery payloads that named you, straight away, without waiting for the 90 days to run out.
  • Session cookies: Expire after 7 days (refresh token) or 15 minutes (access token).

7. Your Rights (GDPR Art. 15-22)

As an EU/EEA resident, you have the right to:

  • Access (Art. 15): Request a copy of your personal data
  • Rectification (Art. 16): Correct inaccurate personal data
  • Erasure (Art. 17): Request deletion of your personal data ("right to be forgotten")
  • Restriction (Art. 18): Request restriction of processing
  • Portability (Art. 20): Receive your data in a structured, machine-readable format
  • Objection (Art. 21): Object to processing based on legitimate interest
  • Withdraw consent: Where processing is based on consent, withdraw at any time

To exercise these rights, visit the Support page or contact privacyrelyo@doombringerz.com. Requests are answered within 30 days. If you believe your rights have been violated, you have the right to lodge a complaint with your local Data Protection Authority (DPA). In the Netherlands, this is the Autoriteit Persoonsgegevens (AP).

8. International Data Transfers

Your data is stored on servers within the European Economic Area (EEA). If data is transferred outside the EEA (e.g., through Discord or Reddit APIs), such transfers are covered by Standard Contractual Clauses (SCCs) or the provider's adequacy decision.

9. Data Security

Relyo implements appropriate technical and organizational measures to protect your data:

  • Relyo holds no passwords. Sign-in runs entirely through Discord and Reddit OAuth2
  • API keys are stored as irreversible cryptographic hashes
  • Vote IP addresses are hashed with a server-side secret salt and stored only as that hash
  • All data in transit is encrypted via TLS/HTTPS
  • Access to personal data is restricted to authorized personnel
  • JWT tokens are stored in httpOnly, secure cookies

10. Children's Privacy

Relyo is not directed at children under 13 (or the minimum age in your jurisdiction). Relyo does not knowingly collect personal data from children under 13. If you believe a child under 13 has provided personal data, contact Relyo and it will be deleted promptly.

11. Changes to This Policy

This Privacy Policy may be updated. Material changes are communicated via the Platform. Your continued use after the effective date constitutes acceptance of the updated policy.

12. Contact

Ridoco
De Nieuwe Erven 3-12572, 5431 NV Cuijk, Netherlands
KVK: 95439609 | BTW: NL005153257B49
Privacy: privacyrelyo@doombringerz.com
Support: doombringerz.com/support