Skip to content
ParTay Studios
HostingPlansOriginal GamesSupportClient Portal

Data and choices

Privacy Policy

How personal information is handled across the website, newsletter, support, billing, and hosting services.

Effective September 2, 2026Owner-approved policy
TermsPrivacyAcceptable UseRefunds and Cancellation
On this pageScopeInformationUseProvidersAnalyticsNewsletterClient portalRetentionRights

ParTay Development LLC, doing business as ParTay Studios (“ParTay,” “we,” “us,” or “our”), is responsible for the personal information described in this policy.

Scope

This policy covers partaystudios.com, its hosting configurator and website support forms, the invite-only client portal, Original Games email updates, direct support contacts, and information processed for accepted hosting orders and services. A third-party website or community may have its own privacy terms.

Information we collect

  • Hosting-planning answers, management and migration preferences, region, timeline, optional budget range, and additional context submitted through the configurator.
  • Support topic, request summary, message, optional public service identifier, and the contact information you provide through a website form.
  • An email address, consent version, subscription status, and delivery events when you request Original Games updates.
  • Client-portal account email, display name, workspace role and membership state, sign-in timestamps, verification attempts, security events, and an opaque VOS Core customer reference.
  • When you use Discord portal access, Discord's stable user ID and display name, a short-lived OAuth state, link status, sign-in timestamps, and related security events. Firestore stores an HMAC-derived identity key rather than the raw Discord user ID.
  • Account, authorized-user, order, configuration, invoice, and transaction references when you become a customer.
  • Website requests, device/browser details, IP address, security events, consent choices, and limited analytics after permission.

Forms do not accept attachments. Do not send passwords, private keys, complete payment-card details, authentication codes, unrestricted logs, or unrelated personal data through public contact routes.

How we use information

We use information to recompute and review hosting recommendations, route and answer inquiries, send receipts, prevent duplicate or abusive submissions, create a staff-only work item, manage newsletter consent, authenticate and authorize portal members, create verified Stripe-hosted billing sessions, accept and administer orders, deliver and secure services, investigate abuse or fraud, keep required business records, comply with law, and improve the website using consented analytics.

Service providers and disclosures

Information may be processed by Cloudflare for delivery, Turnstile verification, and security; Google Cloud and Google Cloud Identity Platform for website, API, Cloud Tasks, Firestore, identity, and secure session hosting; Google Workspace for staff routing; Google Analytics only after consent; Resend for requested receipts, one-time portal codes, staff notifications, newsletter delivery, and unsubscribe management; Stripe for server-authorized hosted billing sessions; and Discord when you choose Discord portal authentication or the official community.

The existing ParTay bot creates a staff-only Discord work item containing the inquiry reference and sanitized routing fields. Names, email addresses, budget values, Discord usernames, and free-text messages are not sent to that ticket. Portal authentication uses Discord's identify scope only and does not request your Discord email, guild list, messaging access, or bot installation.

We may also disclose information when required by valid legal process, to protect rights and safety, or as part of a business transaction subject to applicable safeguards. We do not sell personal information or use website analytics for targeted advertising.

Analytics and cookie choices

Google Analytics is optional. Its tag does not load until you select “Accept analytics.” Advertising storage, ad user data, ad personalization, Google Signals, and user IDs remain disabled. Configurator analytics are limited to entry, allowlisted family selection, primary calls to action, and accepted submission. Analytics never receive contact data, form answers, budget, message text, inquiry references, Discord identity, payment details, confirmation tokens, or service identifiers.

Your selection is stored locally in your browser. Use the persistent “Cookie Settings” button to change it. Rejecting analytics does not prevent access to the website. Turnstile may use strictly necessary security storage when you submit a website form or newsletter request.

Original Games newsletter

The newsletter uses double opt-in. A request remains unconfirmed until you use the one-time confirmation link. Confirmation and suppression records support consent and unsubscribe enforcement. Every promotional message includes an unsubscribe method, and hosting promotions are not added to this list.

Invite-only client portal

Portal access is created only for approved customers and team members; there is no public self-registration. One-time access codes expire after 10 minutes, can be used once, and are stored only as keyed hashes. Authentication is maintained with a strictly necessary secure, HTTP-only session cookie lasting up to 12 hours.

Discord sign-in uses a random, single-use OAuth state that expires after 10 minutes. Authorization codes are exchanged server-side and discarded; Discord access and refresh tokens are not stored. VOS Core must confirm that a Discord user is already associated with an active customer before Discord-only access is created. One Discord identity may be linked to a customer workspace, and conflict checks prevent reassignment to another customer. An email-verified member may optionally link Discord, but Discord cannot be removed when it is the account's only sign-in method.

A clear not-linked notice appears only after Discord verifies the user or an email recipient enters a valid code, preventing the initial sign-in form from revealing customer membership. The portal does not use Google Analytics. Authentication codes, membership and Stripe customer identifiers, service identifiers, billing data, account email, Discord identity, customer references, and OAuth state are not placed in analytics or public application URLs. Stripe-hosted billing can open only after the server verifies the signed-in membership and its customer mapping.

Retention and security

  • GA4 event-level data is configured for two-month retention.
  • Website-form inquiries and their delivery state are ordinarily retained for 24 months. Rate-limit and delivery-deduplication records use shorter operational TTLs.
  • Portal access-code, Discord OAuth-state, and rate-limit records use a 24-hour operational TTL even though codes and OAuth state expire after 10 minutes. Portal sign-in, Discord link and unlink, and billing-session audit records are ordinarily retained for 24 months. Membership and HMAC-derived Discord identity-link records remain while the workspace relationship is active and longer only when required for security, billing, accounting, dispute, or legal obligations.
  • Unconfirmed newsletter requests and confirmation material are retained for eight days; newsletter rate-limit records are retained for 24 hours.
  • Confirmed subscriber data remains while subscribed; minimal unsubscribe, suppression, and consent evidence is retained for six years after the last subscription event.
  • Website and newsletter operational logs are ordinarily retained for 30 days and exclude request bodies and direct contact information.
  • Records may be kept longer when an accepted order, security incident, dispute, accounting requirement, or law requires it.

We use administrative, technical, and physical safeguards appropriate to the information, but no system can guarantee absolute security.

Your choices, rights, and contact

Depending on your location, you may request access, correction, deletion, portability, restriction, objection, or information about disclosures. We may verify identity and retain information where required for security, accounting, legal obligations, or suppression enforcement.

Submit privacy requests through the privacy request form, to admin@partaydevelopment.com, or to ParTay Development LLC, 5900 Balcones Drive, Suite 100, Austin, Texas 78731.

ParTay Studios

ParTay Development LLC, doing business as ParTay Studios.

Products

HostingHosting Paths

Support

ContactWebsite form

Legal

TermsPrivacyAcceptable UseRefunds
© ParTay StudiosEffective September 2, 2026