Privacy
Last updated: 2 September 2026
This notice explains how CardPatrol processes personal data when you visit the website, connect Discord, subscribe or contact support.
1. Controller
CardPatrolAlessandro Di Bitonto, sole proprietorship
Erlenholzstrasse 3
8586 Erlen, Switzerland
support@cardpatrol.ch
2. Data we process
- Website and security data: IP address, request time, requested URL, device/browser information and technical logs.
- Discord data: Discord user ID, username, display name, email returned through OAuth, server membership and Premium-role status.
- Subscription data: selected plan, Stripe customer, Checkout Session and subscription identifiers, payment/subscription status and the Discord user ID linked to the subscription.
- Support data: your email address and the content of messages you send to support.
Full card details are handled by Stripe and are not stored by CardPatrol. The Discord OAuth access token is used to complete server onboarding and is not stored by the CardPatrol application after that request.
3. Why we use the data
We process personal data only as needed to:
- operate, secure and troubleshoot the website;
- identify your Discord account and provide the paid Premium role;
- create, administer and cancel subscriptions;
- prevent misuse and reconcile payment or access problems;
- answer support requests and meet legal obligations.
4. Service providers and recipients
CardPatrol uses the following providers to deliver the service:
- Vercel for website hosting and technical logs;
- Stripe for Checkout, recurring billing, fraud prevention and the customer portal;
- Discord for account authorization, server membership and Premium access;
- Infomaniak for the cardpatrol.ch domain and support email service.
We may also disclose data where required by law, to protect the service or users, or in connection with a legitimate business succession. We do not sell personal data.
5. International processing
Some providers may process data in Switzerland, the EEA, the United States or other countries described in their privacy documentation. Where required, cross-border processing is based on an adequate level of protection, recognized data-transfer frameworks, contractual safeguards or another valid legal basis.
6. Cookies and similar storage
CardPatrol does not use advertising or marketing analytics at launch. A short-lived, essential OAuth nonce cookie is set when you connect Discord. It protects the login flow, is not used for tracking and expires after approximately ten minutes. Stripe and Discord may use their own cookies when you visit their pages; their policies apply there.
7. Retention
Data is kept only for as long as needed for the purposes above and for applicable legal, accounting, security and dispute-resolution duties. Subscription records may therefore remain after cancellation. Short-lived OAuth security data expires automatically. Data that is no longer required is deleted or anonymized where reasonably possible.
8. Your rights
Subject to the Swiss Federal Act on Data Protection and its conditions, you may request information about your personal data, correction of inaccurate data, deletion, restriction of processing or delivery of certain data in a commonly used format. You may also object to particular processing where applicable.
Send requests to support@cardpatrol.ch. We may need to verify your identity before responding. You may also contact the Swiss Federal Data Protection and Information Commissioner.
9. Security and updates
CardPatrol uses access controls, signed webhooks, encrypted connections and limited data collection to protect the service. No internet service can guarantee absolute security. This notice may be updated when the service, providers or legal requirements change; the current version and date will remain published here.
