← Back

Privacy Policy

Last updated: September 30, 2026 · Boxshop, owner Erwin Boxberger, Wiesenweg 10, 74424 Bühlertann

This English translation is provided for your information. In case of doubt, the German version prevails. Deutsche Fassung

1. Controller

Boxshop
Owner: Erwin Boxberger
Wiesenweg 10, 74424 Bühlertann, Germany
Email: info@boxshopde.de
VAT ID: DE458856018

2. General information on data processing

We process personal data only insofar as this is necessary for our services, we are legally obliged to do so or you have given your consent. We state the legal basis in each section: Art. 6(1)(a) GDPR (consent), (b) (contract and requests prior to a contract), (c) (legal obligation, such as retaining invoices) and (f) (legitimate interests – you can object to this, see “Right to object” below).

Without logging in with Discord you cannot use the dashboard, and without an email address we cannot send you invoices and confirmations by email. Beyond that, you are not obliged to provide us with any data. We do not sell data.

3. Login with Discord

You log in to the dashboard with your Discord account (OAuth2). In the process, Discord transmits to us:

  • your Discord ID, your username and your profile picture (avatar)
  • your email address (we always request it)
  • the list of your Discord servers with your permissions there
  • the language setting of your Discord client – only if you have bought or subscribed to something from us, and only as the value “German” or “English” (purpose: see section 7)

We use this data to log you in, to display it in the dashboard, to show you the servers you may manage, to manage your bot settings, for purchase, invoice and subscription emails and to match cancellations and withdrawals to you. We use the access authorisation that Discord grants us at login only at that moment (list of your servers, joining the support server, see section 3a) and do not store it. We remember the IDs of the servers you may manage so that the dashboard finds them faster; we replace them at every login and delete them no later than 90 days after your last login. Legal basis: Art. 6(1)(b) GDPR.

Discord (for users in the European Economic Area: Discord Netherlands BV) processes your data at login as an independent controller. You can find Discord’s privacy policy at https://discord.com/privacy.

Your browser loads profile pictures and server icons directly from Discord (cdn.discordapp.com). In the process, Discord receives your IP address and information about your browser. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in a familiar, easily recognisable display of your servers).

3a. Support server and plan role

At every login we use the Discord permission “Join servers for you” and add your account to our support server if you are not yet a member there. There you receive a role that corresponds to your plan (Free, Basic, Premium or Lifetime). Other members of the support server can see this role; it shows which plan you use. Purpose: easy access to support and to benefits for the community. Legal basis: Art. 6(1)(f) GDPR.

You can object to this at any time – an informal email to info@boxshopde.de is sufficient. We will then remove you and your plan role from the support server and make sure that you are not added again at later logins.

4. Cookies and local storage

We only set cookies that are technically necessary for logging in and for inviting the bot:

Cookies
NamePurposeDuration
asward_tokenLogin to the dashboard – a signed login token with Discord ID, username and avatar identifier7 days
asward_pending_guildremembers the selected server when you invite the bot without being logged in, until after you log in10 minutes
asward_invite_stateprotects the return after inviting the bot against forgery15 minutes
asward_login_… (with a random identifier)protects the login against forgery: links the return from Discord to your browser10 minutes

All four are cookies of our own website. They cannot be read by JavaScript (httpOnly) and are only transmitted over encrypted connections. They are strictly necessary for us to provide the login and the invitation of the bot that you requested; no consent is required for this (§ 25(2) no. 2 TDDDG). Legal basis for the associated processing: Art. 6(1)(b) GDPR. When you log out, we delete the login cookie and invalidate the token.

In addition, your browser keeps settings and intermediate states that you trigger yourself in local storage (localStorage or sessionStorage): language, appearance, the last selected server, drafts of forms in the dashboard and hidden or postponed notices. Only the page in your browser reads these entries; we do not store them on our side. You can delete them in your browser at any time. § 25(2) no. 2 TDDDG applies here as well.

We do not set cookies for advertising or analytics purposes. Only on the purchase page of a one-time purchase does your browser load PayPal’s payment buttons; PayPal may set its own cookies in the process (see section 7).

5. Your account entry

When you log in, we create an account entry in our database on our server (with a copy as a file so that we can restore it after a malfunction). It contains:

  • your Discord ID, your username and your profile picture
  • your email address – the one most recently transmitted by Discord at login or by PayPal with a payment
  • a shortened hash value of your IP address (to prevent misuse; we do not store the IP address itself)
  • the time of your first and of your last login
  • where applicable, notes such as a ban or participation in the partner programme

We store your plan and your purchases separately (sections 7 and 7c). The account entry is deleted automatically 90 days after your last login; while a subscription is running, no earlier than 90 days after it ends; for a paused subscription, the end of the paid period counts. Legal basis: Art. 6(1)(b) GDPR (your account and your contracts) and (f) (protection against misuse).

6. Usage events in the dashboard (pseudonymous)

To find out at which point the setup of the bot is abandoned, we record individual events of the setup process – for example “overview shown without a connected server”, “server connected”, “assistant opened” or “assistant cancelled”. Only the following is stored:

  • the type of event and the time
  • a pseudonym of your account (a hash value formed with a secret key, not a Discord ID)
  • where applicable, the Discord server ID concerned
  • a few technical details on the respective event (at most 512 characters, e.g. the result of an invitation, the number of servers found or the step reached in the setup assistant)

Username, Discord ID, email address and IP address are not stored. Neither cookies nor third-party analytics services are used; the data does not leave our server in Germany. The entries are deleted automatically after 90 days. You can have the entries stored for your pseudonym deleted earlier at any time (contact: see section 1). Legal basis: Art. 6(1)(f) GDPR (legitimate interest in an easy-to-understand setup and in improving the service).

7. Payment (PayPal), purchase confirmations and invoices

On our website, payment is made exclusively via PayPal (purchases directly in Discord: section 7c). PayPal (Europe) S.à r.l. et Cie, S.C.A., 22–24 Boulevard Royal, L-2449 Luxembourg, processes your payment data as an independent controller; you can find PayPal’s privacy policy at https://www.paypal.com/de/webapps/mpp/ua/privacy-full. We do not receive card or account details.

For a subscription we redirect you to PayPal. On the purchase page of a one-time purchase, your browser loads the payment buttons directly from PayPal; in the process, PayPal receives your IP address and information about your browser and may set its own cookies.

From PayPal we receive, at the time of purchase and afterwards via automatic notifications (for example on a renewal, cancellation or refund), the transaction or subscription number, the amount, the payment status and the email address stored with PayPal. We store your plan, its term, the subscription and transaction numbers and your purchases; we store the email address in your account entry (section 5). We use this information to activate your plan, to manage your subscription and to send you purchase confirmations, invoices and subscription-related messages (e.g. on renewal, cancellation or refund) by email. Legal basis: Art. 6(1)(b) GDPR.

So that these emails reach you in your language, we also store only the value “German” or “English” – derived from your language setting in the dashboard, from your choice of language or the language of your browser at the time of purchase and, if you are already a customer, from the language setting of your Discord client at login; if none of these is available, from the country that PayPal reports to us for your payment (we do not store the country itself). We use it exclusively for the language of these emails (Art. 6(1)(b) GDPR); you can request its deletion at any time (contact: see section 1).

For every purchase and every charge we issue an invoice, and for a refund a credit note – with your username, your Discord ID, your email address, the product, the amount and the PayPal transaction number – and file it in our invoice archive. We retain invoices for eight years from the end of the calendar year in which the invoice was issued (§ 14b(1) UStG, § 147(1) no. 4, (3) and (4) AO); after that we delete them. We keep the other details of your purchases for as long as your contract runs and afterwards for as long as we have to retain them as accounting records. Legal basis: Art. 6(1)(c) GDPR.

7a. Sending emails (Brevo)

We send all emails – purchase confirmations, invoices, messages about your subscription, acknowledgements of receipt of cancellations and withdrawals, the emails to the account holder (section 8a) and notifications to us – via the email service Brevo (Sendinblue SAS, registered office in France). Brevo processes the recipient address, the name and the content of the email on our behalf (processor, Art. 28 GDPR). Legal basis: the same as for the occasion of the respective email.

7b. Error monitoring (Sentry)

So that we can detect and fix technical errors, our server and our Discord bot send error reports to the service Sentry (Functional Software, Inc., 45 Fremont Street, 8th Floor, San Francisco, CA 94105, USA). An error report contains the type of error and the error message, the places in the program where it occurred, the address called, the time, technical information about the server and the last log lines before the error; it may contain Discord IDs as well as names of users and servers. For a small proportion of requests we also send response-time measurements. We do not transmit cookies, your IP address, the contents of forms and requests or the values that the program is processing at the time of the error. Email addresses and IP addresses that appear in an error message or log line, as well as access credentials such as tokens in addresses called, are redacted automatically before the report leaves our server. A message in an internal Discord channel notifies us of new errors.

Sentry stores the data in its EU region in Frankfurt am Main and processes it on our behalf (processor, Art. 28 GDPR). Because Sentry is a US company, access from the USA cannot be ruled out; Sentry is certified under the EU-US Data Privacy Framework (adequacy decision of the EU Commission, Art. 45 GDPR). Sentry deletes the error reports automatically when the retention period of our plan expires, at the latest 90 days after receipt. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in stable, error-free operation).

7c. Purchases in the Discord store

You can also buy Basic and Premium directly in Discord (“Buy via Discord”). Ordering, payment and renewal are then handled by Discord; Discord’s privacy policy applies to this (https://discord.com/privacy). We do not receive any payment data in this case.

For each purchase and later for each renewal, cancellation or refund, Discord informs us of: the identifier of the purchase, your Discord ID, the product purchased, the start and end of your entitlement and the identifier of the subscription. We store this information in our database on our server in order to activate your plan for as long as Discord reports the entitlement, and to match cancellations and withdrawals to your purchase. Legal basis: Art. 6(1)(b) GDPR. We delete the information automatically 90 days after your entitlement ends.

8. Contact form

When you use our contact form, we process the following data:

  • name
  • email address
  • Discord ID (optional)
  • content of the message
  • time of submission
  • a shortened hash value of your IP address (protection against mass requests)

We use the data only to handle your request. Legal basis: Art. 6(1)(b) GDPR if your request concerns or prepares a contract with us, otherwise Art. 6(1)(f) GDPR (legitimate interest in answering requests); we process the hash value of the IP address under Art. 6(1)(f) GDPR (protection against misuse). We delete your request as soon as it has been dealt with conclusively, but automatically no later than 90 days after receipt.

8a. Cancellation (“Cancel contracts here” and in the dashboard)

If you cancel via “Cancel contracts here”, we process the following data:

  • the type of cancellation (ordinary or without notice) and, for a cancellation without notice, the reason if you give one
  • the contract you are cancelling
  • the requested time for the contract to end
  • your name and your email address
  • if you provide it: your Discord name or your Discord ID (optional, only for matching)
  • date and time of receipt
  • if you are logged in to the dashboard at the same time: your Discord ID from the login (for matching)

We use this data to match the cancellation to your contract, to carry it out and to confirm receipt to you. For this purpose, we compare your email address and, if you provide it, your Discord name or your Discord ID with the details in our accounts. If you are logged in, we end your subscription via PayPal automatically right away, effective at the end of the paid period.

Without login, we additionally safeguard the implementation: if the details match exactly one account, we send an email to the address stored in that account. The account holder can then confirm the cancellation or stop it with “This wasn’t me”. If the account holder does not click, we carry out the cancellation automatically before the next charge – usually three days beforehand, at the earliest 24 hours after receipt; if the next charge is sooner, immediately – and afterwards send the account holder an email that it has been carried out, if an address is stored in the account. The links in these emails contain only a random identifier of the cancellation and a checksum, no name and no email address. The account holder does not learn your name and your email address. If the account holder stops the cancellation with “This wasn’t me”, we also stop further open cancellations for their account, review the case and, if necessary, contact you via the address you provided. If the account holder has already stopped a cancellation in this way in the last 30 days, we only carry out a further cancellation without login if the account holder confirms it – via the link in the email or with their own cancellation in the dashboard – and additionally review it manually. If the account holder cancels while logged in themselves, we close open cancellations for the same contracts. We store whether and when the account holder confirmed or rejected. In this way we protect customers against someone else ending their subscription. Legal basis: Art. 6(1)(b) and (f) GDPR (performance of the contract, protection against misuse).

We send the acknowledgement of receipt to you, the emails to the account holder and a notification to us via the email service Brevo (section 7a). Legal basis: Art. 6(1)(c) GDPR in conjunction with § 312k BGB (statutory obligation to provide the cancellation button and to confirm) and Art. 6(1)(b) GDPR (performance of the contract). We keep the cancellation as evidence until the regular limitation period expires: three years from the end of the year in which the contract ended (§§ 195, 199 BGB). We keep a cancellation stopped with “This wasn’t me” for three years from the end of the year in which it was received. After that we delete it.

If you cancel while logged in to the dashboard under Account › Cancel subscription, we process the same details. We take your name, email address and Discord ID from your account. If no email address is stored there, you enter one on the page; we store it only with this cancellation, not in your account. It is always an ordinary cancellation at the earliest possible date. We send the acknowledgement of receipt to this email address; it is also available on the page for you to save.

To protect against misuse, we count how many cancellations come from an IP address or – if you are logged in, on this page and in the dashboard – from your account, how many confirmations go to an email address and how often an IP address calls up the confirmation page from the email to the account holder. For this purpose we store only a shortened hash of the IP address, the Discord ID or the email address, not in the cancellation itself, and delete it after two days at the latest (for the confirmation page, one hour after the last call). Legal basis: Art. 6(1)(f) GDPR (protection against misuse).

You can voluntarily tell us why you are cancelling (a selection and a short text): with “Cancel contracts here” after submitting, in the dashboard on the same page together with the cancellation. This is not a prerequisite for the cancellation. We store the details together with the cancellation and use them only to improve our offer. Legal basis: Art. 6(1)(a) GDPR (your consent by submitting); you can withdraw it at any time by email.

8b. Withdrawal (“Withdraw from contract here”)

If you withdraw from a contract via “Withdraw from contract here”, we process the following data:

  • the contract you are withdrawing from – if you are logged in to the dashboard, the selected purchases from your account with date, amount and PayPal transaction or subscription number
  • your name and your email address
  • if you provide them: the order date, your Discord name or your Discord ID and a reason (all optional)
  • date and time of receipt
  • if you are logged in to the dashboard at the same time: your Discord ID from the login

We use this data to confirm receipt to you immediately (by email, on the page and for saving), to match the withdrawal to your contract, to check whether it is effective and to carry it out: we end the subscription and refund your payments via PayPal. For this purpose, we compare your email address and, if you provide them, your Discord details with the details in our accounts. If you are logged in, we stop the renewal of the selected subscriptions via PayPal automatically right away; without login, we do so after we have matched the withdrawal manually. Legal basis: Art. 6(1)(c) GDPR in conjunction with §§ 355, 356a and 357 BGB (statutory obligation to provide the withdrawal function, to acknowledge receipt and to make the refund) and Art. 6(1)(b) GDPR (unwinding of the contract).

We send the acknowledgement of receipt to you and a notification to us via the email service Brevo (section 7a); the refund is made via PayPal (section 7). We keep the withdrawal as evidence until the regular limitation period expires: three years from the end of the year in which it was received (§§ 195, 199 BGB). After that we delete it.

To protect against misuse, we count how many withdrawals come from an IP address or a logged-in account and how many acknowledgements of receipt go to an email address. For this purpose we store only a shortened hash of the IP address, the Discord ID or the email address, not in the withdrawal itself, and delete it after two days at the latest. Legal basis: Art. 6(1)(f) GDPR (protection against misuse).

8c. Feedback in the dashboard

If you send us feedback via the dashboard, we store the category, your text, an optionally attached image, your Discord ID, your username and the time. We also notify ourselves about it in an internal Discord channel (Discord, see section 3) with category, text, image and username. We use the feedback to fix errors and to improve our offer. Legal basis: Art. 6(1)(f) GDPR. We delete the feedback including the image and the notification in the Discord channel automatically 12 months after receipt.

8d. Votes on Top.gg

If you vote for our bot on top.gg, Top.gg (based in the USA, an independent controller) informs us of your Discord ID, the type of vote and whether it was cast on a weekend; we record the time ourselves. With this, we give you the voter role on our support server for 12 hours and show you how often you have voted. With the command /voteleaderboard, anyone on a server with our bot can display the ten users with the most votes together with their number of votes. We delete the information automatically 12 months after the vote. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in rewarding supporters). You can find Top.gg’s privacy policy at https://top.gg/legal/privacy.

9. Data on Discord servers (bot and bot settings)

If a server operator uses our bot on their Discord server, the bot processes data of the members of that server, depending on the functions that the operator switches on in the dashboard, for example:

  • Discord ID, name, profile picture, roles and time of joining
  • messages – for auto-moderation, for XP and levels and for logs of server events
  • tickets and their histories including attachments
  • applications and answers to forms
  • warnings, mutes, bans and other moderation records
  • ban appeals including attachments – also from people without an account with us who use the appeal link
  • birthdays, invitations (who invited whom), votes in polls, participation in giveaways, suggestions and reminders
  • time clock records as well as staff, employee, dues, cash register and storage lists (role-play servers)

The operator of the respective server is the controller for this data: they decide which functions run. We process the data only on their behalf as a processor (Art. 28 GDPR) under our data processing agreement. You should preferably address questions and requests concerning this data to the operator of the server; if they reach us, we forward them to the operator.

We store the settings of a server (e.g. ticket panels, reaction roles, Twitch channels) and the data of the functions in our database on our server (with a copy as a file), linked to the ID of the Discord server. For notifications about Twitch, YouTube and Instagram, the bot queries the public information of the entered channels from these services. If you remove the bot from your server, the settings and data initially remain stored so that you can invite it again without setting it up anew. If you do not add it again within 6 months, we delete them automatically once this period has expired. A custom bot that is linked to Asward-Helper in the dashboard counts like our bot: the period only begins once neither of them is on the server any more. If the bot was already removed before September 30, 2026, the period begins on that day. As long as the server is registered in the server slots of an account with an active paid plan, we do not delete its data even after the period has expired. On request we delete them earlier: an email to info@boxshopde.de is sufficient, and we then delete them without undue delay. Legal basis vis-à-vis you as the server operator: Art. 6(1)(b) GDPR.

10. Hosting, server logs and backups

Our services run on a server in a data centre in Germany. The server is provided by a hosting provider in Germany, which acts on our behalf (processor, Art. 28 GDPR). The database and cache run on the same server and cannot be reached from outside.

With every request, our server processes technically necessary information: IP address, time, address called, amount of data transferred and information about browser and operating system. We record accesses and errors in logs. We use them only to secure operation, to find errors and to ward off attacks; they are deleted with the regular, automatic rotation of the logs. Legal basis: Art. 6(1)(f) GDPR.

Once a day we back up the database and files on our server. The backups are accessible only for the administration of the server and are deleted after 30 days; deleted data may therefore still be contained in a backup for up to 30 days. Legal basis: Art. 6(1)(f) GDPR (protection against data loss).

11. Recipients and transfers to third countries

The following work on our behalf (processors under Art. 28 GDPR):

  • a hosting provider in Germany – server and storage (section 10)
  • Brevo (Sendinblue SAS, France) – sending emails (section 7a)
  • Sentry (Functional Software, Inc., USA; storage in the EU) – error reports (section 7b)

The following process data as independent controllers:

  • Discord – login, operation of the bot, support server, purchases in the Discord store, profile pictures and server icons (sections 3, 3a, 7c, 9)
  • PayPal – payments (section 7)
  • Top.gg – votes (section 8d)

Sentry is the only processor based outside the EU that we use (access from the USA cannot be ruled out; adequacy decision under Art. 45 GDPR). Discord, PayPal and Top.gg may also transfer data to the USA as independent controllers; details can be found in their privacy policies.

12. Your rights

Under the GDPR you have the following rights:

  • Access (Art. 15 GDPR): which data we have stored about you.
  • Rectification (Art. 16 GDPR): correction of inaccurate data.
  • Erasure (Art. 17 GDPR): deletion of your data.
  • Restriction (Art. 18 GDPR): restriction of processing.
  • Data portability (Art. 20 GDPR): transfer of your data.
  • Withdrawal of consent (Art. 7(3) GDPR): at any time, with effect for the future.
  • Objection (Art. 21 GDPR): see the box “Right to object”.

To exercise your rights, please contact: info@boxshopde.de

You also have the right to lodge a complaint with the competent data protection supervisory authority (in Baden-Württemberg: the State Commissioner for Data Protection and Freedom of Information Baden-Württemberg).

Right to object (Art. 21 GDPR)

If we process data on the basis of our legitimate interests (Art. 6(1)(f) GDPR) – for example for the support server, error reports, server logs, protection against misuse or votes on Top.gg – you can object to this at any time on grounds relating to your particular situation. An informal email to info@boxshopde.de is sufficient. We will then no longer process the data unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing serves the establishment, exercise or defence of legal claims.

13. Changes to this privacy policy

We reserve the right to update this privacy policy as required. The current version is always available at asward-helper.store/en/datenschutz.