Privacy Policy
Last updated: 15 August 2026
This Privacy Policy explains what personal data NexaServe ("we", "us", "our") collects when you use our website, dashboard, and modules (the "Service"), why we collect it, who we share it with, and the rights you have over it. NexaServe is the data controller for the personal data described here. This policy should be read alongside our Terms of Service.
1. Data we collect
Account & identity data. When you sign in, we receive your Discord user ID, username, avatar, and — where your Discord account provides it — your email address, plus whether you're a member of our Discord server. This is how your account with us is identified; we don't run a separate email/password signup.
Payment data. Subscription purchases are processed by Stripe — your card details are entered directly into Stripe's own hosted payment form and never reach our servers. We keep a record of the purchase itself (plan, amount, date, Stripe's reference for it), and, for chargeback/dispute purposes, a record that you agreed to our Terms before completing the purchase (timestamp, IP address, which version of the Terms).
Card details for a Third-Party Platform booking. Certain modules complete a real transaction (for example, a ride or ticket) on a Third-Party Platform using a card you provide for that purpose. Those details are transmitted securely and, if retained at all, are stored only in encrypted form — solely so you can see your own transaction history, continue an in-progress transaction, or so we can help troubleshoot a problem you report. We do not use this data for any other purpose and do not sell it.
Your connected Google account (Eats Promo Manager only). If you choose to connect a Google account to the Eats Promo Manager module, we access your Gmail inbox — read-only scanning plus the ability to apply/remove a single label we create — solely to find and organise Uber Eats promo emails on your behalf. We never read, use, or share this data for advertising, and we don't hand it to anyone except as needed to run that feature for you. See Section 8 for our formal Google API statement. You can disconnect this at any time from the module's settings, which revokes our access immediately.
Data used to operate a module on a Third-Party Platform. Several modules sign up for, sign into, or otherwise act on an account on a Third-Party Platform on your behalf — this can involve an email address (yours, or one generated for the purpose), a phone number (rented for the duration needed), and similar details. This is used only to carry out the action you asked for.
Usage & technical data. IP address, browser/device information, timestamps, and security signals (used for rate-limiting, fraud/bot detection, and to keep the Service working reliably) — collected automatically as part of running the Service.
Communications. Messages you send us for support (including via our live chat, which is bridged to a private Discord channel), reviews you submit, and similar content you choose to give us.
2. Why we use it, and on what legal basis
- To provide the Service you asked for — signing you in, running a module, processing a purchase, replying to support — necessary to perform our contract with you.
- To keep the Service secure and working — fraud/bot detection, rate-limiting, debugging — our legitimate interest in running a reliable, abuse-resistant service, balanced against your rights.
- To meet legal obligations — for example keeping records needed for tax, accounting, or responding to a lawful request.
- Where you've given consent — most notably connecting a Google account for Eats Promo Manager, which you can withdraw at any time by disconnecting it.
3. Who we share data with
We share data only where it's needed to provide the Service:
- Stripe — payment processing.
- Discord — authentication and, if you use live chat, message delivery.
- Google — only for accounts that connect Eats Promo Manager, and only for that feature.
- The relevant Third-Party Platform — whichever one a module you're using is actually acting on (for example, the platform a booking or account action is being made with), to the extent needed to carry out that specific action.
- Our hosting and infrastructure providers, who process data on our behalf under their own confidentiality and security obligations, strictly to run the Service.
- Law enforcement or a regulator, if we're required to by law, or to protect our rights, users, or the public (for example, investigating fraud).
We do not sell your personal data, and we do not share it with anyone for their own marketing purposes.
4. International transfers
Some of the providers listed above (including Stripe, Discord, and Google) are based outside the UK/EEA. Where that's the case, we rely on the legal safeguards recognised under UK data protection law (such as the provider's own standard contractual clauses or an applicable adequacy arrangement) to make sure your data stays protected.
5. How long we keep data
We keep personal data for as long as your account is active, plus a reasonable period afterwards to meet legal, accounting, dispute-resolution, or fraud-prevention needs. Card details you provide for a Third-Party Platform booking are kept, encrypted, only for as long as they're useful to you for the purposes in Section 1 — you can ask us to delete this at any time (Section 6). Google account access for Eats Promo Manager is used only while connected; disconnecting stops all further access.
6. Your rights
Under UK GDPR, you have the right to:
- ask for a copy of the personal data we hold about you;
- ask us to correct inaccurate data;
- ask us to delete your data, or restrict how we use it, in certain circumstances;
- object to us processing your data where we rely on legitimate interests;
- ask for your data in a portable format, where technically feasible;
- withdraw consent at any time, for anything we process on that basis (like the Google connection) — this doesn't affect anything already done before you withdrew it.
To exercise any of these, contact us using the details in Section 9. You also have the right to complain to the UK Information Commissioner's Office (ico.org.uk) if you think we've mishandled your data — we'd appreciate the chance to sort it out directly first.
7. Cookies & similar technology
We use a session cookie to keep you signed in, and a small number of other cookies/local storage entries for security (anti-fraud/anti-replay signatures, CSRF protection) and for specific features to work (like a trial-offer link remembering it's already been used on your device). These are functional/essential — we don't use third-party advertising or tracking cookies.
8. Google user data & the Eats Promo Manager module
NexaServe's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Gmail data accessed through Eats Promo Manager is used only to identify and label Uber Eats promo emails at your request, is never used for advertising, is never used to train generalised AI/ML models, and is never transferred to a third party except as strictly necessary to provide that feature or to comply with the law. You can review and revoke this access at any time from your Google Account settings, or by disconnecting it in the module itself.
9. Children
The Service is not directed at, and must not be used by, anyone under 18 — see our Terms of Service. We don't knowingly collect data from anyone under that age.
10. Security
We use reasonable technical and organisational measures to protect the data we hold, including encryption at rest for sensitive fields such as card details and connected-account tokens, and access controls restricting who can view them. No system is completely secure, but we work to keep data protected in line with the sensitivity of what we hold.
11. Changes to this policy
We may update this policy from time to time. If we make a material change, we'll take reasonable steps to let you know, the same way as described in our Terms of Service. Continuing to use the Service after a change takes effect means you accept the updated policy.
12. Contact
Questions about this policy, or want to exercise one of your rights? Reach us on Discord, or by email at [email protected].