Data protection
Privacy Policy
We collect as little as a community server can: what you hand us at sign-in, what your bus reports on duty, and what Stripe needs to bill you. This page sets out all three, and your rights over them.
Last updated 6 October 2026.
The service is operated by Alex Pedley, trading as depart.cloud, based in Scotland.
- Contact: [email protected]
What data we collect
We collect as little as a community server can, and every bit of it is listed here.
Account data, via Discord. Accounts are created only by signing in with Discord. When you do, we receive and store:
- your Discord-verified email address;
- your Discord display name and avatar;
- your Discord user ID, which also sits in your avatar's web address;
- a crew name (an "OMSI username"), assigned on joining and usable across the network, like Alex#4821.
Duty-record data (depart.HR). If you drive on a depart.cloud server, the game server reports your activity and we record it:
- duty sessions: start and end times, duration, route or line, tour, and the map and bus used;
- derived figures: lifetime and monthly hours, favourite line, and familiarisation "certificates";
- live status while you are on duty: current line, tour, destination, vehicle, speed and position.
Playing requires no account, but activity on a server is always recorded against the crew name in use.
Payment data, for supporters. Subscriptions are billed through Stripe. We send Stripe your email address and display name, and link your account to the resulting Stripe customer and subscription IDs. Your card details never reach us. We store only your Stripe customer ID and your supporter expiry date, and we send no marketing of any kind.
Technical and security data.
-
a single essential cookie (
_departcloud_key) that keeps you signed in after you sign in with Discord. It is first-party and does not track you; - server and request logs kept by our hosting provider for security and troubleshooting;
- minute-scale rate-limit records, in memory, to prevent abuse.
We use no analytics, advertising or social-media tracking tools, and we set no advertising or tracking cookies.
What is published publicly.
- Public boards, always: the live status page, duty boards and hours board are public. They show crew names and duty activity (who is on duty now, routes, hours) for anyone driving on the servers, whether or not they have a website account.
- Public profile, only if you publish it: your profile appears at depart.cloud/people/your-name only if you are a supporter and you set your public handle. It shows your display name, avatar, supporter badge, joined date, duty record, certificates and service history. It does not show your email address. Clearing your handle unpublishes it.
Why we use your data, and the lawful bases
UK GDPR and, for visitors from the EU, the EU GDPR govern what we do. Every purpose and its basis:
- Operating your account, recording your duty history, providing depart.HR: contract, meaning the performance of the service you signed up for.
- Recording duty activity on servers under a crew name for the duty record and public boards: contract with crew members, and legitimate interests in operating a multiplayer service whose community record is its core feature.
- Taking supporter payments and managing subscriptions: contract.
- Keeping the service secure, rate-limiting, logging and enforcing the rules: legitimate interests.
- Publishing your public profile: your informed choice. You publish it by setting the handle yourself, and can unpublish it at any time.
- Complying with legal obligations, such as tax records for payments: legal obligation.
Where we rely on legitimate interests, you can object (see your rights).
Who we share data with
We do not sell your data. We share it only with:
- Discord, you sign in with Discord, and Discord acts as controller of your use of its platform (see Discord's own privacy policy).
- Stripe, payment processor for supporter subscriptions, processing your payment and contact details as our processor, and as a controller for its own fraud-prevention and legal purposes (see Stripe's privacy policy).
- Hosting providers, datacentre and infrastructure providers acting as processors for us, in the UK or EU or under UK adequacy arrangements.
- Authorities, where required by law, court order, or to protect the rights, property or safety of the service and its users.
We do not currently transfer personal data outside the UK. If that changes, for example to use non-UK hosting or processors, we will only do so using lawful transfer safeguards such as the UK IDTA or the UK International Data Transfer Addendum, or an adequacy decision, and will update this policy.
Cookies
We use exactly one cookie: the essential, first-party session cookie that keeps you signed in after you sign in with Discord. There are no analytics cookies, no advertising cookies and no third-party cookies on the site. This cookie is strictly necessary for the service you ask for, so we do not ask consent for it.
How long we keep data
- Account data: for as long as your account exists, and for a short period afterwards if you ask for deletion.
- Duty-record data: for as long as your account exists. The duty record is cumulative by design: lifetime hours, service history. A public profile is visible for as long as you keep your handle set.
- Payment records: for as long as UK tax and accounting law requires (currently six years).
- Logs and rate-limit records: short retention, typically days to weeks, following the hosting provider's defaults.
Your rights
You hold the right:
- To be informed (this policy) and to access a copy of your data;
- To rectify inaccurate data; most profile data can also be edited on the site itself;
- To erasure of your data (see below);
- To restrict processing while a dispute is resolved;
- To data portability, where processing is based on contract or consent and is automated;
- To object to processing based on legitimate interests;
- To withdraw consent at any time, where we rely on it;
- To complain to a supervisory authority.
To exercise any right, contact us from the contact details below. We answer within one month.
Deletion. We will delete your account data (email, Discord identity links, public profile) on request. Because the duty record is a shared community history, we will anonymise previously recorded duty sessions, removing the link to you, rather than erase the historical figures, unless you ask us to delete those too. Statutory retention periods for payment records still apply.
Complaints. You may complain to the UK Information Commissioner's Office at ico.org.uk, or, if you are in the EU, to your national supervisory authority.
Security
Personal data stays on access-controlled infrastructure in the UK or EU. Traffic is HTTPS throughout, sessions run on a signed and encrypted cookie, and every payment webhook is HMAC-verified before a byte of it is trusted. Access is limited to the people operating the service, and Discord OAuth tokens are stored as sensitive values and never displayed.
Children
The service is not aimed at children under 13, and you must be at least 13 to have an account. If you believe a child under 13 has given us personal data, contact us and we will delete it.
Changes to this policy
We will post any change on this page and update the date at the top. If a change is material, we will also announce it clearly on the site itself.
Contact
Email [email protected] .