SiriusMC Logo

play.siriusmc.net

24 players online

Join our Discord

804 users online

Privacy Policy

Effective: 8 May 2026 · Version 1.0.0

See also our Cookie Policy.

1. Introduction

SiriusMC operates a network of modded Minecraft servers and the website at siriusmc.net (the "Site"). This Privacy Policy explains how we collect, use, share and protect your personal data when you visit the Site, open a support ticket, link your Minecraft account, or otherwise interact with us off-server.

In-game data captured on our Minecraft servers (chat logs, gameplay actions, sanctions) and purchases made through our separate store-front, FluxStore, aren't covered in detail by this Policy. They have their own arrangements. Contact us if you need information about in-game data, or see the FluxStore privacy notice for purchases.

If anything in this Policy isn't clear, or you have a question about how we handle your data, please get in touch using the details in Section 15.

2. Who we are (Data Controller)

The data controller for personal data processed through the Site is SiriusMC Networks (United Kingdom).

For all data-protection enquiries, contact us at [email protected].

3. What personal data we collect

3.1 Account and authentication data

When you sign in to the Site (for example, to manage support tickets) we use Auth0 as our identity provider. Auth0 processes your Minecraft account identifier, email address (if you chose to provide one), and authentication metadata (login timestamps, session tokens) on our behalf.

3.2 Support ticket data

When you open a support ticket we collect: the linked Minecraft account identifier, your name (or display name), the subject and body of your ticket including any attachments, and any subsequent correspondence with our staff team. Tickets are confidential to you and our staff.

3.3 Player linking data

If you link your Minecraft account to the Site, we store your Minecraft UUID and the Discord identifier (where applicable) used for linking, plus a record of when the link was established.

3.4 Technical and platform data

When you visit the Site we automatically collect:

  • IP address and rough geographic location (country/region)
  • Device, browser and operating-system information
  • Pages requested, referring URL, and timestamps
  • Application error reports (stack traces, request metadata) collected via Sentry

3.5 Communications

If you email us, message us via Discord, or otherwise contact us off-Site, we keep a record of that correspondence so we can follow up.

3.6 Sensitive data

We do not intentionally collect special-category personal data (such as health, ethnicity, political opinions or religious beliefs). Please do not include such information in support tickets or correspondence.

4. How we collect your data

  • Directly from you when you log in, open tickets, link an account, or contact us.
  • Automatically via your browser when you visit the Site, including server logs, cookies (covered in our Cookie Policy), and error monitoring.
  • From third-party identity providers (Auth0 and, where applicable, the Minecraft and Discord platforms) when you authenticate.

5. How we use your data and our lawful basis

Under UK GDPR we must have a lawful basis for each purpose we use your data for. The table below summarises the main purposes and the basis we rely on:

PurposeLawful basis
Operating the Site, authenticating users, and fulfilling support requestsPerformance of a contract / steps prior to entering one (Art. 6(1)(b) UK GDPR)
Securing the Site, preventing abuse, debugging errorsLegitimate interests (Art. 6(1)(f)): keeping the service available and safe
Complying with legal obligations (e.g. responding to lawful requests)Legal obligation (Art. 6(1)(c))
Enforcing our community rules and protecting other playersLegitimate interests (Art. 6(1)(f))

Where we rely on legitimate interests we have carried out a balancing test and consider that those interests are not overridden by your fundamental rights. You can object to such processing; see Section 11.

6. Who we share your data with

We do not sell your personal data. We share it only where necessary with the following categories of recipient:

  • Our staff team, under confidentiality, where they need access to handle a ticket, sanction, or technical issue.
  • Service providers (data processors) acting on our instructions. See Section 13 for the current list.
  • Law enforcement, regulators or courts where we are legally required to disclose information, or where doing so is necessary to protect our rights, property or the safety of others.
  • Successors in the event of a sale, merger or reorganisation of the SiriusMC network. You would be notified before any such transfer.

7. Cookies and similar technologies

The Site currently uses only strictly necessary cookies and similar technologies, mainly to keep you logged in and to protect the Site from abuse. We don't use analytics, advertising or tracking cookies. If that changes we will add a consent mechanism first. For the full list, see our Cookie Policy.

8. International data transfers

Some of our service providers (notably Auth0, Sentry, Discord and our hosting/CDN providers) are based outside the UK and may process your data in the United States or elsewhere. Where personal data is transferred outside the UK we rely on appropriate safeguards under UK GDPR Articles 44–49, including:

  • UK adequacy regulations, where the destination country is recognised as adequate;
  • The UK Extension to the EU-US Data Privacy Framework, where the recipient is certified under it;
  • The UK International Data Transfer Agreement (IDTA), or the EU Standard Contractual Clauses (SCCs) supplemented by the UK Addendum;
  • Binding corporate rules where the recipient has them in place.

You can request a copy of the safeguards we rely on by contacting us.

9. How we protect your data

We apply appropriate technical and organisational measures, including:

  • HTTPS/TLS for all traffic to and from the Site;
  • Encryption of data at rest where supported by our service providers;
  • Role-based access controls limiting who on our team can see ticket and account data;
  • Rate limiting, abuse detection and audit logging;
  • Periodic review of access and integrations.

If a data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the Information Commissioner's Office (ICO) within 72 hours and inform affected users without undue delay where required by UK GDPR.

10. How long we keep your data

We keep personal data only as long as necessary for the purposes set out in this Policy and any legal obligations. Indicative retention periods:

  • Account / authentication data: for as long as your account is active, and up to 30 days after deletion to handle disputes and abuse.
  • Support tickets: up to 24 months after the ticket is closed.
  • Sanctions / moderation records: for the duration of the sanction and up to 3 years afterwards for community-safety purposes.
  • Server access logs and error reports: typically up to 30 days.
  • Linked-account records: until you unlink the account, plus a short retention window for audit purposes.

Where retention is governed by law (for example, tax or accounting records), longer periods may apply.

11. Your rights

Under UK GDPR you have the following rights, which you can exercise free of charge in most cases:

  • Access to a copy of the personal data we hold about you.
  • Rectification of inaccurate data.
  • Erasure of your data (the "right to be forgotten"), in certain circumstances.
  • Restriction of how we process your data while a query is being resolved.
  • Portability of your data in a structured, commonly-used, machine-readable format.
  • Objection to processing based on legitimate interests.
  • Withdrawal of consent at any time, in any case where we rely on consent.
  • The right not to be subject to solely automated decision-making that has legal or similarly significant effects.

To exercise any of these rights, email [email protected]. We will respond within one month and may need to verify your identity first.

You also have the right to lodge a complaint with the UK's supervisory authority, the Information Commissioner's Office (ICO), at ico.org.uk/make-a-complaint (helpline: 0303 123 1113). We'd appreciate the chance to address your concerns first.

12. Children

The Site is not directed at children under 13. Where we rely on consent to process personal data of a child under 13 in the UK, we require verifiable parental consent in line with UK GDPR. If you believe we hold personal data about a child without proper consent, please contact us and we will delete it.

13. Third-party services we use

The following processors act on our behalf or provide services we use to run the Site. Each has its own privacy practices which we recommend you review:

  • Auth0 (Okta) for authentication. Privacy
  • Sentry for error monitoring. Privacy
  • Discord for community and account-linking integrations. Privacy
  • Cloudflare for content delivery and security. Privacy

14. Changes to this Policy

We may update this Policy from time to time. The "Effective" date and version at the top reflect the latest revision. If changes are material we will give reasonable notice (for example, via a banner on the Site) before they take effect. The updated Policy applies to processing we carry out from its effective date.

15. How to contact us

For privacy queries, requests or complaints, email [email protected]. We aim to respond within 30 days.

© 2026 SiriusMC. All rights reserved.