🎁 New giveaways every week — join the Prize Cabin Discord for your chance to win free games!Join Discord
Privacy Policy

How we handle your data

Last updated June 2, 2026. How Prize Cabin collects, uses, and protects your personal data.

On this page
Who We AreWhat Data We CollectHow We Use Your DataWho We Share Data WithInternational Data TransfersHow Long We Keep DataYour RightsHow to Exercise Your RightsCookies and TrackingChildren's PrivacyAutomated Decision-MakingData SecurityChanges to This PolicyContact Us
Who We Are

Prize Cabin LLC is an Ohio limited liability company that operates the Prize Cabin Discord community and the website at prizecabin.net. This Privacy Policy describes how we collect, use, and protect your personal data when you use our services.

For the purposes of the EU General Data Protection Regulation (GDPR), the UK GDPR, and similar laws in other jurisdictions, Prize Cabin LLC is the data controller for personal data described in this Policy.

Registered mailing address: 4496 Mahoning Avenue #950, Youngstown, OH 44515, United States.

What Data We Collect

We collect only the data necessary to run giveaways, identify winners, and operate the community. Specifically:

From Discord authentication (required to log in):
Your Discord user ID (a numeric identifier)
Your Discord username
That you voluntarily provide:
Country of residence (collected when you claim a prize, used to verify eligibility and comply with U.S. sanctions law)
Information provided in support tickets (for prize delivery, residency confirmation, or other support requests)
Collected automatically from your use of the service:
Timestamp of when you first interact with our systems
Giveaway entries, wins, claim status, and delivery records
Daily message counts and voice channel time in our Discord server, collected via ScopliDrop's activity tracking feature
Collected automatically for fraud prevention:
A hashed device fingerprint generated from your browser when you sign in. The fingerprint is computed by a small open-source library that runs only on authenticated pages, never on public pages or to anonymous visitors.
A hashed version of your IP address. We do not store your raw IP — only a one-way hash that lets us compare network signals across accounts without retaining the address itself.
A hashed version of your browser user-agent string.

We use these hashed signals only to detect when one person is operating multiple accounts to gain an unfair advantage. Because each value is hashed with a server-side secret, it cannot be reversed back into a raw fingerprint, IP address, or user-agent — even if our database were compromised.

If you become a paid supporter:
Subscription tier, status, and dates
Payment is processed through MEE6 (which sells and manages subscriptions) and Stripe (which processes the payment). We do not receive or store your payment card details.
If you vote for our server on Top.gg:
Discord ID, timestamp, and whether the vote qualified for a reward
If you win a prize above the US tax reporting threshold:
We collect tax information required to report the prize to the IRS, including your legal name, address, and Taxpayer Identification Number (typically on IRS Form W-9 or equivalent).
How We Use Your Data

Under GDPR and similar laws, we must have a lawful basis for each way we use your data. Here's how we use it and why we're legally permitted to:

Operating the Discord community and website (authentication, displaying wins, enabling entry) — contractual necessity. We cannot provide the service without identifying you.
Delivering prizes you have woncontractual necessity.
Processing subscription paymentscontractual necessity.
Tax reporting for wins above the US reporting thresholdlegal obligation under US tax law.
Recording first-seen timestampslegitimate interest. Helps detect abuse patterns such as bot accounts and multi-accounting.
Detecting and preventing alternate-account fraudlegitimate interest. We compare hashed device fingerprints, IP addresses, and user-agents across accounts to identify when one person is operating multiple accounts to circumvent giveaway eligibility limits, marketplace rules, or supporter-tier benefits. Where we identify a likely violation, we may restrict the affected accounts from specific platform features such as earning in-platform credit or marketplace participation.
Activity tracking (message counts, voice time) — legitimate interest. Used by administrators to understand community engagement and participation trends.
Recording Top.gg votesconsent. You voluntarily vote; we record it only to award you the vote reward.
Who We Share Data With

We share only the minimum data required with third-party service providers (processors) that help us run the service. Each of these providers has its own privacy policy governing how it handles your data:

Discord — authentication and community hosting. discord.com/privacy
ScopliDrop — giveaway bot that processes entries and selects winners. scoplidrop.com/privacy-policy
Supabase — database and backend services. supabase.com/privacy
Vercel — website hosting and content delivery. vercel.com/legal/privacy-policy
MEE6 — subscription sales and management. mee6.xyz/privacy.html
Stripe — subscription payment processing. stripe.com/privacy
Top.gg — server listing and vote tracking (only if you vote). top.gg/privacy

We do not sell your personal data. We do not share your data with advertisers. We do not share your data with any party other than the processors listed above, except when required by law (for example, a valid court order or subpoena) or to protect the rights and safety of Prize Cabin or its community members.

International Data Transfers

Prize Cabin LLC is based in the United States. Most of our processors are also US-based. If you are accessing our service from the European Economic Area (EEA), the United Kingdom, or another jurisdiction with data protection laws, your data may be transferred to and processed in the United States.

For transfers from the EEA or UK to the US, we rely on our processors' own compliance mechanisms, which include certifications under the EU-US Data Privacy Framework and Standard Contractual Clauses where applicable. Each processor linked in the previous section documents its own approach to international transfers.

By using our service, you acknowledge that your data may be processed in jurisdictions whose laws may differ from those of your home country.

How Long We Keep Data

We keep your data only as long as necessary for the purposes described in this Policy, or as required by law. Specifically:

Account data (Discord ID, username) — while you are a member of the Discord server, plus a retention period after you leave for moderation and fraud-prevention purposes.
Giveaway records (game name, winner username, claim date) — retained indefinitely as part of our public giveaway history, which serves transparency and community trust. Winners' Discord usernames appear in the public history.
Subscription and payment records — retained as required by US tax and accounting law (generally at least 7 years).
Top.gg vote records — retained only as long as needed to track vote-reward eligibility.
Activity tracking data — daily per-day breakdowns are retained for 30 days and then automatically deleted by ScopliDrop. Lifetime totals (overall activity level) persist as part of your server profile until you leave the server.
Tax forms (Form W-9 and equivalents) — retained as required by IRS regulations (generally at least 7 years).
Hashed fraud-prevention signals (device fingerprints, IP hashes, user-agent hashes) — retained for up to 2 years from the date of collection, then automatically deleted. This window is long enough to detect alternate-account patterns that may emerge after a dormant period, while bounding how long any individual data point is held.

If you request deletion of your data under "Your Rights" below, we will delete or anonymize the data we can — but some records (notably public giveaway history and tax records) may be retained where legally required or where anonymization is sufficient to protect your identity.

Your Rights

If you are a resident of the European Economic Area, the United Kingdom, or another jurisdiction with applicable data protection law, you have the following rights regarding your personal data:

Right of access — request a copy of the personal data we hold about you.
Right to rectification — request correction of inaccurate or incomplete data.
Right to erasure ("right to be forgotten") — request deletion of your data, subject to legal retention requirements.
Right to restriction of processing — ask us to stop using your data while a dispute is resolved.
Right to data portability — receive a copy of your data in a common, machine-readable format.
Right to object — object to processing based on legitimate interests.
Right to withdraw consent — where we rely on consent, withdraw it at any time (this does not affect the lawfulness of processing done before withdrawal).
Right to lodge a complaint — complain to your local data protection authority if you believe we have handled your data improperly.

Residents of other jurisdictions (including certain US states) may have similar rights under applicable law. We will honor such rights where required.

How to Exercise Your Rights

To make a data request or ask a privacy question, open a ticket in the Prize Cabin Discord server. This is the fastest way to reach us.

Discord invite: https://discord.gg/2vYJRmgex8

You may also write to us by postal mail at: Prize Cabin LLC, 4496 Mahoning Avenue #950, Youngstown, OH 44515, United States.

We aim to respond to requests within 30 days, as required by GDPR. If your request is complex or we need more time, we will let you know.

We may need to verify your identity before acting on a request — this protects you from someone else trying to access your data. Typically we verify by confirming control of the Discord account the request concerns.

Cookies and Tracking

At present, Prize Cabin's website does not use cookies, tracking pixels, third-party analytics, or advertising trackers.

The site uses authentication tokens and browser storage required for Discord sign-in and core site functionality. These are essential to the service and do not track you across other websites.

If we add analytics, cookies, or other tracking technologies in the future, we will update this Policy and — where required by law — ask for your consent before enabling them.

Children's Privacy

Prize Cabin is intended for adults. Our Discord server requires members to be 18 or older, which is stricter than Discord's own minimum age requirement.

We do not knowingly collect personal data from anyone under 18. If you believe a minor has provided us with personal data, contact us (see "How to Exercise Your Rights" above) and we will delete it promptly.

Automated Decision-Making

Giveaway winners are selected at random by automated software (the ScopliDrop bot). We do not believe this constitutes "automated decision-making that produces legal or similarly significant effects" under GDPR Article 22, because:

Not winning a free giveaway does not produce a legal or similarly significant effect on you.
Winner selection is random and is not based on profiling or analysis of your personal characteristics.
All eligible entrants have an equal chance per entry; supporter tiers receive proportionally more entries, but each entry has the same random chance as any other.

Separately, we use automated checks to detect alternate-account fraud, and an account identified as high-risk may be automatically restricted from certain platform features (for example, earning in-platform credit or using the marketplace). Because such a restriction can have a significant effect, we apply the following safeguards:

Detection is graduated — an automated restriction is triggered only by stronger combined signals (such as multiple linked accounts, or a shared device together with a very new account or closely matching usernames), not by a single ambiguous signal.
You can request human review of any restriction by opening a ticket, and a confirmed-legitimate account can be exempted from automated restriction.
We use this profiling only to prevent one person from operating multiple accounts to gain an unfair advantage, and for no other purpose.

If this analysis is ever challenged or if we introduce features that might cross the Article 22 threshold, we will update this Policy and provide you with the additional rights it grants.

Data Security

We take data security seriously. Our technical and organizational measures include:

All data transmitted between your device and our services is encrypted using HTTPS.
Database access is restricted by row-level security policies that limit what each user can read or modify.
Sensitive identifiers used for fraud prevention (IP addresses, device fingerprints, user-agent strings) are stored only as one-way hashes salted with a server-side secret, so they cannot be reversed into raw values even with full database access.
Prize keys are sealed on the server and are not revealed to anyone — including the winner — until the winner explicitly requests reveal.
Secrets (API keys, webhook tokens) are stored in secure, restricted environment variables and are rotated when needed.
Sensitive backend operations use server-side API routes with service-role credentials rather than exposing them to the browser.
Administrator access to backend data is restricted to authorized Discord accounts.

No system can be guaranteed perfectly secure. In the event of a data breach that affects your personal data, we will notify affected users and appropriate regulatory authorities as required by applicable law.

Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date at the top of this page.

For material changes, we will announce the update in the Prize Cabin Discord server.

For material changes, we may ask you to acknowledge the updated Policy the next time you sign in. For non-material changes, your continued use of the service after the change means you accept the updated Policy.

Contact Us

For privacy-related questions, data requests, or complaints:

Open a ticket in our Discord server: https://discord.gg/2vYJRmgex8
Postal mail: Prize Cabin LLC, 4496 Mahoning Avenue #950, Youngstown, OH 44515, United States.

Residents of the EEA or UK also have the right to lodge a complaint with their local data protection supervisory authority.