This policy explains what data LazyTickets handles, why, who we share it with and how you can exercise your rights. It covers this website (lazytickets.io), the panel (app.lazytickets.io) and the Discord bot.
1. Who is responsible
Who runs LazyTickets — full legal name, tax number and postal address — will be published here before any paid plan can be bought. Until then, for anything about these documents or your data, write to hola@lazytickets.io.
2. What we handle
If you visit this website
- No analytics and no advertising. There are no tracking cookies and no third-party pixels.
- We set one cookie,
lazybot.locale, holding the language you pick, for one year. It is a functional cookie: without it the site would not remember your language. - Our hosting provider and Cloudflare, which serves the site, log technical details of each request (IP address, browser, page requested) to deliver it and protect it from abuse.
If you sign in to the panel with Discord
- From your Discord account: your id, username, display name, avatar and, if you allow it, your email address.
- Which servers you can open in the panel, and with which role. When you sign in we read your list of Discord servers to work this out, but only keep the ones the bot is in.
- A session cookie,
lazybot_session, which expires after 8 hours, and another,lazybot.guild, that remembers the server you had open. Your browser also keeps whether you collapsed the sidebar.
If you are a member of a server that uses the bot
The bot handles what it needs to run that server's tickets:
- The messages, attachments and events of your tickets (who opened it, who handled it, when it closed) and, if the server turns it on, the rating you leave.
- The ticket's transcript when it closes, which the server can share by link.
- If the server turns the AI on: the questions you ask in the channels where the AI answers, and short notes about you that the AI keeps so it does not ask you the same thing twice (the platform you use, for example). Those notes belong to that server alone and never show up on another.
- If you are staff: what is needed to work out staff payouts, if the server uses that feature.
If you run a server
- The bot's and the panel's settings.
- The documentation you connect or upload for the AI to answer from.
- The panel's change log and your server's AI usage.
If you buy a plan
Payments are processed by Stripe. We never see or store your card details. We keep your Stripe customer id, what you bought, when and for which server, and the billing details Stripe sends back to us.
3. Why we use it, and on what legal basis
- To provide the service you or your server asked for: opening and handling tickets, making transcripts, showing the panel, answering with the AI when it is on. Basis: performance of a contract (Art. 6(1)(b) GDPR).
- To take payment and keep the accounts. Basis: the contract, and our tax and accounting obligations (Art. 6(1)(b) and 6(1)(c)).
- Security and abuse prevention: technical logs, usage limits, isolation between servers. Basis: our legitimate interest in keeping the service safe (Art. 6(1)(f)).
- Answering your messages when you write to us. Basis: our legitimate interest in replying or, if you are a customer, the contract.
We do not sell your data, we do not advertise with it, and we do not use it to train AI models.
Each server's role
Whoever runs a Discord server decides to use LazyTickets there: which categories exist, who sees the tickets, whether transcripts are kept and whether the AI is on. For the content of a server's tickets, we handle the data on that server's behalf and as it has configured things. If you want something removed from a particular server, the quickest route is to ask its staff; you can also write to us and we will help.
4. Who we share it with
Only with the providers we need to run the service, each for its own part:
- A hosting provider in the European Union: the servers and the database.
- Cloudflare: delivering the website and storing attachments and transcripts.
- Discord: the platform the bot runs on. Discord handles your data under its own privacy policy.
- Stripe: payments and invoicing.
- Anthropic, OpenAI and MiniMax: only when a server turns the AI on. They receive the text needed to write each answer (the question, the ticket's context and the relevant parts of the server's documentation) and, in OpenAI's case, the documentation so it can be indexed. We do not send them your email or payment details.
We may also disclose data to the authorities where a law requires us to.
Transfers outside the European Economic Area
Cloudflare, Discord, Stripe, Anthropic and OpenAI are based in the United States, and MiniMax outside the European Economic Area. When data leaves the EEA it does so with the safeguards the GDPR requires, such as the EU-US Data Privacy Framework where the provider is certified, or the European Commission's standard contractual clauses.
5. How long we keep it
- Your panel account: while you use it. It is refreshed each time you sign in, and we delete it if you ask.
- Session: 8 hours.
- Transcripts: as long as each server sets; on the free plan, 180 days at most.
- The AI's notes about a member: notes about a one-off situation expire after 30 days; lasting ones are kept until they are replaced or the server deletes them from the panel.
- A server's data (settings, tickets, documentation): while the server uses the bot. If the bot is removed, it is kept so the bot can be added back without losing anything, until the server's admins ask us to delete it.
- Purchases and invoices: as long as tax and accounting law requires.
- Technical logs: the minimum our providers need to keep the service secure.
6. Your rights
You can ask us to access, correct or delete your data, to restrict or object to how we use it, or to receive it in a portable format. Write to us from the email address or Discord account you use LazyTickets with, so we can check it is you, and we will reply within one month.
If you think we have mishandled your data, you can complain to the Spanish Data Protection Agency (aepd.es) or to the data protection authority in your country.
7. Minimum age
The panel and buying plans are for people aged 16 or over. If we learn we have collected data through the panel from someone younger, we will delete it.
8. Security
Everything travels encrypted. Each server's data is isolated from every other server's: the panel only shows a server to people with permission on it, and checks again with Discord at short intervals. Access to the infrastructure is limited to the people who maintain it.
9. Changes to this policy
If we change this policy, we will update the date at the top. If the change is significant, we will announce it in the panel or on our Discord server before it takes effect.