This Privacy Policy explains what information Positions (“we”, “us”) collects when you use this website and game, how we use it, and your choices. By using the Service, you agree to this policy.
1. Information we collect
- Account details — when you create a website account: your chosen username, email address, and (if you set one) a password, stored only as a securely salted hash, never in plain text.
- Google Sign-In — if you sign up or sign in with Google, we receive your Google account's email address, name, and a Google account ID through Google's OAuth service, so we can create or match your account. We do not receive your Google password. Accounts created this way have no password until you set one.
- Roblox account link — if you link your Roblox account, we receive your Roblox user ID and username through Roblox’s OAuth service. We do not receive your Roblox password.
- Discord sign-in — if you use our Discord verification bot (
/prompt) or optionally link Discord on your Account page, we receive your Discord user ID and username through Discord's OAuth service, to link your Discord account to your Roblox account (bot) and/or your website profile (optional link). We do not receive your Discord password. - Account standing — moderation information such as warnings or bans and their reasons.
- Session data — a login cookie to keep you signed in, and standard technical logs (such as IP address and request info) processed by our hosting provider for security and reliability.
2. How we use your information
- To create and manage your account and keep you signed in.
- To connect your website account to your in-game identity for moderation and account standing.
- To assign the correct role (Verified/Unverified) in our Discord server once you link your Discord and Roblox accounts.
- To enforce our rules — for example, applying warnings or bans across the game and website.
- To keep the Service secure and prevent abuse.
3. Cookies
We use a single essential cookie to keep you logged in (a session token). We do not use advertising or tracking cookies.
4. Third-party services
- Google — signing in/up with Google uses Google OAuth (Google Sign-In). We request only your basic profile info — name, email address, and Google account ID — to create or match your Positions account. We do not receive your Google password, and we do not access your Gmail, Google Drive, or any other Google data beyond this basic profile. Your use of Google is governed by the Google Privacy Policy.
Positions's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We do not sell this data, use it for advertising, or share it with third parties beyond what is described in this Privacy Policy.
- Roblox — account linking uses Roblox OAuth. Your use of Roblox is governed by the Roblox Privacy Policy.
- Discord — our verification bot and the optional website account link use Discord OAuth. We request only your basic profile info — Discord user ID and username — never your Discord password, messages, or server data beyond what's needed to assign your Verified role. Your use of Discord is governed by the Discord Privacy Policy.
- Brevo — we use Brevo to send account and update emails on our behalf.
- Cloudflare — the website, database, and API are hosted on Cloudflare, which processes technical/security data on our behalf.
5. Storage, security & sharing
Your data — your account details, your linked Roblox profile (ID and username), and the account-standing data we create for moderation — is stored in a database hosted on Cloudflare. Passwords are only ever stored as a secure hash, never in readable form.
We do not sell, rent, transfer, or use your data for personal gain, and we only disclose it if required by law. We rely on Cloudflare’s infrastructure for storage and security; if Cloudflare’s own systems are ever compromised by an attack outside of our control, we cannot be held responsible for that breach. We only store the limited profile and moderation data described above — no payment details, addresses, or similar sensitive personal information.
6. Data retention & deleting your account
We keep your account information while your account exists. You can delete your website account at any time — this permanently removes your website data (your account, linked Roblox info, and account-standing records on this site). Note:
- Your in-game progress stays. Deleting your website account does not remove Roblox-side game data such as your levels or XP — that lives on Roblox, not with us.
- Moderation can still apply. If your account was suspended or terminated, that punishment can still be enforced in-game through your Roblox account even after you delete your website account.
7. Children’s privacy & parental consent
Positions is used by people of many ages, including children, and we collect only the limited information described above. If a child creates or uses an account, we assume that their parent or guardian has given consent for them to do so.
If you are a parent or guardian and want your child's account and data deleted, the only way is to log into that child's account and press the “Delete account” button on the settings page. This permanently removes the account and its data. We cannot delete accounts through other requests because we can't otherwise verify who owns the account.
8. Your choices & rights
- You can download a copy of your data at any time from your account page.
- You can unlink your Roblox account or delete your website account.
- To exercise any of these, contact us using the details below or use the built-in web account features.
9. Changes to this policy
We may update this Privacy Policy as the Service evolves. Continued use after changes means you accept the updated policy.
10. Contact
Questions or requests? Reach us on our Discord server or by email at 1chenyipreal@gmail.com.
Positions is not affiliated with, sponsored by, or endorsed by Roblox Corporation.
