Legal

Privacy Policy

What we collect, why we are allowed to, how long we keep it, and what you can ask us to do about it.

Last updated 24 September 2026

Server rules

This Privacy Policy explains how we collect, use, store, and share personal data when you use our website, whitelist application, web store, Discord integrations, and our FiveM game server.

By using our website or connecting to our server, you automatically agree to this policy and all its statements.

Summary

The short version. The sections below give the detail, and if anything here differs from them, the detailed sections apply.

  • You sign in with Discord. We do not run passwords or email accounts for players.
  • Before the whitelist quiz we run an automated verification check on your IP address and device to block ban evasion and duplicate accounts. IP addresses and device fingerprints are stored hashed, and verification records are kept for 90 days.
  • Connections from a VPN, proxy, hosting provider, or Tor exit are refused. When a check suggests an application is linked to another account, a staff member reviews it - it is never decided automatically.
  • Store payments are handled by Tebex. We never collect or store card numbers.
  • To let you play, we process the identifiers FiveM makes available (such as your license and Discord ID) and your IP address.
  • We use no advertising or analytics trackers, and we do not sell personal data.
  • You have rights over your data, including access, correction, and objection. See Your rights.

Scope

This policy covers:

  • Website at atleast.lv (home, rules, whitelist application, store, and related authentication flows).
  • FiveM server operated under the ATLEAST RP / Atleast.lv branding, including queue, whitelist gate, gameplay accounts, moderation, and store delivery.
  • Supporting systems we operate that the website and server call, and our Discord integrations used for authentication, whitelist, roles, and staff moderation alerts.

It does not cover how third parties process data under their own policies - see Third-party services.

What we collect

Website and Discord sign-in

When you sign in with Discord on our website, we receive Discord account information through Discord OAuth. We store in your website session:

  • Discord user ID
  • Discord username
  • Display name, including the Discord global name where available
  • Avatar URL or reference

The OAuth scopes we request are identify and guilds.

We also process technical data for the website session:

  • Session cookie and session identifier
  • IP address
  • Browser user agent
  • CSRF and framework security cookies typical of a Laravel application

Whitelist verification

Before you can start the whitelist quiz, we run an automated check whose purpose is to block ban evasion, duplicate accounts, and connections that hide their origin. For that check we process:

  • Your IP address and the approximate country it resolves to
  • The network operator (ASN) the address belongs to
  • A device fingerprint derived from characteristics your browser exposes, such as screen size, time zone, language, fonts, and graphics capabilities
  • A persistent identifier stored in a cookie and in your browser's local storage
  • The result of a Cloudflare Turnstile anti-bot check
  • The age of your Discord account, derived from your Discord ID

IP addresses and device fingerprints are stored hashed with a secret server-side value. We keep the hashes so we can tell whether two applications came from the same device or network, not to identify you personally or to track you across other websites.

We compare these signals with earlier applications. A connection identified as a VPN, proxy, hosting provider, or Tor exit is refused automatically. Where signals suggest an application is linked to another account, it is placed in a queue for a staff member to review - that decision is never made automatically against you.

Verification records are kept for 90 days. Hashed matching signals and staff decisions may be kept longer, because they are what prevents a banned player returning under a new account.

Whitelist application (quiz)

To apply you must sign in with Discord. Our site then contacts our whitelist API using your Discord ID to load quiz questions and submit your answers.

We retain your Discord ID, quiz answers, pass or fail result, score, and application timestamps for whitelist administration and anti-abuse. Passing the quiz grants access, including the whitelisted Discord role assigned through our systems.

Web store and payments

Our in-site store uses Tebex Headless checkout. When you use the store we may process:

  • Your IPv4 address, passed to Tebex when creating a basket, where available
  • Tebex basket identifiers
  • Package selections and checkout status
  • FiveM account details returned after Tebex FiveM login, such as username, ID, and avatar, used to show you as signed in for checkout
  • Discord ID where a package requires Discord delivery, taken from your Discord session or store cookies

Browser cookies and storage used for the store include tebex_basket_ident (basket identifier, also mirrored in local storage), fivem_user (FiveM store identity for checkout state), tebex_discord_id, and the Laravel session cookie.

Payment card details are processed by Tebex and its payment providers. We do not collect or store card numbers on atleast.lv.

Purchases may unlock Discord roles, in-game items or slots, ban-appeal package effects, and similar rewards described on the store page.

FiveM server connection and account identifiers

When you connect to our FiveM server we process identifiers made available by FiveM, Rockstar, and linked platforms:

  • Rockstar / FiveM license and license2
  • Discord identifier, required to join
  • FiveM (Cfx.re) identifier
  • Steam, Xbox Live (xbl), and Microsoft (live) identifiers when present
  • IP address
  • FiveM display name

Our queue requires your license and Discord identifiers. Your connection may be refused if Discord is missing, if you are not in our Discord server, or if you lack the required role. If our permissions service is temporarily unreachable, the check may be skipped so that players are not locked out.

We store account and character data in our game database, including the linked identifiers above, character profile information, and the session and play activity needed to run the server.

Moderation, bans, reports, screenshots, and anticheat

For safety and rule enforcement we may process:

  • Ban, warn, kick, and admin-jail records
  • Player reports submitted to staff
  • Admin action logs
  • Screenshots of a player's game client taken by authorised staff, and related images posted to staff Discord channels
  • Anticheat signals and related enforcement data
  • Connection anti-spam and rate-limit data keyed by license or connection endpoint

Admin logs on the game panel use a rolling retention window measured in days. Other moderation records, such as bans, are kept longer where enforcement requires it.

Gameplay logs, statistics, and operational telemetry

We operate logging and statistics systems that may record:

  • Script and activity logs including player name and license identifier
  • Playtime, economy, travel, moderation counters, and achievement statistics, usually associated with license and Discord ID
  • Server status and player counts shown on the website

In-game voice, chat, and phone systems process communications content as needed to deliver those features to other players and, where configured, for moderation.

What we do not collect

  • We do not operate an email and password account system for players. Discord is used for sign-in.
  • We do not use third-party advertising or web analytics trackers on the public site.
  • We do not ask for government identity documents.

We do not sell personal data, and never will!

Why we are allowed to process it

Under the GDPR we rely on the following lawful bases:

  • Contract - Discord sign-in, whitelist application, store checkout, and running the game server. You asked us to provide these.
  • Legitimate interests - whitelist verification, anticheat, moderation, ban enforcement, and rate limiting, to keep the server fair, safe, and free of ban evasion.
  • Legitimate interests - security logging and abuse prevention, to protect our systems and our players.
  • Legal obligation and legitimate interests - retaining records for disputes, chargebacks, and accounting.

Where we rely on legitimate interests we have weighed those interests against your rights. In short: the data used for verification is limited to what identifies a device or connection rather than a person, it is stored hashed, it is kept for a limited period, and the alternative - an unmoderated server where banned players return freely - would harm the community we are asked to protect. Where verification signals link an application to another account, that decision is reviewed by a person rather than taken automatically. You can object to this processing using the contact details below.

Cookies and similar technologies

We use:

  • Essential cookies - Laravel session, CSRF protection, store basket, and linked FiveM or Discord checkout state.
  • Verification identifier - a cookie and matching local storage entry used to recognise repeat whitelist applications from the same browser.
  • Local storage - store basket identifier for the store interface.

These keep you signed in, protect forms, complete purchases, and prevent duplicate applications. We do not use advertising or analytics cookies. You can clear cookies and storage in your browser; doing so may sign you out or reset your cart.

How long we keep data

  • Website sessions - short-lived, measured in hours.
  • Store cookies - days, commonly up to about a week.
  • Verification attempts - 90 days.
  • Hashed verification signals and staff decisions - kept while needed to prevent ban evasion.
  • Whitelist and quiz records - as long as needed to administer whitelist and prevent abuse.
  • Game accounts and characters - while your account exists, and a reasonable period after inactivity or a deletion request.
  • Bans and serious moderation records - as long as necessary for enforcement and safety.
  • Admin action logs - rolling retention measured in days.
  • Payment records - primarily held by Tebex; we keep delivery references needed for fulfilment and disputes.

Who we share data with

  • Discord - OAuth login, guild membership and roles, bot actions, staff webhooks for moderation alerts.
  • Tebex - store catalogue, baskets, authentication providers including FiveM, checkout, and package delivery.
  • Cfx.re / FiveM / Rockstar - connection, licensing, and platform identifiers required to play.
  • Steam / Microsoft / Xbox - only when those identifiers are presented by the FiveM client.
  • Cloudflare - sits in front of our website, providing network protection and the Turnstile anti-bot check.
  • IP reputation providers - used to identify VPN, proxy, and hosting connections during whitelist verification.
  • Hosting, database, and infrastructure providers that run atleast.lv, our APIs, and the game server on our behalf.
  • Anticheat, screenshot, and media tooling providers used for moderation and integrity.
  • Staff and moderators with authorised access to admin tools, logs, and Discord staff channels.
  • Authorities, if required by applicable law.

International transfers

Our stack and third parties may process data in the EU and in other countries. Where transfers outside the EEA or UK occur, we rely on the safeguards those providers offer, such as standard contractual clauses, or on the necessity of the transfer to provide the service you requested.

Third-party services

These providers process data under their own policies, which we recommend reading:

  • Discord
  • Tebex
  • Cfx.re / FiveM
  • Rockstar Games / Take-Two
  • Cloudflare
  • Steam and Microsoft, where those accounts are linked through FiveM
  • Our anticheat vendor, where applicable

Our website links to Discord and YouTube; those platforms process data under their own terms when you use them.

Your rights

Under the GDPR as applied in Latvia, you may have the right to:

  • Access the personal data we hold about you
  • Rectify inaccurate data
  • Erase your data, subject to the limits below
  • Restrict or object to certain processing, including processing based on legitimate interests
  • Data portability, where applicable
  • Withdraw consent, where processing is based on consent

How to exercise your rights: email [email protected], or open a Discord ticket or contact @raymans. Include your Discord ID and, where relevant, your FiveM license identifier so we can find your records. We aim to respond within one month.

Limits that apply to multiplayer games:

  • We may retain ban and abuse-related data after a general deletion request, because deleting it would defeat the ban.
  • Data already shared with other players, such as chat they have seen or economy interactions, may not be fully erasable.
  • Payment history may be retained for accounting, fraud, and dispute handling.
  • Identifiers issued by FiveM, Discord, or Steam must also be managed on those platforms.

Children

ATLEAST RP is directed at adults. Our services are categorically not intended for anyone under 14 (with exceptions), or a higher age where your country requires one. If you believe a minor has provided personal data, contact us and we will take appropriate steps.

Rockstar and FiveM age ratings and platform terms may also apply.

Security

We use technical and organisational measures appropriate to a game community and web application: access-controlled admin tools, API keys, staff permission roles, HTTPS across the public website, and hashing of the identifiers used for verification. No method of transmission or storage is completely secure.

Changes to this policy

We may update this policy from time to time. The date shown at the top of this page is the date of the most recent change. Continuing to use the website or server after an update means you accept the revised policy, except where the law requires additional notice or your consent.

Contact