Legal

Privacy Policy

Last updated September 15, 2026. This policy covers acoservice.app, the owner and admin consoles, the ACO sites and Discord bots we host, and the documentation. It is part of the Terms of Service. ACOService is a product of Soni's World d/b/a ResiFactory.

1. Who this policy is for

Two kinds of people use ACOService. Operators run an ACO on the platform and pay us for it. Members join an operator’s ACO through that operator’s site and Discord. For a member, the operator decides what to collect and why; we host it for them. This policy explains our part.

2. What we collect

  • Sign-in identity. When you sign in with ResiFactory we receive your ResiFactory user id, display name, email address and, if you have linked one, your Discord user id. When you sign in with Discord we receive your Discord user id, username, avatar and email. We never see your passwords.
  • Operator account and configuration. The ACOs you own, their names, domains, branding, pages, theme, editor grants, API tokens (stored hashed), and the settings you choose.
  • Platform billing. Your Stripe customer and subscription ids, plan, status and renewal date. Card details are entered on Stripe’s pages and held by Stripe; we do not store card numbers for the platform subscription.
  • Member data an operator’s ACO collects. Profile details a member gives their ACO — contact, shipping and checkout details, and account credentials for the services that ACO automates — are stored encrypted at rest. The operator decides what to ask for and is responsible for collecting it lawfully; we process it on the operator’s behalf.
  • Discord activity the bot needs. Guild and role membership for access checks, the messages and commands sent to the bot, and support ticket transcripts.
  • Technical data. IP address, browser and device information, timestamps, and error logs — the ordinary server logs of running a website.

3. Why we use it

  • To sign you in and keep your session secure.
  • To run the operator’s site, member area and bot, and to know who owns what.
  • To bill the platform subscription and to apply discount codes.
  • To answer support requests and investigate abuse or fraud.
  • To keep the platform working: monitoring, backups, debugging.
  • For advertising. We use account, usage and technical data to advertise ACOService and related products — to you, and to build audiences of people like you on advertising platforms — and to measure whether those ads work.

We do not sell personal data.

4. Who we share it with

  • Stripe, for platform billing, under Stripe’s own privacy policy.
  • Discord, which the bots and sign-in run on, under Discord’s terms.
  • ResiFactory, our sign-in provider and part of the same company.
  • Hosting and infrastructure providers that run our servers and databases.
  • The operator whose ACO you are a member of. Your member profile belongs to that ACO; its staff can see what you gave it.
  • Advertising and analytics partners, who receive the technical data and identifiers needed to show and measure our ads, under their own policies.
  • Authorities, when the law requires it.

5. Cookies

We set a session cookie so you stay signed in, and the cookies our sign-in flow needs to complete securely. We may also set advertising and analytics cookies and pixels so we can advertise ACOService and measure those ads. Your browser’s settings control whether those are accepted.

6. How long we keep it

Account and configuration data stays while your account exists. When a platform subscription is closed, the operator’s sites go offline but nothing is deleted, so paying again restores them. Encrypted database backups are kept for a limited period and then overwritten. Server logs are kept for a short operational window. You can ask us to delete your account and its data; some records (invoices, abuse reports) are kept where the law requires.

7. Your choices and rights

You can see and change what your account holds from the consoles. You can unlink Discord or change your ResiFactory sign-in methods on resifactory.net. To request a copy of your data, a correction, or deletion, open a ticket in the ACOService Discord. Members should ask their ACO’s operator first, since the operator controls their profile.

8. Security

Sensitive member data and stored credentials are encrypted at rest. Access is limited to the people who run the platform and to the operator’s own staff. No system is perfectly secure; if we learn of a breach that affects you, we will tell you.

9. Age

ACOService is for adults. Discord requires its users to be at least 13, and an operator may set a higher minimum for their ACO. We do not knowingly collect data from children.

10. Changes and contact

We may update this policy; the date at the top changes when we do and material changes are announced in the ACOService Discord. Questions: open a ticket in the ACOService Discord.