1. Controller
The controller of your personal data is Karima HAFAF, entrepreneur individuel, trading as Mercenary Routes, 25 rue Louis Blanc, 21000 Dijon, France. Privacy contact: contact@mercroutes.com.
2. Data we collect
- Account data: email address, password hash, account settings, language, default kingdom, login and session data.
- Purchase data: Stripe order reference, amount, product purchased, invoice data, credit balance, credit history, pass status, and refund history.
- Service usage data: coordinate searches, delivered coordinates, credit consumption, and access pass status.
- Game-related data: kingdom, X/Y coordinates of observed Mercenary Exchanges, timestamps, availability status, confidence, and technical metadata.
- Application and technical data: installation identifier, app version, platform, consent choices, IP address, browser/device data, logs, and timestamps.
- Support data: messages and information needed to answer support requests.
We do not ask for or collect your Total Battle password.
3. Why we use data
We use data to create and manage accounts, provide the application and coordinate services, process purchases and refunds, deliver private coordinates to the right account, maintain security, prevent abuse, fix technical problems, answer support requests, and meet accounting, tax, and legal obligations.
4. Legal bases and providers
Processing is based on contract performance, legal obligation, legitimate interest for security and reliability, and consent where an optional feature requires it. Providers include Cloudflare for hosting and API infrastructure and Stripe for payments. We do not sell personal data or use it for advertising profiling.
5. Retention
Account data is kept while the account is active and up to 12 months after closure. Accounting records may be kept for 10 years where required by law. Technical and security logs are generally kept up to 12 months. Support messages may be kept up to 3 years after the last exchange.
6. Your rights
You may request access, correction, deletion, restriction, portability, or object to processing based on legitimate interest. You may withdraw consent where processing is based on consent. Contact contact@mercroutes.com. You may also lodge a complaint with your data protection authority; in France, this is the CNIL.
7. Cookies and local storage
Mercroutes is intended to use only cookies or local storage necessary for account sessions, security, language preferences, and service operation. Analytics, advertising, or third-party tracking would require an update before being enabled.
8. MercRoutes Support application on Discord
MercRoutes Support provides pre-written, verified answers about Mercenary Routes and Target Scout through server-only slash commands. It does not generate answers with artificial intelligence, read ordinary messages or channel history, monitor direct messages, or send unsolicited messages.
When a slash command is invoked, Discord sends the command name, the question entered for /ask, the selected locale, and technical interaction metadata that can include server, channel, interaction and user identifiers and an interaction token. The application uses only the command and question to select an approved answer, the locale to choose French or English, the server identifier to restrict use to the authorized server, and the interaction data needed to return an ephemeral response.
The application code does not persist question text, Discord usernames, user IDs, channel IDs, interaction tokens or ordinary message content in a database, file, analytics product or support log. Processing occurs in volatile memory for the duration of the request. Cloudflare hosts the endpoint and may process normal network and security metadata as an infrastructure provider; request bodies, Discord identifiers and question text are not written by the application to operational logs.
For current service information, the application may send read-only GET requests to public Mercenary Routes endpoints. Questions and Discord identifiers are never included in those requests. The selected ephemeral answer is returned to Discord and automatic mentions are disabled.
Every incoming interaction must have a valid Discord Ed25519 signature before it is parsed or handled. Missing, malformed and false signatures are rejected. Hosting secrets are not stored in the application source.
Because Discord interaction data is not retained by this application, there is normally no stored bot interaction data to delete. Users may request confirmation or report a privacy concern at contact@mercroutes.com.