Privacy Policy
Last updated: September 2026
1. What this policy covers
Opus Solutions runs two separate lines of business, and they collect different data in different ways:
- Project services — custom websites, online stores, landing pages, mobile applications and graduation projects. Data here comes from the project request form and from the conversation and materials that follow.
- Discord bot subscriptions — standardised bot products activated on your Discord server. Data here comes from Discord OAuth and from your subscription.
There is more than one way to be identified to us. A Discord account is required only for the bot line. You can request, discuss and receive a website or application project without ever connecting a Discord account. Part A below describes the project data, Part B describes the bot data, and Part C applies to both.
We collect only what is necessary to provide, secure and improve what you asked for.
2. How we use data
Whichever line you deal with, your data is used only for the following purposes:
- To understand, quote, build and deliver the work or service you asked for.
- To communicate with you about your project or your subscription, and to provide support.
- To send service-related notifications, such as subscription expiry reminders or a reply in your project conversation.
- To issue invoices and keep the accounting and tax records we are required to keep.
- To detect and prevent fraud, abuse and unauthorised use.
- To improve the quality and reliability of what we offer, through aggregated and anonymised analytics.
We do not sell, rent, or share your personal data with third parties for their own marketing purposes. We do not use your data for advertising, profiling, or automated decision-making that affects your legal rights.
3. Cookies
Opus Solutions uses only strictly necessary cookies. These include:
- Session cookies: to maintain your authenticated session on the bot dashboard.
- CSRF cookies: to protect against cross-site request forgery attacks.
- Project access cookie: a strictly necessary cookie that lets you return to a project request you submitted without signing in. It is described in A2.
We do not use advertising cookies, tracking cookies, analytics cookies, or any third-party cookies for marketing purposes. You can control cookie settings through your browser, but disabling necessary cookies may prevent parts of the site from functioning correctly.
Part A
Project services data
This Part applies when you ask us about, or engage us for, a website, store, landing page, application or graduation project. No Discord account is involved.
A1. Project requests
When you submit the project request form, we collect exactly what the form asks for:
- Your name, as you type it.
- Your preferred contact method (email or WhatsApp) and the contact details you give for it.
- Your project brief: the idea for the website or application, the main outcome you need it to achieve, the features you selected, the approximate budget range you selected, and any deadline you mentioned.
- The messages you and we exchange afterwards in that request conversation.
Why: to understand what you are asking for, to prepare a quote, and to talk to you about it. We do not use a project request for anything else, and we do not add you to a marketing list because of it.
Encryption: your name, your contact details and every message in the conversation are encrypted at rest before they are stored. A one-way hash is used to find your own request without exposing the underlying identifier. Nobody browsing the database sees your brief or your phone number in plain text.
Notification to us: when you submit a request or send a message, our system alerts the owner through a private Discord message. That alert deliberately contains only your first name as you typed it and a shortened reference number. The content of your brief, your contact details and your messages are never copied to Discord.
Retention: a project request and its conversation are kept while the request is open and while any resulting project is running. After that, they are kept only as long as we need them for support, accounting and legal obligations, and are then deleted. You may ask us to delete a project request earlier, subject to those obligations.
A2. The project access cookie (no account required)
You can submit a project request as a guest, without signing in. So that you can come back to your own conversation, we set a strictly necessary cookie named opus_project_access on your browser.
- It holds a randomly generated access token for the request you created — nothing else. It contains no name, no contact details and no project content.
- It is HTTP-only, so page scripts cannot read it, and it is sent over HTTPS in production.
- It expires after 90 days, or when you clear your browser cookies. Clearing it means you can no longer open that conversation from that browser, so keep the confirmation we send you.
If you are signed in with a Discord account when you submit a request, the request is linked to that account instead, so you can reach it from any browser.
A3. Material you give us during a project
To build a project we usually need material from you: text and images, product data, brand assets, business details, and access to systems such as hosting, a domain registrar, a payment gateway, analytics or app store accounts.
- We use that material only to build, test and deliver the agreed work.
- We hold it only for as long as the project and its support window need it.
- We ask you to issue us accounts of your own rather than share your personal passwords, so that you can revoke our access at handover. Please revoke it once the project is complete.
- You can ask us to return or delete project material at any time after handover.
If the material you give us contains other people’s personal data — for example a customer list you want imported — you remain responsible for having a lawful basis to share it with us, and we process it only on your instructions for that project.
Part B
Discord bot subscription data
This Part applies only to the Discord bot product line. It does not apply if you are a project client and have not bought a bot subscription.
B1. Discord OAuth
Opus Solutions uses Discord OAuth 2.0 to authenticate bot customers and link activation codes to Discord accounts. It is the identity method for the bot line only; it is not required to use our project services. When you authenticate via Discord, we receive:
- Your Discord user ID (a unique numeric identifier).
- Your Discord username and avatar URL.
- Your Discord email address — used to send your receipt and to contact you about your subscription.
- The list of servers you belong to — used only so you can pick, from a dropdown, which of your own servers the bot should be installed on. We do not read messages, members, or any content inside those servers.
We request the identify, email and guilds scopes from Discord OAuth, and Discord shows you these on the authorization screen before you approve. We request nothing beyond them. This data is used to identify your account, display your information in the dashboard, and associate your activated subscriptions with your Discord identity.
Discord OAuth tokens are stored temporarily and securely for the duration of your session. You can revoke Opus Solutions’ access at any time through your Discord Authorized Apps settings.
B2. Subscription and service data
Alongside the Discord account data above, the bot line involves:
- Guild data: Discord server (guild) ID and server name associated with the subscription you have activated.
- Purchase data: order ID, invoice ID, product ID, product name, and transaction amount from our payment processor. We do not receive or store full payment card details.
- Service data: activation codes (stored encrypted), subscription status, plan type, product type, service expiry dates, and configuration settings, including any image you upload for a bot feature.
B3. Retention on the bot line
- Account and service data is retained for the duration of your subscription plus ninety (90) days after termination or expiry.
- Aggregated, anonymized analytics data may be retained indefinitely for business intelligence purposes.
- Data that we are legally required to retain (e.g., for tax or compliance purposes) will be kept for the period required by applicable law.
After the retention period ends, your data is permanently deleted from our systems. You may request earlier deletion by messaging us on WhatsApp at +966 59 723 2969, subject to legal retention requirements.
Part C
Applies to both lines
C1. Communications
If you contact us on WhatsApp, through a project conversation, or on our Discord support server, we may retain a record of that communication for support, quality assurance and record-keeping purposes.
C2. Third-party services
Opus Solutions relies on the following third-party services to operate. Each has its own privacy policy and data processing terms, which we encourage you to review. The line each one serves is noted, because they are not shared between the two:
- Discord — OAuth authentication and bot hosting for the bot line. Also used to send us the private new-request alert described in A1, which carries only a first name and a reference number. Privacy Policy
- PayPal — payment processing for bot subscriptions. Privacy Policy
- Paddle — payment processing and merchant of record for bot subscription purchases only. Paddle does not process project work, and project clients’ data is not sent to it. Privacy Policy
- Supabase — database and storage for both lines, including the encrypted project request records. Privacy Policy
- Railway — application hosting for the bot line. Privacy Policy
Each third party processes data in accordance with its own terms and applicable data protection laws. Opus Solutions ensures contractual safeguards are in place with each processor where required by applicable law.
C3. Your rights
Depending on your jurisdiction, you may have the following rights regarding your personal data:
- Right to Access: Request a copy of the personal data we hold about you.
- Right to Rectification: Request correction of inaccurate or incomplete data.
- Right to Deletion: Request deletion of your personal data, subject to legal retention requirements.
- Right to Data Portability: Request a machine-readable copy of your data.
- Right to Object: Object to the processing of your data for certain purposes.
To exercise any of these rights, message us on WhatsApp at +966 59 723 2969. Email support is not available at the moment. Tell us whether your request concerns a project or a bot subscription, so we can find the right records. We will respond within the timeframe required by applicable law (typically 30 days). We may need to verify your identity before processing your request.
C4. Data security
Opus Solutions implements reasonable technical and organizational measures to protect your data, including:
- Encryption of sensitive fields at rest using AES-256-GCM — including activation codes, and the names, contact details and message content in project requests.
- All traffic served over HTTPS/TLS.
- Strict access controls to encrypted data, limited to authorized automated systems and to the owner account.
- Hashing of sensitive identifiers (activation codes, email addresses, requester identifiers) for lookup without exposing plaintext values.
- Rate limiting and cross-site request forgery protection on the forms that accept your data.
While we take these precautions seriously, no online service can guarantee absolute security. You use the services at your own risk. We encourage you to use strong, unique passwords, and to enable two-factor authentication on any account you connect to us.
C5. Changes to this policy
We may update this Privacy Policy when necessary to reflect changes in our practices, legal requirements, or our services. Changes are reflected in the “Last updated” date at the top of this page, and material changes are published on this website. We encourage you to review this policy periodically.
C6. Contact
Questions, concerns, or requests about this Privacy Policy or your personal data: message us on WhatsApp at +966 59 723 2969. Email support is not available at the moment.
If your question is about a Discord bot subscription, you can also reach us on our bot support server: https://discord.gg/dMpJWpxGD2
Questions? Message us on WhatsApp at +966 59 723 2969. Email support is not available at the moment.