Privacy Policy
Last updated: March 2026
We respect your privacy and are committed to protecting your personal data. This Privacy Policy explains what data we collect, how we use it, and your rights under applicable data protection laws — including the LGPD (Lei Geral de Proteção de Dados, Lei 13.709/2018) for Brazilian users and the GDPR (General Data Protection Regulation, EU 2016/679) for users in the European Economic Area.
LGPD and GDPR are distinct laws. LGPD is Brazil's own data protection law supervised by the ANPD (Autoridade Nacional de Proteção de Dados). GDPR is the EU/EEA law supervised by each member state's DPA. They share similar principles but have different legal bases, penalty structures, and enforcement mechanisms. NexusPrism complies with both where applicable.
United States: The US has no single federal privacy law equivalent to LGPD or GDPR. Key applicable laws include COPPA (Children's Online Privacy Protection Act) — we do not knowingly collect data from children under 13; and CCPA/CPRA — California residents have rights similar to those listed below. If you are a US resident, you may exercise those rights by contacting us.
1. Data Controller
NexusPrism is the data controller for personal data collected through this website and the Minecraft server. For privacy inquiries, contact us via the Contact page or on Discord.
2. Data We Collect
We collect only the minimum data necessary to provide our services:
- Minecraft username: Required to deliver purchased items to your in-game account.
- Email address: Collected by our payment processors (Stripe, PayPal, MercadoPago) for payment confirmation and receipts.
- Purchase history: Records of completed transactions, including items purchased, amounts, and timestamps.
- IP address: Logged by the Minecraft server for security purposes (anti-cheat, ban enforcement).
- Contact form messages: Name, email, and message content submitted via the contact form.
- In-game activity: Player statistics and gameplay data (only if consent is given).
We do not collect passwords, payment card numbers, or full payment details — these are handled by our payment processors.
3. How We Use Your Data
- Order fulfillment: Delivering purchased items to your Minecraft account.
- Customer support: Responding to contact form messages and support tickets.
- Server security: Detecting and preventing cheating, ban evasion, and abuse.
- Communications: Sending purchase receipts and, where consented, server announcements.
- Analytics: Understanding server usage and improving our services (only with consent).
4. Legal Basis for Processing
Under LGPD (Art. 7), we process data based on:
- Contract performance (Art. 7, II): Processing your username and purchase data to fulfill your order.
- Legitimate interest (Art. 7, IX): IP logging for server security and ban enforcement.
- Consent (Art. 7, I): Activity tracking, marketing, and Discord notifications — only with explicit in-game consent.
- Legal obligation (Art. 7, II): Retaining transaction records as required by Brazilian law.
Under GDPR (Art. 6), the equivalent bases are: contract (b), legitimate interests (f), consent (a), and legal obligation (c).
5. Consent Types
Our plugin uses a built-in consent manager. The following consent types can be granted or revoked in-game:
- ACTIVITY_TRACKING: Tracking your in-game statistics and playtime for leaderboards and analytics.
- PURCHASE_HISTORY: Storing your purchase history for support and account management.
- DISCORD_NOTIFICATIONS: Sending automated notifications to our Discord server when you make a purchase or earn an achievement.
- STATISTICS: Including your data in aggregated server statistics (always anonymized).
- MARKETING: Sending occasional promotional messages about new products or server events.
You may withdraw any consent at any time in-game or by contacting us.
6. Data Sharing
We do not sell or rent your personal data. We share data only with:
- Payment processors: Stripe, PayPal, and MercadoPago receive the minimum data required to process your payment. Each is bound by their own privacy policies and compliance obligations.
- Discord: If you grant DISCORD_NOTIFICATIONS consent, anonymized purchase events may be sent to our Discord server via webhook.
No data is shared with third-party advertisers or data brokers.
7. Data Retention
- Order records are retained for 90 days by default. Legal transaction records may be kept longer as required by law.
- Contact form messages are retained for as long as necessary to resolve the inquiry.
- IP address logs are retained for up to 6 months for security purposes.
- In-game activity data is retained for the duration of your consent unless you request deletion.
8. Your Rights
Depending on your location, you have the following rights over your personal data:
- Access: Request a copy of the data we hold about you. (LGPD Art. 18, I–II; GDPR Art. 15)
- Correction: Request correction of inaccurate or incomplete data. (LGPD Art. 18, III; GDPR Art. 16)
- Deletion / Anonymisation: Request deletion or anonymisation of unnecessary data. (LGPD Art. 18, IV; GDPR Art. 17)
- Portability: Receive your data in a structured, machine-readable format. (LGPD Art. 18, V; GDPR Art. 20)
- Objection: Object to processing based on legitimate interest. (LGPD Art. 18, IX; GDPR Art. 21)
- Withdraw consent: Revoke consent at any time, without affecting prior processing. (LGPD Art. 8, §5; GDPR Art. 7(3))
- Complaint: Brazilian users may file a complaint with the ANPD (gov.br/anpd). EU/EEA users may contact their national DPA.
Contact us via the Contact page or Discord. We respond within 15 business days (LGPD) / 30 days (GDPR).
9. Cookies & Tracking
The NexusPrism webstore uses only essential session cookies required for cart functionality and admin authentication. We do not use third-party tracking cookies, advertising pixels, or analytics services that require consent.
10. Changes to This Policy
We may update this Privacy Policy periodically. The "Last updated" date at the top reflects the most recent revision. We encourage you to review this page regularly.