Privacy Policy
We place paramount importance on protecting your personal data. Discover exactly what data we collect, why, and what your rights are.
Last updated : October 4, 2026
At StaffMeets, trust is at the heart of our platform. This policy transparently explains what data we collect, for what specific reasons, and what your rights are over it under the GDPR.
1. Data Controller
2. Data collected
Via Discord OAuth2 (at login)
When you log in via Discord, we receive and store the following information in our database (users & accounts table):
| Data | Source | Why |
|---|---|---|
Discord ID | Discord API | Unique identifier & identity verification |
Discord Username | Discord API | Profile display |
Discord Avatar (CDN URL) | Discord CDN | Displaying your profile picture |
Email | Discord API | Account identification. Never displayed publicly. |
OAuth Access Token | Discord OAuth2 | Automatically join the StaffMeets Discord server on login |
Role (candidate / recruiter) | StaffMeets | Define your mode of use on the platform |
Via your activity on the platform
Candidate Profile
- Bio (written by you)
- Desired roles & skill levels
- Availabilities
- Languages spoken
- Timezone
- Portfolio (titles + URLs)
Projects (Recruiters)
- Project name & type
- Project description
- Website URL
- Linked Discord server ID
- Discord invite URL
- Member count (via bot)
Jobs (Recruiters)
- Role sought & contract type
- Short & long description
- Requirements & benefits
- Keywords (tags)
- Publication status
Applications
- Cover letter (written by you)
- Status (pending, reviewing, accepted, rejected)
- Application date
3. Purpose of processing
Authentication & Security
Verify your identity via Discord OAuth2, maintain your secure login session, and protect the service against identity fraud.
Legal basis: Performance of contractProviding the matchmaking service
Display your profile to recruiters, recommend jobs matching your skills, and allow recruiters to manage their applications.
Legal basis: Performance of contractDiscord Integration (Auto-join)
Upon login, your Discord Access Token is used once to automatically add you to the StaffMeets support server, making it easier to access help.
Legal basis: Legitimate interestInternal notifications (moderation)
When an job is created, updated, or deleted, non-personal information (role, status, number of requirements) is sent to a private internal Discord webhook to assist moderation.
Legal basis: Legitimate interest5. Retention & Security
Retention period
Your data is retained as long as your account is active. Upon account deletion, your data (profile, projects, jobs, applications) is permanently deleted by cascade within a maximum of 30 days.
Security
All communications are encrypted via HTTPS/TLS. The database is hosted on Neon infrastructure (Europe) with SSL-secured connections. Discord Access Tokens are not permanently stored after the OAuth session.
6. Your rights (GDPR compliance)
Under the General Data Protection Regulation (GDPR - EU Regulation 2016/679), you have the following rights:
- Right of access : Obtain a copy of the data we hold about you.
- Right of rectification : Correct inaccurate information directly from your profile page.
- Right to erasure (right to be forgotten) : Permanently delete your account and all associated data (profile, applications, jobs, projects).
- Right to object : Object to the processing of your data on legitimate grounds.
- Right to portability : Receive your data in a structured, commonly used and machine-readable format.
You also have the right to lodge a complaint with your national data protection authority (e.g., CNIL in France): cnil.fr
7. Contact us
To exercise any of your GDPR rights, report a privacy issue, or ask any question related to this policy, contact us via our Discord support server:
Discord Support Server
discord.gg/gtdG3h5KQT