When you use Motion Archive, we collect the following categories of data to operate the platform, prevent fraud, and improve your experience:
Account data — your Discord or Google identity (user ID, username, avatar), email address, and any display name you set.
Purchase data — order history, items purchased, prices paid, payment processing details handled by Stripe.
IP address — recorded on page visits, purchases, spin wheel usage, and authentication events. Used for fraud prevention, ban enforcement, and analytics.
Device fingerprint — a unique identifier derived from your browser and device, stored in a cookie (motion_did). Used to prevent ban evasion and link activity across sessions.
Page view history — every page you visit on the site is logged with the URL path, HTTP referrer, your IP address, browser user agent, and timestamp.
Interaction events — on-site interactions such as product clicks, searches, cart additions, and checkout steps are recorded alongside the page path, IP address, and optional metadata (e.g., the product slug you clicked).
Session data — your login session is stored server-side via a secure cookie so you remain authenticated between visits.
Support communications — messages you send through our ticket system or Discord DMs initiated by our team.
Engagement data — spin wheel participation records including IP address and prize received.
Cart contents — items you add to your cart are stored on your account so they persist between sessions.
Referral data — if you use or share a referral code, we record which accounts were linked.
2. How We Use Your Data
All collected data serves one or more of the following purposes:
Delivering your digital purchases and maintaining your order history.
Authenticating your account and keeping your session secure.
Detecting and preventing fraud, ban evasion, and abuse via IP and device fingerprint matching.
Understanding how users navigate and interact with the site so we can improve it (analytics).
Providing customer support through our ticket system.
Sending transactional emails (order confirmations, delivery notifications) where you have provided an email address.
Processing affiliate and referral credits.
Complying with legal obligations.
3. Data Retention
We retain your data for as long as your account exists and for a reasonable period afterwards to satisfy legal and operational obligations. Delivery file links are automatically expired 7 days after delivery. Activity logs are retained for up to 60 days. You may request full deletion at any time (see Section 5).
4. Third-Party Services
Stripe — payment processing. Stripe handles card data directly and is PCI-DSS compliant. We only receive a payment intent ID and status.
Cloudflare — CDN, DDoS protection, and R2 object storage for delivered files. Cloudflare may process request metadata including IP addresses.
Discord — used for OAuth login and optional DM notifications. Your Discord user ID and avatar URL are stored on our servers.
Google — used as an alternative OAuth login method. Your Google user ID and email are stored if you sign in via Google.
Supabase / PostgreSQL — database hosting where all user data is stored.
5. Your Rights (GDPR & Data Erasure)
If you are in the European Economic Area or United Kingdom, you have the following rights under GDPR:
Right of access — you can request a copy of all data we hold about you.
Right to erasure ("right to be forgotten") — you can request deletion of the personal data we hold about you. See "How erasure works" below for exactly what is removed and what we are required to keep.
Right to rectification — you can request correction of inaccurate data (e.g., updating your email address).
Right to restriction — you can ask us to pause processing your data while a dispute is resolved.
Right to object — you can object to processing based on legitimate interests (e.g., analytics).
How to make a request. Email support@motionarchive.eu from the address associated with your account, or open a support ticket in your Client Portal. We may ask you to confirm your identity before we act, so that nobody else can request the deletion of your data. We aim to respond within 30 days.
How erasure works. When we action an erasure request we remove everything that identifies you: your account details, email address, linked Discord or Google identity, IP addresses and device identifiers, saved cart, support tickets and messages, reviews, referrals, spin records, analytics and activity logs, and the personal content attached to your orders — the names, handles, custom text and any artwork you uploaded. Your account is left with no identifying information and can no longer be used to sign in, and we will not contact you again.
What we must keep. We are legally required to retain records of the transactions themselves for accounting and tax purposes, so the order number, amounts, fees, currency, dates and status are kept in anonymised form — stripped of anything that connects them to you. This is permitted under Article 17(3)(b) GDPR, which allows retention where processing is necessary for compliance with a legal obligation.
What we cannot delete for you. Payments are processed by Stripe, and card details never reach our servers. We can only erase data held on our own platform. Stripe keeps its own records of your payment under its retention obligations as a regulated payment processor — to ask about those, contact Stripe directly using the privacy contact details in their privacy policy.
Effect on your purchases. Erasure removes your access to previously purchased files and any download links. We cannot restore them afterwards, so please download anything you want to keep before making a request.
6. Cookies
We use the following cookies:
Session cookie — keeps you logged in. Expires when your session ends or after the configured session lifetime.
motion_did — device fingerprint identifier used for fraud prevention and ban enforcement. Persists across sessions.
We do not use advertising cookies or sell your data to third-party advertisers.
7. Changes to This Policy
We may update this Privacy Policy from time to time. The "Last Updated" date at the top reflects when material changes were last made. Continued use of the site after an update constitutes acceptance of the revised policy.