privacy policy effective 2026-09-11 01 / who is responsible for your data this notice explains how personal data is handled when you visit ela.grce.me, purchase ela, join its discord community, connect your e-pal account or use its automation features. it also covers information received about e-pal users through enabled features. it does not describe unrelated grace products. ela is offered under the grace brand. its operator is responsible as controller for ela’s customer accounts, purchases, support and service security. privacy enquiries can be sent to: grace admin@grce.me (mailto:admin@grce.me) privacy is part of how we design ela. we aim to limit collection and retention to what the service and our legitimate obligations need. privacy-oriented does not mean anonymous: account identifiers, usable session information and payment records can identify you. 02 / data we collect and process | category and source | data and purpose | account connection — from you, e-pal and discord | on login, ela stores e-pal session information, e-pal user id and customer id, discord id, discord username and avatar url. these connect the correct accounts, authenticate supported tasks and provide your bot access. session information is sensitive because it can authorise activity on your account. | configuration — supplied by you | instant text configurations and arcade room id, together with the feature settings or instructions you choose to use. these let ela run your requested automation. | enabled features — from e-pal and your instructions | depending on the features used, ela processes client/profile identifiers, profile or activity information, client collections, conversations and replies, order status or counts, gifts, tips and service/transaction history. client-collection features compile lists of prospective clients. this can involve other people’s personal data, not just your login fields. | purchases — from you and payment providers | order and customer references, contact and billing information made available with the order, selected tier, price, payment status and any subscription details. for custom purchases using shopify, the agreed amount and full written scope are sent to shopify and retained with the order. for sumup custom purchases, ela saves the full scope, confirmed amount, confirmation time, policy version, payment reference and verified payment status in a private order record on its ionos-hosted server. for new checkouts, sumup receives the amount, currency, full agreed scope as the checkout description, and payment reference, and processes payment information on its hosted checkout. before opening a new payment page, ela checks that sumup retained the full scope. checkouts created before this change may contain only a short description and reference. ela does not receive full card numbers or card security codes through its own checkout endpoint. | support and community — from you and discord | messages you send us, account and order references needed to resolve enquiries, and relevant moderation or abuse reports. messages posted in community channels are visible to people with access to those channels. | website and security — from your browser and infrastructure | requests, ip addresses and technical connection information can be processed by the web server and infrastructure providers. the checkout endpoint uses a salted hash of an ip address for short-lived rate limiting; this does not prevent apache, cloudflare or other providers from handling the original ip address. do not put passwords, payment-card details, session credentials or sensitive information about other people in a custom-order brief, public channel or support email. if required account identifiers or session information are not provided, the associated bot functions cannot operate. if necessary order details are missing, we may be unable to activate a purchase. 03 / purposes and lawful bases | purpose | lawful basis where we act as controller | access, account connection and requested automation | performance of our contract with you, or steps you request before entering it, where the processing is objectively necessary for that service. | payments, order administration and support | contract for fulfilling purchases and resolving service enquiries; legal obligation where tax, accounting or other binding requirements require records. | security, reliability and fair community use | legitimate interests in preventing misuse, investigating incidents and keeping the service operational, balanced against the rights and expectations of the people affected. | other people’s data used in enabled features | a contract with an ela customer is not itself a lawful basis for processing someone else’s data. where we determine the purpose, an appropriate basis, such as a documented and proportionate legitimate interest, must apply. where we act only on a business customer’s instructions, that customer determines the purpose and must establish its own lawful basis. | optional processing that requires permission | consent where legally required. any such consent must be separate and withdrawable; reading this notice is not blanket consent to every type of processing. where a business customer determines how its clients’ data is used and we process it only on that customer’s documented instructions, the customer is the controller for that use and we act as its processor. the applicable processing arrangements must address instructions, security, assistance, subprocessors and deletion. contact us before using ela for business-client processing if those arrangements have not been agreed. this notice is not a substitute for them. 04 / automation and information about other people ela executes the modules and configurations enabled for a connected account. these can post content, create activity, identify client profiles, send replies and accept or reject orders. sentry can maintain a connection and perform supported actions while the user’s device is off. client collection, pooling and activity features use profile or activity information to select or engage with profiles; this can involve profiling. these tasks are not a guarantee of any purchasing behaviour or exposure result. do not use ela to make decisions about someone that have legal or similarly significant effects without first establishing the relevant legal requirements and safeguards. if an automated message, order action or use of your profile concerns you, contact the account operator or admin@grce.me (mailto:admin@grce.me). we will investigate our involvement and assist with an applicable rights request. information obtained indirectly comes from the connected e-pal account and the profiles, conversations, activity and transaction records available to it through the enabled functions. visibility on a platform does not remove a person’s privacy rights. 05 / who receives data • e-pal receives the authenticated requests and actions needed to run enabled features. its own handling of account activity is governed by its policies. • discord provides the bot interface and community. commands, account identifiers and communications routed through discord are also subject to discord’s privacy policy (https://discord.com/privacy). • shopify and the payment services selected at checkout process payment, customer and order information. see shopify’s consumer privacy policy (https://www.shopify.com/legal/privacy/consumers). their roles and purposes are described in their notices. • sumup processes custom payments when you select it. its checkout collects the payment information it requires; ela verifies the resulting payment reference and status through sumup. see sumup’s privacy policy (https://www.sumup.com/en-gb/privacy/). • cloudflare handles website delivery and security where traffic passes through it. the website loads fonts from google fonts, which receives the browser requests necessary to supply them. • hosting, storage and email providers process information needed to operate the service, retain its records and handle enquiries. our current arrangements are described below. • professional advisers, authorities or another recipient may receive necessary information when a legal obligation, claim or security investigation requires it. any business transfer involving data must respect applicable law and appropriate notice. hosting, storage and support infrastructure ela uses ionos for hosting and cloudflare as a reverse proxy for its domain. ionos provides the hosting infrastructure on which ela runs. cloudflare handles proxied website requests for delivery and security. these providers process the technical information needed to provide their services. we do not sell personal data. we do not make account sessions or private configurations available to other customers. however, a feature you enable may intentionally publish a post, send a message or create other visible e-pal activity. check what a feature does before enabling it. 06 / international processing providers such as discord, shopify, sumup, cloudflare and google operate internationally. the location of our own server does not mean every copy or provider operation stays in the same country. where we are responsible for a restricted international transfer, the applicable transfer requirements must be met, for example through an adequacy decision or an appropriate contractual safeguard with the required assessment. contact admin@grce.me (mailto:admin@grce.me) for details or a copy of the safeguards relevant to your data. a provider’s global presence is not, by itself, a safeguard. 07 / how long information is kept ela retains bot data, including stored activity data, for up to six months before deleting it. this is the standard maximum retention period for operational bot data. purchase, billing and other records that must be kept to meet legal obligations are handled separately, and are retained only for the relevant requirement. a request for earlier deletion is considered under the rights described in this policy. cancelling billing, leaving discord and revoking an e-pal session are different events and do not automatically erase order or support records. information may be deleted earlier when no longer needed. if a legal obligation requires specific records to be kept beyond the standard period, we limit retention to what that obligation requires and restrict further use. custom order records are kept for the agreed delivery and access period and any applicable accounting, refund or legal-claim requirement. we review records and remove or redact personal details when no longer required. an abandoned checkout does not create a duty to keep its full scope indefinitely. these order records are separate from operational bot data. shopify, sumup and other providers may retain records under their own policies and legal obligations. ela’s six-month bot-data limit does not promise that every provider erases its independent records at the same time. contact us for a deletion request or information about a particular record. 08 / minimisation and security ela uses hashing and salting where appropriate as part of its data-handling approach. hashing produces a one-way representation; a salt makes matching precomputed hashes harder. these techniques do not make every record anonymous, and pseudonymised information can still be personal data. session information needed to authenticate requests must remain usable for that function: it cannot all be irreversibly hashed and still perform the same task. identifiers, saved post text, support messages and custom scopes kept by ela, shopify or sumup may also need to remain readable. sumup order records are stored outside the public website directory with restricted file access. a private confirmation link lets the purchaser view and download the scope and verified status; anyone given that link can view it, so keep it private. we do not claim that every stored field is salted, hashed or encrypted. we take responsibility for using appropriate technical and organisational safeguards and limiting access to what is necessary. no online system is risk-free. protect your discord and e-pal accounts, avoid sharing credentials and contact admin@grce.me (mailto:admin@grce.me) promptly if you suspect a compromised connection. we will assess incidents and make any notifications required by law. 09 / website storage and external services the ela site’s own code does not add advertising trackers or an analytics platform. it keeps the current checkout selection and a custom-checkout request identifier in the page’s memory while you use it. that information is not a payment-card record. the server also maintains short-lived rate-limit entries. sumup checkout, shopify checkout and customer accounts, discord, and infrastructure security services may use their own cookies or similar technologies. their notices and controls apply to those services. google fonts is an external resource and receives a connection when a page requests the font. any future optional analytics or advertising technology requiring consent must be disclosed and offered with the appropriate choice before activation. 10 / your choices and rights you can ask for access to your personal data, correction of inaccurate information, deletion, restriction of processing or a portable copy where the applicable conditions are met. you can withdraw any consent we rely on without affecting the lawfulness of processing before withdrawal. these rights can have legal exceptions. your right to object you may object to processing based on legitimate interests, including related profiling, because of your circumstances. you may object to direct marketing at any time. email admin@grce.me (mailto:admin@grce.me) and describe the processing you want us to review. send requests to admin@grce.me (mailto:admin@grce.me). we will ask only for information reasonably needed to identify the relevant records and verify your authority, respond within the applicable statutory timeframe, and explain any permitted extension or refusal. requests are normally free. you can complain to the information commissioner’s office (https://ico.org.uk/make-a-complaint/), or another relevant supervisory authority, without having to contact us first. disconnecting or revoking an e-pal session stops that connection where the platform supports it; it does not itself cancel shopify billing. use subscription management (https://ela.grce.me/buy#manage-subscription) to stop renewals and contact us separately for deletion. if data is controlled by an ela business customer, we will help identify the responsible account operator and assist within our role. 11 / updates and independent platforms we will update this notice when the service or its data practices change, show the effective date and communicate material changes where required. a new notice does not authorise unrelated processing without the necessary lawful basis. ela is an independent service and is not affiliated with or endorsed by epal, inc. (https://www.linkedin.com/company/epalgg) or discord. their names and trademarks belong to their respective owners.