This Privacy Policy explains which personal data Galaxy Panel ("GP") collects, why we need it, who receives it and what you can do about it. By using GP, you agree to what is described here.
Account data
Username, email address and your password - the password is stored only as a one-way hash, we cannot read it. Also your settings, such as display currency, notification choices and whether two-factor authentication is on, and your personal API key.
Orders and balance
Your orders with the link and quantity you entered, prices, status and refunds, your balance and total spending, and your discount tier or roles.
Payments
Deposits with amount, method, status and reference. For manual payment methods this can include details you enter yourself, such as a transaction ID. Payments through automatic checkout are processed by our payment provider; we do not receive or store your wallet or card credentials.
Support
Support tickets with your messages and the order IDs you mention.
Linked accounts
If you link or log in with Discord or Telegram: your Discord or Telegram ID and username. If you link Discord, your Discord roles are kept in sync with your panel roles.
Rewards
Which promo codes you redeemed, your affiliate invite code, who invited you (if you registered with an invite link) and the commissions paid for it, and which announcements you have seen or closed.
Technical data
Your IP address (we keep the most recent one on your account), browser information and a random device identifier stored in a cookie. Our server also logs warnings and errors, which can contain technical details of a request.
To provide the service
To create and secure your account, process orders and payments, show your history, calculate discounts, promo codes and affiliate commissions, and answer support tickets.
Security and fraud prevention
Your IP address and device identifier help us to protect accounts, detect abuse such as fraud, multiple accounts or self-referrals, and to recognise banned users who try to come back with a new account.
Messages from us
- Emails for things you trigger or need for your account: login codes (two-factor authentication), password resets and updates about your tickets.
- Direct messages on Discord or Telegram if you linked them and left the notifications on - for example when a ticket is answered or a deposit is confirmed. You choose this in your profile.
- Announcements as popups inside the panel, and news on our Discord server.
Improving GP
To understand how the site is used and to fix problems. We do not use advertising or analytics trackers.
GP only uses cookies and storage that the site needs. There are no advertising or tracking cookies.
- Session cookie - keeps you logged in (up to 7 days) and protects forms against forgery (security token).
- Device cookie (
gp_device) - a random identifier valid for one year, used for security and to recognise banned users. - Invite cookie (
gp_ref) - remembers an affiliate invite link for 30 days until you register. - Browser storage - small settings such as which sidebar menus you collapsed. They stay on your device.
You can delete cookies in your browser at any time; you may then have to log in again.
We protect your data with industry-standard measures: passwords are stored as hashes, connections are encrypted, access for our team is limited to what their role needs and staff actions are logged. You can add two-factor authentication in your profile.
No system is completely secure, so please also do your part: use a strong, unique password and never share your API key.
How long we keep data
We keep your data while your account exists and as long as needed to run GP, resolve disputes, prevent abuse and meet legal obligations.
What you can do yourself
- Change your email and password, and switch two-factor authentication on or off, in your profile.
- Link or unlink Discord and Telegram and choose which notifications you get.
- Regenerate your API key at any time.
What you can ask us
You can ask Support for a copy of your data, for corrections or for the deletion of your account. Some records, such as payments or data we need to prevent fraud, may have to be kept for a limited time; where possible we delete or anonymise the rest.
Changes to this policy
We may update this policy at any time. The date at the top shows the latest version; significant changes will also be announced inside the panel or by the contact information you gave us.
Contact
Questions or concerns about your data? Open a ticket in Support or write to us on our official Discord server.
Thank you for choosing Galaxy Panel for your social media needs.
