Kal-Shop privacy

Privacy Policy

This policy explains how Kal-Shop, a BUG Studios product, handles information when you browse the marketplace or use a native, Google, or Discord account.

Last updated September 23, 2026

Information we collect

When you choose Continue with Google, Kal-Shop requests only the OpenID Connect identity scopes openid, email, and profile. Google provides a stable account identifier, your verified email address, and basic profile information such as your display name.

When you register directly, Kal-Shop stores your display name, email address, a salted one-way password hash, a platform role, and the minimum profile fields needed to operate your marketplace account. Native registration does not currently verify ownership of the supplied mailbox. Bounded failure counters, temporary lock timestamps, and authentication security events are stored to protect the login boundary.

When you continue with Discord, Kal-Shop requests only the identify and email scopes. Discord provides a stable account identifier, verified email address, username or display name, and related basic identity fields. Kal-Shop stores the namespaced provider identifier, verified email address, platform role, and minimum profile fields—not the Discord token.

When an entitled user requests an approved private product file, Kal-Shop records the order, product-file identifier, account identifier, request time, a bounded browser user-agent value, and an HMAC-protected hash of the first network address supplied by the hosting platform. The raw network address is not stored in the download audit record.

How Google and Discord user data is handled

Google identity data is used only to authenticate you, create or locate your Kal-Shop account, maintain your signed-in session, and enforce account permissions. Kal-Shop does not request access to Gmail, Google Drive, contacts, calendars, or other Google product data.

Google access tokens and refresh tokens are not stored. Kal-Shop verifies Google's signed identity token on the server and then issues its own short-lived, HttpOnly session cookie. Google user data is not sold, used for advertising, or shared with data brokers.

Discord access and refresh tokens are not stored. The short-lived access token is used only to request the current verified identity, then Kal-Shop attempts immediate token revocation and issues its own session. Kal-Shop does not request Discord servers, messages, contacts, or presence data.

How we use information

  • Authenticate users and maintain secure account sessions.
  • Create and operate marketplace accounts and public creator profiles.
  • Authorize access to account, seller, entitlement, and protected-download features.
  • Protect Kal-Shop, its users, and its infrastructure from misuse or security threats.
  • Meet applicable legal obligations and enforce the Terms of Service.

Service providers and disclosures

Kal-Shop uses Google and Discord only when you select those identity options, Vercel for application hosting and request delivery, and Neon-compatible PostgreSQL infrastructure for account and credential data. These providers process information only as needed to supply their services under their own contractual and security obligations.

Information may also be disclosed when required by law, to protect rights or safety, or as part of a business reorganization where appropriate safeguards apply. Kal-Shop does not share authentication data for targeted advertising.

Cookies and sessions

Kal-Shop uses essential cookies for Google and Discord authorization flows and the first-party account session. The production session cookie is HttpOnly, Secure, SameSite=Lax, and expires after twelve hours. Signing out clears the Kal-Shop session. The current public marketplace does not use advertising cookies.

Retention and account requests

Account and profile identifiers are retained while the account is active and for the limited period needed for security, integrity, dispute resolution, or legal compliance. Short-lived OAuth-flow data and session cookies expire automatically. Product scan, publication, and successful protected-download actions create audit records used for marketplace integrity and security. A formal retention schedule will be published before paid fulfilment or broad seller onboarding is enabled.

To request access, correction, or deletion of account data, use the current developer support contact displayed on Kal-Shop's Google authorization screen. Requests may require identity verification before account data is changed or deleted.

Security and international processing

Kal-Shop applies server-side identity verification, encrypted transport, restricted environment secrets, bounded sessions, and database authorization checks. No online service can guarantee absolute security. Hosting and database providers may process information in countries other than your own, subject to their safeguards and applicable law.

Children and policy changes

Kal-Shop is intended for game developers and marketplace users who can lawfully enter an online agreement in their location. It is not directed to children below the age at which they may consent to online services. This policy may be updated as features or legal obligations change; the published date above will be revised when that happens.