Last updated: 23 August 2026
Privacy Policy
This document explains which personal data we collect when you use this website and the CoralMC services, why we collect it, who we share it with and what rights you have. It is written to be read: where a technical term is unavoidable, we explain it.
1. Who processes your data
The data controller is Coral Services Limited MT32883222. For any matter concerning your personal data, including exercising the rights described below, you can write to [email protected].
2. What data we collect
We only collect the data we need to run the services you use. Not every user provides every piece of data: it depends on what you do on the site.
- Account: if you sign in, this happens exclusively through Discord. From Discord we receive your identifier, username, profile picture and the associated email address. We never create or store any password.
- Game identity: your Minecraft username and account UUID, when you link your game profile or use the statistics.
- Technical session data: IP address and browser type (user agent), recorded alongside sign-in sessions for security purposes.
- Support: the content of the tickets you open, messages, attachments and images you upload, including any purchase receipts.
- Live chat: the username and email address you provide to start the conversation, and the content of the messages. Your IP address and browser are stored only in one-way encrypted form (a hash), so they are not readable.
- Applications: if you apply to join the staff, your form answers, Discord identifier, Minecraft username and UUID.
- Purchases: orders are handled by Tebex. Your card details never pass through our systems and we do not store them. We only receive the order confirmation and the data needed to deliver what you bought.
- Moderation: if you are sanctioned on the network, we keep the evidence of the violation, which may include IP addresses and your sanction history.
3. Why we use it and on what basis
Every processing activity has a specific legal basis, as required by the GDPR:
- Providing the service (art. 6.1.b, performance of a contract): running your account, support, purchases and site features.
- Security and abuse prevention (art. 6.1.f, legitimate interest): recording IP addresses and sessions to detect unauthorised access, ban evasion and fraudulent activity. This is a concrete interest: without it we could not protect accounts or enforce the rules.
- Usage statistics (art. 6.1.a, consent): understanding which pages are used. These tools do not start unless you agree, and you can change your mind at any time.
- Legal obligations (art. 6.1.c): keeping tax records relating to purchases for the period required by law.
4. Who we share data with
We do not sell your data and we do not pass it to third parties for advertising. We only share it with the providers needed to run the service:
- Discord — authentication and account linking.
- Tebex — store order and payment processing.
- Cloudflare — attack protection and anti-bot verification (Turnstile).
- Google Analytics — usage statistics, only with your consent.
- PostHog — product analytics, only with your consent.
- minotar.net and mc-heads.net — services that generate Minecraft avatar images. When a page shows an avatar, your browser contacts these services directly, and they can see your IP address.
Some of these providers are based in the United States. In those cases the transfer relies on the safeguards required by the GDPR, such as the standard contractual clauses approved by the European Commission or participation in the Data Privacy Framework.
5. How long we keep it
We keep account data for as long as the account exists. Tickets, applications and moderation evidence are kept for as long as they serve the purpose they were collected for: sanction evidence in particular is retained because it is the justification for a decision and is needed to review any appeal. There is no scheduled automatic deletion in place: if you want your data removed, write to us and we will take care of it. Tax records for purchases are kept for the period required by law.
6. Your rights
The GDPR grants you rights you can exercise at any time by writing to [email protected]. We reply within one month.
- Access: find out what data we hold about you and obtain a copy of it.
- Rectification: correct inaccurate or incomplete data.
- Erasure: ask for your data to be removed, where we have no legal obligation or legitimate reason to keep it.
- Restriction: ask us to pause processing while we verify an objection you raised.
- Portability: receive the data you provided in a machine-readable format.
- Objection: object to processing based on legitimate interest, explaining your situation.
- Withdrawing consent: turn analytics off whenever you want, from the "Cookie preferences" link at the bottom of every page. Withdrawal does not make previous processing unlawful.
If you believe the processing of your data breaches the rules, you can lodge a complaint with the Italian Data Protection Authority (www.garanteprivacy.it) or with the supervisory authority of the country where you live.
7. Minors
CoralMC services are not aimed at children under 14. If you are a minor, use the site and the network with the consent of whoever holds parental responsibility. If we become aware of data collected from a child under 14 without such consent, we delete it.
8. How we protect data
Connections to the site are encrypted (HTTPS). Access to the internal panel is limited to authorised personnel and governed by specific permissions. Some particularly sensitive data, such as the IP address and browser of live chat visitors, is stored only in one-way encrypted form. No system is perfectly secure: should a breach occur that poses a risk to your rights, we will notify you as required by law.
9. Changes to this policy
If the processing described here changes, we update this document and the date at the top. Where the changes concern purposes that require consent, we will ask for it again.
Coral Services Limited MT32883222 — [email protected]
CoralMC Help
Offline
Checking...
