This Privacy Policy describes how Zloma Scripts collects, uses, retains, and protects personal information across our FiveM storefront, checkout integrations, and support channels.
1. Identity of the Data Controller & Scope
This Privacy Policy explains how Zloma Scripts collects, processes, and protects personal data across our FiveM digital storefront, product documentation, Discord authorization flows, and CFX.re asset linking.
• Data Controller for Storefront & Support:
Zloma Scripts
Privacy & Data Protection Contact: support@zloma.dev
(For additional legal and provider details, please refer to our Impressum page).
• Data Controller for Payments & Billing (Merchant of Record):
All financial checkouts, payment card processing, billing records, invoicing, and VAT/sales tax calculations are conducted exclusively by Tebex Limited (8 Duncannon Street, London, WC2N 4JF, United Kingdom). Tebex acts as an independent Data Controller and official Merchant of Record for all order payments. Zloma Scripts never receives, collects, or stores payment card numbers or bank account details.
2. Legal Bases for Processing (GDPR Article 6)
We process personal data strictly under the lawful bases defined in Article 6 of the EU General Data Protection Regulation (GDPR) and UK GDPR:
• (a) Performance of a Contract (Art. 6(1)(b) GDPR): Necessary to authenticate your Discord identity, link your CFX.re account, generate Tebex checkout baskets, and deliver purchased digital resources securely via CFX Keymaster or Discord role assignments.
• (b) Legitimate Interests (Art. 6(1)(f) GDPR): Necessary to maintain storefront stability, verify delivery webhook signatures, defend against unauthorized scraping or DDoS attacks, prevent fraudulent chargebacks, and provide effective customer support.
• (c) Consent (Art. 6(1)(a) GDPR): Applicable strictly when you voluntarily opt-in to optional visitor performance analytics and speed insights through our cookie consent banner.
3. Specificity of Discord & CFX.re Data Processing
To verify product eligibility, assign community roles, and securely distribute FiveM scripts, we integrate with Discord and CFX.re / CitizenFX. We adhere to strict data minimization principles:
• Discord OAuth & Verification:
When you connect via Discord, we process strictly what is required: your Discord User ID (snowflake), username/display name, avatar URL, and server role/guild membership status needed to verify ownership and grant support access. We DO NOT read, collect, or store private Discord messages, contact lists, or your private Discord email address unless explicitly displayed and authorized during the OAuth consent flow.
• CFX.re / CitizenFX Integration:
When verifying asset delivery, we process your CFX.re portal/forum account identifier and Keymaster license eligibility. This data is used solely to authorize your digital ownership and dispatch encrypted resources to your Keymaster account. We DO NOT collect, access, or store FiveM game server player logs, chat history, or internal server telemetry.
4. Cookies, Local Storage & Consent Gating
Our storefront respects your privacy and enforces strict EU ePrivacy Directive and GDPR consent gating. By default, zero optional tracking scripts or performance telemetries are executed when you arrive on our website.
• Strictly Necessary Storage (No Tracking): We use essential local browser storage solely for functional operation: (1) 'zs_cookie_consent' stores your preference selection ('granted' or 'denied'), and (2) local shopping cart state keys maintain your selected packages while browsing.
• Optional Performance Analytics: External analytics (such as Vercel Analytics and Vercel Speed Insights) remain blocked until you explicitly click 'Accept All' on our cookie preferences modal.
• Managing Preferences: You can change your choice or withdraw your consent at any time by clicking 'Cookie Settings' in the website footer.
5. Concrete Data Retention Schedule
We do not retain personal data indefinitely. Data is stored only for defined, concrete retention periods matching the specific purpose of collection:
• Discord User IDs & License Eligibility: Retained for the duration of an active product license plus 12 months after expiration, transfer, or cancellation to maintain audit logs and resolve support claims.
• Delivery Webhook & Transaction Logs: Retained for 30 to 90 days to diagnose delivery errors, troubleshoot Keymaster API failures, and investigate potential abuse.
• Customer Support Tickets & Correspondence: Retained for 12 to 24 months after ticket closure to maintain continuity of support for server updates and configurations.
• Security & Server Access Telemetry: Retained for 14 to 90 days before automatic rotation/deletion.
• Cookie Consent Preferences: Retained in local browser storage for up to 12 months (or until cleared manually by the user).
• Accounting & Billing Records: Retained exclusively by Tebex Limited in compliance with UK/EU statutory tax and financial retention obligations.
6. Third-Party Processors, Controllers & External Policies
To operate our digital marketplace, we engage trusted external service providers. We disclose all major third parties along with direct links to their official privacy documentation:
• Tebex Limited (Merchant of Record & Payment Controller): Processes checkouts, card payments, VAT, and invoices. View policy: https://www.tebex.io/legal/privacy
• Discord Inc. (Identity & Community Platform): Processes OAuth authentication and support roles. View policy: https://discord.com/privacy
• CFX.re / CitizenFX / Rockstar Games (Game Asset Platform): Processes Keymaster asset linking and verification. View policy: https://forum.cfx.re/tos
• Vercel Inc. (Cloud Hosting & Optional Telemetry): Provides cloud infrastructure and optional performance insights. View policy: https://vercel.com/legal/privacy-policy
7. International Data Transfers (GDPR Chapter V)
Some of our external service partners (including Discord, Vercel, and CFX.re) process data on cloud servers located in the United States or outside the European Economic Area (EEA). Where personal data is transferred internationally, Zloma Scripts ensures that such transfers are protected by adequate legal mechanisms under Chapter V of the GDPR, such as the EU-U.S. Data Privacy Framework (DPF), European Commission Adequacy Decisions, or binding Standard Contractual Clauses (SCCs).
8. Your Data Subject Rights (GDPR Articles 15–22)
If you are located in the European Union, EEA, or United Kingdom, you possess comprehensive rights regarding your personal data:
• Right of Access (Art. 15): Request confirmation and a copy of the personal data we hold about you.
• Right to Rectification (Art. 16): Request correction of inaccurate or incomplete records.
• Right to Erasure / 'Right to be Forgotten' (Art. 17): Request deletion of your Discord link or support records where processing is no longer necessary.
• Right to Restriction of Processing (Art. 18): Request temporary freezing of your data processing under specific conditions.
• Right to Data Portability (Art. 20): Receive your provided data in a structured, commonly used, machine-readable format.
• Right to Object (Art. 21): Object at any time to processing based on legitimate interests.
• Right to Withdraw Consent (Art. 7(3)): Withdraw your consent for optional analytics at any time via 'Cookie Settings' in our footer without affecting prior lawful processing.
9. Supervisory Authority & Privacy Inquiries
To exercise your data protection rights or submit a privacy inquiry, please contact our Data Controller directly via email at support@zloma.dev or open a verified ticket in our official Discord support server.
Additionally, under Article 77 GDPR, you have the right to lodge a complaint with your competent national or regional Data Protection Supervisory Authority if you believe your personal data has been processed unlawfully. For Bavaria, Germany, the competent authority is the Bayerisches Landesamt für Datenschutzaufsicht (BayLDA).
Last updated: July 2026 • Controller: Zloma Scripts (support@zloma.dev)
This Privacy Policy is intended to provide the information required under Articles 12–14 of the EU GDPR (Regulation (EU) 2016/679) and applicable UK data protection law.