GROUPSPACE
Legal · privacy

Privacy policy

What GROUPSPACE holds about you, why, for how long, who else sees it, and how to make it go away. Written to be read by the people it describes, including the ones who never signed up.

Last updated 10 August 2026

Draft. This document is a working draft prepared for GROUPSPACE and has not been reviewed by a lawyer. Do not publish it as binding policy until counsel has read it — particularly the sections covering children’s data, and the Roblox and Discord platform terms it depends on.

Summary

GROUPSPACE is management software for online communities — mostly Roblox groups. It stores the structure of a community, the records its staff file, its internal economy, and data sent from games it is connected to.

Most of what GROUPSPACE holds about a person is held on behalf of a community, not for ourselves. A small amount — your account, your billing, our logs — is ours. The distinction matters and the next section sets it out.

  • For a linked platform account we store the user id and the username. That is the whole of it.
  • We do not sell personal data and we do not use it to train AI or language models.
  • We do not track anyone across experiences or join platform data to outside datasets.
  • In-game chat is only stored where a workspace has deliberately switched it on, is capped at 30 days, and is readable only by people holding a specific permission — with every read logged.
  • Roblox’s erasure webhook is handled continuously, and revoking our access to a platform account expunges what we obtained through it.

Controller or processor

Data protection law distinguishes the party that decides why data is collected (the controller) from the party that handles it on instruction (the processor). GROUPSPACE is both, in different places, and which one it is changes who you should contact.

DataOur roleWho decides
Your GROUPSPACE account, sign-in, billing, support conversations, our own security and service logsControllerWe do. This policy is the notice for it.
Everything inside a workspace: members, positions, records, ledger entries, operations, attendance, game sessions, chatProcessorThe workspace owner does. They are the controller. Our instructions come from them, under the DPA.
Aggregated, de-identified service statisticsControllerWe do. These carry no user or workspace identifiers.
If you are a member of somebody's workspace. The community that runs the workspace decides what is recorded about you and who can see it. Ask them first. If you cannot reach them, or they will not act, write to privacy@groupspace.xyz and we will route the request and tell you who the controller is.

What we collect

Account data

  • Display name and email address.
  • Authentication data: password hash where a password is used, and the identifiers returned by a platform sign-in.
  • Workspace memberships, positions and permissions.
  • Preferences — notification settings, interface settings.

Linked platform identities

When you connect a Roblox, Discord or other platform account, we store the platform user id and the username or display name, plus the tokens needed to keep the connection working. Nothing else. See the minimisation section below.

Workspace and organisation data

  • The org chart: organisations, units, positions, and who holds them.
  • Applications you submit and their outcome.
  • Time and attendance: shifts, clock-ins, clock-outs, and the corrections applied to them.
  • Operations you are rostered onto or take part in.
  • Quota progress.

Records filed by staff

Arrests, warnings, citations, commendations, internal notes, community background flags, incident reports and disciplinary entries — whatever the community’s own rules produce. Each entry carries the subject, the author, a timestamp, and whatever the author typed. Records are the point of the product and they are also the part most capable of being unfair, which is why the acceptable use policy has a section about them.

Ledger and economy data

Double-entry ledger entries in the workspace’s own currency: payroll accruals, fines, transfers, tax calculations, and payout runs. Where a payout is settled in a platform currency, we hold the calculated instruction and the fact that it was marked settled. We do not hold, move or touch real money or Robux.

Game session and presence data

Where a community has installed the game integration, its game servers send us events about the players in them: joins and leaves, session duration, which server and experience, presence, door checks, and the events the community has configured. This is first-party data from the customer’s own games, sent by their own installation of our SDK.

Chat messages, where enabled

Only if the workspace has opted in. Filtered message text as the platform produced it, the sender, the channel type, and when it was sent. Covered in full below.

Billing data

Plan, subscription status, invoices, and the payment processor’s customer reference. Card numbers go to the processor and never reach our systems.

Technical and support data

  • Server logs: IP address, user agent, request path, timing, and a correlation id.
  • Audit log entries: who did what in a workspace, when, and from where.
  • Error reports, which may incidentally include a user or workspace id where an error was specific to one.
  • Anything you send us in a support conversation.

Platform data minimisation

Roblox’s rules for third-party applications require data minimisation, and we build to them rather than to what the API would technically let us take.

FieldStored?
Platform user idYes. It is the join key for everything.
Username / display nameYes, so a human can recognise who a record is about.
Group memberships and rolesRead at the moment of verification. We store the verified outcome, not a mirror of the platform's directory.
Date of birth or ageNo.
Avatar images, profile photosNo.
Email address from the platformNo.
Friends lists, inventories, purchase historyNo.
Anything from an experience the customer does not ownNo.
No cross-experience tracking. Quotas and analytics can span several games where those games all belong to the same customer and the data comes from their own installation of our SDK. There is no cross-workspace player reputation graph, no fingerprinting, and no linking of platform data to outside datasets. This is a platform prohibition, not a design preference, and it is not something a customer can turn on by asking.

Why we hold it

Where GROUPSPACE is the controller, these are the purposes and the legal bases we rely on under the UK GDPR and EU GDPR. Where GROUPSPACE is a processor, the basis is the workspace owner’s, not ours.

PurposeDataLegal basis
Giving you an account and running the serviceAccount data, platform identitiesPerformance of a contract with you.
Taking paymentBilling dataPerformance of a contract; legal obligation for tax records.
Keeping the service secure and availableLogs, audit entries, error reportsLegitimate interests — running a service that is not trivially abused.
Answering support requestsSupport conversations, account dataPerformance of a contract; legitimate interests.
Service and security noticesEmail addressPerformance of a contract; legitimate interests.
Meeting platform obligations, including erasure requestsPlatform identitiesLegal obligation and legitimate interests.
Complying with the lawWhatever the obligation coversLegal obligation.

We do not run behavioural advertising and we do not profile people for marketing. If we ever send a marketing email it will be to an account holder, about GROUPSPACE, with an unsubscribe link, on consent or soft opt-in.

Chat history

Chat history is the most sensitive thing in the product. It is treated as such.

ControlHow it works
Off by defaultA workspace has no chat data at all unless an owner deliberately enables it and acknowledges what they are taking on.
Plan-gated with a signed DPAAvailable on the top plan only, and only once a data processing addendum is signed. The gate exists so there is a contract with anyone storing this.
30-day hard capEvery message is written with an expiry. A purge job deletes it. Retention can be configured downward, never upward, and it is real deletion rather than a hidden flag.
Filtered text onlyWe store the text the platform's own filter produced. We do not capture, reconstruct or attempt to recover unfiltered text.
Moderator-onlyReading chat requires a dedicated permission that is not included in any default position template. It has to be granted on purpose.
Every read auditedWho searched, for whose messages, and when. Chat search is exactly the surface that gets abused internally, so the log exists to catch it.
Encrypted at restHeld encrypted and separately from the main tables.
Purged on erasureA Roblox erasure request deletes a user's messages immediately, ahead of the retention clock.
If you play in a game connected to GROUPSPACE. Whether your messages are retained is the community’s decision, not ours. Ask the community that runs the game. They are the controller of that data and they are obliged to be able to tell you.

Children's data

This section is not boilerplate. Roblox’s audience skews young, and a large share of the people whose data passes through GROUPSPACE are children.

Two different populations

WhoAge positionWhat we hold
People who sign in to GROUPSPACE13 or over. Roblox OAuth will not let an under-13 account authorise a third-party application, and our terms set the same floor.Account data, platform identity, whatever their workspace records.
Players in a connected gameAny age. There is no floor, because they never come near a GROUPSPACE sign-in page.Platform user id and username, session and presence data, records filed about them, and chat where the workspace enabled it.

The second row is the one that matters. A player can have a substantial GROUPSPACE record without ever having heard of GROUPSPACE.

We do not shelter under Roblox

Roblox operates its own children’s privacy programme on its own platform. That posture does not extend to our servers. When a game sends us data about a child, GROUPSPACE and the community that runs the game carry their own obligations for it — including under COPPA in the United States, the UK Age Appropriate Design Code, and the equivalent rules elsewhere. We say this plainly because the alternative — assuming the platform covers it — is how this goes wrong.

What follows from that

  • We never ask a child for anything. There is no data collection surface pointed at players. Everything we hold about a player arrives from the community’s own game server.
  • Minimisation is stricter than the law’s floor. User id and username. No age, no birth date, no avatar, no contact details.
  • No profiling and no advertising. Nothing in GROUPSPACE targets a player, scores them, or feeds an ad system. There is no ad system.
  • No AI training. Children’s chat is not training data, for us or for anyone.
  • Chat is gated hardest. Opt-in, top plan, signed DPA, 30-day cap, dedicated permission, audited reads. The controls in the section above exist principally because this data is largely about children.
  • Deletion is fast and unconditional. An erasure request through the platform purges everything for that user id across every workspace, with no review step and no exceptions we grant on request from a customer.

Parents and guardians

If you are a parent or guardian and you believe we hold data about your child, write to privacy@groupspace.xyz. Tell us the Roblox username or user id — that is all we can search on, because it is all we store. We will identify what is held, tell you which community is the controller, and delete our copy on request. We will not ask you to prove your identity with documents we would then have to store; we will verify through the platform account instead.

Where the request concerns data a community controls, we act on it as a processor and tell the community. We will not leave a child’s data in place because a customer objects.

For community owners

If you run a workspace connected to a game with young players, you are a controller of children’s data. Enabling chat history multiplies that responsibility. Get advice before you switch it on, and read the children’s data annex of the DPA.

How long we keep it

CategoryRetention
Account dataWhile the account exists, then deleted. Some fields survive briefly in backups until those age out.
Linked platform identity and tokensUntil you unlink or revoke access, at which point it is expunged.
Workspace content — org structure, records, ledger, operations, attendanceSet by the workspace owner within their plan’s limits. The free plan is capped at 30 days of history; paid plans extend it. Deleted when the workspace is deleted, after the grace period.
Chat messagesThe workspace's retention setting, hard-capped at 30 days. Deleted by an expiry job, not flagged.
Game session and presence dataThe workspace's retention setting. Aggregated figures that carry no user id may outlive the underlying rows.
Audit logRetained longer than the data it describes, because an audit log that can be trimmed is not an audit log. Target retention [audit log retention period].
Billing records and invoicesKept for as long as tax and accounting law requires, currently [statutory financial retention period].
Server and security logs[log retention window], then deleted.
Support conversations[support retention period] after the conversation closes.
BackupsRolling. A deleted item disappears from backups as they cycle out, within [backup cycle window].

Where an account is suspended for non-payment rather than terminated, data is retained for 90 days so it can be recovered if you come back.

Who we share it with

We do not sell personal data. We do not share it for anyone else’s marketing. We share it in four situations and no others.

  • Within your workspace. Other members see what the workspace’s permission model lets them see. That is the product working as intended and the owner configures it.
  • Service providers. The infrastructure we run on — hosting, database, payment processing, transactional email, error tracking. Each is bound by contract, may only act on our instructions, and the categories are listed on the subprocessors page.
  • Connected platforms. Where you have linked an account or the customer has installed the game integration, data moves between us and that platform to make the feature work.
  • Law and safety. Where we are legally required to disclose, or where disclosure is necessary to protect someone from serious harm. We will tell the affected people unless we are prohibited from doing so.

If GROUPSPACE is ever sold or merged, data may transfer to the buyer. We will give notice before that happens and the buyer will be bound by terms no weaker than these.

International transfers

GROUPSPACE is operated from the United States (Ohio) and primary infrastructure — the application and the database — is hosted with Railway in the United States, US East. Payment processing is handled by Stripe in the United States.

Where data leaves the UK or the European Economic Area, the transfer relies on an adequacy decision where one exists, and otherwise on the standard contractual clauses (with the UK addendum where relevant) plus a transfer risk assessment. Details of the mechanism for a specific provider are available from privacy@groupspace.xyz.

We are not claiming certification under any transfer framework. We are describing the mechanism we use.

How it is protected

These are practices, not accreditations. GROUPSPACE holds no security certification and does not claim one.

  • Encryption in transit on every connection, and encryption at rest for chat history, held separately from the main tables.
  • A permission model enforced at query time rather than by filtering results afterwards — filtering afterwards leaks the existence of records through result counts.
  • An append-only audit log covering privileged actions, with chat reads logged individually.
  • Signed, replay-protected webhooks in both directions, with idempotency on ingest.
  • Least-privilege staff access, granted for a reason and logged when used.
  • Development against the CASA (OWASP-based) requirements that Roblox applies to third-party applications, and against the platform’s security expectations generally. Aligning our practices with a standard is not the same as being assessed against it, and we do not say otherwise.
  • Error tracking and structured logging with correlation ids, so an incident can be reconstructed.

No system is perfectly secure. If we suffer a breach affecting personal data we will notify the relevant supervisory authority and affected controllers without undue delay, and affected individuals where the law requires it.

Found a vulnerability? security@groupspace.xyz. Read the security research section of the acceptable use policy before you start testing.

Your rights

Depending on where you live you have some or all of these rights. We honour them for everyone rather than checking your jurisdiction first.

RightWhat it means here
AccessA copy of what we hold about you, and an explanation of where it came from.
RectificationCorrection of anything wrong. For a record filed by a community, we route the request to them — we will not rewrite their record on our own initiative.
ErasureDeletion. See the next section for the fast paths.
RestrictionAsk us to stop processing while a dispute is resolved.
ObjectionObject to processing we base on legitimate interests, including on grounds specific to your situation.
PortabilityYour data in a machine-readable format. Workspace owners have a self-service export.
Withdraw consentWhere we relied on consent, withdraw it at any time. That does not undo processing already done.
ComplainComplain to your data protection authority. In the UK that is the Information Commissioner’s Office; elsewhere in Europe it is your national authority. GROUPSPACE LLC is a United States company with no establishment in the UK or the EU, so there is no single lead supervisory authority for us under the one-stop-shop mechanism — complain to the authority where you live.

Write to privacy@groupspace.xyz. We respond within one month and will say so if a request is complex enough to need longer. We verify identity proportionately — usually by confirming control of the account or platform identity, not by asking for documents we would then have to keep.

Where a request concerns data a community controls, we will forward it and tell you who they are. Where the community will not act and the data is a child’s, we will act anyway.

Erasure and revocation

The Roblox erasure webhook

When a Roblox user exercises their right to erasure, Roblox notifies us over a signed RightToErasureRequest webhook. The handler runs continuously, verifies the HMAC signature before parsing anything, enforces a 300-second replay window, and honours only requests that arrive from the platform.

For that user id, across every workspace holding data for them, we purge records, game sessions, operation participation and chat messages. This is deletion, not anonymisation, and it is not reversible. The erasure itself is written to the audit log so it can be shown to have happened without keeping the data that would prove it.

We do not honour erasure requests that arrive any other way as platform requests. A message asking us to delete someone’s data is not an authenticated instruction, and acting on one is how the wrong person’s record gets deleted on somebody else’s say-so. Requests that reach us directly go through the identity checks in the rights section instead — same outcome, different door.

Revoking access

Unlinking a platform account, or revoking our authorisation from the platform’s own settings, expunges the data we obtained through that connection. You do not need to ask us and you do not need a reason.

Platforms without an erasure signal

Roblox provides this webhook; other platforms we support do not. For those, erasure runs through a manual request to privacy@groupspace.xyz — same purge, same audit entry, different trigger.

Data you have copied elsewhere

If a community has exported GROUPSPACE data into its own database, a Discord bot, or a spreadsheet, the erasure obligation follows the data. Our purge removes our copy. It cannot remove theirs.

Cookies

GROUPSPACE sets two cookies — a session cookie and an OAuth state cookie — and no analytics or advertising cookies at all. The cookie policy names them and explains what each one does.

Changes

We will update this policy as the product changes. Material changes — new categories of data, a new purpose, a new class of recipient — get at least 30 days’ notice by email to account holders and a notice in the application. Everything else takes effect on publication and the date at the top changes.

Previous versions stay available so you can see what moved.

Contact

The controller for the data described in this policy is GROUPSPACE LLC, an Ohio limited liability company, c/o ZenBusiness Inc., 100 E Broad St Ste 1350, Columbus, OH 43215, United States.


  • privacy@groupspace.xyz — data subject requests and anything about this policy.
  • dpo@groupspace.xyz — our data protection contact, for anything that needs to go over the product team’s head. A statutory data protection officer is not generally required of a company this size, but the chat-history feature is systematic monitoring of data about children, which is the case where one can be: [decision needed before chat history leaves beta]
  • security@groupspace.xyz — vulnerability reports and suspected incidents.
  • legal@groupspace.xyz — contracts, the DPA, and formal notices.
GROUPSPACE LLC is established in the United States and has no establishment in the UK or the EU. Where a company in that position offers a service to people inside those territories, a representative under Article 27 of the GDPR and its UK equivalent may have to be appointed: [decision needed before launch].
Unfilled placeholdersNo certifications claimed

All legal documentsData processing addendumSubprocessorsCookie policy