Privacy Policy
In effect from 2 October 2026 Hydra Labs
The short version
If you are a player on a server that uses FiveStaff: the server's owner decides what is collected about you and why. We hold it for them. Ask them first, and we will help them answer you.
If you are staff: we hold your Discord account details, what you did in the panel, and enough to keep your account secure. If you are just reading this site: it sets no cookies and we are not tracking you.
This box is a summary for convenience and is not part of the agreement. Where it and the wording below differ, the wording below is what applies.
1. Who we are
FiveStaff is operated by Hydra Labs. For questions about anything on this page, open a ticket in our support Discord (discord.gg/hydralabs).
2. Who is responsible for what
This matters more than anything else on the page, so it is first.
Your server's data: the owner decides, we hold it
When a FiveM server installs FiveStaff, the server's owner decides what is recorded about their players and why. Under UK data protection law they are the controller and we are their processor: we act on their instructions, we do not use their players' data for our own purposes, and we do not sell it to anybody.
So if you played on a server and want to know what is held about you, or want it deleted, the server's owner is the person to ask. If you cannot reach them, ask us in our support Discord and we will help — including telling you which server holds what, where we are allowed to.
Where we decide: accounts, billing, security and the shared list
We are the controller for:
- staff and owner accounts, and how people sign in;
- billing and the records we must keep of it;
- keeping the service secure, and investigating abuse of it; and
- the optional shared ban list, which exists across servers rather than inside one.
3. What is collected
If you are reading this website
fivestaff.gg sets no cookies and runs no analytics, no advertising tags and no third-party trackers. Our web server and Cloudflare keep ordinary request logs — the address you connected from, the page you asked for, the time and your browser's user agent — for a short period, to keep the site up and to stop abuse. See the Cookie Policy.
If you are staff on a server that uses FiveStaff
- your Discord account: its ID, username, display name, avatar and the email address on it;
- which servers you are staff on and what you are allowed to do there;
- a record of what you did in the panel — every action on a player, and every time you read a player's identifiers, their framework data or watched them;
- sign-in information: sessions, devices, two-factor settings and recovery codes, and the address you signed in from;
- what you have asked to be notified about, and your quiet hours.
If you play on a server that uses FiveStaff
The server's owner decides which of these their server collects:
- the identifiers your game connects with — your FiveM licence, and where your game provides them your Steam, Discord, Rockstar and Xbox identifiers, plus the IP address you connected from;
- the names you have used in game, when you first and last played, and how long you have played;
- characters on your account, and the money, vehicles, items and job your server's framework holds for them;
- reports about you and reports you made, including the evidence attached to them — which can include a screenshot taken from your game and a recording of where you and others were in the minutes before;
- what staff recorded about you: notes, warnings, kicks, bans, appeals and your trust score;
- events from your play — joining and leaving, deaths, kills, vehicles, money, items and doors — where the server has that turned on;
- while a member of staff is watching you, a live view of your game, and audio if they call you. Your server's rules must tell you that staff can do this.
4. Why, and on what legal basis
| What for | Basis |
|---|---|
| Giving staff the service they signed up for | Performance of our contract with them |
| Holding a server's player records on its owner's behalf | The owner's own basis, under their instructions — usually their legitimate interest in running a fair server |
| Keeping the service secure, preventing abuse and fraud | Our legitimate interests |
| The shared ban list, for the most serious bans | Our legitimate interests, and those of the servers using it, in keeping proven cheaters out |
| Billing, accounting and tax records | Our contract, and our legal obligations |
| Answering you when you contact us | Our legitimate interests |
Where we rely on a legitimate interest, we have weighed it against what it means for the person involved, and you can ask us about that assessment or object to it — see section 8.
5. Who else sees it
We do not sell personal data and we do not share it for advertising. We use a small number of companies to run the service — hosting, payments, storage, email, sign-in and push notifications. Each of them is listed, with what they do and where they are, on who processes your data.
Working out an unfamiliar framework. If a server runs a framework FiveStaff does not know and its owner chooses to have it set up automatically, we send the layout of that server's game database — its table and column names, when its main tables were last written to and how they relate to one another — and a few example rows to an AI service to work out where characters, money, inventories and vehicles are kept. If the first answer does not hold up against the server's own data, a second request is made with what was wrong and a few example rows from any other table it needs. Player names, identifiers, contact details and anything typed into a free-text field are hidden before anything is sent. Nothing is sent unless the owner chooses this, and they can set the layout up themselves instead.
Beyond that, data is shared:
- with the staff of the server that holds it, as its owner's permissions allow;
- with other servers, in the narrow case of the shared ban list described in section 2, and then only as hashes and a category;
- where we are required to by law, or to establish or defend a legal claim; and
- with a buyer, if the business is ever sold — who would be bound by this policy.
6. Where it is kept
The service runs on servers in Europe. Some of the companies we use are in the United States; where data reaches them it is covered by the UK's approved transfer mechanisms — the International Data Transfer Addendum to the European Commission's standard contractual clauses, or the UK extension to the EU–US Data Privacy Framework. The subprocessor list says which applies to whom.
7. How long it is kept
- A server's records, reports, evidence and logs are kept for as long as that server's plan says — 30 days on the free plan, 12 months on Pro — and are then deleted automatically, including the files behind them.
- A ban that is still in force, and the identifiers it covers, is kept while it is in force. A ban nobody can enforce is not a ban.
- Staff accounts are kept while the account exists. Delete it and we remove it, keeping only what the audit record needs to stay honest — that an action was taken, by whom, and when.
- Billing records are kept for six years, because tax law requires it.
- Request logs are kept for a short period, measured in days, and then dropped.
- Backups are kept on a rolling basis and overwritten; something deleted from the service leaves the backups as they roll.
8. Your rights
Under UK data protection law you can ask us to:
- tell you what we hold about you, and give you a copy;
- correct it if it is wrong;
- delete it, where there is no good reason for us to keep it;
- restrict what we do with it, or object to our using it where we rely on a legitimate interest;
- give you, or somebody else, a portable copy of what you gave us.
Open a ticket in our support Discord (discord.gg/hydralabs) and say which of these you are asking for. A ticket is private between you and us. We answer within one month. If your request is about a particular server's records, we will usually need to pass it to that server's owner, who decides — and we will tell you that we have.
If you are not happy with how we have handled it, you can complain to the Information Commissioner's Office at ico.org.uk. We would rather you came to us first.
9. How it is kept safe
- Everything travels encrypted, and the connection from your game server to us is authenticated and signed.
- Sensitive identifiers are stored hashed, so the ban list a game server holds cannot be read backwards into a list of people.
- Server keys and API keys are stored as hashes and shown once.
- Every staff read of identifiers, framework data or live view is permission-checked and written to the audit log.
- Two-factor authentication is available to every account, and we recommend it for anybody with the power to ban.
If something does go wrong, we will tell the people affected and the Information Commissioner's Office where the law requires it. Report a security problem by opening a ticket in our support Discord , not in a public channel, and we will take it seriously.
10. Children
FiveStaff is for the staff of a game server and is not aimed at children. You need a Discord account to use it, which means being at least 13, or older where your country sets a higher age. If you believe a child's data is held here without a proper basis, tell us in our support Discord and we will look into it.
11. Changes
We will update this policy as the service changes. The date at the top says when the current wording took effect, and we will tell account holders by email before a change that materially affects them.
Last updated 2 October 2026. Previous versions are available on request in our support Discord .