1. Who we are
Koja Scripts (“we”, “us”, “our”) operates the website at https://kojascripts.eu. This Privacy Policy explains what personal data we collect when you visit the website or purchase a Product, how we use it and the rights you have under the GDPR and similar regulations.
2. Data we collect
Account data
When you sign in with your CFX/Forum account, we receive your forum user ID, username, display name and avatar URL. This data is stored in a short-lived signed session cookie (cfx_session) and is used to identify you across the store.
Order data
When you place an order, Tebex shares the transaction ID, the products purchased, total paid and a billing email with us so we can fulfil the order, provide receipts and respond to support requests. We do not receive or store your full payment card details.
Optional Discord data
If you join our Discord server or leave a review tied to a Discord ID, we may store and display your public Discord username and avatar to enrich the on-site experience.
Technical data
We collect basic technical information such as IP address, browser user-agent, referrer and the pages you visit. This data is used to keep the site secure, debug errors and aggregate anonymised usage statistics.
3. Cookies
We use a small number of cookies, grouped as follows:
- Essential cookies — required for the basket, currency selection, login session and CSRF protection. These cookies cannot be disabled if you wish to make a purchase.
- Preference cookies — remember your display currency and dismissed banners. Stored in your browser’s
localStorage. - Analytics cookies — optional; help us understand how the store is used and which products are popular. Loaded only after you accept them in our cookie banner.
4. Why we process your data (legal basis)
- Contract — to deliver Products you purchase and provide post-sale support.
- Legitimate interests — to operate, secure and improve the Website.
- Consent — for optional analytics and marketing cookies.
- Legal obligation — to keep invoices and tax records as required by law.
5. Third-party processors
We share the minimum data required to operate the store with the following providers:
- Tebex / Overwolf Ltd. — payments, checkout and order delivery. See tebex.io/privacy-policy.
- Cloudflare — DDoS protection, CDN and storage (R2) for product imagery.
- CFX.re — authentication provider for your store account.
- Discord — community support and review enrichment.
- Dokploy / our hosting provider — infrastructure for serving the website.
6. How long we keep your data
- Login session cookies: deleted when you log out or after their lifetime expires.
- Order records: retained for as long as required by tax and accounting law (typically 5–7 years).
- Support conversations: retained for up to 24 months after the last interaction.
7. Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you;
- request correction of inaccurate data;
- request deletion of your data (subject to legal retention obligations);
- withdraw consent for optional analytics at any time;
- object to or restrict certain processing;
- file a complaint with your local data protection authority.
To exercise any of these rights, contact us via Discord at https://dc.kojascripts.eu.
8. Security
We use TLS for all traffic, hash sensitive tokens, and limit access to production data to a small number of operators. While no system can be 100% secure, we take reasonable precautions to protect your data from unauthorised access, loss or misuse.
9. Changes
We may update this Privacy Policy occasionally. Changes take effect when posted on this page and the “Last updated” date is revised.