Privacy Policy
Last updated: June 27, 2026
1. Overview
This Privacy Policy explains what information RIM (Rolux Interface Module) collects, why we collect it, and how it is stored and protected. RIM is a hotel-management tool for Welcome to Bloxburg, a Roblox game. We collect the minimum information needed to operate the service securely.
2. Information We Collect
Account information (via OAuth sign-in)
When you sign in with Google or Discord, our authentication provider receives and we store:
- Your email address
- Your display name (from your OAuth provider profile)
- Your avatar/profile image URL (if provided by the OAuth provider)
- A unique Discord ID and/or Google ID, used only to prevent duplicate accounts and to authenticate you on future sign-ins
We never receive or store your Google or Discord password. Sign-in is handled entirely by the OAuth provider; RIM only receives the profile fields listed above.
In-app activity data
If you use RIM as hotel staff, a manager, or an owner, RIM stores the operational data you enter or that is generated by your actions, including:
- Hotel, room, facility, and menu configuration you or your hotel owner create
- Bookings, table assignments, and orders, including the in-game (Roblox) display name of guests you serve
- Housekeeping logs and session records tied to hotel sessions you participate in
- An append-only audit log of account-level and operational actions (e.g. "booking.create", "room.update_price"), which records the action taken, the actor, a before/after snapshot of the changed data, and the IP address the request came from
Guest display names entered into RIM (for bookings, orders, and table assignments) are Roblox in-game names, not real-world identities, and are limited to 20 characters per Roblox’s own display name limit.
Technical & security data
To protect the service from abuse, our rate-limiting system temporarily processes your user ID and IP address to enforce request limits. This data is used only for rate limiting and is not retained as part of your permanent profile.
Analytics (if enabled)
RIM may use Vercel Speed Insights and/or Vercel Analytics to understand site performance and usage patterns (e.g. page load times, general traffic volume). When enabled, this can include aggregated, privacy-respecting metrics such as page paths, approximate load times, device/browser type, and country-level location, depending on which Vercel product is active at any given time. These tools are designed not to use cookies for cross-site tracking and do not collect content you enter into RIM. If and when this is active in the deployed app, it will be covered by Vercel’s own privacy policy in addition to this one.
3. What We Do NOT Collect
- We do not collect real names, physical addresses, phone numbers, or payment information.
- We do not process real money or Robux transactions.
- We do not access your Google or Discord password.
- We do not sell your data, and we do not use your data for advertising.
4. How We Use Your Information
- To authenticate you and maintain your session securely
- To operate core features: bookings, orders, housekeeping, table assignments, and session management
- To enforce role-based permissions
- To maintain audit logs for security, accountability, and dispute resolution between hotel staff
- To detect and prevent abuse, including duplicate accounts and rate-limit violations
- To understand aggregate performance and usage, if analytics are enabled
5. Who Can See Your Data
Access is restricted by Row Level Security at the database level and role checks at the application level:
- Your profile (email, display name, avatar) is visible to other authenticated RIM users, consistent with how Discord/Roblox communities normally display member identity.
- Hotel operational data (bookings, orders, etc.) is visible only to active members of that specific hotel.
- Audit logs for a hotel are visible only to that hotel's Owner and to the RIM administrator.
- No RIM user can read, modify, or delete another hotel's data unless they are an active member of that hotel.
6. Data Retention
We use soft deletion rather than permanently erasing operational records, because historical hotel session data and audit trails need to remain consistent for other members of a hotel even after a particular account is disabled. Audit log entries are append-only and are never deleted or modified once written, by design.
If you wish to have your account deactivated, contact us through the support channel referenced in Section 8. We will disable your account; data tied to shared hotel records (e.g. a booking you created) may be retained as part of another hotel’s operational history, with your direct account access removed.
7. Security
We apply multiple layers of protection to your data, including encrypted transport (HTTPS/TLS), database-level Row Level Security on every table, role-based authorization, rate limiting, input validation, and append-only audit logging. No method of transmission or storage is 100% secure, but we take reasonable, industry-standard steps to protect your information.
8. Your Choices
- You can review the profile information visible to you by checking your account settings within RIM.
- You can request account deactivation at any time.
- You can revoke RIM's access to your Google or Discord account at any time directly through Google or Discord's own account settings, which will prevent future sign-ins.
9. Children's Privacy
RIM is not directed at children and relies on the age requirements of our OAuth providers (Google and Discord) for account eligibility. We do not knowingly collect personal information from children in violation of applicable law.
10. Changes to This Policy
We may update this Privacy Policy as RIM evolves — for example, if we add or remove analytics tools. We will update the “Last updated” date above when we do. Significant changes affecting how your data is used may be announced through the RIM application or community channels.
11. Contact
Questions about this Privacy Policy or your data can be directed through the support channel linked in the RIM application or community server.
See also our Terms of Service.