ACOMASTER

Privacy

What the platform stores, why, and who can see it.

Last updated August 30, 2026

ACOMaster is an operations dashboard used by automated-checkout organizations (ACOs). This page explains what the platform stores, why, and who can see it.

Who runs this site

ACOMaster runs every ACO's console, including the one at the address you arrived from. Each ACO gets its own subdomain — youraco.acomaster.net — but the software, the servers, and this policy are ours. Reach us at hello@acomaster.net.

ACOMaster is not affiliated with, endorsed by, or sponsored by Discord, or by any retailer named anywhere on this site.

What Discord tells us when you sign in

Signing in uses Discord's official OAuth flow. You are sent to discord.com to approve it, and Discord shows you the request before anything happens.

We ask for exactly two read-only scopes:

  • identify — your Discord user ID, username, and avatar.
  • guilds.members.read — your current membership and role IDs in the one ACO Discord server whose dashboard you are opening.

That is the whole request. We never receive your Discord password. We cannot read your messages, post as you, join servers for you, or see anything in a server you have not joined. If you ever see a page asking for your Discord password directly, it is not us — Discord logins happen on Discord.

When Home displays your stored avatar, your browser fetches it from cdn.discordapp.com. The avatar URL identifies your Discord account, and Discord receives the request time, IP address, and browser details. We do not send the ACOMaster page address as a referrer.

What we store

  • Your identity — the Discord ID, username, and avatar above.
  • Your membership — which ACO you belong to and what role you hold there.
  • Your onboarding acknowledgement — the exact rules version and publication you acknowledged, how the platform observed it, the observation time, and the current access-role delivery state. We do not store your Discord OAuth token.
  • What you put in — checkout profiles, shipping and billing addresses, retailer account logins, and mailbox credentials, where you or your ACO have added them.
  • What you owe and what you say you paid — payment requests your ACO has sent you, the amount and method you report through the bot, and any payment screenshot you choose to send. Screenshots are encrypted and deleted after 90 days; a record that one was sent is kept.
  • Your activity — an audit record of changes to memberships, roles, and stored records, so an ACO can answer who changed what.
  • A session cookie — set after sign-in, expiring after 30 days.

How stored credentials are protected

Retailer passwords, payment-card details, and mailbox credentials are encrypted at rest and masked in the interface. Payment cards and retailer logins go further: they are sealed to a key your ACO holds and we do not, so we store them without being able to read them — see "Using your payment card" in the terms. Access is scoped per organization at the database level, so one ACO's staff cannot read another ACO's records — that boundary is enforced by the database, not only by the application.

The Discord channel observer

An ACO's owner may connect an ACOMaster bot to channels in their own Discord server to read checkout confirmations posted there by checkout bots. It reads messages only in the channels the ACO explicitly selects, in a server that ACO controls, and captured messages are deleted after 30 days.

Payment requests in Discord

When your ACO bills you, the bot sends you a direct message with the total, a breakdown of what it covers, and the payment handles of the person you are paying. A person at your ACO decides when to send it; nothing is sent automatically.

There is no setting here to switch this off — the direct message is how your ACO bills you. If you close your Discord DMs or block the bot, it cannot reach you: your ACO is shown that the message did not arrive, and what you owe stays on your Billing page regardless.

That message contains a button to tell us you have paid and, if you choose, to send a screenshot of the payment. Nothing else in the conversation is read — the bot only looks for an image after you have pressed that button.

We will never ask you for a password, a card number, or a login in a Discord message. If a message claiming to be from your ACO asks for any of those, it is not us. The amounts and payment handles in a real message always match your Billing page, and that page is the one to trust.

What we do not do

  • We do not sell or rent your data.
  • We do not run advertising or third-party analytics trackers on this site.
  • We do not publish a directory of the ACOs on ACOMaster, or of their members.
  • We do not share your records with other ACOs.

Your ACO's role

The ACO you belong to decides who on its staff can see your records, and its own agreement with you covers the checkout service itself. ACOMaster provides the software and enforces the boundaries described above.

Questions, corrections, deletion

Write to hello@acomaster.net and say what you need. If you want your data removed, tell us which ACO you belong to so we can find you.

Privacy — ACOMaster