Privacy Policy
Last updated: July 2026 · The Obsidian Consortium (OB.CN) · Corp ID 98809146
1. Introduction
The Obsidian Consortium ("OB.CN", "we", "us") operates obsidianconsortium.space (the "Site"). This Privacy Policy explains what personal data we collect, why we collect it, how we use it, and what rights you have under GDPR (EU), CCPA (California), and EVE Online's terms.
By using the Site, authenticating via EVE SSO, or purchasing from our store, you consent to the data practices described in this policy.
2. Data We Collect
2.1 EVE Online Data (via EVE SSO + ESI)
When you authenticate via EVE SSO, we collect the following from CCP's OAuth2 + ESI APIs:
| Data Field | Source | Purpose | Retention |
|---|---|---|---|
| Character ID | SSO JWT | User identification | Permanent (until account deletion) |
| Character Name | SSO JWT | Display + audit log | Permanent |
| Corporation ID | SSO JWT | Membership verification | Permanent |
| Corporation Roles | ESI | Officer role assignment | 30 days |
| Character Portrait | images.eveonline.com | Display in header + dashboard | Cached locally for 7 days |
| Skill Points + Queue | ESI | Dashboard widget | 15 min (refreshed) |
| Wallet Balance | ESI | Dashboard widget | 15 min (refreshed) |
| Location + Ship | ESI | Dashboard widget | 15 min (refreshed) |
| Blueprints | ESI | Blueprint tracker | Until manual deletion |
| Industry Jobs | ESI | Dashboard widget | 15 min (refreshed) |
| PI Colonies | ESI | PI tracker | 15 min (refreshed) |
| OAuth2 Access Token | SSO callback | ESI authentication | 20 min (auto-refreshed) |
| OAuth2 Refresh Token | SSO callback | Auto-refresh access tokens | Until revoked |
2.2 Data You Provide Directly
- WooCommerce orders: Your EVE character name (for contract delivery), shipping address (for physical merch), email (for order confirmations).
- SRP claims: Killmail URL, fleet context, fit details.
- Hauling jobs: Pickup + destination stations, cargo details, collateral.
- Buyback quotes: Items you paste into the buyback tool.
- Wiki edits: Content you contribute to corp wiki pages.
2.3 Technical Data (Automatic)
- IP address: Logged in the audit log on every SSO login (for security).
- Browser user agent: Logged with audit entries.
- Cookies: See Section 4 below.
- Server logs: Hostinger retains web server logs for 14 days (standard practice).
2.4 Payment Data (We Do NOT Store)
For real-money purchases via Stripe or PayPal:
- Credit card numbers: Never touch our servers — processed entirely by Stripe.
- PayPal credentials: Never touch our servers — processed entirely by PayPal.
- We receive only: transaction ID, amount, customer email, billing country.
3. How We Use Your Data
| Purpose | Data Used | Legal Basis (GDPR) |
|---|---|---|
| Member authentication | Character ID, name, corp ID | Contract (membership) |
| Role assignment | Corp roles | Contract |
| Dashboard display | Skills, wallet, location, ship | Contract |
| Order fulfillment | Character name, shipping address | Contract |
| Security audit | IP, user agent, event type | Legitimate interest |
| SRP claim processing | Killmail, fleet context | Contract |
| Wormhole mapping | System IDs, signatures | Contract |
4. Cookies
The Site uses the following cookies:
| Cookie | Purpose | Duration |
|---|---|---|
| wordpress_logged_in_* | WordPress session (admin only) | 14 days |
| wp-settings-* | Admin UI preferences | 1 year |
| woocommerce_* | Cart contents, checkout | Session |
| wp_woocommerce_session_* | Customer session | 2 days |
| obcn_active_char | Active character (multi-char switcher) | 1 day |
We do not use Google Analytics, Facebook Pixel, or any third-party tracking cookies. The Site is privacy-respecting by design.
5. Data Sharing
We do NOT sell your data. We share data only with:
- CCP hf: Via ESI — your character ID is sent to ESI to fetch your data. CCP already has this data (it's their game).
- Stripe / PayPal: For real-money payments — they receive only the transaction amount and your billing email.
- Discord: Via webhooks — we send character name + event info to our Discord server. Discord stores this per their privacy policy.
- Hostinger: Our hosting provider — they store the database and files. Hostinger is GDPR-compliant.
- zKillboard: When you submit an SRP claim with a killmail URL, we fetch kill data from zKillboard's API. zKillboard receives no data from us — we only read from them.
We do not share data with: advertising networks, social media platforms (beyond Discord webhooks), data brokers, government agencies (without a valid legal order).
6. Data Security
- OAuth2 tokens are encrypted at rest using AES-256-CBC with the OBSIDIAN_ENCRYPTION_KEY constant.
- Database is hosted on Hostinger's MySQL with TLS in transit and at-rest encryption.
- SSL/TLS enforced site-wide (Let's Encrypt certificate, auto-renewed).
- WordPress admin protected by 2FA (Two Factor plugin) + Wordfence rate-limiting + strong password requirement.
- Audit log records all SSO logins, role changes, and configuration updates.
- Recovery mode (?obcn_recovery=1) allows admin access even if the plugin fails.
Despite these measures, no system is 100% secure. If a breach occurs, we will notify affected members via Discord + email within 72 hours per GDPR Article 34.
7. Your Rights (GDPR + CCPA)
If you are in the EU/EEA (GDPR) or California (CCPA), you have these rights:
- Access: Request a copy of all data we hold about you.
- Rectification: Correct inaccurate data (e.g. wrong character name).
- Erasure ("right to be forgotten"): Request deletion of your account + all associated data.
- Restriction: Ask us to limit processing (e.g. freeze your account temporarily).
- Portability: Receive your data in a machine-readable format (JSON).
- Objection: Object to processing based on legitimate interest.
- Withdraw consent: Revoke EVE SSO access via the EVE Developer Portal.
To exercise these rights, contact us via Discord or email (privacy@obsidianconsortium.space). We respond within 30 days per GDPR Article 12.
8. Data Retention
| Data Type | Retention Period |
|---|---|
| Active member accounts | Until you leave the corp + 30 days |
| Audit log entries | 2 years |
| SRP claims | 3 years |
| WooCommerce orders | 7 years (tax compliance) |
| Wiki revisions | Permanent (history) |
| Wormhole map data | Until map deleted |
| Server logs (Hostinger) | 14 days |
9. Children's Privacy
EVE Online is rated T (Teen) by the ESRB. We do not knowingly collect data from anyone under 13. If you believe we have collected data from a child under 13, contact us and we will delete it immediately.
10. International Data Transfers
The Site is hosted in the EU (Hostinger Estonia). EVE Online data is held by CCP hf. in Iceland. Discord data is held in the US. By using the Site, you consent to these international transfers per GDPR Chapter V.
11. Changes to This Policy
We may update this Privacy Policy at any time. Material changes will be announced in Discord and on the /news/ page. Continued use after changes take effect constitutes acceptance.
12. Contact
For privacy questions or data requests:
- Email: privacy@obsidianconsortium.space
- Discord: DM an officer
- Data Protection Officer: Alex Drax (CEO)
© 2026 The Obsidian Consortium (OB.CN). EVE Online and all related trademarks are property of CCP hf.