Privacy Policy
Last updated October 7, 2026
1. Who we are
Bing Monitors is a Discord bot and website that sends alerts when Pokémon products restock at certain retailers. It is operated by 2548489 Alberta Inc. ("we", "us"), based in Calgary, Alberta, Canada.
This policy explains what personal information we collect, why, how long we keep it, who we share it with, and the choices and rights you have. It covers:
- our website at bingmonitors.com (the "Site"),
- the Bing Monitors Discord bot and the alerts it posts (the "Bot"),
- the beta waitlist and our community Discord server, and
- any paid subscription (together, the "Service").
It does not cover Discord, the retailers whose pages we monitor, or our payment provider. Each of them has its own privacy policy, and we link to them in section 6.
Privacy Officer. Our Privacy Officer is responsible for our compliance with this policy and answers questions about it, including questions about our service providers outside Canada (section 7). Contact the Privacy Officer at bingmonitors@gmail.com or in the support channel of our community Discord server.
2. The short version
- We collect very little: mostly Discord IDs and names, the settings of the servers you add the Bot to, and, once paid plans launch, your email and billing status from our payment provider.
- We never see your Discord password, your Discord messages, or your card details.
- We don't sell your personal information, we don't use it for advertising, and the Site has no tracking cookies, no ad pixels, and no third-party analytics.
- Our servers are in the United States, so your information is stored there (section 7).
- You can ask us to see, fix, or delete your information at any time (section 9).
3. What we collect and why
We collect personal information only for the purposes listed here. If we want to use it for a new purpose, we will ask you first unless the law allows otherwise.
3.1 When you join the waitlist or sign in on the Site
You sign in with Discord. We ask Discord for two permissions (Discord calls them "scopes"):
identify: lets us read your Discord user ID, username, and display name. We store your user ID and your display name (or your username if you have no display name). We do not ask for your email address, and we do not read your server list, messages, or friends.guilds.join(only when you join the waitlist): lets us add you to the Bing Monitors community Discord server. We use it when you press Join the beta. That's where we announce beta waves and answer support questions. You can leave that server at any time without losing your place in line.
Discord gives us a temporary access token for these permissions. We use it during sign-in and do not store it.
From that, we keep:
| Information | Why we keep it |
|---|---|
| Discord user ID and display name | To hold your place on the waitlist, admit you, and recognize you when you sign in again |
| Your referral code, and who referred you (if anyone) | To run the referral program: once 3 friends join with your link, you move to the front of the line, once. We note when you've used that. |
| Whether a referral counted | A referral counts only if the new Discord account is at least 30 days old. We work this out from the Discord user ID itself (Discord IDs encode their creation date). This keeps the line fair. |
The source tag in your sign-up link (for example tiktok), if there was one | To learn which channels bring people to us |
| Dates you joined, were admitted, and were sent your invite; whether your invite DM could be delivered | To run the waitlist and resend invites that didn't arrive |
| Which Discord server claimed your beta access | To apply the beta to the right server, once |
Sign-in session. When you sign in, we set one cookie (see section 8) and store a scrambled (hashed) copy of its value with your user ID and display name so we know you're signed in. Sessions last up to 30 days or until you sign out.
3.2 When you add the Bot to a Discord server
The Bot uses only Discord's basic "Guilds" access. It does not read the messages in your server, and it does not see your member list. When a server owner or admin adds and sets up the Bot, we collect:
| Information | Why we keep it |
|---|---|
| The server's ID, name, owner's Discord user ID, and approximate member count | To run the Service for that server, apply its plan and member limits, and contact its owner about the server |
| The channels, roles, and webhooks the Bot uses | To post alerts where you asked. Webhook tokens are encrypted before we store them. |
| Your alert settings ("feeds"): stores, regions, filters, price limits, role pings | To send you the alerts you chose |
| The products your server tracks, and the Discord ID of the admin who added each one | To check those products and alert you, and to answer support questions about who changed what |
| Products you muted | To stop alerts you asked us to stop |
| A short code we generate for each server, shown in the footer of its alerts | To trace alerts that are re-posted somewhere they shouldn't be (see our Terms of Service) |
Who ran which command. When someone in your server uses an admin command or a button (for example /setup, /track add, or Mute), we record their Discord user ID and username with the action, the time, and the server. We use this record for security, to troubleshoot, and to answer the server owner's questions.
Report button. Anyone who can see an alert can press Report to tell us it was wrong. We record their Discord user ID, the server, the alert, and any note they type (up to 500 characters). Please don't put personal information in the note.
Links you paste. When you track a product with /track add, we store the product link. Before we accept it, our systems check that it's a Pokémon product. If it isn't, the link and the server's name and ID are shown to our team for review.
3.3 When you subscribe
Payments are handled through Stripe. Your full payment-card number is submitted to Stripe rather than stored by us. You purchase the subscription from 2548489 Alberta Inc., operating as Bing Monitors; Stripe processes payments and manages billing on our behalf. From the payment provider and the /subscribe command, we receive and keep:
- your email address (for receipts, billing notices, and account questions),
- the Discord user ID of the person who subscribed and the server it applies to,
- your plan, subscription status, renewal date, and the provider's customer and subscription IDs, and
- records of payments, refunds, and disputes.
3.4 When you contact us
If you open a support ticket in our Discord server or email us, we keep the conversation and any information you choose to give us so we can help you and keep a record of what we did.
3.5 When you visit the Site
We count visits ourselves, without cookies. For each page view or button click we record only: the page, a source tag from the link (if any), the name of the referring website (for example google.com, not the full address), and the time. We do not record your IP address, browser, device, or location, and we can't tie these counts to you.
Our web server does not keep access logs of IP addresses. Our Site loads no third-party scripts, fonts, or images; everything is served from our own server.
3.6 Information we do not collect
We do not collect your Discord password, your email through Discord, your messages, your payment card, government ID, precise location, or any sensitive information (health, finances beyond your subscription, and so on). We do not knowingly collect information from children (section 10).
4. How we use personal information
We use it to:
- Provide the Service: run the waitlist, set up the Bot, send alerts, and apply your plan.
- Communicate with you: send your beta invite, service notices (for example, that a webhook broke, a tracked link was removed, or the beta is ending), billing notices, and support replies (section 5).
- Bill you for a subscription and handle refunds and disputes.
- Keep the Service secure and fair: prevent abuse, enforce plan limits and our Terms, trace re-posted alerts, and investigate reports.
- Improve the Service: understand which features and alerts work, measure alert accuracy from reports, and see how people find us, using counts rather than profiles.
- Meet legal obligations: keep tax and accounting records, respond to lawful requests, and establish or defend legal claims.
We do not use your information to make automated decisions that have legal or similarly significant effects on you, to profile you for advertising, or to train AI models.
4.1 Your consent
By signing in with Discord, adding the Bot to a server, or subscribing, you consent to our collecting, using, and disclosing your information as this policy describes. Where the law requires it, we ask for express consent (for example, Discord's own permission screen when you sign in). You may withdraw consent at any time, subject to legal or contractual limits, by contacting our privacy officer. If you do, we may not be able to keep providing the Service (for example, we can't send alerts to a server whose settings we no longer have).
Where the GDPR or a similar law applies to us, our lawful bases are: contract (to provide the Service you asked for), legitimate interests (keeping the Service secure, preventing abuse, and improving it), legal obligation (tax and accounting records), and consent (adding you to our community server and sending your beta invite).
5. Messages we send you
- Beta invite. If you join the waitlist, the Bot sends you one direct message on Discord when you're admitted, with your invite link. If your DMs are closed, your waitlist page shows the link instead.
- Service notices. The Bot posts notices about your server's setup, health, and billing to a channel in your server.
- Announcements. We post news and beta waves in our community server. You can mute or leave it at any time.
- Billing and subscription emails are sent by us or through Stripe on our behalf, including receipts, failed-payment notices, renewal reminders and notices of subscription or price changes.
We don't send marketing emails. To stop receiving messages from us, tell us in the support channel of our community server, and we'll stop within 10 business days. Messages you need to use a paid service (receipts, notices about your own server) continue while you're a customer.
6. Who we share personal information with
We do not sell personal information, and we do not share it for advertising. We share it only as follows:
| Who | What and why | Where |
|---|---|---|
| Discord Inc. | The Bot and sign-in run on Discord. Alerts, notices, and Bot replies are sent through Discord and are visible to whoever can see that channel under your server's settings. | United States (Discord Privacy Policy) |
| Hetzner Online GmbH | Hosts our servers and database. | Ashburn, Virginia, United States (Hetzner privacy) |
| Stripe (paid plans only) | Processes subscription payments and supports billing on our behalf. Bing Monitors is the seller. | United States and other countries (Stripe Privacy Policy) |
| Google (Gmail) | Stores the emails you send us and our replies. | United States and other countries (Google Privacy Policy) |
| Professional advisers | Our lawyers, accountants, and auditors, under duties of confidentiality. | Canada |
| Authorities and others, when the law requires | To comply with a law, court order, or lawful request, to protect someone's safety, to investigate fraud or a breach of our Terms, or to defend our legal rights, as the law permits. | Varies |
| A buyer or successor | If our business or its assets are sold, merged, or reorganized, to the parties involved, who must use it only as this policy describes. | Varies |
We require providers processing personal information on our behalf to protect it under the applicable service agreements. Discord, Stripe, and Google may also process information for their own purposes, such as operating their platforms, preventing fraud and meeting legal obligations, as described in their privacy policies.
What other people in your server can see. Alerts and Bot posts are visible to members of the channel they're posted in. The trace code in each alert's footer identifies the server, not a person. The Bot's replies to your commands are visible only to you.
What our team sees. Our admins run a private Discord server for operating the Service. Notices there include server names and IDs, the Discord IDs of server owners and of people who press Report (with their note), links refused by our Pokémon check, and the names and IDs of waitlist members whose invite couldn't be delivered. Only our team can see that server.
7. Where your information is stored
Our servers are in Ashburn, Virginia, United States, and Discord, Stripe, and Google are based outside Canada. Your personal information is therefore stored and processed in the United States (and wherever those providers operate), and it may be accessible to courts, law enforcement, and national security authorities there under US law.
To get written information about our policies and practices for service providers outside Canada, or to ask questions about how they collect, use, disclose, or store personal information for us, contact our privacy officer (section 1).
8. Cookies
Visitors get two cookies, both strictly necessary, both first-party, and neither used for tracking or advertising:
| Cookie | What it does | How long |
|---|---|---|
bm_oauth | Protects the Discord sign-in step against forgery, and remembers your referral or source tag until sign-in finishes | 10 minutes (deleted when sign-in completes) |
bm_session | Keeps you signed in | Up to 30 days, or until you sign out |
If you block cookies, you can still read the Site, but you can't sign in.
Do Not Track. Because we don't track you across websites, we don't change anything in response to a browser's "Do Not Track" signal or Global Privacy Control signal. There's nothing to turn off.
9. Your rights and choices
You can, at any time:
- Access the personal information we hold about you and learn how we've used and disclosed it;
- Correct it if it's wrong;
- Withdraw consent (section 4.1);
- Delete it: we will delete or anonymize it unless we need to keep it for a legal reason (such as tax records), and we'll tell you what we kept and why. Server logs are the exception: we don't edit them (section 11);
- Stop messages from us (section 5); and
- Complain to us or to a regulator (below).
How to ask. Open a ticket in the support channel of our community server, or email bingmonitors@gmail.com. We may need to confirm you control the Discord account involved (for example, by asking you to message us from it). We respond within 30 days, and tell you if we need more time and why, as the law allows. Access requests are free.
Server owners. If you own a server that used the Bot, you can ask us to delete that server's settings, tracked products, and records, even after you've removed the Bot.
Regulators. If you aren't satisfied with our answer, you can contact:
- the Office of the Privacy Commissioner of Canada: priv.gc.ca, or
- the Office of the Information and Privacy Commissioner of Alberta: oipc.ab.ca.
9.1 Geographic eligibility
The Service is offered only in Canada, excluding Quebec, and the United States. Eligibility restrictions do not remove any privacy rights that applicable law gives you.
9.2 Residents of the EU, EEA, UK, and Switzerland (if served)
The Service is intended for residents of Canada, excluding Quebec, and the United States. If data protection law in your country applies to us, you also have the right to data portability, to object to processing based on our legitimate interests, and to complain to your local data protection authority. Our lawful bases are listed in section 4.1.
9.3 Residents of US states
We do not sell or "share" personal information (as California law defines those terms), use it for targeted advertising, or use sensitive personal information. California residents may request the categories and specific pieces of personal information we've collected and its sources, purposes, and recipients (all described in this policy), and ask us to delete or correct it. We won't discriminate against you for using these rights. An authorized agent may make a request on your behalf with your signed permission.
10. Children
The Service is not directed to children under Discord's minimum permitted age. You must be at least 13 years old, or the higher minimum age required by Discord where you live, to sign in, join the waitlist, or use the Bot. If you are below the age of majority, a parent or legal guardian must review and agree to the Terms for your use. Only adults who have reached the age of majority where they live may purchase and manage paid subscriptions, including subscriptions used by eligible teenagers.
We do not knowingly collect personal information from children under 13. If we learn we have, we will delete it. If you believe a child has given us information, contact our privacy officer.
11. How long we keep information
Apart from expired sign-ins, we don't yet delete information automatically on a schedule. Until we do, we keep it while we need it to run the Service, and we delete it when you ask (section 9), except our server logs and what the law requires us to keep. In particular:
- your sign-in cookie expires after 30 days, and we then delete its record;
- a server's settings are kept after the Bot is removed, so reinstalling it restores them, until the owner asks us to delete them;
- our server logs, which can include Discord user and server IDs, are kept on our server for security and troubleshooting. We don't remove individual log entries when you ask us to delete your information; and
- billing records are kept for 6 years after the end of the tax year they relate to, as Canadian tax law requires.
12. How we protect information
We use safeguards appropriate to the sensitivity of the information, including:
- encryption of Discord webhook tokens at rest (AES-256-GCM), and TLS encryption of all traffic to the Site;
- storing only a hash of sign-in session tokens, so a database copy can't be used to sign in;
- a firewall that keeps our database unreachable from the internet;
- never collecting card details or passwords at all.
No system is perfectly secure. If a breach of security safeguards involving your personal information creates a real risk of significant harm to you, we will notify you and the privacy regulators as the law requires, and we keep a record of every breach.
13. Changes to this policy
We'll post any change on this page and update the date at the top. If a change is significant, for example a new purpose or a new kind of recipient, we'll also announce it in our community server before it takes effect, and ask for your consent where the law requires.