Stonetavern

Privacy Policy

Stonetavern · Updated 25 August 2026

This policy explains how Stonetavern (stonetavern.app), a non-commercial World of Warcraft fan community, handles information in connection with our website and the social-media channels we operate. It describes what the site actually loads and sends — read off the code, not off intentions.

1. Nothing measuring you loads until you allow it

The first time you open the site you are asked, before any of it runs. Until you answer, none of the services below are loaded: their scripts are not in the page at all. You can accept everything, accept nothing beyond what the site needs to work, or pick per purpose.

Advertising — Meta (Facebook)

If you allow this, the site loads the Meta Pixel from connect.facebook.net and reports your page view and certain actions (opening the download, joining Discord, clicking register, completing registration, opening the donation link) to Meta. The same events are additionally sent a second time from our own server to Meta through the Meta Conversions API, so blocking scripts in your browser does not by itself stop the second copy — your choice here does, because our server checks it too. Meta receives your IP address, your browser's user agent, the page address, and the Meta cookies (_fbp, _fbc) if present. When you register, a one-way hash (SHA-256) of your email address and of your account number is sent along so Meta can match the event. Meta uses this data for its own advertising measurement and targeting under its own terms.

Statistics — PostHog

If you allow this, the site loads PostHog. We run PostHog on our own server; the browser reaches it through stonetavern.app/ingest, which forwards to posthog.stonetavern.app. It records page views, automatically captures clicks and form interactions (autocapture), builds heatmaps, measures page performance, and makes a session recording — a replay of your visit: the pages, the mouse movement, the scrolling and the clicks. Text you type into input fields is masked in that recording. PostHog also records which site sent you here (referrer, utm_* and ref parameters, and advertising click identifiers such as fbclid, gclid and ttclid if they are in the address you arrived on).

To be plain about it: when you allow the advertising purpose, your visit becomes part of Meta's advertising data about you. That is what a pixel is for. If you would rather it did not, choose "Only what's needed" — the site works exactly the same.

2. Changing or withdrawing your choice

Your answer is stored in a cookie named st-consent on your own device. It records the version of this question, whether you allowed statistics, and whether you allowed advertising — nothing else, and no identifier. "Privacy choices" at the bottom of every page reopens the panel; withdrawing takes effect immediately and the scripts are no longer placed in the page. Deleting the cookie has the same effect and you will be asked again. If we add or change a service, the version changes and you are asked again rather than being carried over.

Cookies that Meta or PostHog have already set in your browser are theirs, not ours; clearing your browser's site data for those domains removes them, and Meta's own settings govern what Meta keeps.

3. What the site needs in order to work at all

These are not optional and are not used to profile you. They stay on our own servers.

CookieWhat it is for
st_sessionKeeps you signed in to your game account.
st_discord_state, st_discord_pending Short-lived, protects the Discord sign-in against request forgery.
st-consentYour answer to the question above.
st-themeLight or dark.
st-lpWhich version of the landing page you were shown.
st-regTen minutes after a successful registration, so the next page knows it happened.

Our web server also writes ordinary access logs (IP address, time, address requested, user agent), as any web server does, to operate the site and defend it against abuse.

4. Error reports

When something breaks in your browser, the site reports the error to Sentry software running on our own server (Bugsink). It is configured to send no personal data (sendDefaultPii: false) and no performance traces; it sends nothing at all on a visit where nothing goes wrong. It does not measure audiences and does not build profiles, which is why it is not part of the choice above.

5. Social-media publishing

We use the official APIs of social platforms (including TikTok, Instagram, Facebook, YouTube and others) to publish our own content to our own accounts, including via scheduling tools we host ourselves. When we connect one of our accounts, the platform issues us an access token that we store solely to publish our posts on our behalf. We do not access, collect, or store data belonging to other users of those platforms, and we request only the permissions needed to publish our own content.

6. How we use information

Information is used to operate our website, our game realms and our community, to publish our own social content, and — only with your consent — to measure how the site is used and how people find it. We do not sell personal data. We do not share it with third parties except the services named above, the platform you are viewing our content on, and where required by law.

7. Access tokens

Access tokens for our own social accounts are retained only while a channel remains connected and are deleted when we disconnect it or when they expire. You can revoke our access at any time from the relevant platform's app/permissions settings.

8. Children

Our services are not directed to children under 13 (or the minimum age in your jurisdiction), and we do not knowingly collect their personal data.

9. Changes

We may update this policy from time to time; the date above will change accordingly. If the change concerns the services in section 1, the consent question is asked again.

10. Contact

Privacy questions or data requests: [email protected].