Privacy Policy
This policy explains how Stonetavern (stonetavern.app), a non-commercial World of Warcraft fan community, handles information in connection with our website and the social-media channels we operate. It describes what the site actually loads and sends — read off the code, not off intentions.
1. Nothing measuring you loads until you allow it
The first time you open the site you are asked, before any of it runs. Until you answer, none of the services below are loaded: their scripts are not in the page at all. You can accept everything, accept nothing beyond what the site needs to work, or pick per purpose.
Advertising — Meta (Facebook)
If you allow this, the site loads the Meta Pixel from
connect.facebook.net and reports your page view and certain actions (opening the
download, joining Discord, clicking register, completing registration, opening the donation link)
to Meta. The same events are additionally sent a second time from our own server to Meta through the
Meta Conversions API, so blocking scripts in your browser does not by itself stop
the second copy — your choice here does, because our server checks it too. Meta receives your IP
address, your browser's user agent, the page address, and the Meta cookies (_fbp,
_fbc) if present. When you register, a one-way hash (SHA-256) of your email address and
of your account number is sent along so Meta can match the event. Meta uses this data for its own
advertising measurement and targeting under its own terms.
Statistics — PostHog
If you allow this, the site loads PostHog. We run PostHog on our own server; the
browser reaches it through stonetavern.app/ingest, which forwards to
posthog.stonetavern.app. It records page views, automatically captures clicks and
form interactions (autocapture), builds heatmaps, measures page
performance, and makes a session recording — a replay of your visit: the pages,
the mouse movement, the scrolling and the clicks. Text you type into input fields is masked in that
recording. PostHog also records which site sent you here (referrer, utm_* and
ref parameters, and advertising click identifiers such as fbclid,
gclid and ttclid if they are in the address you arrived on).
To be plain about it: when you allow the advertising purpose, your visit becomes part of Meta's advertising data about you. That is what a pixel is for. If you would rather it did not, choose "Only what's needed" — the site works exactly the same.
2. Changing or withdrawing your choice
Your answer is stored in a cookie named st-consent on your own device. It records the
version of this question, whether you allowed statistics, and whether you allowed advertising —
nothing else, and no identifier. "Privacy choices" at the bottom of every page
reopens the panel; withdrawing takes effect immediately and the scripts are no longer placed in the
page. Deleting the cookie has the same effect and you will be asked again. If we add or change a
service, the version changes and you are asked again rather than being carried over.
Cookies that Meta or PostHog have already set in your browser are theirs, not ours; clearing your browser's site data for those domains removes them, and Meta's own settings govern what Meta keeps.
3. What the site needs in order to work at all
These are not optional and are not used to profile you. They stay on our own servers.
| Cookie | What it is for |
|---|---|
st_session | Keeps you signed in to your game account. |
st_discord_state, st_discord_pending |
Short-lived, protects the Discord sign-in against request forgery. |
st-consent | Your answer to the question above. |
st-theme | Light or dark. |
st-lp | Which version of the landing page you were shown. |
st-reg | Ten minutes after a successful registration, so the next page knows it happened. |
Our web server also writes ordinary access logs (IP address, time, address requested, user agent), as any web server does, to operate the site and defend it against abuse.
4. Error reports
When something breaks in your browser, the site reports the error to Sentry
software running on our own server (Bugsink). It is configured to send no personal data
(sendDefaultPii: false) and no performance traces; it sends nothing at all on a visit
where nothing goes wrong. It does not measure audiences and does not build profiles, which is why it
is not part of the choice above.
5. Social-media publishing
We use the official APIs of social platforms (including TikTok, Instagram, Facebook, YouTube and others) to publish our own content to our own accounts, including via scheduling tools we host ourselves. When we connect one of our accounts, the platform issues us an access token that we store solely to publish our posts on our behalf. We do not access, collect, or store data belonging to other users of those platforms, and we request only the permissions needed to publish our own content.
6. How we use information
Information is used to operate our website, our game realms and our community, to publish our own social content, and — only with your consent — to measure how the site is used and how people find it. We do not sell personal data. We do not share it with third parties except the services named above, the platform you are viewing our content on, and where required by law.
7. Access tokens
Access tokens for our own social accounts are retained only while a channel remains connected and are deleted when we disconnect it or when they expire. You can revoke our access at any time from the relevant platform's app/permissions settings.
8. Children
Our services are not directed to children under 13 (or the minimum age in your jurisdiction), and we do not knowingly collect their personal data.
9. Changes
We may update this policy from time to time; the date above will change accordingly. If the change concerns the services in section 1, the consent question is asked again.
10. Contact
Privacy questions or data requests: [email protected].