CoOptimal Gaming
COOPTIMAL GAMINGLEGAL // PRIVACY OPERATIONS
PRIVACY POLICY

How COG handles member information

This policy describes how CoOptimal Gaming (COG) handles personal information in connection with cooptimalgaming.org, the member and admin portals, COG-operated community game servers, account linking, memberships, queues and support.

Effective and last updated: 8 September 2026
COG uses Steam as the primary member identity. Discord linking is optional. COG does not ask for or store your Steam or Discord password, and the current Discord linking flow does not retain the temporary Discord OAuth access token after the link is established.

1. Who this policy applies to

This policy applies when you use COG websites, member services, COG-operated game servers, queue services, membership functions, Discord linking or support. COG is an independent community server operator and is not the developer or publisher of Wardogs and is not affiliated with or endorsed by them.

Where the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs) apply to COG, this policy is intended to describe COG's information-handling practices in a clear and transparent way. It does not claim that every provision of the Privacy Act applies in every circumstance.

2. Information COG collects and holds

Steam identityYour verified SteamID64 is the primary COG account identifier. If Steam Web API profile enrichment is configured and available, COG may also store your Steam persona name, profile URL and avatar URLs. Steam OpenID authentication still works without that enrichment.
Discord linkIf you choose to link Discord, COG stores your Discord user ID, display/username, avatar URL or related display metadata, link time and role-synchronisation state. If the COG Discord bot is configured, COG may check whether you are in the configured Discord server and which COG-managed membership roles apply.
COG accountInternal member ID, account status (for example active, suspended or banned), account creation/update information, enforcement reason and administrative action history where applicable, admin assignment, membership entitlement and temporary entitlement overrides.
Membership and billingMembership plan, subscription state, billing period dates, grandfathered/legacy-plan state, pending plan transitions, checkout/session references, payment-provider customer/subscription references, provider plan or price identifiers, and limited transaction/status information needed to reconcile paid memberships. The COG database is designed to store provider references and billing state rather than full payment-card or bank-account credentials.
Servers and queuesQueue entries, designated whitelist server selections, queue position and operational data needed to provide server access, member whitelist entitlement and queue operation. Game-server or integration data may be added where required to operate the service.
Support and administrationSupport ticket contents, issue category, account diagnostics submitted with a ticket, administrative actions, entitlement changes and security/audit records. If COG enables Discord support alerts, a limited new-ticket alert containing the ticket number, member display identity, category and subject may also be posted to a restricted COG staff/support Discord channel; the full ticket message and attached diagnostics are not included in that alert.
Portal notificationsNotification content, category and importance, intended audience or recipient, creation time, optional portal action/destination, and delivery state such as unread, read or dismissed. Administrative broadcasts may also record delivery/read counts so COG can operate and review member communications.
Technical dataNormal web-server information may include IP address, request time, browser/user-agent details, requested paths and error/security logs. The portal uses an essential PHP session cookie to maintain an authenticated session.

3. How information is collected

  • Directly from you, for example when you open a support ticket or select account/membership actions.
  • From Steam when Steam OpenID verifies control of your Steam account and, where configured, when Steam's Web API is used for optional public-profile enrichment.
  • From Discord when you deliberately authorise the COG OAuth link. COG currently requests the identify scope for account linking. If bot role synchronisation is configured, the bot may query membership and COG-managed role state in the configured Discord server.
  • From payment providers when paid checkout/subscriptions are enabled, including verified webhook notifications and provider API responses about checkout, subscription status, renewals, cancellations, plan changes, failed payments, refunds/reversals and provider identifiers.
  • From COG systems, including the website, queue service, server integrations, support and administrative audit functions.

4. Why COG uses this information

COG uses information to authenticate members, maintain account sessions, operate game-server access, member whitelist designations and queues, calculate membership entitlements, display membership benefits, link Discord accounts, synchronise configured Discord roles, administer and reconcile paid subscriptions, preserve applicable grandfathered-plan state, process requested plan changes/cancellations, deliver persistent account, billing, support, service and administrative notices through the member portal, prevent abuse or duplicate account linking, provide support, investigate faults, enforce community/server rules, record suspensions/bans and related billing or Discord cleanup actions, and maintain security/audit records.

COG does not use the browser to decide its own membership entitlement or admin authority. Paid entitlement decisions are made by the server-side application using COG's stored account/subscription state together with verified payment-provider events or provider API information. A browser redirect from a checkout or billing page is not treated as proof of payment by itself.

5. Cookies and browser storage

COG uses an essential server-side PHP session cookie so you can stay signed in. Production sessions are configured as secure, HTTP-only cookies with SameSite=Lax. The production member/account state is loaded from the COG backend rather than using browser localStorage as an authority for membership or access.

The current portal does not implement an advertising or behavioural-tracking cookie system. Some portal pages currently request Google-hosted web-font resources; normal request metadata such as an IP address and browser headers may therefore be visible to Google when those resources are loaded.

6. When information may be disclosed

COG may disclose or transmit limited information where necessary to operate a feature you use, including to:

  • Valve/Steam for Steam authentication and optional public-profile lookup;
  • Discord for optional account linking, membership-role synchronisation and, when COG enables staff support alerts, limited new-ticket notifications to a configured COG staff/support channel;
  • payment providers such as Stripe or PayPal when you choose or manage paid membership, including the information required to create/manage a provider customer or subscription, associate the transaction with your COG account, verify billing events and reconcile subscription status;
  • hosting, database and infrastructure providers used to operate COG systems;
  • game-server or service integrations to provide server status, access or queue functionality; and
  • law enforcement, regulators, courts or other persons where disclosure is required or authorised by law.

COG administrators may access member information where reasonably required for account support, moderation, billing administration and reconciliation, security and service operation. Administrative actions are designed to be recorded in an audit log.

When you use Stripe or PayPal, those providers process payment and transaction information under their own privacy terms. Depending on the provider and payment method, the provider may collect information such as your name, contact details, billing address, payment-method details, transaction amount, subscription status, fraud/security signals, cookies/device or interaction information used for payment security, refunds, disputes or chargebacks. COG receives only the information made available to it as the merchant/service operator and does not receive or store your full card number from Stripe Embedded Checkout or other provider-controlled checkout interfaces. You can review Stripe's Australian Privacy Policy and PayPal's Australian Privacy Statement.

7. Overseas processing

Some third-party services used by COG—such as Steam, Discord, Google-hosted web fonts, Stripe and PayPal—operate global infrastructure. Information sent to those providers may therefore be processed or stored outside Australia, potentially including the United States and other countries in which those providers or their service providers operate. The exact processing locations are controlled by the relevant third party and may change.

Where Australian privacy law requires COG to take steps concerning overseas disclosure, COG will take reasonable steps appropriate to the circumstances. You should also review the privacy information published by the third-party service you choose to use.

8. Security

COG's current production design includes HTTPS, server-side session handling, secure/HTTP-only cookies, CSRF protection for state-changing API requests, prepared database statements, server-side admin permission checks, protected storage for service credentials and verification of payment-provider webhook notifications before billing state is applied. Duplicate provider events are designed to be handled idempotently. COG does not require a COG password because Steam is the primary identity provider.

No internet-connected service can guarantee absolute security. If COG becomes aware of a security incident, it will investigate and take steps appropriate to the nature of the incident and applicable law.

9. Retention and deletion

COG retains information while it is needed to operate the account/service, administer and reconcile subscriptions, preserve applicable grandfathered-plan history, deliver and record portal notifications, protect security, handle refunds/disputes, resolve disputes, support members, keep required business/audit records or meet legal obligations. Billing references and transaction/subscription records may therefore need to be retained after a subscription ends where reasonably required for accounting, fraud prevention, chargebacks, consumer claims, audit or legal obligations. Notification delivery/read/dismissal records may be retained while reasonably required for service operation, support, administration or audit, and may be removed under COG retention practices when no longer needed. At present, the portal does not provide an automated self-service account-deletion function. Disconnecting Discord removes the active Discord link from the COG account, but security/audit information about administrative or account actions may be retained where reasonably required.

You may request access to, correction of, or deletion/restriction of personal information through Member Portal → Support. A request may require identity verification and may be refused or limited where retention is required or permitted by law, or where deletion would compromise security, fraud prevention, legal obligations or the rights of others.

10. Access, correction and privacy complaints

To request access to or correction of your COG account information, or to raise a privacy concern, use the authenticated Support section of the member portal and clearly identify the request as a privacy matter. COG may ask you to confirm control of the relevant Steam-authenticated account before acting on a request.

At present, the portal code has not been supplied with a separate unauthenticated privacy email, phone number or postal address. The configured privacy-request path is the authenticated Support function. COG should add an alternate public contact channel if required for its legal obligations; this policy deliberately does not invent contact details that have not been supplied.

COG will review a privacy complaint and respond within a reasonable period. If the Privacy Act applies to the matter and you remain dissatisfied after giving COG a reasonable opportunity to respond, information about making a complaint to the Office of the Australian Information Commissioner is available at oaic.gov.au.

11. Changes to this policy

COG may update this policy when the portal, payment systems, server integrations or legal obligations change. The current effective date will be shown at the top of this page. Material changes that significantly alter how member information is handled should be communicated through the site or member portal where practical.