Privacy policy
Last updated: 2026-10-07
This policy explains how Igniva Dev handles personal information when you browse our Roblox resource marketplace, create an account, buy or sell resources, subscribe to a membership, or contact support. Igniva Dev is independent of Roblox Corporation.
1. Information we collect
- Account information: your email, display name, account identifier, password hash, login sessions, roles, membership and account status. We store a protected password hash, rather than a readable password.
- Profile and marketplace content: the avatar, banner, bio, creator specialties, listings, images, uploaded files, product updates, ratings, reviews and forum posts that you submit.
- Purchases and subscriptions: the products and add-ons ordered, amount, currency, payment status, refunds, disputes, subscription plan, paid period and Stripe customer, checkout, payment and subscription identifiers.
- Seller information: seller account identifiers, onboarding and verification status, outstanding requirements, balances, transfers, revenue shares and payout status supplied by Stripe.
- Support and safety information: support tickets, project requests and messages, reports, moderation decisions, reasons, warnings, suspensions and administrative activity records.
- Technical information: IP address, browser and request information handled by our hosting and payment providers, security events and operational logs. Authenticated checkout, onboarding and download problems are recorded using coarse error categories, account identifiers and internal resource references so administrators can investigate them; raw payment errors, passwords and secret keys are not stored in this diagnostics list. Diagnostic issue records are removed after 90 days. Igniva uses hashed rate-limit identifiers derived from account, email or IP information to limit abuse.
Stripe’s payment forms collect payment details directly. Igniva does not receive your full card number or card security code. Identity documents and bank details requested during seller onboarding are submitted to Stripe; do not send them in an Igniva support ticket.
2. Why we use information
We use account, order and membership information to provide the services you request: sign-in, purchase confirmation, file access, seller onboarding, revenue allocation, membership benefits, support and essential account emails. The legal basis is performance of our contract, or steps you request before entering a contract.
We process accounting and transaction information where required by applicable legal obligations. We use security, moderation and administrative records for our legitimate interests in preventing fraud, protecting users and enforcing marketplace rules, balanced against your rights. A privacy policy is an explanation of processing, rather than blanket consent to unrelated uses.
If an optional activity requires consent, we will request it separately. We do not install advertising trackers. Optional product visit statistics run only when you enable them in Privacy preferences on a product page. You can disable them there at any time. We respect browser Do Not Track and Global Privacy Control signals. With your consent, we use a browser-tab session reference, or a daily hash derived from your signed-in account, to avoid counting repeat visits. Sellers see aggregate product totals, never visitor identities.
3. What is public and who can see private information
Your published display name, avatar, banner, bio, specialties, membership badge, listings, reviews and forum contributions are visible publicly. Avoid putting private information in these fields or uploaded public images.
Support ticket conversations are available to the requester and authorised administrators. Project request conversations are available to their customer and seller. Seller dashboards show the sales and revenue information needed to manage those sales. Administrators can access account, order, support and moderation information as needed to operate the marketplace.
Product downloads require an authorised account and a server-side access check. Published profile and product images are public; purchased resource files are not exposed as unrestricted public storage links.
4. Providers and disclosures
Cloudflare provides hosting, database and file storage, website delivery and security, account email sending and automated profile-image checks. Data needed for those functions, including submitted profile images, is processed through those services.
Stripe provides payment processing, membership billing, the customer portal and seller onboarding and payouts. We share the identifiers, contact information and transaction information needed for these functions. Stripe also processes information independently for purposes such as identity verification, fraud prevention and compliance with financial laws. See Stripe’s privacy policy.
We disclose information when necessary to comply with a valid legal request, protect users or establish, exercise or defend legal claims. Social links take you to Discord, YouTube, X or TikTok; those services apply their own policies when you visit them. We do not sell personal information.
5. Automatic moderation
Display names and service text are checked for prohibited content and impersonation. Profile images are checked using Cloudflare Workers AI. A high-confidence safe result can publish an image automatically; uncertain images are held for administrator review. Content checks can reject or hold changes, and administrators can remove inappropriate published content.
Warnings are issued by administrators. Warning thresholds can automatically restrict account actions; bans require a separate administrator decision. If you think a moderation result is wrong, contact Ingivadev@gmail.com for a human review.
6. Cookies and browser storage
| Item | Purpose | Duration |
|---|---|---|
| cp_session cookie | Secure sign-in | Normal sign-in: browser-session cookie with a server session valid for up to one day. Remember me: up to 30 days. Sign-out invalidates the current session. |
| igniva:visit-consent and igniva:visit-session in session storage | Your optional product-statistics choice and, only if enabled, a random reference to avoid counting repeat visits | Until the browser tab session ends. Disabling statistics removes the reference. |
| cp_language cookie | The language you select | Up to one year |
| igniva:sale-sound local storage | Your account’s sale-notification sound preference | Until you clear it or browser storage is removed |
Stripe’s payment components may use their own cookies or similar technology for payment security, fraud prevention and optional Link features. Their notices explain these uses. You can clear site data in your browser; clearing the session cookie signs you out and clearing preferences resets them.
Copyright-case information
Copyright notices and counter-notices contain legal names, postal addresses, telephone numbers, email addresses, signatures, evidence and statements. They are visible to the claimant, the affected seller and authorised administrators to assess rights, manage claims and give the other party an opportunity to respond. They are not public catalog information. Processing is based on our legitimate interests in handling rights claims and, where applicable, legal obligations or establishing, exercising or defending legal claims. We retain case records while necessary for the claim, relevant legal obligations or applicable claim periods; ask us about a specific record. Do not include unrelated sensitive information.
7. How long information is kept
Daily hashed product-visit references are removed by scheduled cleanup after 35 days. Aggregate daily product counts contain no visitor identifiers and are kept for seller performance reports. Withdrawing consent stops further collection; previously recorded aggregate totals remain.
Account and purchased-access records are kept while needed to operate your account and provide your library. Published content is kept while it remains available on the marketplace. Following a deletion request, records are assessed for removal or anonymisation; information needed for an outstanding transaction, complaint, security incident, legal claim or accounting obligation may have to be retained for that purpose.
Login sessions expire after one day or, with Remember me, 30 days. Password-reset links expire after 30 minutes, are single-use, and reset-token records are removed after use or expiry cleanup. Delivered account-email bodies are cleared from Igniva’s email queue after sending. These expiry periods do not mean that all related account or transaction records are automatically deleted at the same time.
The duration of transaction and safety records depends on applicable accounting requirements, unresolved obligations, the nature of an incident and relevant legal claim periods. Contact us to ask about the retention of a particular record.
8. International processing and security
Cloudflare and Stripe operate internationally, so processing can occur outside your country, including outside the EEA. Their published data-processing terms describe safeguards for international transfers, including European Commission standard contractual clauses for restricted transfers where applicable. See Cloudflare’s data-processing terms and Stripe’s data-processing terms. These provider documents explain their safeguards; they do not mean that all Igniva data stays in the EEA. Contact Ingivadev@gmail.com to ask which arrangements apply to a particular processing activity and request information about the relevant safeguards.
Igniva uses encrypted website connections, protected password hashes, access controls and verified payment notifications. No online service can promise perfect security. Keep your password private and report suspected account compromise promptly.
9. Your rights and complaints
Depending on the applicable law, you can request access, correction, deletion, restriction or portability of your personal information, and object to processing based on legitimate interests. If a use depends on consent, you can withdraw that consent without affecting earlier lawful processing. Some information must be retained to meet legal obligations.
Contact Ingivadev@gmail.com. We may ask for proportionate information to verify that a request concerns your account. We normally respond within one month; if a lawful extension is needed, we will explain it. You can complain to the competent data-protection authority, including the authority in your country of residence, work or the place of the alleged infringement.
10. Changes
We update this policy when our handling of information changes. The date at the top identifies the version. Material changes affecting existing accounts will be communicated through an appropriate account notice or email.
11. Who is responsible
The operator below is responsible for the personal information processed to run Igniva Dev. Contact us about privacy, access or deletion requests.
Jostein Tørum Haugerud (IgnivaDev)Angelltrøvegen 136, 7048 Trondheim, NorwayIngivadev@gmail.com