Privacy Policy
Last updated: 2026-09-27
This policy explains which personal data SF Development processes, why, for how long, and how to exercise your rights under the Brazilian General Data Protection Law (LGPD, Law 13.709/2018).
Data we collect
Public site (sfdevelopment.com.br): anonymous visit metrics through Plausible, when enabled. No cookies are set and no IP address is stored.
Customer panel (painel.sfdevelopment.com.br): your Discord identity (id, username and avatar) to sign you in, and your orders and licenses (product, amount, payment status and the Mercado Pago payment identifier). Card and Pix data are handled by Mercado Pago and never pass through our servers. The panel uses only the session cookie needed to keep you signed in.
Support: the messages you send in tickets on our Discord.
License activation: when a licensed script starts, we receive the license key, the public IP address and a hash of the hardware identifier (HWID) of the FiveM server, and the script version. They are used to validate the license and fight piracy. This system does not send us any data about the players on your server.
Purposes and legal bases
Sign-in, orders, delivery of the scripts and support: performance of the contract (LGPD art. 7, V). Payment and tax records: compliance with legal obligations (art. 7, II). License validation, security and fraud and piracy prevention: legitimate interest (art. 7, IX).
Sharing
We share data only with the providers needed to run the service: Mercado Pago (payments), Discord (sign-in and support) and our hosting provider. SF Development does not sell personal data or use it for advertising.
Retention
License activation records are kept for 30 days. Orders, licenses and payment records are kept while the license exists and for the period required by tax and consumer law. Administrative audit records are kept for up to 180 days, except those tied to money or to a deletion, which are kept for the legal period.
SF Livestream and connected platforms
When a player chooses to link a creator account, SF Livestream requests only the minimum read-only access needed to identify the account and verify livestream activity. Depending on the selected platform, this may include the channel or account identifier, display name, avatar, public channel description, follower or subscriber count, total views, and public livestream status.
For YouTube, the app uses the YouTube Data API with the youtube.readonly scope. For TikTok, it uses Login Kit with the user.info.basic scope. The app does not publish content, edit channels, read private messages, or request passwords.
OAuth credentials are processed only on SF Development servers, are never sent to the FiveM server or exposed to customers, and are not stored after the account-linking flow. YouTube and Twitch access tokens are also revoked immediately after the required public profile data is retrieved.
The linked public profile fields and the livestream activity records are stored in the database of the FiveM server that installed SF Livestream, under the control of that server owner. SF Development only runs the authorization flow and the livestream status lookups on the owner's behalf, without keeping that data.
Players can unlink an account at any time inside SF Livestream and revoke access in the security settings of the connected platform. To delete the linked data, contact the staff of the server where the account was linked.
Use of connected platform data is also governed by the applicable platform terms and privacy policies, including the Google Privacy Policy and the YouTube Terms of Service.
Your rights
You may request confirmation that we process your data, access, correction, anonymization or deletion of unnecessary data, portability, information about who we share it with, and the revocation of consent (LGPD art. 18). We answer within 15 days.
Contact
For privacy and data requests, open a private ticket on our Discord.