Back

Effective: 2026-08-19 Last updated: 2026-08-19

This notice explains what MSPGeek, Inc. does with personal data. It covers the MSPGeek forums, website, Discord server, Slack workspace, MSPGeekChatBridge, the MSPGeek bot, and Goots Fabric.

MSPGeek, Inc. is a nonprofit corporation registered in South Carolina, United States, and is the data controller for the processing described here. Goots Fabric is a trading name of MSPGeek, Inc., not a separate company.

Privacy contact: [email protected] General contact: [email protected] Copyright: [email protected] Postal: MSPGeek, Inc., 235 Wansley Road Taylors SC, 29687


1. The short version

There are three categories of data here and we treat them differently.

Content is not confidential. Anything you post — messages, code, logs, screenshots, images, links, uploads, profile fields — is permanent and visible to others. How wide that audience is depends on where you post it (see section 2.1), but in every case it is far wider than a private conversation, and we make no effort to keep it confidential. Assume anything you post will outlive your account and reach people you did not anticipate.

Account and verification data is not public. Your email address, real name, employer, password, IP addresses, authentication tokens, membership and donation records, and moderation history are not published by us. We protect these to the best of our ability.

If you use your real name as your display name, or identify yourself in a post, that is content rather than account data and is not confidential. See section 2.1.

Support requests are not public. Tickets and correspondence are handled privately in our service desk and are not posted to the community.

2. What we collect

2.1 Content you post

We collect post and message content, uploaded files, images and attachments, profile fields, display names, reactions, votes, and follows. All of it is retained indefinitely.

Who can see it depends on where you post:

WhereAudience
Public forum areasAnyone on the internet, including people with no account. Indexed by search engines.
Restricted forum areasSigned-in members with access to that area
Discord and SlackEveryone who has joined either platform — see below

Discord and Slack are bridged. Every public channel is relayed between the two platforms, and some private channels are as well. In practice this means anything you post in a bridged channel — messages, files, images, links — is visible to everyone on both platforms, regardless of which one you posted from. Relayed messages appear as though posted by a bot, so it is usually obvious when a channel is bridged.

Private channels are only ever bridged to their equivalent private channel on the other platform. If you post in a bridged private channel, your message reaches the members of that same channel on Discord and Slack — and nobody else.

Restricted does not mean confidential. Content in a members-only forum area, a Discord channel, or a Slack channel is visible to a large number of people whose behaviour we cannot control. Our Terms prohibit republishing community content elsewhere, and we enforce that when we learn of it — but we cannot prevent it, and we do not guarantee that content stays inside the community.

Treat everything you post as though it may become public.

2.2 Registration and verification data (not public)

To join, you complete a registration form in Discord. We collect:

FieldRequiredHolds
Full nameYesYour real name
Business emailYesYour work email address
Business nameYesYour employer
Job titleNoYour role
About meNoFree text you write
Discord user IDAutomaticYour Discord account identifier
Discord usernameAutomaticYour Discord handle

This is used to confirm you are eligible to be here — that you work in the MSP channel or in IT. It is not published, and is visible only to MSPGeek staff and volunteers with admin access.

It is not routinely reviewed. We look at it when investigating a report, a suspected eligibility breach, or an abuse incident.

2.3 Forum account data (not public)

DataPurpose
Email addressAccount, notifications, recovery
Password (stored hashed)Authentication
IP addressSpam prevention, abuse investigation, security
Browser user agentSecurity, troubleshooting
Discord / Slack OAuth identifiersSingle sign-on
Moderation records — warnings, restrictions, bans, staff notesEnforcing our Terms and Code of Conduct
Paid membership statusAccess to supporter tiers
Donation records — donor identity, amount, dateAccounting

2.4 Support requests (not public)

If you contact us for help or raise a ticket, we record your name, email address, company, the content of your request, our replies, and your ticket history over time in our service desk (HaloPSA).

Do not send us client or end-user personal data. If you paste a log, ticket body, or screenshot from your own environment, redact it first. Anything you send becomes part of the ticket record.

2.5 Direct messages

We do not read your DMs.

  • Discord DMs happen outside our server. We have no access to them.
  • Slack DMs are not bridged and are not exported by us. On our Slack plan, workspace administrators can export public channel content only; private channels and DMs require Slack’s approval, which needs valid legal process or the consent of the people involved.

This is a limit on what MSPGeek can reach, not a statement about Discord or Slack, who hold your DMs on their own systems.

If you report a DM to us as part of a Code of Conduct complaint, we see only what you choose to send us.

2.6 What we do not collect

Paid memberships. Supporter tiers are sold and processed by Discord. We see who is subscribed and at what tier. We never receive your payment card details, billing address, or any other payment information — that stays with Discord.

Donations. We accept donations via PayPal. Transaction records are retained for accounting purposes.

Merchandise. Our merchandise store is operated by Spreadshirt (myspreadshop). If you order, Spreadshirt handles the transaction and your shipping details under their own privacy policy. We do not receive your payment details.

We do not receive or store full payment card numbers. We do not sell personal data. We do not use it for advertising and we do not build advertising profiles.

2.7 Where your data lives

Whether something is confidential depends on what it is, not where it lives. Content you post is not — it’s visible to other participants wherever you posted it. Account, verification, and support data is, and is visible only to MSPGeek staff.

SystemOperated byHoldsConfidential?
DiscordDiscord Inc.Your Discord account, messages, uploadsNo – Content
SlackSlack / SalesforceYour Slack account, messages, uploadsNo – Content
Forums (Invision)MSPGeek, on DigitalOceanForum accounts, posts, uploads, IP logsContent No; account data yes
Verification databaseMSPGeek, self-hosted MySQLName, email, company, title, bio, Discord IDYes
HaloPSAHaloPSA (vendor-hosted)Name, email, company, ticket historyYes
MSPGeekChatBridgeMSPGeek, on Microsoft Azure (East US 2)Message identifiers only — see 3.1n/a
Goots FabricMSPGeek, on Microsoft Azure and SupabaseContent, account names, verification dataContent no; verification data yes

3. Systems we operate ourselves

3.1 MSPGeekChatBridge

MSPGeekChatBridge (which appears in Discord as MSPGeekBot) relays messages between our Discord server and our Slack workspace. It is a modified build of the open-source Matterbridge project, self-hosted by MSPGeek on a virtual machine in Microsoft Azure (East US 2).

Discord privileged intents: Message Content, and Server Members. Message Content is required to relay message text. Without it the bridge cannot function.

What it processes: message content, author display name, Discord and Slack user IDs, channel and workspace identifiers, timestamps, message IDs, and edit and deletion events.

What it stores. Messages are relayed in memory and are never written to disk. The bridge keeps a mapping file recording which message on one platform corresponds to which message on the other, so that edits and deletions can be matched up. That file contains message identifiers, channel identifiers, and platform names only — no message text and no usernames. It holds the most recent 5,000 mappings and older entries are discarded automatically. Backups of the host virtual machine are retained for 30 days.

We maintain no archive, log, or database of bridged message content.

Edits and deletions. Editing or deleting a message on one platform propagates to the mirrored copy on the other, provided the bridge is running at the time. Changes made while the bridge is offline may not propagate, and very old messages may no longer be matched once their mapping has been discarded. Contact [email protected] if you need a stranded copy removed.

Cross-platform disclosure. Content posted in a bridged channel is transmitted to the other platform and is visible to everyone there. Discord and Slack each retain data under their own policies, which we do not control.

3.2 The MSPGeek bot

Our registration bot (the Discord application named MSPGeek, which appears in Discord as MSPGeek Bot) handles member registration and grants access to the community. It is a separate Discord application from MSPGeekChatBridge, despite the similar names.

Discord privileged intents: Message Content, and Server Members. Presence is not requested.

Message content. The bot reads messages in a small number of designated channels in order to match automated help responses to common questions. Message content is never stored and never logged. It is evaluated in memory and discarded.

What it stores. The registration fields in section 2.2, written to a MySQL database operated by MSPGeek. An admin console lets staff review registrations; it displays name, email, and processing status.

Staff accounts. Staff who sign in to the admin console do so with Discord. We store their Discord account identifier, nickname, role, and encrypted Discord access and refresh tokens.

Join and leave records. When a member joins or leaves the server, the bot posts a record to a private staff channel in Discord containing the member’s username, display name, account creation date, and join or leave time. These remain in that Discord channel indefinitely.

3.3 Goots Fabric

Goots Fabric is a community management platform operated by MSPGeek, Inc. under that trading name. MSPGeek uses it for its own community, and also offers it to other Discord communities.

What it holds for MSPGeek members: community content, member account names, and verification data.

Where. The application is self-hosted by MSPGeek on Microsoft Azure. The database is hosted by Supabase. The Supabase project is currently located in Ireland and is being migrated to the United States; this notice will be updated when that happens.

Shared infrastructure. Goots Fabric serves multiple communities from a shared database. Each community’s data is isolated at the database level and is not accessible to other communities. Where the same person participates in more than one community, their data is held separately for each.

Who can see registration data. Today, only MSPGeek administrators can see the registration data described in section 2.2. Vendors, sponsors, and channel operators see only what any other participant sees. If we extend access to channel operators in future, we will update this notice and announce the change before it takes effect.

3.4 Age

MSPGeek is for participants aged 18 and over. We do not knowingly process the personal data of children.

4. Why we process data, and our legal basis

PurposeLegal basis
Operating the forums, Discord, Slack, the bridge, and Goots FabricLegitimate interests — running the community you joined
Verifying eligibility to participateLegitimate interests — maintaining a community for MSP and IT professionals
Authentication and account securityLegitimate interests; contract
Spam, abuse, and fraud preventionLegitimate interests
Moderation and enforcementLegitimate interests; contract
Paid memberships and donationsLegal obligation; contract
Email notifications you opted intoConsent

You may object to processing carried out on the basis of legitimate interests. See section 8.

5. How long we keep things

DataRetention
Public posts, uploads, contentIndefinitely — see section 6
Registration and verification dataLife of the account; deleted on request
Forum account record and emailLife of the account
IP addresses attached to posted contentAutomatically removed after 365 days
Bridge message-identifier mappingMost recent 5,000 mappings; backups 30 days
Join and leave records in DiscordIndefinitely
Moderation and ban recordsIndefinitely, to enforce bans against re-registration
Support ticketsRetained while useful for context; anonymised on request
Donation recordsAs required for accounting and tax

6. Deleting your account, and what stays

Request deletion at [email protected], or use the account tools in your forum settings.

We remove or anonymise your account record, email address, profile, and verification data. Verification records are deleted manually by staff on request.

Your posts remain. Content you posted stays on the forums, in Discord, and in Slack, because removing it would break years of accumulated technical discussion that other people have replied to and rely on. Posts are shown as authored by a deleted or anonymised user, and stored IP addresses are removed.

If you need specific content removed rather than your account, ask us and we will consider it. We do not guarantee removal.

We may retain ban and moderation records after deletion in order to enforce the ban.

Deleted data may persist in system backups for up to 30 days before those backups expire.

6.1 Your service desk record

On request we will anonymise your record in our service desk. This removes your name, email address, and company from the record and wipes the associated email correspondence, so the ticket history is no longer linked to you.

7. Who we share data with

We do not sell personal data. We use the following providers:

PartyRoleWhat they receive
Discord Inc.The Discord platformEverything you do on Discord; bridged content from Slack
Slack Technologies / SalesforceThe Slack platformEverything you do on Slack; bridged content from Discord
Invision Power ServicesForum softwareForum data
DigitalOceanForum hostingForum accounts, posts, IP logs
Microsoft AzureHosting for the bridge, verification bot, and Goots FabricData held by those systems
SupabaseDatabase behind Goots FabricContent, account names, verification data
LovableCurrent development platform for Goots FabricGoots Fabric data, pending migration
HaloPSA (Halo Service Solutions)Service deskName, email, company, ticket history
Discord Inc.Paid membership tiersSubscription status and payment, handled entirely by Discord
PayPalDonationsDonor identity, amount
Spreadshirt (myspreadshop)Merchandise storeOrder and shipping data, if you order

Discord and Slack are independent controllers for data held on their own platforms, governed by their own privacy policies rather than this one.

We will also disclose data where legally required, or where necessary to investigate abuse, protect our rights, or protect the safety of participants.

8. Your rights

Depending on where you live, you may have the right to access, correct, delete, or export your data, to object to or restrict processing, to withdraw consent, and to complain to your data protection authority.

To exercise any of these, contact [email protected]. The forum software also provides self-service export and deletion tools in your account settings.

We respond within one month. There is no charge and no penalty for asking.

Note on public content: the right to erasure does not extend to removing your public posts from the historical record, for the reasons in section 6. It does extend to your account and verification data.

9. International transfers

MSPGeek is based in the United States and most of our infrastructure is located there. The Goots Fabric database is currently in Ireland. If you participate from outside the US, your data is transferred to and processed in the US.

Content you post is public worldwide by design.

10. Security

We protect account and verification data to the best of our ability with the resources of a volunteer-run nonprofit. Passwords are stored hashed. Stored authentication tokens are encrypted. Administrative access is limited to staff who need it.

We do not guarantee security. We are a free community run by volunteers, not a security vendor. Use a unique password here.

If we become aware of a breach affecting your personal data we will notify you and the relevant authorities where required by law, including under the South Carolina Breach Notification Act and the GDPR.

11. Cookies

The forums use cookies for login sessions, display preferences, and spam prevention. A full list of the cookies we set and why is published at https://forums.mspgeek.org/cookies/

Embedded third-party content — videos, images, and posts from other sites — may set its own cookies and track you, exactly as if you had visited that site directly.

12. Changes

We may update this notice. We will post the updated version here and change the “Last updated” date. Material changes will be announced in the community.