Privacy at a glance
- Who we are. TrucklineMP is run by Hayley Weighill from Great Britain. She is responsible for your personal data (the "controller"). "We" in this policy means her and the volunteer staff who help run TrucklineMP.
- What we collect. Your Steam account details, what you put on your profile, what you do on the platform (companies, events, support, moderation), what happens while you play (sessions, position, chat, jobs, playtime, distance and top speed), and security data such as IP addresses and a device cookie.
- What is public. A lot of TrucklineMP is public by design: your profile, SteamID64, company memberships, your live position, name and company on the map while you play, and some moderation records (active public bans and your driver licence). Your driving statistics are private unless you choose to share them. Section 5 has the full list.
- Why. To run the service, keep it safe and fair, and fix and improve it.
- Analytics are off unless you say yes. We don't sell your data, and we don't show ads from ad networks.
- Who else gets data. A small number of providers that run parts of the service for us (hosting, Cloudflare), Discord, Patreon if you support us there, and services you choose to connect.
- Your rights. You can ask to see, correct, delete or move your data, and object to how we use it. Email [email protected].
- Young people. You must be 13 or older. If you are under 18, you need a parent's or guardian's permission. See Information for Young Players.
This summary is here to help. The full policy below is what counts.
1. Who we are and how to contact us
TrucklineMP is operated by Hayley Weighill, an individual based in Great Britain. She is the controller of the personal data described in this policy.
- Privacy questions, rights requests and complaints: [email protected]
- Security issues: [email protected]
- General help: https://trucklinemp.com/support
- Postal address: available on request from [email protected]
We are not required to appoint a data protection officer and have not done so. All privacy matters go to [email protected].
When we ask you to accept this policy, we are asking you to confirm that you have read it. We do not treat that as your consent to anything. Where we rely on consent (for example analytics), we ask for it separately.
2. What this policy covers
This policy covers personal data we process through:
- our websites, including trucklinemp.com, beta.trucklinemp.com, the sign-in service at id.trucklinemp.com, the recruitment portal at recruitment.trucklinemp.com, our documentation site, and the file download and image servers;
- the TrucklineMP launcher, the multiplayer client, our official game servers, and the live map, as far as they send data to our systems;
- our public API, developer tools, OAuth apps and webhooks;
- our Discord servers and our Discord bots, including where a company adds our bot to its own server;
- sign-in on other devices (QR sign-in and mobile sign-in);
- messages you send us by email or through support.
It does not cover services run by others, even if you reach them through TrucklineMP. That includes Steam, Discord, Patreon, Stripe and Link, YouTube, Twitch, Google, company-run Discord servers and websites, third-party apps built on our API, and embedded content such as Spotify players. Their own privacy policies apply.
Our beta site and development game servers use separate test databases. If you use them, this policy applies there too.
3. The information we collect
3.1 Signing up and your account
Steam sign-in. You sign up and sign in with Steam. Steam tells us your SteamID64. We then use the Steam Web API to read your public Steam profile (name, avatar, account creation date, profile visibility) and your list of owned games with playtime.
We use this once, at sign-up, to check you meet our sign-up requirements: for example, that your profile and game details are public, that you own Euro Truck Simulator 2 and have played it for a minimum time, and that your Steam account is old enough. We don't store your game library. If we turn down a sign-up, our server logs record your SteamID64 and playtime so we can look into problems.
What we keep for your account:
- account ID, numeric web ID, SteamID64, display name (taken from Steam at first), @handle and avatar;
- account creation date, your timezone and language preference if you set them;
- an email address, but only if one has been added to your account (we don't ask for one at sign-up);
- when you last signed in on the website and when you last used the launcher.
Each time you sign in, we refresh your avatar from Steam unless you have uploaded your own.
Access controls. Before creating or opening an account, we check your SteamID64 against our list of banned identifiers. If you are on it, we show you a notice that explains why, or at least a message with our contact address (section 3.7). When sign-ups are limited, we also check an allow list. Staff can link a Steam account to an existing account on request, or let someone skip the sign-up requirements.
Enterprise accounts. We create a small number of accounts for partner organisations. These sign in with an access token instead of Steam. We log each successful enterprise sign-in (time, IP address, browser and the site you were sent on to) and keep these logs for 90 days. Only the operator can see them.
3.2 Your profile and connected accounts
Profile. Display name, handle, avatar or uploaded picture, banner, bio (which can include embedded media), signature, colour theme and cosmetic items, social links you add by hand (such as TikTok, X, Medal or World of Trucks), and your company memberships. Uploaded pictures are converted to WebP, which removes photo metadata such as location.
Connected accounts. When you connect another service, we store what we need to keep the link working:
| Service | What we store |
|---|---|
| Discord | Discord ID, username, avatar and access tokens |
| YouTube | channel ID, name, link and access tokens |
| Twitch | Twitch ID, name, avatar and access tokens (we don't keep your Twitch email) |
| your Google account identifier and access tokens | |
| Patreon | Patreon ID, full name, membership status, tier and access tokens, plus updates Patreon sends us when your membership changes |
Connecting Discord also:
- syncs your roles between TrucklineMP and our Discord servers;
- runs our ban-evasion checks (section 6);
- attaches any earlier moderation cases recorded against that Discord ID to your account.
If you turn on Discord Linked Roles, we send Discord your name or handle and whether you are a staff member.
Live status. When someone views your profile, we ask Twitch and YouTube whether your linked channel is live, using your channel or login ID.
Recognition. We record:
- achievements, some of which are awarded automatically (for example a sign-in streak);
- programme badges, with the reason and who gave them;
- staff roles and position history;
- translation contributions (your preferred language, and whether you opted in to public credit).
Driver licence. Every account has a driver licence card. It is built automatically from your in-game moderation history and shows a standing tier and a dated list of violations, including expired ones. It has a QR code and a shareable image.
Configurations. If you use a supported tool, such as Truckline Utils, to save game configurations to your account, we store them. Their names can appear on your profile unless you hide them.
3.3 Security and sign-in data
- Sessions. Each time you sign in, we create a session. It records a session token, when it expires, your IP address and browser details (user agent), and which checks you passed and when (for example two-factor authentication, a passkey, or a recent identity check before a sensitive action). A session lasts up to 7 days and renews while you use it.
- Two-factor authentication. Your authenticator app secret (stored encrypted) and your backup codes (stored only as salted hashes).
- Passkeys. Public key, credential ID, usage counter, device type, whether it is backed up, supported transports, the authenticator model identifier, an optional name you give it, and when it was created. Fingerprints and face scans never leave your device; we never receive them.
- Trusted devices. If you choose to skip two-factor codes on a device for 30 days, we store a hashed device token, a description of the browser, when it was last used, and when it expires or was revoked.
- 2FA recovery requests. If you lose your second factor, you can ask for recovery. We store your explanation, the request status and dates, and the reviewing staff member's decision and note. Reviewers see your name, handle, avatar, account age, SteamID64 and which 2FA methods you have. Completing recovery removes your 2FA methods and signs you out everywhere else.
- QR and mobile sign-in. When you sign in by scanning a QR code or through a mobile sign-in link, we store short-lived codes, the IP address and browser of the device involved, and an encrypted copy of the session being handed over. Mobile access tokens last up to 30 days. If you turn on notifications in a mobile app, we store its push token. We don't send push notifications today.
- Legal acceptances. Which version of each legal document you accepted, and when.
- Sign-in audit events. Records of sign-in steps, such as when legal documents were shown and accepted, linked to your session.
- Security controls.
- We keep rate-limit counters keyed by IP address or account.
- Cloudflare Turnstile runs a human check on sign-in pages. Cloudflare receives your IP address to do this.
- If a device probes our site for security holes, we block its IP address for 30 days.
- We set a device identifier cookie for ban-evasion detection (section 6 and the Cookie Policy).
3.4 Playing TrucklineMP
Launcher sign-in. You approve the launcher in your browser. We then issue it a token, which lasts 30 days. We store it as a hash along with when it was last used.
Game sessions. When you start playing, we create a game session containing:
- your account ID, web ID, username, avatar and SteamID64;
- whether you are banned or staff;
- your roles and in-game permissions;
- the legal documents you have accepted.
We share this with our official game servers, so they can let you in and apply your permissions. We run these servers ourselves; there are no community-run servers. The session stays active while you play and expires 30 minutes after you leave. Our servers never receive your email address or IP address from our systems.
What game servers report back to us:
- when you join and leave each server, which builds your session history;
- your in-game position (exact map coordinates), direction and speed, plus fuel, fines and cargo status, every few seconds;
- jobs you take: cargo, trailer, start and destination company, city and country, distance, weight, ferry use, urgency, and a route trail of up to 2,000 sampled points;
- in-game chat messages.
Live map. While you are online, our public live map shows:
- your exact in-game position, direction, speed and server;
- your account ID, web ID, name and handle;
- your main company (name, tag and colour), if you are in a public company;
- the kind of trailer you are pulling (for example box, tank or flatbed);
- a short trail of where you have just driven.
Anyone can view the map without signing in, and other websites can embed it. You disappear from the map within about a minute of leaving a server. This is your position on the game map, not your real-world location.
If you choose to share your driving statistics on the map (or make them public), people who select you on the map also see your statistics and your current job: cargo, weight, trailer, where you are driving from and to, planned distance, urgency, when you started and how far you have driven.
Traffic and freight. We use the positions of everyone on a server to work out traffic: jams, road speeds, journey times, crashes, parking and traffic history. Traffic reports are public. A reported queue can list the account IDs of the trucks in it, as the live map already shows them. Crash reports don't name drivers. Freight flows between cities are combined across at least three drivers and don't identify anyone.
Driving statistics. Our game service counts:
- time online and time spent driving;
- distance driven and your top speed;
- number of sessions, days active, your longest session, and when you were first and last seen;
- a daily history of these figures, and whether you are online now.
Online time only counts while your game is actually connected and reporting to a live server. Distance and top speed only count driving within the server's speed limit, so glitches and teleports don't count.
You choose who sees your statistics in Settings: only you (the default), people who follow you, or everyone. You can separately choose to show them on the live map. Staff who manage accounts can always see them. The public playtime leaderboard only includes players who set their statistics to everyone.
Fair-play checks. To keep the game fair, our game service records signs of cheating or abuse: teleports, speeds over the server limit, positions it had to reject or that arrived late. For each event it stores your account ID, the server, the time, the values involved and where on the game map it happened. It also looks at patterns, such as jobs finished impossibly fast, jobs that are too short or have no cargo, repeated cancelled jobs, very long idle sessions, or playing on two servers at once, and gives accounts a risk score. Only staff with permission can see these records. They don't trigger any action automatically (section 6).
In-game chat. We store each message's text, channel (public, team or whisper), sender, recipient (for whispers), server and time, so staff can investigate reports and enforce the rules. Staff with moderation permissions can read chat, including whispers, and see chat statistics such as the most active chatters and possible spam. Chat is deleted after 90 days.
In-game moderation. Staff can kick, mute or ban players from the game or the website. We record the action, reason, server and staff member (section 3.7).
What we don't receive. Our servers don't receive hardware identifiers, system specifications or crash dumps from the launcher or game client.
Downloads. Launcher and game files are delivered by Cloudflare, which sees your IP address when you download them.
3.5 Companies (VTCs and VBCs), events and partners
Company data. Name, tag, description, branding, style, timezone, contact email, social links, linked Discord server, verification applications, news, media albums and gallery links. Company pages and their contact details are public.
Memberships:
- Rosters are public: name, avatar, role and join date, plus SteamID64 through our API.
- Any signed-in user can see a person's company membership history.
- Employee ID pages are public and stay public after a member leaves.
What company managers can see and record:
- each member's last-active time on TrucklineMP;
- leave-of-absence requests;
- private notes about members;
- the company's audit log;
- applications to join, including your answers;
- support tickets sent to the company, including satisfaction ratings.
Managers can also keep a company blacklist. It can automatically remove or reject listed people, and it can include free-text entries about people who have no account.
Joining a company:
- If a company requires a minimum playtime, we check your owned games and playtime with Steam, and store your Euro Truck Simulator 2 and American Truck Simulator minutes.
- Companies can hire from a talent pool you choose to join. Recruiters at every company can see it.
Announcements and API keys.
- Companies can post automatic Discord announcements. These can include members' names, handles and profile links. By default they no longer include the reason someone was removed or blacklisted.
- Managers can give API keys access to their company's data.
Events.
- We record the event details, RSVPs (status, waitlist and approvals), event bans and depot slot assignments.
- Event text is checked by our content filter (section 6).
- Attendee lists are shown according to your event activity setting.
- RSVPs are sent to the organising company's Discord channel and to apps the company has connected. If you hide yourself from the roster, you aren't named in these.
- Event calendar feeds (ICS) are public and contain event details only.
- Organisers can plan a convoy route on the live map. The route is shown to everyone, to attendees or to organisers only, as the organiser chooses.
- Automatic attendance. From 15 minutes before a convoy until 30 minutes after it ends, we check where attendees are driving in game. If you are on the event's server and close to the planned route (or between the start and end cities), we count the time you spend there and the distance you drive along the route. Once you have been there long enough (up to 15 minutes, depending on the event), we mark you as having attended and send you a notification afterwards. The organising company's event managers see whether you attended, how long you were there and how far you drove. Organisers and staff can correct it.
- While a convoy is running, the live map lists the attendees on its public roster, but only those whose event activity setting is public.
Company ads.
- Companies can promote themselves in ad slots on TrucklineMP. Ad images are public.
- We choose who sees company ads based on your account (for example, whether you are in a company, and how active you are).
- We count views and clicks. To stop double counting, we keep a short-lived key made from your account ID, or from a hash of your IP address if you are signed out, for 5 minutes (views) or 24 hours (clicks).
- If you report an ad, we store your report.
Partners and partner tools.
- Managers of partner organisations can see their members and add people to partner roles, which are synced to Discord.
- If you link DBus World, it can read your company memberships.
- If you sign in to Truckline Utils, it receives your account ID, web ID, name, avatar and roles.
3.6 Community features and content
Community polls. How your answers are stored depends on the poll:
- Anonymous polls are handled by a separate voting service. It never learns who you are: your browser holds a one-time voting credential, and you get a signed receipt.
- Confidential polls store an encrypted link to your account. Staff can decrypt it only for an approved export, and that needs approval from two people.
- Raw answers are deleted after the retention period set for the poll (between 7 and 730 days after it closes). Anonymous totals and receipts are kept.
- Older polls may have stored your account ID with your answers, and some questions may have asked for contact details.
Embeds and links. Some content loads material from other services straight into your browser:
- profile bios and company pages can load Spotify, Apple Music and Discord widgets;
- YouTube, Vimeo and Twitch videos load when you click them, although YouTube preview images load straight away;
- images in posts, galleries and event banners can come from other image hosts.
When your browser loads this content, those services receive your IP address and browser details. We only store the link.
Legacy forum data. We used to run forums. Posts, threads and forum settings from that time are still stored and can appear on your profile. We don't use them for anything else. Your "Hide forum activity" setting still applies.
3.7 Support, reports, appeals and moderation
Support.
- Tickets: subject, messages, category, priority, status, assigned staff member, internal staff notes (which you can't see), and your satisfaction rating.
- Help articles: feedback you give and how you use them.
- Other records: subscriptions to known issues, and drafts saved in your browser.
- Attachments are checked for malware before they are shared.
Reports. When you report a person, profile or piece of content, we create a ticket with your account ID and what you told us.
Appeals. Appeals go through support. How long you have to wait before appealing depends on the type and severity of the decision. If you can't sign in, you can appeal by email (see "Moderation notices" below).
Discord tickets.
- When you open a ticket in one of our Discord servers, we store your Discord ID, name and avatar, your form answers, and all messages, including edits, deletions and attachment links.
- Staff see your moderation standing and up to five active bans when the ticket opens.
- When the ticket closes, a transcript, including internal staff notes, is copied into our main database.
Moderation records:
- Bans: scope, severity, the reason shown to you (kept separate from staff's internal note), internal note, the rule it relates to, whether the decision was automated, evidence, restrictions, whether the ban is public, and the staff member who issued it.
- Warnings, mutes and kicks.
- Moderation cases, including Discord message, channel and server IDs.
- Your moderation standing: a score that our Discord bot calculates from warnings.
- Moderation notices: a record of what we did and why, described below.
- The credential blacklist: SteamID64, Discord ID and other connected account IDs, used to stop people coming back. It is described below.
- Blocked IP addresses.
- The staff blacklist: people barred from staff roles, with reasons, notes and evidence files.
The credential blacklist. We store these IDs as they are, not hashed. An entry is added when:
- staff issue a permanent ban;
- staff delete an account and choose to block its IDs;
- staff add an entry by hand. This can be for someone who never had an account with us.
Bans that the game server issues automatically don't add an entry.
If you never had an account with us and are on the list, the entry was added by our staff. You can ask what we hold about you and why by emailing [email protected].
Entries don't last forever. Each one has a set term (section 10). Before it ends, staff review it and can renew it. There is no fixed limit on how many times it can be renewed, but every renewal needs a review and a written reason. An entry tied to a permanent ban can only be renewed while that ban is active. If nobody renews an entry, it expires and the block ends. An entry tied to a permanent ban is also lifted straight away if the ban is lifted, for example after a successful appeal, if the ban was a mistake, or if it is reduced.
Moderation notices. When staff delete an account or issue a permanent ban, we create a notice. It shows:
- what we did and until when;
- the reason shown to you, which is separate from staff's internal note;
- the rule it relates to;
- the date of the decision;
- whether the decision was automated.
We store the notice not tied to your account record, only to your Steam and Discord IDs, so it is still there if the account is deleted. The next time you sign in with Steam, we show you the notice on our sign-in service. We reach that page with a short-lived link (15 minutes) that holds none of your personal data. If you are not on the credential blacklist, you confirm that you understand and can then create a new account. If you are on it, the notice appears every time you try to sign in while the block lasts.
If you can't sign in, you can appeal by emailing [email protected] and quoting the number on the notice. You can also complain to the Information Commissioner's Office or to your own data protection authority (for example, UODO in Poland), or go to court (section 13).
The staff blacklist. If we can match you to an account, we tell you when you are added. You can see the entry at https://trucklinemp.com/account/status, and the recruitment eligibility check tells you when it ends and how to contest it. You don't see the reasons, notes or evidence. Each entry has a term based on its severity (section 10), and staff can renew it when they review it.
You can see your own moderation record for the past 12 months at https://trucklinemp.com/account/status.
3.8 Staff recruitment and volunteering
Applications. When you apply for a staff role, we record:
- your name and email address, copied from your account;
- your answers, including built-in questions about age, country, timezone and languages;
- the declarations you make (for example that your answers are true, or that you accept a non-disclosure agreement);
- drafts, saved on our servers and in your browser.
Eligibility checks. Before you can apply, we check automatically that you:
- have linked Discord, and hold the required role in our Discord server;
- are not blacklisted;
- have an old enough account;
- have no disqualifying warnings;
- meet any company membership requirements;
- are outside the waiting period between applications.
We also flag duplicate email addresses used within 90 days, and ages outside a position's range, for staff to review.
Reviewing. Staff record:
- scorecards, reviewer notes, flags, stage history, internal messages and audit events;
- interview slots.
When you are accepted, our Discord bot receives your name and email address to onboard you. It records invite codes, interview times, recruiter notes and roles. Interviews can be created as Discord scheduled events, which include the slot notes. The bot also records which of your Discord servers it shares with you, and it can message you about the outcome.
Calendar invitations. If an interviewer uses a connected Google or Microsoft calendar, the provider receives your email address (Microsoft also receives your name), the interview title, time, location and notes.
Talent pool. If your application for a role with a minimum age of 18 does not succeed, staff may keep your profile in a talent pool for future roles. An entry lasts 365 days and can be renewed once. You can ask to be removed or marked "do not contact" at any time.
Staff and volunteers. If you join the team, we also keep:
- role and position history (shown on your public profile);
- leave-of-absence requests (dates, type and reason);
- strikes, time tracking and descriptions, onboarding and training progress, timezone and availability;
- work attachments, stored privately and checked for malware;
- which staff documents and non-disclosure agreements you accepted, and when;
- audit logs of your staff actions, with your IP address and browser. Some audit alerts go to a private staff Discord channel;
- moderation statistics, such as how many bans, mutes, kicks and warnings each staff member has issued, which staff with permission can see.
If you choose "medical" as a leave type, that tells us something about your health. We use it only to manage your leave, only leave managers can see it, and we rely on your explicit consent. You can choose "personal" instead and don't have to give details.
3.9 Supporter memberships
Patreon. We take support through Patreon. If you link Patreon (see section 3.2), we use your membership status and tier to give you supporter benefits, including roles on our website, on our Discord servers and in game. When a membership lapses, we record the date so your benefits can continue for 3 days. Patreon handles your payment, and we never receive your payment details.
Staff-granted benefits. Staff can grant supporter benefits without payment. We record the tier, reason, expiry and staff member.
Supporter visibility. Active supporters are shown on our Supporters page with their tier, and get a badge on their profile. You can hide your Patreon membership in Settings, which also takes you off the Supporters page.
Earlier paid memberships. We used to sell paid memberships through Link, Stripe's consumer payment service. We no longer sell them. We keep the Stripe customer and subscription records we already hold (IDs, tier, price, status and dates) as needed for tax and accounting.
3.10 Developers
API keys. Name, scopes, permissions, project membership, and last-used IP address and browser. The key itself is stored only as a hash.
API request logs. For every request made with a key we log:
- time, endpoint, method, status and response time;
- IP address, user agent and country;
- the website origin, and the names (not values) of query parameters.
We also log anonymous requests that fail, are rate-limited or look like attacks.
Security events. We record suspicious API activity with the IP address and user agent. It can trigger a temporary IP block.
Who can see request logs. Members of a developer project can see their project's request logs, including IP addresses, for 90 days. Our staff see only masked, summarised data.
OAuth apps. We store app details, redirect addresses, hashed client secrets, and grants and tokens (codes last 2 minutes, access tokens 1 hour, refresh tokens 30 days). App owners can see the IP address that last used their app.
What an app you approve receives:
- your account ID and web ID;
- with the
profilescope: your name, avatar, handle and SteamID64; - your company memberships and online status, if you approve those scopes.
Apps never receive your email address. Our own first-party apps don't ask for approval.
Webhooks. We store the destination address, the events chosen, a signing secret we generate, and delivery logs (the payload and the start of the response).
- Some company events, such as members joining, applications, role changes and RSVPs, include other people's account IDs. If someone hides themselves from an event roster, their account ID is left out of RSVP events.
- Ban and appeal events go only to the affected person's own webhooks.
Leaked keys. If GitHub finds one of your API keys in public code, it tells us. We store the link and warn you.
Event embeds. If a website embeds our event widget, requests to it can be logged with the viewer's IP address for security.
3.11 Discord
Our moderation bot runs in our official Discord servers. It:
- checks messages against moderation rules and our content filter;
- applies automatic penalties when warnings add up: timeouts of 5 minutes, 1 hour, 24 hours and 7 days, then a ban;
- removes raid and spam accounts;
- logs message edits and deletions, joins, leaves and role changes to private staff channels and our database;
- gives your roles back when you rejoin;
- applies bans across our servers and links them to your TrucklineMP account;
- runs support tickets and recruitment onboarding.
The TrucklineMP bot runs in our servers and in company servers that add it. It:
- stores those servers' settings, owner and membership history;
- can show TrucklineMP profile, roster and activity information in those servers;
- if you have linked Discord, sends you a direct message for each TrucklineMP notification (title, text and link), including notifications from the last 14 days when you first link.
It does not read message content.
Webhooks. We post some updates to Discord channels, for example:
- support alerts in private staff channels, showing a ticket's subject and the user's name;
- company announcements;
- error alerts.
Once content is posted to Discord, Discord's privacy policy applies to it.
3.12 Beta programmes
Beta non-disclosure agreement (NDA). When you accept the beta NDA, we record:
- your Discord ID, username and avatar;
- your IP address and browser;
- the NDA version and time;
- a priority flag based on your company membership.
Accepting again replaces the earlier record.
Beta tester and open beta selection. We choose participants automatically. We score and draw accounts using:
- account age;
- company and event activity;
- how recently you signed in;
- whether you own a company, are staff, or are a supporter;
- bans and active Discord moderation cases.
Invitations are sent through Discord. We keep a do-not-invite list. Open beta access can be removed automatically if you stop meeting the criteria (section 6).
3.13 Device, usage and log data
-
Cloudflare. All traffic to our sites passes through Cloudflare. It protects the service and delivers files, and sees your IP address and request details.
-
Server logs. Our web servers and apps log requests (page addresses, browser, referring page) and some events with account IDs or SteamID64s. We keep them for short periods for troubleshooting and security.
-
Analytics (only with your consent). If you accept analytics, our self-hosted PostHog records:
- pages you visit, the page you came from and campaign tags;
- browser, device, screen size and language, and your approximate country or region (from your IP address);
- an anonymous ID stored in a cookie;
- the names of browser errors;
- masked session replays where turned on (we mask all text and form inputs).
We never link analytics to your account.
-
Error and performance monitoring (no cookies). Our servers send error reports and performance traces to the same self-hosted PostHog. These contain the error type and the page or route. They can also include the page address. We also count sign-in successes and failures without linking them to you.
The Cookie Policy lists every cookie and browser storage item we use.
3.14 Where we get information from
- You, when you sign up, fill in your profile, post, apply, open tickets or connect services.
- Automatically, while you use our sites, the launcher and the game.
- Services you connect or use to sign in: Steam, Discord, YouTube, Twitch, Google, Patreon, DBus World and Truckline Utils.
- Our game servers, which report sessions, positions, jobs and chat.
- Other people:
- reports about you;
- notes, blacklists and applications kept by company managers;
- staff moderation records;
- mentions of you in tickets.
- Discord, when our bots process events in servers where they run.
- GitHub, if one of your API keys leaks.
- Local reference lists, such as lists of hosting-provider IP ranges and disposable email domains, used in ban-evasion checks.
3.15 What we don't collect
- We don't collect government ID, card numbers, real-world precise location, or biometric data.
- We don't ask for special category data (such as health, religion or sexual orientation). The only exception is the optional "medical" leave type for staff (section 3.8).
- Please don't put sensitive information in your profile, posts, tickets or chat.
4. How we use your information and why we're allowed to
UK and EU data protection law requires a legal basis for each use of personal data. These are the main ones.
| What we do | Legal basis |
|---|---|
| Create and run your account, sign you in, keep you signed in | Contract |
| Check you meet the sign-up requirements | Contract; legitimate interests (preventing abuse) |
| Provide the features you use: profiles, companies, events, polls, notifications and connected services | Contract |
| Run multiplayer: launcher, game sessions, servers, the live map, chat and statistics | Contract |
| Show public profiles, leaderboards, the live map and public API data | Contract; legitimate interests (an open community and developer tools) |
| Count driving statistics and show them as you choose | Contract |
| Work out traffic, road speeds and freight flows from positions | Legitimate interests (useful live map and route planning) |
| Record event attendance automatically | Contract (event features); legitimate interests (helping organisers run convoys) |
| Fair-play checks on game data | Legitimate interests (a fair game and preventing cheating) |
| Staff and moderation statistics | Legitimate interests (managing and overseeing the team) |
| Keep accounts and the service secure: sessions, 2FA, rate limits, bot checks, IP blocks | Contract; legitimate interests (security) |
| Detect ban evasion and fake accounts | Legitimate interests (preventing fraud and abuse) |
| Keep the credential blacklist, and tell you why we banned you or deleted your account | Legitimate interests (stopping banned people coming back; being open with people about our decisions); contract (enforcing our terms), but only for people who have an account. Entries about people without an account rely on legitimate interests only |
| Moderate content and behaviour, enforce our rules, publish public bans and driver licences | Legitimate interests (a safe, fair community); contract (enforcing our terms); legal obligation (online safety laws) |
| Handle support tickets, reports and appeals | Contract; legitimate interests |
| Run staff recruitment and manage volunteers | Steps you ask us to take before joining; legitimate interests (a trustworthy team) |
| Use health information from a "medical" leave request | Explicit consent |
| Give and manage supporter benefits, and keep records of earlier paid memberships | Contract; legal obligation (tax and accounting records) |
| Run the developer platform and its security logs | Contract; legitimate interests (security) |
| Run our Discord servers, bots and automatic moderation | Legitimate interests (a safe, well-run community) |
| Select beta testers and run beta programmes | Legitimate interests (fair selection and testing); contract (the beta NDA) |
| Show company ads | Legitimate interests (helping companies grow the community) |
| Product analytics and session replay | Consent |
| Error and performance monitoring | Legitimate interests (keeping the service working) |
| Report child sexual abuse material, respond to lawful requests, and meet other legal duties | Legal obligation |
| Protect someone in an emergency | Vital interests |
| Establish, exercise or defend legal claims, including keeping audit logs and admin action logs for 6 years | Legitimate interests |
Legitimate interests. Where we rely on legitimate interests, we have weighed our interests against your rights and expectations, taking particular care with young users. You can ask us for details.
For UK users, some safety purposes are recognised legitimate interests under UK law, such as preventing and detecting crime and safeguarding vulnerable people.
Do you have to give us data? You need a Steam account and the account data in section 3.1 to use TrucklineMP. Without it we can't provide the service. Everything else you add is up to you.
New purposes. We only use data for something new if it fits with why we collected it, or if we have a new legal basis and tell you first.
5. What other people can see
Anyone, including people who aren't signed in:
-
Your profile: display name, handle, avatar, banner, bio, cosmetics and badges (including a programme badge's reason and who gave it), achievements, public social links, staff roles and position history, account age, company memberships and employee IDs.
-
Supporter status: your Patreon membership and tier, and your listing on the Supporters page, unless you hide your Patreon membership.
-
Through our public API: your SteamID64 and profile. The API can list and search all accounts, including by SteamID64.
-
Your driver licence and moderation history:
- active public bans, with your name, handle, avatar, scope, severity, the reason, the rule it relates to, whether the decision was automated, and dates. Bans that are lifted, expired or made by mistake are not listed;
- while a ban is active and public, it is shown on your profile.
In-game bans are public by default. Event bans are not public by default. Other bans are public only if staff make them public.
Your SteamID64 and the evidence for a ban are not part of a public ban. Evidence is shown only to the banned person, for items staff mark as visible to them, and to staff with permission to review bans. Your SteamID64 as part of a ban is shown only to you and to staff.
-
The live map, while you play: your position, name, handle and main company (section 3.4).
-
Your driving statistics, only if you set them to everyone. That also puts you on the playtime leaderboard and shows your statistics and current job on the live map.
-
Company information: rosters, contact details, news and media, events and their calendar feeds, and company ads.
Search engines and other crawlers, including AI crawlers, can index public pages.
Signed-in users can also see:
- a person's company membership history;
- event attendee lists, according to each attendee's setting.
Company managers see the information about their members described in section 3.5.
Our staff see what they need for their role. That can include private information, such as support tickets, chat (including whispers), session details and moderation records. Staff access is permission-based and recorded in audit logs.
Your controls (Settings, under Security & privacy and Connected accounts):
- who can see your event activity;
- who can see your driving statistics, and whether they show on the live map;
- whether your YouTube and Twitch links and your Patreon membership are shown;
- whether external configurations are shown;
- whether your legacy forum activity is shown.
To be left off the Supporters page, hide your Patreon membership in Settings, or contact [email protected].
6. Automated decisions and profiling
Some of our systems make decisions or assessments automatically.
-
Sign-up requirements. At sign-up we check your Steam profile automatically, as described in section 3.1. If you don't qualify, we can't create an account for you. You can ask support for a manual review.
-
Ban-evasion detection. We compare accounts using these signals:
- Discord ID and email address;
- IP address and IP range;
- browser and device;
- several accounts on one device or IP address;
- bursts of sign-ups;
- links up to two steps away between accounts (for example, you share a device with an account that shares an IP address with a banned account).
We compare hashed values of these signals. The raw IP addresses and browser details come from session records. The checks run:
- at sign-up;
- when you link Discord;
- every 30 days for every account.
Our device and IP lists (hosting providers, disposable email domains) are kept on our own servers and aren't shared with anyone.
Results:
- Most matches only flag an account for staff to review.
- An account is automatically restricted pending review only when its Discord ID or email address exactly matches an account with an active ban. We send you a notification, which doesn't say which account matched. You can appeal.
- Staff make any further decision. You can challenge a flag or restriction through support.
-
Discord automatic moderation. Our moderation bot can automatically time you out or ban you from our Discord servers when warnings add up (section 3.11), and can remove raid or spam accounts. After 5 active warnings, the bot bans you automatically. The direct message we send you says the ban was automatic, explains why, and links to how to appeal. You can appeal through a Discord ticket or support.
-
Content filter. Event text is checked against moderation rules, and matching content can be blocked. Staff can review it on request.
-
Beta selection. Beta testers and open beta participants are chosen by automatic scoring and a weighted draw (section 3.12). Open beta access can be removed automatically. You can ask for a review.
-
Recruitment and company checks.
- Staff applications are gated by the automatic checks in section 3.8. Staff make every hiring decision.
- Company blacklists can remove or reject listed people automatically, based on rules the company's managers set.
-
Security blocks. Suspicious traffic can be blocked automatically: API IP blocks last 30 minutes, and blocks on devices probing for security holes last 30 days.
-
Company ads are chosen based on your account activity and company membership. This has no legal or similarly significant effect on you.
-
Fair-play checks. Our game service scores accounts for signs of cheating (section 3.4). A score only helps staff decide what to look at. It never bans, mutes or restricts anyone by itself; staff make any decision, and you can challenge it through support.
-
Event attendance. We mark you as attended automatically when your in-game position shows you took part in a convoy (section 3.5). If it's wrong, ask the organiser or support to correct it.
Your safeguards. Where a decision made without human involvement has a legal or similarly significant effect on you, you can:
- ask us why it was made;
- tell us your side;
- ask a person to review it;
- challenge it.
Write to [email protected] or open a support ticket.
7. Cookies and analytics
We use cookies and similar storage that are needed to run and secure the service. Analytics cookies are used only if you accept them. You can change your choice at any time with the privacy settings link in the footer.
- We respect Do Not Track and Global Privacy Control: if your browser sends either signal, we don't start analytics.
- We don't use advertising or cross-site tracking cookies.
Full details are in the Cookie Policy.
8. Who we share information with
8.1 Service providers
These providers process data for us, on our instructions:
| Provider | What they do for us |
|---|---|
| SummerHosting sp. z o.o. (Poland) | Hosts our servers and databases, including our self-hosted analytics, content filter and mail server |
| Cloudflare, Inc. (USA) | Network protection, secure connections (Cloudflare Tunnel), DNS, file storage and delivery (R2), human checks (Turnstile), and processing incoming webhooks |
| Amazon Web Services (USA) | Delivery of emails we send, and delivery reports for them |
We also run these services ourselves, so no outside company processes data for them:
- analytics and monitoring (PostHog);
- the content filter;
- email storage;
- our issue tracker;
- the anonymous voting service;
- our Discord bots.
8.2 Other organisations that receive data
These organisations use the data under their own privacy policies:
- Steam (Valve): sign-in and profile lookups.
- Discord:
- accounts you link and Linked Roles;
- our bots and the direct messages they send;
- webhook posts;
- role sync.
- Stripe and Link: records of earlier paid memberships.
- Patreon: if you link it.
- Google (including YouTube), Twitch and Microsoft: accounts you link, live-status checks, and calendar invitations for interviews.
- DBus World and Truckline Utils: if you use them with your account.
- GitHub: if one of your API keys leaks.
- Websites whose content your browser loads: Spotify, Apple Music, Discord widgets, YouTube, Vimeo, Twitch, image hosts, OpenMapTiles (map fonts on the live map) and DMCA.com (a badge in our footer).
8.3 Other users, companies, apps and the public
- Public information (section 5) can be seen and reused by anyone, including through our public API.
- Company managers see member data for their company.
- Apps you approve receive the scopes you allow.
- Webhooks you or your company set up receive event data at addresses you control.
- Once data leaves us this way, the person or service that receives it is responsible for how they use it.
8.4 Legal and safety
We may share information when the law requires it, for example:
- with the UK National Crime Agency, where UK law requires us to report child sexual exploitation and abuse content;
- with police, courts or regulators, in response to a lawful request;
- in an emergency, where we believe someone's life or safety is at risk.
8.5 If TrucklineMP changes hands
If TrucklineMP is moved to a new operator, such as a company or community organisation, your data would move with it. This policy would keep applying until you are told otherwise.
8.6 No selling
We don't sell personal data. We don't share it for cross-context behavioural advertising, and we don't use ad networks or data brokers.
9. International transfers
We are based in the UK. Our servers are in Poland, in the EU.
- EU users: your data comes to us under the European Commission's adequacy decision for the UK.
- UK users: UK law recognises the EU as providing adequate protection.
Some providers and recipients are in the United States or elsewhere, including Cloudflare, Amazon Web Services, Stripe, Discord and Patreon. Cloudflare's file storage may hold data outside the UK and EU. For these transfers we rely on:
- the EU–US Data Privacy Framework and its UK Extension, where the provider is certified;
- or standard contractual clauses and the UK transfer addendum.
You can ask us for a copy of these safeguards.
Our volunteer staff may access data from other countries. They do so under our control, bound by confidentiality, and only as their role needs.
10. How long we keep information
We keep personal data only as long as we need it. For some records, the law or the risk of disputes means we keep them longer.
| Information | How long we keep it |
|---|---|
| Account and profile | Until you or we delete the account |
| Sign-in sessions (including IP address and browser) | Until the account is deleted, so we can protect accounts and detect ban evasion |
| Trusted devices, passkeys and 2FA settings | Until you remove them, recovery is completed, or the account is deleted |
| 2FA recovery requests, sign-in audit events and legal acceptances | Until the account is deleted |
| Enterprise sign-in logs | 90 days |
| QR and mobile sign-in codes | Minutes, then deleted; mobile access tokens last up to 30 days |
| Launcher tokens | 30 days of validity |
| Game session data used by servers | While you play, then 30 minutes |
| Live map positions | About a minute after you leave a server |
| In-game chat | 90 days |
| Game session history, jobs and driving statistics | Until the account is deleted (see "When you delete your account") |
| Fair-play records | 90 days |
| Event attendance and time at an event | Until the event or your account is deleted |
| Notifications you have read | 180 days |
| Server population figures | Per minute for 120 days, then as hourly totals that don't identify anyone |
| Moderation records, including bans, warnings and cases | Until the account is deleted, except the credential blacklist, moderation notices and audit logs below |
| Credential blacklist | To stop banned people coming back, for a set term that staff can renew at review: 5 years from listing or last review for a permanent ban, 3 years if staff deleted the account without a ban, up to 5 years for an entry added by hand. Entries nobody renews expire and are deleted 90 days later. Removed entries are also deleted after 90 days |
| Moderation notices | Until the end of the longest related measure; if there is none, 1 year |
| Staff blacklist | By severity, so we can keep people out of staff roles: low 1 year, medium 2 years, high 3 years, permanent 5 years. Staff can renew an entry at review. Removed entries and their evidence files are deleted after 90 days |
| Blocked IP addresses | Until they expire (30 minutes for the API, 30 days for probing). We delete the record of a block 1 year after it expires |
| Audit logs and admin action logs | 6 years, then deleted. This matches the time limit for legal claims in the UK and in Poland |
| API request logs | 90 days |
| Anonymous API usage summaries | 30 days |
| API security events | 180 days |
| Webhook and company announcement delivery logs | 30 days |
| Support tickets, Discord ticket transcripts and reports | As long as needed to handle the issue and any follow-up or dispute |
| Recruitment applications | As long as needed for the recruitment process and any dispute that follows; your answers, name and email are removed if you delete your account |
| Recruitment talent pool | 365 days, renewable once, or until you ask to be removed |
| Staff records | While you are on the team, and afterwards as long as needed for accountability and security |
| Beta NDA acceptance | As long as the NDA can be enforced |
| Poll answers | Set per poll: raw answers 7 to 730 days after the poll closes; anonymous totals and receipts are kept |
| Company ad view and click counts | 35 to 95 days |
| Records of earlier paid memberships | As needed for tax and accounting |
| Analytics and session replay | Up to 24 months |
| Server logs | Short periods, normally days to weeks |
| Encrypted backups | Until the backup is deleted (see below) |
When you delete your account. You can delete your account from Settings, or from the sign-in service. Deletion happens straight away and can't be undone. Deleting your account doesn't cancel a Patreon membership, so cancel it on Patreon if you no longer want to pay.
What we delete:
- your account and profile;
- your sessions and 2FA methods;
- connected accounts, notifications, legal acceptances and support tickets;
- your own bans, warnings and appeals;
- companies you own, including their data, and threads you started;
- your uploaded pictures;
- the answers and messages in your staff applications, plus your name and email address on them.
What we keep:
- Records about other people or shared data that you created, such as bans or notes you issued as staff, company events, or files you uploaded for the team. These stay, but are shown as made by "Deleted account".
- Anonymous application records. A staff application's outcome and review scores are kept without your name, email address or answers.
- The credential blacklist, if staff permanently banned you, or deleted your account and chose to block its IDs. It lasts for the term in the table above, and staff review it before it ends.
- Moderation notices, if you were permanently banned or staff deleted your account. They aren't linked to your account, and are kept for the period in the table above.
- The staff blacklist, if you were on it, for the term in the table above.
- Audit logs, which can include your IP address and browser, and a record that your account was deleted. They are kept for 6 years. If staff delete an account, the audit record no longer stores its email address.
- Content held in other people's records, such as messages in someone else's ticket or Discord transcript.
- Game history and statistics. These are stored in a separate system and aren't yet deleted automatically. Email [email protected] and we'll delete them.
- Stripe and Link payment records, which Stripe keeps under its own policy.
- Encrypted backups. Deleted data can remain in our encrypted backups until those backups are deleted.
11. How we protect information
Technical protections:
- connections to our sites are encrypted;
- 2FA secrets are encrypted, and backup codes, API keys and other secrets are stored as hashes;
- signals used for ban-evasion detection are hashed with a secret key;
- backups are encrypted with a key kept offline;
- Cloudflare protects the service from attacks.
How staff access is controlled:
- staff access is based on permissions and recorded in audit logs;
- staff with admin dashboard access must use two-factor authentication.
No system is perfectly secure. If a breach is likely to put you at risk, we will tell you and the relevant regulators as the law requires.
To report a security issue, email [email protected].
12. Your rights and choices
You have these rights over your personal data:
- Access: get a copy of your data.
- Correction: fix anything that's wrong.
- Deletion: ask us to delete your data.
- Restriction: ask us to limit how we use it.
- Portability: get data you gave us in a reusable format.
- Objection: object to uses based on legitimate interests.
- Withdraw consent: at any time, without affecting what we did before.
- Automated decisions: your rights over significant automated decisions (section 6).
Blacklists and moderation notices. You can ask us whether you are on the credential blacklist or the staff blacklist, and ask us to review or remove an entry. Email [email protected] and, if you have one, quote the number on your moderation notice.
Right to object. You can object at any time to our use of your data based on legitimate interests. That includes ban-evasion checks, public moderation records, company ads, leaderboards and the live map. We will stop unless we have compelling reasons that override your interests, or we need the data for legal claims.
Doing it yourself:
- Settings > Data export gives you a quick copy of your basic account data. For a full copy of everything, email us.
- You can delete your account in Settings.
- You can edit your profile, change visibility settings and unlink connected accounts in Settings.
- You can manage 2FA and passkeys at https://id.trucklinemp.com/security.
- You can change your analytics choice using the privacy settings link in the footer.
Asking us. Email [email protected] from any address and include your account handle or SteamID64. We may ask you to confirm the request while signed in, so we know it's you. You can use an authorised agent, who must show us your written permission.
Timing and cost.
- We reply within one month. For complex requests we can extend this by up to two more months, and we'll tell you why.
- If we need more information to identify you or understand your request, the clock pauses until you give it.
- Our searches will be reasonable and proportionate.
- Requests are free, unless they are clearly unfounded or excessive.
- If we can't do what you ask, we'll explain why.
Complaints. Please complain to us first at [email protected].
- We will acknowledge your complaint within 30 days.
- We will look into it without undue delay.
- We will tell you the outcome.
You can also complain to a data protection regulator (section 13).
13. Extra information for your region
13.1 United Kingdom and European Economic Area
- UK regulator: the Information Commissioner's Office, https://ico.org.uk/make-a-complaint/.
- EEA regulators: you can complain to the regulator where you live or work, or where you think the law was broken. They are listed at https://www.edpb.europa.eu/about-edpb/about-edpb/members_en.
13.2 United States
Depending on your state, you may have the right to:
- know what personal information we collect, use and disclose;
- access it and get a portable copy;
- correct it;
- delete it;
- opt out of its sale, targeted advertising, or profiling that has legal or similarly significant effects;
- not be discriminated against for using these rights.
These rights come from laws in states including California, Colorado, Connecticut, Delaware, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah and Virginia. We give these rights to every US user.
What we collect, in the categories US law uses:
| Category | Examples |
|---|---|
| Identifiers | Account ID, handle, SteamID64, Discord ID, IP address, email if provided |
| Customer records | Name and email on applications, supporter details |
| Commercial information | Membership tier and history |
| Internet activity | Sessions, logs, API use, analytics (with consent) |
| Approximate location | Country or region from your IP address (in-game positions are not real-world locations) |
| Audio or visual information | Pictures you upload, moderation evidence |
| Professional information | Staff applications and volunteer records |
| Inferences | Moderation standing, ban-evasion flags, fair-play risk scores, beta scores |
| Sensitive information | Account login credentials, messages in support tickets and chat |
- Where it comes from, why, and who receives it: sections 3, 4 and 8.
- How long we keep it: section 10.
We use sensitive information only to provide and secure the service. We don't use it to infer things about you.
No selling or sharing. We don't sell personal information or share it for cross-context behavioural advertising. That includes the data of people under 16. We treat a Global Privacy Control signal as an opt-out request.
Appeals. If we refuse your request, you can appeal by replying to our decision or by emailing [email protected] with "Appeal" in the subject line. We'll answer within 45 days. If you're still not satisfied, you can contact your state attorney general.
Other notices:
- We don't share personal information with third parties for their direct marketing (California "Shine the Light" law).
- We keep de-identified data only in de-identified form and don't try to re-identify it.
13.3 Brazil
Under the Brazilian General Data Protection Law (LGPD), you have the right to:
- confirm that we process your data, and get access to it;
- correct it;
- have unnecessary or excessive data anonymised, blocked or deleted;
- move it to another provider;
- have data processed on the basis of consent deleted;
- know who we share it with;
- be told what happens if you refuse consent, and withdraw consent;
- ask for a review of automated decisions.
You can complain to the ANPD at https://www.gov.br/anpd.
13.4 Canada
You can access and correct your information and withdraw consent. You can complain to the Office of the Privacy Commissioner of Canada at https://www.priv.gc.ca.
Quebec residents:
- Hayley Weighill is the person in charge of protecting personal information. You can reach her at [email protected].
- Tools that could profile you, such as analytics, are off by default.
- You can complain to the Commission d'accès à l'information at https://www.cai.gouv.qc.ca.
13.5 Switzerland
Your data may go to the countries listed in section 9. You can complain to the Federal Data Protection and Information Commissioner at https://www.edoeb.admin.ch.
13.6 Japan
Under the Act on the Protection of Personal Information, this policy sets out:
- our name and contact details (section 1);
- why we use your data (section 4);
- how to make a request (section 12);
- how we protect your data (section 11).
We handle your data in the UK and the EU, which Japan recognises as having equivalent protection. Some providers are in the United States (section 9). You can complain to us, or to the Personal Information Protection Commission at https://www.ppc.go.jp/en/.
13.7 India
As India's Digital Personal Data Protection Act comes into force, you have these rights:
- access information about your data;
- have it corrected or erased;
- have grievances addressed;
- nominate someone to act for you.
Our grievance contact is Hayley Weighill at [email protected]. You must use our grievance process before complaining to the Data Protection Board of India.
13.8 Australia and New Zealand
You can access and correct your information by contacting us. You can complain to:
- the Office of the Australian Information Commissioner, https://www.oaic.gov.au;
- the New Zealand Privacy Commissioner, https://www.privacy.org.nz.
13.9 Turkey
Under Law No. 6698 (KVKK), you can:
- ask whether we process your data, and get information about it;
- learn why we process it and who receives it;
- ask for corrections or deletion;
- object to decisions made only by automated analysis;
- claim compensation for unlawful processing.
Apply to us first. You can then complain to the Personal Data Protection Authority at https://www.kvkk.gov.tr.
13.10 Other countries
If you live somewhere else, you may have similar rights under local law. Contact us and we'll respond according to the law that applies to you.
14. Children and teens
Age rules.
- You must be at least 13 to use TrucklineMP.
- If you are under 18, you need a parent's or guardian's permission.
- If your country sets a higher age for using a service like ours without parental consent, that age applies to you.
We don't verify ages at sign-up; our sign-up rules (including Steam's own minimum age) are what keep children under 13 out. If we find out that an account belongs to a child under 13, we delete it.
How we protect young users:
- We don't show ads from ad networks, and we don't sell data.
- Analytics are off unless someone chooses to turn them on. If you are under 16, please ask a parent or guardian before accepting analytics.
- We don't allow content that is harmful to children, for anyone of any age (see the Terms of Service).
Much of TrucklineMP is public by design, including profiles and live map positions, so think carefully about what you share. Driving statistics start private, and stay that way unless you change them.
Parents and guardians can find more at Notice to Parents, and can contact [email protected] to access or delete a child's account.
15. Changes to this policy
We update this policy when our services or the law change. When we make changes, we will:
- publish the new version with a new version number and effective date;
- summarise what changed at the end of the policy;
- ask you to review and accept the new version the next time you sign in.
You can ask us for earlier versions.
16. Contact us
- Privacy, rights and complaints: [email protected]
- Security: [email protected]
- Support: https://trucklinemp.com/support
- Controller: Hayley Weighill, Great Britain (postal address on request)
What changed in this version
Version 2.3.0 explains how bans, blacklists and moderation notices work:
- Credential blacklist: we now say how an entry is added (a permanent ban issued by staff, staff deleting an account and choosing to block its IDs, or staff adding someone by hand, including people who never had an account), how long it lasts, and that staff review and renew it. An entry tied to a permanent ban is lifted when the ban is lifted (section 3.7).
- Entries from before this update: each got a term counted from the date this update was applied. None was lifted by the update.
- Moderation notices: when staff delete an account or issue a permanent ban, we keep a record of what we did and why, show it to you when you next sign in, and tell you how to appeal if you can't sign in (sections 3.7 and 10).
- Staff blacklist: you are told when you are added, can see the entry on your account status page, and we say how long entries last (sections 3.7 and 10).
- Public bans: only active public bans are listed. Your SteamID64 and the evidence are no longer public. Evidence is shown only to the banned person and to staff who review bans. Event bans are no longer public by default (section 5).
- Automatic decisions: after 5 active warnings our Discord bot bans you automatically, and the message now says so, explains why and links to how to appeal. If a new account is restricted for matching a banned account, you now get a notification (section 6).
- Company announcements: by default they no longer include the reason someone was removed or blacklisted (section 3.5).
- Ban notifications: they now include the rule and whether the decision was automated.
- How long we keep information: we set fixed terms for blacklists, blocked IP records, moderation notices, and audit and admin action logs (6 years). The audit record of an account deleted by staff no longer stores the email address (section 10).
Version 2.2.0
Version 2.2.0 updates supporter memberships:
- Patreon only: we now take support through Patreon. We use your linked Patreon membership status and tier to give you roles on our website, on our Discord servers and in game, and record when a membership lapses for a 3-day grace period (section 3.9).
- Paid memberships through Link (Stripe): we no longer sell them. We keep the records we already hold as needed for tax and accounting.
- Supporters page: listings now show your tier, and you can leave the page by hiding your Patreon membership in Settings.
- Deleting your account: you no longer need to cancel a paid membership first. Deleting your account doesn't cancel a Patreon membership.
Version 2.1.0
Version 2.1.0 adds the new game and event features:
- Driving statistics: we now count time driving, distance and top speed as well as playtime. They are private by default, and you choose who sees them. The playtime leaderboard only includes players who make their statistics public.
- Live map: listed everything the map shows about you, including your main company and trailer type. If you choose to share your statistics on the map, it also shows them and your current job. Added traffic and freight information worked out from positions.
- Events: added convoy routes and automatic attendance from your in-game position during a convoy.
- Fair-play checks: added the records our game service keeps about possible cheating, and that they never trigger action on their own.
- Staff: added moderation and chat statistics that staff can see.
- Retention: added how long we keep fair-play records, event attendance, read notifications and server population figures, and corrected how long you stay on the live map after leaving.
Version 2.0.0
This is a full rewrite of the policy. We reorganised it and checked it against how the platform works today. The main changes:
- Reorganised around what we collect, why, who sees it and how long we keep it, with a short summary at the top and a section on your rights in each region.
- Sign-up: added the Steam sign-up checks, including that we read your game list and playtime once at sign-up without storing them.
- Security features: added passkeys, trusted devices, 2FA recovery requests, and QR and mobile sign-in.
- Multiplayer: added game sessions and what our game servers receive, exact live map positions, jobs and route trails, session history and the driver licence.
- Public information: explained what is public, including SteamID64 through our API, public bans, the live map, leaderboards and the Supporters page.
- Payments: added paid memberships sold through Link (Stripe) as merchant of record.
- Companies: added company tools and what managers can see (member activity, blacklists, talent pool, employee IDs), plus company ads and partner tools.
- Discord: added our bots' automatic moderation, the direct messages sent for notifications, and Linked Roles.
- Other services: added the services we contact or load content from, including Twitch, YouTube, Steam, DBus World, Truckline Utils, GitHub, Amazon Web Services, OpenMapTiles and DMCA.com.
- Hosting: named our hosting provider (SummerHosting, Poland) and described Cloudflare's role in full.
- Automated decisions: added a section on them and your safeguards.
- Error monitoring: explained that our servers send error and performance data to our own analytics service without cookies.
- Deletion and retention: rewrote the deletion section to describe exactly what is removed and what is kept, and updated the retention table.
- Other additions: US, Brazil, Canada, Switzerland, Japan, India, Australia, New Zealand and Turkey sections, a complaints process, and a staff and volunteer section.
- Removed: descriptions of features that no longer exist, such as the old forum, email sign-up, the "betatesters" bot and calendar-based availability checks.