World Vehicles is run by Appi. This page says exactly what data the website and the resource collect, why, and who else sees it. Last updated 13 September 2026.
Questions, corrections or a deletion request: open a ticket in our Discord. That is the way to reach us, and it is read every day.
Visiting the website
The web server keeps standard access logs: your IP address, the page requested, the time, the referrer and your browser's user agent string. They exist to keep the site running and to investigate abuse.
The site uses Google Analytics 4 (property G-QQSYZZ223F) to count visits and see which pages people read. It sets its own cookies, records the pages you open, your approximate location derived from your IP, and your device and browser type, and sends that to Google. Google acts as our processor for this, under its own terms.
There is no advertising network, no Meta pixel, no cross-site retargeting and no fingerprinting.
If you would rather not be counted, any tracker blocker or Google's own opt-out add-on stops it, and nothing on the site breaks without it.
Cloudflare sits in front of the site as a CDN and protection layer, so Cloudflare processes the same connection data on our behalf.
If you arrive with utm_ parameters in the link, those five values and a timestamp are stored so we can tell which post or video brought you. They are not tied to a person and not tied to your IP.
Fonts and videos
The stylesheet loads two typefaces from Google Fonts. Your browser fetches them from fonts.googleapis.com and fonts.gstatic.com, which means Google receives your IP address when a page loads.
The video thumbnails on the site are static images hosted by us. YouTube is contacted only after you click play, and then through youtube-nocookie.com. If you never press play, YouTube never sees you.
Signing in with Discord
Signing in is optional. It exists so a buyer can see their licence keys.
When you authorise the application, Discord gives us your profile and we store these fields against your account:
| Stored | Why |
|---|---|
| Discord user id | The only identifier we match you by |
| Username, display name, legacy discriminator | To show who is signed in |
| Avatar and banner hashes, avatar URL | To show your picture |
| Email address and whether Discord verified it | To reach you about your purchase |
| Locale, MFA flag, Nitro type, account flags | Returned by Discord with the profile |
| Whether you are a member of our Discord server, and its name | Support and customer roles |
| The raw profile response | So we can correct a field without asking you to sign in again |
| First and last sign-in timestamps | Housekeeping |
We ask for the scopes identify, email and guilds. We cannot read your messages, see your friends, or post anything as you.
Discord access tokens are not stored. The token is used once, during sign-in, and discarded.
Accounts are matched only by Discord user id. We deliberately do not match by email address, because that would let anyone holding a Discord account with the same address take over an existing account.
Sessions and cookies
| Cookie | Set by | Life | Purpose |
|---|---|---|---|
user |
Us | Until you sign out | Your session. Secure, HttpOnly, SameSite=Lax |
wv_oauth_state |
Us | 10 minutes | Protects the sign-in against request forgery |
wv_oauth_next |
Us | 10 minutes | Remembers the page you were heading to |
wv_admin_csrf |
Us | 24 hours | Form protection, staff only |
_ga, _ga_QQSYZZ223F |
Google Analytics | Up to 2 years | Tells returning visits apart |
The first four are needed for the site to work at all. The Google Analytics ones are not: blocking them changes nothing for you.
Each sign-in also writes one row holding your account id, IP address, user agent, session token and the time. Signing out deletes that row.
Buying
Payments are handled by Tebex Limited, who are the merchant of record. They take the payment, issue the invoice and handle refunds under their own terms and privacy policy.
We never see your card details. From a completed order we receive the transaction id, the buyer's email address and the list of purchased packages.
The licence system
Each purchase creates a licence record holding the licence key, the Tebex transaction id, the package ids, the buyer email, the status and timestamps.
A licence binds to the public IP address of the game server that first validates it. That address is stored in the licence record. You can change it yourself from your account page, once every 12 hours.
Every validation attempt is written to an audit log: the licence, the outcome, the IP address it came from and the time. That log is what lets us see a key being shared across several servers, and it is the only place your server IP appears.
What the resource sends us
This matters to server owners, so it is worth stating plainly.
When the resource starts it sends one request: the licence key and a random one time value, to our licence API. Nothing else. As with any network request, the receiving side sees the connecting IP address, and that is exactly how the binding works.
No player data ever leaves your server. Not identifiers, not names, not chat, not positions, not anything about your players. The resource has no telemetry.
How long we keep things
| Data | Kept |
|---|---|
| Access logs | Short-term, for operations and abuse |
| Google Analytics data | Held by Google under its own retention, up to 14 months by default |
| UTM rows | Indefinitely, they contain no personal data |
| Account and Discord profile | Until you ask us to delete it |
| Session rows | Until you sign out |
| Licence records | While the licence exists, then as long as accounting requires |
Your rights
If you are in the EU, the UK or another region with comparable law, you may ask for a copy of your data, correct it, have it deleted, take it elsewhere, or object to how we use it. Ask through Discord or the address at the top and we will answer.
Deleting your account removes your profile and sessions. The licence record survives, because it is the record of a purchase and of which server it is bound to. After deletion it is no longer linked to a Discord account.
Children
The site and the resource are not aimed at children. Do not create an account if you are under the minimum age for Discord in your country.
Changes
If this page changes in a way that matters, we will say so in our Discord. The date at the top always reflects the current version.