Frontier Wing Industries — Privacy & Cookies
Last updated: October 3, 2026
Frontier Wing Gaming operates this community website and its ATS and Star Citizen recruitment system. This notice explains the current setup. Contact our staff through the community Discord lobby with privacy questions or requests. Do not post personal information or credentials in public channels.
What we collect
- Discord sign-in: your Discord account ID, username, and display name. We request Discord's
identifypermission, not access to your email, messages, password, or payment details. The OAuth access token is used to retrieve your identity during sign-in and is not saved in the application database. - Application details: the Discord username entered on the form, in-game username(s), selected division(s), time zone, availability, experience, motivation, and application reference and submission time.
- Review and invitation records: application status, private reviewer notes, review time, invitation URL and expiry, associated division role IDs, delivery time, and delivery/notification errors. The form requires agreement to recruitment review, an acceptance DM, and the community rules; the current database does not keep a separate consent receipt or rules-version history.
- Reviewer access: a password hash in private server configuration, not the plaintext password. A session records that the reviewer is signed in.
- Technical records: our hosting and proxy servers can record IP addresses, requested URLs, timestamps, browser/user-agent information, response codes, and errors. Rate-limit records contain a Discord ID for submissions or a client address for reviewer login attempts, plus timestamps.
Why we use it
We use these details to verify the account that applied, review applications, show application status, invite accepted members to the shared Discord server, assign approved division roles, protect sign-in and forms, and diagnose service problems. Application details are available to authorized recruitment reviewers.
Cookies and browser storage
| Name | Type | Purpose | Duration |
|---|---|---|---|
fwi_session | First-party session cookie | Discord sign-in, account/reviewer session, and protection against forged form requests | Before sign-in, normally until the browser session ends. After sign-in, an eight-hour lifetime, renewed by activity; signing out clears it. Browser session restoration can preserve session cookies. |
fwi_cookie_notice_v1 | First-party local storage | Remembers that you dismissed the cookie notice | Until you clear this site's browser storage |
On the public HTTPS site, the session cookie uses Secure, HttpOnly, and SameSite=Lax settings. It contains signed session information rather than your full application answers. The notice preference is a local browser value and is not sent to our application API.
We have no analytics, advertising pixels, or marketing cookies installed. The notice's Got it button dismisses an informational notice; it does not authorize optional tracking. You can block cookies or clear site data in your browser, but recruitment sign-in and form submission need the session cookie.
Services involved
- Discord: handles account authorization, invitations, division roles, and acceptance DMs. If the private review webhook is enabled, it receives a short notice with the applicant's Discord display name, division, application reference, event/status, and review-page link—not the full application answers or reviewer notes. Discord operates under its own privacy policy.
- OVH-hosted VPS: hosts the website, application database, and server configuration. Nginx Proxy Manager and Apache handle web requests on that VPS.
- Google Fonts: the browser currently downloads typefaces from Google's font services. These requests disclose connection information such as your IP address and browser/request headers to Google. Google states that its Fonts API does not set or log cookies. See Google Fonts privacy information.
- Background video: current ATS and Star Citizen videos are served from our own website. YouTube embeds are not enabled in the current configuration.
We do not sell application data or use it for advertising. External Discord links take you to Discord; Discord's own site and app may use their own cookies and storage. Third-party services may process information in countries other than your own.
Storage and retention
Applications are stored in a private SQLite database on the VPS, with server-side backups. The current application has no automatic expiry or deletion schedule: application and review records remain until staff remove them. Invitation links expire after 24 hours, but their stored records do not automatically disappear. Logs follow the server/proxy rotation settings; we do not promise a fixed deletion period for all logs or backups.
Rate-limit entries older than 24 hours are removed when another rate-limited request is processed. Retained cookies and browser-storage values follow the durations above. Discord controls retention of its own messages, invitations, and account information.
Your choices and requests
Applying is optional. Avoid including sensitive personal information in free-text answers. You can sign out, clear cookies/browser storage, or ask staff through the community Discord lobby to access, correct, withdraw, or delete your application information. Staff may need to verify your Discord identity before responding. Deleting website records does not automatically delete Discord messages, membership, roles, or historical backups; discuss those separately with staff. Your rights may also depend on the law that applies to you.
Changes
We will update this page when the site's data use changes. The date above identifies this version.