Privacy Policy
Last updated: 13 July 2026
This policy explains what personal data the Steam Data API (“we”, “us”) collects, why, how we protect it, and the rights you have over it. We collect the minimum needed to run the Service - we do not sell your data.
1. What we collect
- Account data - your email address and a securely hashed password. (We never store your password in plain text.)
- Billing data - plan and subscription status. Payments are processed by Stripe; we never see or store your card details - Stripe returns only a customer/subscription identifier.
- Usage data - API request counts, endpoints called, timestamps and rate-limit/quota state, tied to your API key, so we can meter usage, enforce plans and prevent abuse.
- Technical data - your IP address (used for rate limiting and abuse prevention) and basic request logs.
We do not require or collect your Steam account, Steam credentials, or inventory in order to use the API. (If you voluntarily pass a public SteamID to the inventory endpoint, we query that public profile on your behalf and do not retain it beyond a short cache.)
2. How we use it
- Authenticate you and operate your account and API keys.
- Process subscriptions, quotas and billing.
- Enforce rate limits, detect and prevent abuse, and secure the Service.
- Provide support and send essential service communications (e.g. account, billing, security notices).
Under the GDPR, our legal bases are performance of our contract with you (running the Service), our legitimate interests (security, abuse prevention, improving the Service), and consent where required.
3. Who we share it with
We share data only with the processors needed to run the Service, under appropriate data-processing terms:
- Stripe - payment processing.
- Our hosting provider - to run the servers and database.
We may also disclose data if required by law or to protect our rights. We do not sell or rent your personal data, and we don’t use it for third-party advertising.
4. Cookies
We use a single strictly-necessary cookie (sdk_session) to keep you logged in to the dashboard. Your
light/dark theme preference is stored locally in your browser. We do not use advertising or cross-site tracking cookies.
5. Data retention
We keep account and billing data for as long as your account is active and as required for legal/accounting purposes. Detailed request logs are retained on a rolling basis (typically up to a few months) and then aggregated or deleted. When you delete your account, we delete or anonymise your personal data except where we must retain it by law.
6. Your rights
Depending on where you live (e.g. the EU/EEA under GDPR, or California under CCPA), you may have the right to access, correct, export, restrict, or delete your personal data, and to object to certain processing. You can update or delete your account from the dashboard, or contact us to exercise any of these rights. You also have the right to complain to your local data-protection authority.
7. Security
We protect your data with encryption in transit (HTTPS), hashed credentials, scoped access controls and API-key isolation. No system is perfectly secure, but we take reasonable measures appropriate to the sensitivity of the data.
8. International transfers & children
Our providers may process data in regions outside your own; where required we rely on appropriate safeguards. The Service is not directed to children, and you must be at least 16 (or your country’s age of digital consent) to use it.
9. Changes
We may update this policy; material changes will be posted here with a new “last updated” date and, where appropriate, notified to you.
10. Contact
For any privacy question or request, contact our data controller at [email protected] or via our Discord.