Privacy Policy
Last updated: 2026-08-05
This Privacy Policy describes what data SteamVaults ("we", "us", "the service") collects, why we collect it, and what your rights are. We have deliberately built the product to collect as little personal data as possible.
1. What we collect
When you sign in to SteamVaults, we collect:
- SteamID64 β your public Steam account number. This is your identity on the service.
- Persona name β the public display name set on your Steam profile.
- Avatar URL β the public profile image URL provided by Steam.
- IP address and User-Agent β processed by our hosting and abuse-prevention infrastructure for abuse prevention and rate limiting; they are not stored in the SteamVaults user profile, first-party analytics table, or application logs.
- Wallet address β only when you submit a withdrawal. We retain it associated with that withdrawal record.
- Sanctions-screening result β when you withdraw, the wallet address is checked against the configured public on-chain sanctions oracle (see "Third parties" below). We record only the resulting status; no paid screening-provider transaction ID is currently generated or stored.
- Cookies β see the "Cookies" section.
Railway, our hosting provider, separately records each HTTP request's source IP address and User-Agent in its edge HTTP logs. This infrastructure logging operates regardless of analytics consent and is not SteamVaults application analytics. According to Railway's log-retention documentation, retention is 7 days on Hobby/Trial, 30 days on Pro, and up to 90 days on Enterprise; actual retention follows the current Railway workspace plan.
If you use the public support form without signing in through Steam, we collect the category you select and the details you enter, plus a SteamID64 and Steam trade ID only if you choose to provide them. The form has no dedicated email, phone, or postal-address field and does not require those details. Any text you enter in the free-form details field is stored with the ticket, so do not enter contact details, passwords, private keys, recovery phrases, or Steam Guard codes. The request IP address is processed transiently for abuse prevention and rate limiting and is not retained in SteamVaults application logs.
For each public support request, we generate an access code. The raw code is shown only once and is not stored; only its SHA-256 hash is stored. You use the same code each time you check that request's status.
2. Information we do not require
We do not provide dedicated fields for or require the following information. Do not put any of it in the public support details field, because all free-form details are stored with the ticket:
- Your email address.
- Your phone number.
- Your postal address.
- Government-issued ID documents.
- Your full legal name.
- Your Steam password β Steam OpenID authentication does not send it to us.
- Your private wallet keys or recovery phrase β we never need them.
- Your Steam Guard codes.
This is by design. The fewer fields we hold, the less harm a breach could cause.
3. Why we collect each item ("purposes")
- SteamID64, persona name, avatar URL β to authenticate you via Steam OpenID and to display your account to you.
- Steam inventory items (fetched live, not stored) β to quote prices and execute trades you initiate.
- IP address β transient infrastructure processing for abuse prevention and rate limiting, without retention in SteamVaults application logs.
- Wallet address + sanctions-screening result β to reduce sanctions and withdrawal risk. This narrow automated check is not represented as a complete AML or KYC program.
- Transaction records (Steam trade ID, USD value, USDT amount, network, timestamp) β to operate the service, support you on disputes, and satisfy record-keeping rules.
- Public support data β to handle trade, security, and general support requests and to prevent abuse.
- SHA-256 hash of the public support access code β to verify access to a request's status without retaining the raw code.
- Session cookie β to keep you signed in.
- Optional analytics β explicit consent. Our first-party tracker records product-funnel events; Google Analytics records page paths, page titles, and browser/device measurements. The Google tag is blocked until you allow analytics.
4. Third parties we share data with
We only share data with the parties strictly required to operate the service:
- Valve / Steam β your SteamID64 is sent to Steam's OpenID endpoint to authenticate you. Steam's inventory and trade APIs are queried with that SteamID64 to fetch the items you want to sell. Steam's privacy policy applies to what Steam does with that data.
- Polygon RPC provider β the destination address is encoded in a read-only
eth_callto Chainalysis' public on-chain sanctions oracle and, if you confirm a withdrawal, in the blockchain transaction sent to Polygon. No paid Chainalysis API or exchange-custody integration is currently configured. - Railway β hosts the application, database, cache, and infrastructure logs. Doppler stores runtime secrets; customer support text is not intentionally sent to Doppler.
- Google Analytics (Google LLC) β only after explicit consent, receives the page path and title plus browser/device measurement data. We do not send query parameters, SteamID64, wallet addresses, Steam trade URLs, or first-party funnel payloads to Google. Advertising storage, signals, and personalization are disabled. Google's privacy policy applies to Google's processing.
- Polygon RPC providers β when we broadcast a withdrawal, the destination wallet address and the transaction itself become public on-chain data. This is irreversible.
We do not sell your data, do not share it with advertisers, and do not use it for marketing.
5. How long we keep your data
- Account data (SteamID64, persona, avatar) β until an authenticated deletion request is completed, subject to records that must be retained.
- Optional first-party analytics events β automatically deleted after 90 days.
- Google Analytics data β retained under the data-retention settings selected for the Google Analytics property and Google's applicable system-retention policies.
- Transaction and sanctions-screening records β only as long as required by applicable law and reasonably necessary for accounting, fraud prevention, sanctions compliance, and dispute handling. The period varies by record type and jurisdiction.
- Public support data β only as long as reasonably necessary to resolve the request, maintain support accountability and security, and comply with applicable law. The period varies by request.
- On-chain transactions β public on the blockchain forever, outside our control.
After deletion, transaction records that must still be retained remain subject to purpose and access restrictions. SteamVaults does not currently claim that those records are moved into a physically separate compliance archive.
6. Your rights
Depending on where you live, you may have rights under GDPR (EU/UK), PIPA (Korea), CCPA (California), LGPD (Brazil), or similar laws. We honor these rights worldwide regardless of jurisdiction:
- Right of access β request a copy of the personal data we hold about you.
- Right of correction β request that inaccurate data be corrected. (Most of your data comes from Steam β corrections may need to be made in Steam first.)
- Right of deletion ("right to be forgotten") β request that we erase your account. Some transaction records may still be retained as described under "How long we keep your data".
- Right of portability β request a machine-readable export of your data.
- Right to object / restrict β object to certain processing where you have grounds under your local law.
Requests to access or export, correct, delete, or restrict account data require Steam sign-in and recent reauthentication through the official in-service process. The anonymous support form will not be used to disclose or change account data. We will handle the request within the period required by applicable law.
If you are unhappy with our response you may complain to the data protection authority in your country.
7. Cookies and tracking
We use an essential session cookie plus consent-gated first-party analytics and Google Analytics:
- Session cookie β required to keep you signed in.
httpOnly,Secure,SameSite=Strict. - Functional referral storage β when a valid
refcode is present, we keep that code in this browser's local storage so it can be attached to Steam sign-in and attribute a genuinely new registration. It is not used for advertising and does not require analytics consent. - Optional first-party analytics β after explicit consent, we record a random session ID, page path, external referrer host, UTM campaign values, device class, event time, and your internal user ID if signed in.
- Google Analytics β after the same explicit consent, Google's tag records page views using the path and title without URL query parameters. Google may process network and browser/device data as described in its privacy policy. Advertising storage, signals, and personalization remain disabled.
- The first-party analytics store does not retain your raw IP address, wallet address, or Steam trade URL. Neither analytics integration receives wallet addresses or Steam trade URLs.
You may refuse analytics and continue using the service. Open Cookie preferences in the footer at any time. Choosing Essential only stops future analytics, asks our server to clear the current first-party analytics session and its events, and sends Google an analytics-consent denial. Account and transaction records require the separate authenticated data-request process described above.
8. Children
SteamVaults is not directed at children under 18 and we do not knowingly collect data from anyone under 18. If you believe a minor has used the service, contact support immediately so we can remove the account.
9. International transfers
SteamVaults routes data through infrastructure that may be located outside your country of residence. In particular:
- Steam operates from servers globally; SteamID64 / inventory queries transit through Steam's infrastructure.
- Railway, Doppler, Google Analytics, the Polygon RPC provider, and other cloud infrastructure may process data outside your country. The public Polygon blockchain is globally replicated.
- Blockchain RPC providers operate globally.
Where required by law (e.g., GDPR Chapter V) we rely on Standard Contractual Clauses or equivalent transfer mechanisms with these processors.
10. Security
We use TLS for data in transit, restrict internal access, redact sensitive values from application logs, and monitor the service for security and abuse. No system is perfectly secure β if we ever detect a breach affecting your data, we will notify you and the relevant authority within the time frame required by law.
11. Changes
We may update this Privacy Policy. Material changes will be announced in-app and on this page at least 14 days before they take effect.
Privacy requests involving account data require sign-in or recent Steam reauthentication before data can be returned or changed.
Support