Privacy Policy
Last updated: 2026-10-09
1. What we collect
We collect: your Steam ID (after OpenID sign-in), email (if you link one or sign in with Google/Discord/email), persona name + avatar from your linked provider(s), inventory snapshots (refreshed on demand), trade history (created by your activity on the site), wallet ledger entries, and request-level logs (IP, user-agent, request id).
2. Why we collect it
Authentication, anti-fraud, trade reconciliation, support, and (where you consented) analytics + marketing.
3. Cookies
Strictly-necessary: cs2sell_session (auth),csrf (CSRF token), cs2sell_locale (language). Optional: analytics + marketing cookies (opt-in via the cookie banner and toggleable from the Footer → Cookie Settings link).
4. Your rights (GDPR / CCPA)
- Export — request a JSON file of all your data via Account → Security → Export your data. We notify you when it's ready; the download link stays valid for 7 days.
- Delete — Account → Security → Delete account signs you out everywhere, removes your sign-in methods and personal details right away, and schedules the remaining records for anonymization after 30 days.
- Access, rectify, restrict, object — email [email protected].
5. Data sharing
We share data only with subprocessors needed to deliver the service: Steam (for trade verification), Resend (transactional email), BunnyCDN (image hosting), Blockbook (for crypto deposit tracking), and our DPO. We do not sell personal data.
6. Retention
Wallet ledger: 7 years (regulatory).
Auth sessions: 30 days rolling.
Server-side request logs: 30 days.
Everything else: until you delete your account.