USD USD
EUR EUR
CNY CNY

1. Introduction

At csPortfolio.gg, we take your privacy seriously. This Privacy Policy explains how we collect, use, store, and protect your personal data in compliance with the General Data Protection Regulation (GDPR) and EEA consumer protection laws.

Quick Summary:

• We collect minimal data necessary to provide our services (Steam ID, email, inventory data)

• Payment information is handled by Polar.sh (not stored by us)

• You can request access, export, or deletion of your data at any time

• We do not store data longer than necessary to provide our services

1.1 Data Controller

csPortfolio.gg is the data controller for personal information processed through our platform. We are based in Iceland (EEA member) and subject to Icelandic data protection laws and GDPR.

1.2 Contact Information

For privacy-related inquiries, contact us at:

2. What Data We Collect

2.1 Account Information

When you create an account via Steam OAuth, we collect:

Legal basis: Contractual necessity (to provide our services)

2.2 Email Address (Optional)

If you choose to verify your email, we collect:

Legal basis: Consent (you opt-in to email verification)

2.3 Inventory Data

To provide portfolio tracking, we fetch and store:

Note: We only access public inventory data available through Steam's API. If your Steam profile is private, we cannot fetch your inventory.

Legal basis: Contractual necessity (core service functionality)

2.4 Usage Analytics

We collect anonymized usage data for service improvement:

Legal basis: Legitimate interest (service improvement and performance monitoring)

2.5 Payment Information

Important: We do NOT store payment information (credit cards, billing addresses, etc.). All payment processing is handled by Polar.sh, who acts as the Merchant of Record.

Polar.sh collects and processes:

  • Payment card details
  • Billing address
  • Transaction history

Refer to Polar.sh's Privacy Policy for details on their data handling.

2.6 Demo Access Records

If you're granted demo access, we store:

Legal basis: Contractual necessity (subscription management)

3. How We Use Your Data

3.1 Service Provision

We use your data to:

3.2 Communication

We may send emails (if you verified your email) for:

You can opt-out of non-essential emails through your account settings.

3.3 Service Improvement

We analyze anonymized usage data to:

3.4 Security & Fraud Prevention

We monitor for:

4. Third-Party Data Sharing

4.1 Service Providers

We share limited data with third-party services necessary for our platform:

Polar.sh (Payment Processing)

Third-Party Market APIs (Price Data)

PurelyMail (Email Delivery)

Steam API (Valve Corporation)

4.2 Legal Obligations

We may disclose data if required by law:

We will notify affected users unless legally prohibited from doing so.

5. Data Retention

5.1 Active Accounts

For active accounts, we retain data as long as necessary to provide our services. We do not store data longer than required for operational, legal, or security purposes.

5.2 Demo Accounts

Demo access records are retained for audit purposes:

5.3 Logs & Analytics

6. Your Rights (GDPR)

Under GDPR and EEA consumer protection laws, you have the following rights:

6.1 Right to Access

What it means: You can request a copy of all personal data we hold about you.

How to exercise: Email support@csportfolio.gg with subject "Data Access Request"

Response time: Within 30 days

6.2 Right to Rectification

What it means: You can correct inaccurate or incomplete data.

How to exercise: Update your profile in Settings, or email us for manual corrections

Response time: Immediate (via Settings) or within 7 days (via email)

6.3 Right to Erasure ("Right to be Forgotten")

What it means: You can request deletion of all your personal data.

How to exercise: Email support@csportfolio.gg with subject "GDPR Request - Data Erasure"

Response time: Within 30 days (as required by GDPR)

Note: Some data may be retained for legal or compliance purposes (e.g., anonymized audit logs for demo grants).

6.4 Right to Data Portability

What it means: You can export your data in a machine-readable format (JSON).

How to exercise: Coming soon via Settings → Export Data (currently email us)

Data included: Account info, inventory data, container records, demo history

Response time: Within 7 days

6.5 Right to Restrict Processing

What it means: You can request we pause processing your data (but not delete it).

How to exercise: Email support@csportfolio.gg with subject "Restrict Processing"

Effect: Your account will be suspended but data retained for later reactivation

6.6 Right to Object

What it means: You can object to data processing based on legitimate interest (e.g., analytics).

How to exercise: Email us with specific objections

Effect: We will stop the objected processing unless we have compelling legal grounds

6.7 Right to Withdraw Consent

What it means: You can withdraw consent for email notifications at any time.

How to exercise: Email support@csportfolio.gg to opt-out of notifications, or use unsubscribe links in emails

Effect: We will stop sending non-essential emails (security alerts still sent)

6.8 Right to Lodge a Complaint

What it means: You can complain to your national data protection authority if you believe we violated GDPR.

Iceland DPA: Persónuvernd (Iceland Data Protection Authority)

EU DPAs: Find your national DPA

7. Data Security

7.1 Technical Measures

We implement industry-standard security measures:

7.2 Access Control

7.3 Monitoring & Incident Response

7.4 Data Breach Notification

In the event of a data breach:

8. Cookies & Tracking

8.1 Authentication Tokens

We use localStorage (not cookies) to store:

These are essential for service functionality and do not require consent under GDPR.

8.2 No Third-Party Tracking

We do NOT use:

  • Google Analytics or similar tracking tools
  • Facebook Pixel or social media trackers
  • Advertising cookies or retargeting
  • Cross-site tracking or fingerprinting

8.3 Session Management

Sessions are managed server-side via JWT tokens. No session cookies are set by our platform.

9. International Data Transfers

9.1 EEA-Based Hosting

Our production server is hosted in the European Union/EEA region. Personal data is stored within EEA borders and subject to GDPR protections.

9.2 Third-Party Services

Some third-party services may transfer data outside the EEA:

All third-party processors are required to maintain GDPR-equivalent protections.

10. Children's Privacy

csPortfolio.gg is not intended for users under 16 years old (GDPR age limit). We do not knowingly collect personal data from children.

If you believe a user under 16 has created an account, please contact us at support@csportfolio.gg and we will delete the account promptly.

Note: Steam's Terms of Service require users to be 13+ (USA) or 16+ (EEA). We rely on Steam's age verification.

11. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect:

When we make significant changes:

We recommend reviewing this policy periodically to stay informed of how we protect your data.

12. Contact & Data Protection Officer

For privacy-related questions, data subject requests, or complaints:

12.1 General Inquiries

12.2 Data Subject Requests

For GDPR requests (access, erasure, portability, etc.), email support@csportfolio.gg with:

Response time: Within 30 days (as required by GDPR)

12.3 Complaints

If you're unsatisfied with our response, you can lodge a complaint with:

Solo Developer Note: csPortfolio.gg is developed and maintained by a solo developer. While we strive for prompt responses, please allow up to 30 days for complex data requests (as permitted by GDPR).

13. Your Trust Matters

We built csPortfolio.gg to help the CS2 community track their inventories without compromising privacy. Your trust is essential to us, and we're committed to:

Thank you for trusting csPortfolio.gg with your data.