Information we process
We process the Steam account identifier and profile fields returned by Steam OpenID when you sign in, account and plan state, hashed web sessions, API-key records, request and credit accounting, security events, and messages you send to support.
Infrastructure may process IP address, user agent, timestamps, requested paths, status codes, and request identifiers for security, reliability, rate limiting, and diagnostics. Secrets and query strings containing credentials are not intended for application logs.
Inventory and credential handling
Public Steam inventory pages may be stored as durable snapshots. Caller-supplied steamLoginSecure values and Trade URLs are used only for the authorized request path, bypass shared inventory storage, and are not persisted by ItemData.
Do not send personal information or credentials that the documented API does not request.
Why we process data
We use this information to provide and secure the service, authenticate accounts, enforce limits, account for credits, prevent abuse, diagnose failures, answer support requests, and meet legal obligations.
Retention and your choices
We retain information only as long as needed for the purposes above, contractual obligations, security, dispute resolution, and legal requirements. Exact retention varies by record type and backup lifecycle.
You may request access, correction, or deletion of account information, subject to legal and security exceptions, by contacting [email protected]. You can revoke an API key from the dashboard and sign out to end the current browser session.
Privacy contact
Send privacy questions or requests to [email protected]. We may need to verify that a requester controls the relevant account before fulfilling a request.