Privacy Policy
Last updated: March 2026
What We Collect
When you sign in and use TradeUpBot, we collect and store the following information:
- Steam ID — your unique Steam identifier, received via Steam OpenID authentication
- Display name — your public Steam display name
- Avatar URL — your public Steam profile avatar
- Email address — provided to us by Stripe when you subscribe to a paid plan
- Subscription status — your current plan tier and billing status
- Usage data — claims, verifications, and feature usage for rate limiting
What We Do Not Collect
TradeUpBot does not collect, store, or have access to:
- Steam password — authentication is handled entirely by Steam OpenID; we never see your password
- Steam inventory data — we do not access or read your Steam inventory
- Payment card details — all payment processing is handled by Stripe; card numbers never touch our servers
- Marketplace credentials — we do not store your CSFloat, DMarket, or Skinport login details
Cookies
TradeUpBot uses a single session cookie for authentication. This cookie identifies your login session and is required for the service to function. We do not use tracking cookies, advertising cookies, or third-party analytics cookies.
Third-Party Services
TradeUpBot integrates with the following third-party services:
Payment processing for subscriptions. Stripe receives your payment information directly and shares your email address with us for account management. See Stripe's privacy policy at stripe.com/privacy.
Authentication via Steam OpenID. We receive your public Steam ID and display name. See Valve's privacy policy at store.steampowered.com/privacy_agreement.
Market data sources for skin listings and pricing. We fetch public marketplace data from these services. Your TradeUpBot account is not linked to accounts on these platforms.
Data Retention
Your account data (Steam ID, display name, subscription status) is retained for as long as your account is active. If you cancel your subscription, your account data remains available should you choose to resubscribe.
You may request deletion of all your account data at any time by contacting us via Discord. Upon request, we will delete your account information within 30 days.
Data Security
We implement reasonable security measures to protect your data, including encrypted connections (HTTPS), secure session management, and limited data retention. However, no method of electronic transmission or storage is 100% secure.
Changes to This Policy
We may update this privacy policy from time to time. Changes will be reflected by updating the "Last updated" date at the top of this page. Continued use of the service constitutes acceptance of the updated policy.
Contact
For privacy-related inquiries, data deletion requests, or questions about how your information is handled, please reach out via Discord or through the platform's support channels.