Skip to content
SteamLabs Legal

Legal

Privacy Policy

What we collect, why we collect it, who else is involved, and the rights you have.

Introduction

SteamLabs is a platform for managing and automating Steam accounts that you own or control. This policy explains what personal data we process when you use the SteamLabs dashboard and the services it provides, why we process it, who else is involved, and the rights you have.

We process personal data in accordance with the EU General Data Protection Regulation (GDPR).

Who we are

SteamLabs is a trade name of Emrys Software, a sole proprietorship (eenmanszaak) registered in the Netherlands.
E-mail: [email protected]

Emrys Software is the controller for the processing described in this policy.

What data we collect

We collect what the service needs to work, and nothing beyond that:

  • Account data: your name, e-mail address and password (stored as a one-way hash), plus optional settings such as an avatar, timezone or two-factor authentication (secrets stored encrypted).
  • Billing data: the billing name, company name, address and VAT number you enter, together with your top-ups, balance history and the invoices we issue. Card and wallet details are handled by our payment providers; we never see or store full card numbers.
  • Steam accounts you add: the credentials needed to sign those accounts in (account name, password, and authenticator secrets where you provide them), and the data those accounts produce while we work with them: profile details, inventories, trades, market listings and task history. Credentials are stored encrypted.
  • Marketplace keys you connect: API keys for third-party marketplaces, stored encrypted.
  • Technical data: your IP address, browser session data, and the country your connection appears to come from (supplied by our edge network).
  • Things you write to us: messages in the community chat and reports you submit through the feedback tools.

Why we process it

Each purpose rests on a legal basis from the GDPR:

  • Providing the service you signed up for: running the tasks you start, on the accounts you added (performance of a contract).
  • Processing top-ups and issuing invoices (performance of a contract, and a legal obligation once an invoice exists).
  • Keeping the platform secure and preventing abuse (legitimate interest).
  • Meeting Dutch tax and accounting obligations (legal obligation).

We do not use your data for advertising, we run no trackers, and we never sell personal data.

The automated billing address check

When you save your billing details, we may ask an automated service whether the address you entered looks like a real place. This exists to catch obvious mistakes and nonsense entries before they end up on an invoice.

  • What is sent: only the name and address fields from the billing form. Your e-mail address, payment history and IP address are never sent.
  • Who receives it: OpenAI, whose language model produces the verdict.
  • What it does: the verdict is advisory. It blocks nothing: your details are saved whatever the outcome, and at most you are shown a correction suggestion you can freely dismiss. No decision with legal or similarly significant effect for you is made automatically on the basis of this check.
  • What we keep: a record of each check (the submitted name and address, the verdict, and the IP address the submission came from; the IP address is recorded by us and never shared with OpenAI). These records are deleted after 180 days.

Address autocomplete

The billing form can suggest addresses while you type. When this is enabled, the text you type into the address field is forwarded to Google's Places service to produce suggestions. The request goes through our own server: your browser never contacts Google directly, and Google sets no cookies on our pages through this feature.

Your Steam accounts

The Steam accounts you add to SteamLabs are your own. We store their credentials for one purpose: signing the account in, through a proxy you supply, to carry out the tasks you start or schedule. We do not act on your accounts beyond your instructions.

SteamLabs is not affiliated with, endorsed by, or connected to Valve Corporation or Steam.

Who receives your data

We use a small number of service providers, each for a specific job. They process personal data on our behalf and only as needed for that job:

  • Stripe: card and wallet payments; receives the details needed to process a payment.
  • CoinGate: cryptocurrency payments.
  • Our accounting provider: the bookkeeping service where our issued invoices are filed, as Dutch law requires us to keep them; receives the details printed on your invoice. It processes data inside the European Union.
  • OpenAI: the billing address check described above; receives only the name and address fields.
  • Google: address autocomplete suggestions on the billing form; receives the address text you type, relayed through our server.
  • Cloudflare: sits in front of the site, carries all visitor traffic, and tells us which country a connection appears to come from.

Beyond these, personal data leaves us only when the law requires it, for example a tax audit or a binding order from an authority. We never sell personal data.

International transfers

Our accounting provider processes data in the European Union. Stripe, CoinGate, OpenAI, Google and Cloudflare may process data outside the EEA, notably in the United States. Where that happens, the transfer is covered by an EU adequacy decision (such as the EU-US Data Privacy Framework) or by the European Commission's Standard Contractual Clauses.

How long we keep it

  • Account, Steam account and billing profile data: kept while your account exists, deleted when your account is deleted.
  • Invoices and the records behind them: kept for 7 years, the Dutch statutory retention period for accounting records. Invoices deliberately survive account deletion; deleting your account does not delete them.
  • Address check records: deleted after 180 days.
  • Payment provider delivery logs: kept up to 90 days for debugging and dispute handling.

Cookies

We use the session cookie that keeps you signed in and protects forms against cross-site request forgery. Your theme preference (light or dark) lives in your browser's local storage. There are no analytics, advertising or cross-site tracking cookies.

How we protect it

Steam account credentials, authenticator secrets and marketplace API keys are encrypted at rest. Passwords are stored as one-way hashes. All traffic is encrypted in transit. Access to production systems is limited to the people who operate SteamLabs.

Your rights

Under the GDPR you can ask us for access to your data, correction, deletion, restriction of processing, and portability, and you can object to processing based on legitimate interests. Write to [email protected] and we will respond within one month.

Deletion has one limit: invoices and the accounting records behind them must be kept for 7 years by Dutch law, so they are excluded until that period ends.

If you believe we handle your data unlawfully, you can complain to the Dutch data protection authority, the Autoriteit Persoonsgegevens.

Children

SteamLabs is a paid service aimed at adults. It is not directed at children, and we do not knowingly process the data of anyone under 16. If you believe a minor holds an account, contact us and we will remove it.

Changes to this policy

We may update this policy as the service evolves. The date at the top shows when it last changed, and meaningful changes are announced in the dashboard. The current version always lives at this address.

Contact

Questions about this policy or about your data: [email protected].

© 2026 Emrys Software SteamLabs is not affiliated with Valve Corporation or Steam.