When you buy something on Steam with a credit card, Valve collects your full credit card details — including card number, expiration date, and security code — and shares them with payment processors and uses them for anti-fraud checks.
This analysis describes what Steam's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
The clause defines the data collection and processing mechanism necessary for Steam to execute financial transactions on its platform. It establishes Valve's role as a processor of payment information and clarifies the data flow between Valve, users, and third-party payment service providers.
Your complete credit card information, including the CVV security code, is processed by Valve before being passed to payment processors, creating an additional point of exposure for sensitive financial data compared to a direct payment processor relationship.
How other platforms handle this
If you choose to pay through third parties or by invoice, we may get data from our payment partners. This allows us to send you invoices or process your payments.
You may give us your Identity Data, Contact Data, Financial Data, Profile Data, and other information by filling in forms or by corresponding with us by post, phone, e-mail or otherwise.
NIM container releases that collect data, collect it for the following purposes: (a) to properly configure and optimize products for use with Software; and (b) to improve NVIDIA products and services.
"In order to make a transaction on Steam (e.g. to purchase Subscriptions for Content and Services or to fund your Steam Wallet), you may need to provide payment data to Valve to enable the transaction. If you pay by credit card, you need to provide typical credit card information (name, address, credit card number, expiration date and security code) to Valve, which Valve will process and transmit to the payment service provider of your choice to enable the transaction and perform anti-fraud checks. Likewise, Valve will receive data from your payment service provider for the same reasons.Excerpt from Steam's Privacy Policy
REGULATORY FRAMEWORK: Payment card data processing engages PCI DSS (Payment Card Industry Data Security Standard) compliance obligations.
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
Netflix updated its Privacy Statement on April 18, 2026, disclosing voice recording collection and expanded household ad profiling for the first time.
Google's Privacy Policy covers Search, Gmail, YouTube, Maps, and every site running Google Analytics. Here is what it actually authorizes.
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
The clause defines the data collection and processing mechanism necessary for Steam to execute financial transactions on its platform. It establishes Valve's role as a processor of payment information and clarifies the data flow between Valve, users, and third-party payment service providers.
Your complete credit card information, including the CVV security code, is processed by Valve before being passed to payment processors, creating an additional point of exposure for sensitive financial data compared to a direct payment processor relationship.
ConductAtlas has identified this type of provision across 296 platforms. See the full comparison.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Steam.