Steam · Steam Privacy Policy · View original document ↗

Transaction and Payment Data Collection

Medium severity Unique · 0 of 343 platforms
Share 𝕏 Share in Share 🔒 PDF
Recent governance activity Steam recorded 2 documented changes in the last 30 days.
Start monitoring updates
Monitor governance changes for Steam Create a free account to receive the weekly governance digest and monitor one platform for governance changes.
Create free account No credit card required.
Document Record

What it is

When you buy something on Steam with a credit card, Valve collects your full credit card details — including card number, expiration date, and security code — and shares them with payment processors and uses them for anti-fraud checks.

This analysis describes what Steam's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

The clause defines the data collection and processing mechanism necessary for Steam to execute financial transactions on its platform. It establishes Valve's role as a processor of payment information and clarifies the data flow between Valve, users, and third-party payment service providers.

Consumer impact (what this means for users)

Your complete credit card information, including the CVV security code, is processed by Valve before being passed to payment processors, creating an additional point of exposure for sensitive financial data compared to a direct payment processor relationship.

How other platforms handle this

Paramount+ Medium

"By clicking 'Next', you are indicating that you have read and agree to the TERMS OF USE AND PRIVACY POLICY"

OpenAI Medium

We automatically collect certain information from your device, including information about your web browser, IP address, time zone, and some of the cookies that are installed on your device. Additionally, as you browse the Service, we collect information about the individual web pages or products th...

Microsoft Azure Medium

Location data. Data about your device's location, which can be either precise or imprecise. For example, we collect location data using Global Navigation Satellite System (GNSS) (e.g., GPS) and data about nearby cell towers and Wi-Fi hotspots. Location can also be inferred from a device's IP address...

See all platforms with this clause type →

Monitoring

Steam has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.

Start Monitor free trial Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
In order to make a transaction on Steam (e.g. to purchase Subscriptions for Content and Services or to fund your Steam Wallet), you may need to provide payment data to Valve to enable the transaction. If you pay by credit card, you need to provide typical credit card information (name, address, credit card number, expiration date and security code) to Valve, which Valve will process and transmit to the payment service provider of your choice to enable the transaction and perform anti-fraud checks. Likewise, Valve will receive data from your payment service provider for the same reasons.

— Excerpt from Steam's Steam Privacy Policy

ConductAtlas Analysis

Institutional analysis (Compliance & governance intelligence)

REGULATORY FRAMEWORK: Payment card data processing engages PCI DSS (Payment Card Industry Data Security Standard) compliance obligations. In the EU, this also engages GDPR Art. 6(1)(b) (contractual necessity) and Art. 32 (security of processing). Under CCPA §1798.140, financial information constitutes 'personal information.' The GLBA (15 U.S.C. §6801) may apply to the extent Valve is considered a financial institution for payment data purposes, though this is unlikely given its gaming platform status. FTC Act Section 5 applies to data security failures.

Full compliance analysis

Regulatory citations, enforcement risk, and due diligence action items.

Track 1 platform — free Try Monitor free for 14 days

Free: track 1 platform + weekly digest. Monitor: 25 platforms + same-day alerts. No credit card required.

Applicable agencies

  • FTC
    The FTC has enforcement authority over inadequate payment data security practices under FTC Act Section 5, as established in FTC v. Wyndham and subsequent actions.
    File a complaint →
  • CFPB
    The CFPB has jurisdiction over payment data practices and consumer financial protection issues arising from credit card data processing on digital platforms.
    File a complaint →

Applicable regulations

CCPA/CPRA
California, USA
COPPA
United States Federal
Connecticut Data Privacy Act Amendments
US-CT
CAN-SPAM
United States Federal
ePrivacy Directive
European Union
FTC Act Section 5
United States Federal
GDPR
European Union
Indiana Consumer Data Protection Act
US-IN
Kentucky Consumer Data Protection Act
US-KY
UK GDPR
United Kingdom
Universal Opt-Out Mechanism Expansion 2026
US

Provision details

Document information
Document
Steam Privacy Policy
Entity
Steam
Document last updated
May 5, 2026
Tracking information
First tracked
April 18, 2026
Last verified
April 18, 2026
Record ID
CA-P-002931
Document ID
CA-D-00182
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
63210b28892392d9dae07097221e6ab8458f850d4edd68ce4be0bc540f120bb5
Analysis generated
April 18, 2026 10:57 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Steam
Document: Steam Privacy Policy
Record ID: CA-P-002931
Captured: 2026-04-18 10:57:26 UTC
SHA-256: 63210b28892392d9…
URL: https://conductatlas.com/platform/steam/steam-privacy-policy/transaction-and-payment-data-collection/
Accessed: June 17, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
Medium
Categories

Other risks in this policy

Related Analysis

Compliance Governance Intelligence

Need to monitor specific governance provisions?

Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.

Arbitration clauses AI governance Data rights Indemnification Retention policies
Start Compliance free trial

Or start with Monitor →

Built from archived source documents, structured governance mappings, and historical version tracking.

Frequently Asked Questions

What does Steam's Transaction and Payment Data Collection clause do?

The clause defines the data collection and processing mechanism necessary for Steam to execute financial transactions on its platform. It establishes Valve's role as a processor of payment information and clarifies the data flow between Valve, users, and third-party payment service providers.

How does this clause affect you?

Your complete credit card information, including the CVV security code, is processed by Valve before being passed to payment processors, creating an additional point of exposure for sensitive financial data compared to a direct payment processor relationship.

Is ConductAtlas affiliated with Steam?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Steam.