When you buy something on Steam with a credit card, Valve collects your full credit card details — including card number, expiration date, and security code — and shares them with payment processors and uses them for anti-fraud checks.
This analysis describes what Steam's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
The clause defines the data collection and processing mechanism necessary for Steam to execute financial transactions on its platform. It establishes Valve's role as a processor of payment information and clarifies the data flow between Valve, users, and third-party payment service providers.
Your complete credit card information, including the CVV security code, is processed by Valve before being passed to payment processors, creating an additional point of exposure for sensitive financial data compared to a direct payment processor relationship.
How other platforms handle this
"By clicking 'Next', you are indicating that you have read and agree to the TERMS OF USE AND PRIVACY POLICY"
We automatically collect certain information from your device, including information about your web browser, IP address, time zone, and some of the cookies that are installed on your device. Additionally, as you browse the Service, we collect information about the individual web pages or products th...
Location data. Data about your device's location, which can be either precise or imprecise. For example, we collect location data using Global Navigation Satellite System (GNSS) (e.g., GPS) and data about nearby cell towers and Wi-Fi hotspots. Location can also be inferred from a device's IP address...
Monitoring
Steam has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"In order to make a transaction on Steam (e.g. to purchase Subscriptions for Content and Services or to fund your Steam Wallet), you may need to provide payment data to Valve to enable the transaction. If you pay by credit card, you need to provide typical credit card information (name, address, credit card number, expiration date and security code) to Valve, which Valve will process and transmit to the payment service provider of your choice to enable the transaction and perform anti-fraud checks. Likewise, Valve will receive data from your payment service provider for the same reasons.— Excerpt from Steam's Steam Privacy Policy
REGULATORY FRAMEWORK: Payment card data processing engages PCI DSS (Payment Card Industry Data Security Standard) compliance obligations. In the EU, this also engages GDPR Art. 6(1)(b) (contractual necessity) and Art. 32 (security of processing). Under CCPA §1798.140, financial information constitutes 'personal information.' The GLBA (15 U.S.C. §6801) may apply to the extent Valve is considered a financial institution for payment data purposes, though this is unlikely given its gaming platform status. FTC Act Section 5 applies to data security failures.
Full compliance analysis
Regulatory citations, enforcement risk, and due diligence action items.
Free: track 1 platform + weekly digest. Monitor: 25 platforms + same-day alerts. No credit card required.
Netflix updated its Privacy Statement on April 18, 2026, disclosing voice recording collection and expanded household ad profiling for the first time.
Google's Privacy Policy covers Search, Gmail, YouTube, Maps, and every site running Google Analytics. Here is what it actually authorizes.
Compliance Governance Intelligence
Need to monitor specific governance provisions?
Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.
Built from archived source documents, structured governance mappings, and historical version tracking.
The clause defines the data collection and processing mechanism necessary for Steam to execute financial transactions on its platform. It establishes Valve's role as a processor of payment information and clarifies the data flow between Valve, users, and third-party payment service providers.
Your complete credit card information, including the CVV security code, is processed by Valve before being passed to payment processors, creating an additional point of exposure for sensitive financial data compared to a direct payment processor relationship.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Steam.