When you buy something on Steam using a credit card, your card details are collected by Valve and transmitted to a payment processor, and Valve also receives payment data back from that processor for anti-fraud purposes.
This analysis describes what Steam's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
Full credit card details are processed by Valve before transmission to payment service providers, meaning Valve is an intermediary in the payment data flow rather than relying solely on direct processor collection.
Provision renamed from "Transaction and Payment Data Collection" to "Transaction and Payment Data Processing" with no severity change.
View full change record →Valve processes your full credit card number, expiration date, and security code as part of payment transactions before transmitting that data to payment service providers. This data processing arrangement means Valve handles raw payment credentials, which creates data security relevance for users.
How other platforms handle this
to request that your data be transferred to a third party (data portability)
Your organization may allow you to access and export your data in order to back it up or transfer it to a service outside of Google.
Further, you may take legal actions in relation to any potential breach of your rights regarding the processing of your Personal Information, as well as to lodge complaints before the competent data prot...
"In order to make a transaction on Steam (e.g. to purchase Subscriptions for Content and Services or to fund your Steam Wallet), you may need to provide payment data to Valve to enable the transaction. If you pay by credit card, you need to provide typical credit card information (name, address, credit card number, expiration date and security code) to Valve, which Valve will process and transmit to the payment service provider of your choice to enable the transaction and perform anti-fraud checks. Likewise, Valve will receive data from your payment service provider for the same reasons.Excerpt from Steam's Privacy Policy
(1) REGULATORY LANDSCAPE: Processing of credit card data by Valve as an intermediary engages PCI DSS (Payment Card Industry Data Security Standard) compliance obligations, which are enforced by card networks rather than a government agency.
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
Ad personalization controls removed. Contact scanning added. Advertiser data partnerships quietly dropped. A timeline of every change.
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
Full credit card details are processed by Valve before transmission to payment service providers, meaning Valve is an intermediary in the payment data flow rather than relying solely on direct processor collection.
Valve processes your full credit card number, expiration date, and security code as part of payment transactions before transmitting that data to payment service providers. This data processing arrangement means Valve handles raw payment credentials, which creates data security relevance for users.
ConductAtlas has identified this type of provision across 289 platforms. See the full comparison.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Steam.