Skip to main contentSkip to footer
All companies
Privacy PolicyAnalyzed 2026-08-30

Steam (Valve)

80score
Risk level
Low Risk

Weighted across nine legal categories. Lower is worse.

Executive summary

This document is a comprehensive Privacy Policy that excels in data protection, offering robust GDPR/CCPA compliance, explicit user rights, and clear retention/deletion protocols. However, it defers broader contractual terms—including intellectual property, liability limits, payment mechanics, and general dispute resolution—to the separate Steam Subscriber Agreement, leaving several consumer-protection categories unaddressed within this text.

Category breakdown

6 of the nine categories are not addressed by this document, so they are left out rather than scored.

Acceptance of Terms & Scope

Contract formation and service boundaries

72

The policy clearly defines its scope as data processing and explicitly references the Steam Subscriber Agreement for broader contractual definitions, avoiding vague overreach. Acceptance is implied rather than explicitly clickwrap here, which slightly reduces transparency but remains standard for privacy notices.

Key findings

  • Scope is narrowly tailored to data collection and processing
  • References SSA for undefined capitalized terms
  • No explicit clickwrap or age verification mechanism detailed in this text

Evidence from the document

Other capitalized terms in this Privacy Policy shall have the meanings defined in the Steam Subscriber Agreement ("SSA").

Recommendations

  • Add a brief conspicuous statement confirming that account creation constitutes acceptance of this Privacy Policy
  • Include a direct link to the SSA during account setup for full transparency

User Accounts

Registration, suspension, and termination

64

Account deletion includes a helpful 30-day grace period and clear anonymization rules, but the document lacks specifics on suspension, violation triggers, cure periods, or appeal processes. Data export before closure is partially addressed via portability rights but not explicitly guaranteed prior to termination.

Key findings

  • 30-day restoration grace period after deletion request
  • Matchmaking data permanently anonymized rather than deleted
  • No mention of suspension, appeals, or pre-termination data export guarantees

Evidence from the document

We allow you to restore your Steam User Account during a grace period of 30 (thirty) days from the moment you request deletion of your Steam User Account.

Recommendations

  • Explicitly guarantee data export/download capabilities before account closure
  • Add a section detailing suspension criteria, notice periods, and human review for appeals

Data Privacy

Data collection, usage, and protection

91

Exceptionally strong privacy framework with explicit CCPA/GDPR compliance, granular opt-outs, clear purpose limitation, and no data selling. Users retain substantial control via a dedicated dashboard, and cross-border transfers are safeguarded with SCCs and DPF certification.

Key findings

  • Explicit 'does not sell Personal Data' commitment
  • Comprehensive GDPR/CCPA rights including access, rectification, erasure, restriction, and portability
  • Standard Contractual Clauses and DPF certification for international transfers
  • Clear marketing opt-out mechanisms

Evidence from the document

Valve does not sell Personal Data.
You can opt out or withdraw your consent to receive marketing emails at any time by either withdrawing the consent on the same page where you previously provided it or clicking the "unsubscribe" link provided in every marketing email.

Recommendations

  • Consider reducing identity verification friction for routine data requests
  • Publish a clear data retention schedule table for greater transparency
Read the source documentSee the full interactive report

Ex-TerCo provides automated analysis of legal documents for informational purposes. This is not legal advice. Terms can change at any time.