Steam (Valve)
Weighted across nine legal categories. Lower is worse.
Executive summary
This document is a comprehensive Privacy Policy that excels in data protection, offering robust GDPR/CCPA compliance, explicit user rights, and clear retention/deletion protocols. However, it defers broader contractual terms—including intellectual property, liability limits, payment mechanics, and general dispute resolution—to the separate Steam Subscriber Agreement, leaving several consumer-protection categories unaddressed within this text.
Category breakdown
6 of the nine categories are not addressed by this document, so they are left out rather than scored.
Acceptance of Terms & Scope
Contract formation and service boundaries
The policy clearly defines its scope as data processing and explicitly references the Steam Subscriber Agreement for broader contractual definitions, avoiding vague overreach. Acceptance is implied rather than explicitly clickwrap here, which slightly reduces transparency but remains standard for privacy notices.
Key findings
- Scope is narrowly tailored to data collection and processing
- References SSA for undefined capitalized terms
- No explicit clickwrap or age verification mechanism detailed in this text
Evidence from the document
Other capitalized terms in this Privacy Policy shall have the meanings defined in the Steam Subscriber Agreement ("SSA").
Recommendations
- Add a brief conspicuous statement confirming that account creation constitutes acceptance of this Privacy Policy
- Include a direct link to the SSA during account setup for full transparency
User Accounts
Registration, suspension, and termination
Account deletion includes a helpful 30-day grace period and clear anonymization rules, but the document lacks specifics on suspension, violation triggers, cure periods, or appeal processes. Data export before closure is partially addressed via portability rights but not explicitly guaranteed prior to termination.
Key findings
- 30-day restoration grace period after deletion request
- Matchmaking data permanently anonymized rather than deleted
- No mention of suspension, appeals, or pre-termination data export guarantees
Evidence from the document
We allow you to restore your Steam User Account during a grace period of 30 (thirty) days from the moment you request deletion of your Steam User Account.
Recommendations
- Explicitly guarantee data export/download capabilities before account closure
- Add a section detailing suspension criteria, notice periods, and human review for appeals
Data Privacy
Data collection, usage, and protection
Exceptionally strong privacy framework with explicit CCPA/GDPR compliance, granular opt-outs, clear purpose limitation, and no data selling. Users retain substantial control via a dedicated dashboard, and cross-border transfers are safeguarded with SCCs and DPF certification.
Key findings
- Explicit 'does not sell Personal Data' commitment
- Comprehensive GDPR/CCPA rights including access, rectification, erasure, restriction, and portability
- Standard Contractual Clauses and DPF certification for international transfers
- Clear marketing opt-out mechanisms
Evidence from the document
Valve does not sell Personal Data.
You can opt out or withdraw your consent to receive marketing emails at any time by either withdrawing the consent on the same page where you previously provided it or clicking the "unsubscribe" link provided in every marketing email.
Recommendations
- Consider reducing identity verification friction for routine data requests
- Publish a clear data retention schedule table for greater transparency
Ex-TerCo provides automated analysis of legal documents for informational purposes. This is not legal advice. Terms can change at any time.