← Back to home
Privacy Policy
Last updated: 2026-08-06
This Privacy Policy explains how CSOutpost ("we", "the Service") collects, uses, and protects your information.
1. Information we collect
- Account data: email (for email-password registration), Steam ID, Steam username, Steam avatar (Steam OpenID).
- Trade link: the public Steam trade URL you provide. Used to read your CS2 inventory and generate post text.
- Inventory snapshot: we cache a daily snapshot of your tradable CS2 items (name, price, rarity, icon URL) — read from public Steam endpoints.
- Authentication: bcrypt-hashed passwords (never plaintext); TOTP secrets and recovery codes encrypted at rest with AES-256-CBC.
- Login history: IP address, user-agent, login method, timestamp — for security audit only, visible to you in dashboard.
- Subscription / payment data: plan tier, billing email, payment provider transaction IDs (NOWPayments). We do NOT store card or wallet credentials.
- Service logs: post results (success/failure timestamps and target groups) for the bot operations you authorized.
2. How we use your information
- To operate the auto-posting service you subscribed to.
- To generate post text from your inventory and your trade link.
- To authenticate you and detect compromised sessions.
- To process subscription payments and provide receipts.
- To communicate operational notices (security alerts, plan changes, billing).
3. Data we do NOT collect or sell
- We do NOT sell or rent your data to third parties.
- We do NOT use your data for advertising or profiling outside the Service.
- We do NOT store your Steam password — login is handled by Valve via OpenID.
- We do NOT have access to private items, friends list, or chat history.
4. Third parties
- Valve / Steam — OpenID login + public inventory.
- skin.broker — item price lookup (only item names sent, no user data).
- NOWPayments — crypto payment processing (subject to their policy).
- Cloudflare — CDN + DDoS protection (request metadata).
- Mailgun / SMTP provider — outbound transactional email (verification, password reset).
- Hosting: Hetzner Cloud (EU region).
5. Browser extension (CSOutpost Trade Sender)
The optional CSOutpost Trade Sender Chrome extension exists for one purpose: when you sell an item on CSOutpost Market, it sends the Steam trade offer to the buyer from your own logged-in Steam session, so you do not have to build the offer by hand.
What it accesses, and only while you click "Send via Extension":
- Your Steam session identifiers (
g_steamID, g_sessionID) read from the Steam page in your own browser. Used to send the offer as you, and to verify you are logged into the Steam account that owns the sale. Never transmitted to CSOutpost or anyone else.
- Your CS2 inventory listing from Steam, read once to confirm the sold item is still in your inventory before sending. Not stored, not transmitted.
- The order details (buyer trade link, item asset ID) fetched from CSOutpost for the sale you are fulfilling.
- The resulting trade offer ID, sent back to CSOutpost so your sale can be marked as dispatched and your funds released when the buyer accepts.
What it never does:
- It does NOT read your browsing history, bookmarks, or any tab other than the Steam trade page it opens itself.
- It does NOT run in the background, on a schedule, or without your click. There is no automatic or unattended trading.
- It does NOT see or store your Steam password. Steam Guard confirmation still happens on your own phone.
- It does NOT send any item without first verifying the Steam account and the item — if either check fails, nothing is sent.
- It does NOT collect analytics, and no extension data is sold or transferred to third parties.
The extension requests access to steamcommunity.com (to send the offer) and csoutpost.com (to read the order and report the result). It requests no other host access. You can remove it at any time from chrome://extensions; removal does not affect your CSOutpost account or completed sales.
6. Cookies
We use a single first-party session cookie (csoutpost.sid) to keep you logged in. HTTP-only, Secure, SameSite=Lax. No advertising or tracking cookies.
7. Data retention
- Account data: kept while account is active. Deletion on request removes it within 30 days.
- Login history: 90 days, then automatic purge.
- Post logs: 12 months for the operational dashboard, then aggregated.
- Backups: encrypted daily, retained 7 days, then rotated.
8. Your rights
- Access and download your data — contact [email protected].
- Delete your account — contact us; complete erasure within 30 days.
- Disable 2FA, change trade link, change min-price filter — self-service in dashboard.
- EU residents: GDPR rights apply (access, rectification, erasure, portability, objection).
9. Security
HTTPS-only (Cloudflare Origin Cert). Passwords bcrypt + cost 12. TOTP secrets and bot credentials encrypted with AES-256-CBC. Bcrypt-hashed recovery codes. Daily Postgres backups encrypted to remote storage. Hetzner cloud isolation.
10. Changes to this policy
Material changes are emailed to active subscribers and noted on the page header. Last updated date above.
11. Contact
Questions: [email protected]
Terms of Service · Home