Privacy Policy
Last updated: 30 August 2026
This policy explains what personal data CSAlpha collects, why, and what rights you have. The data controller is the individual sole trader operating CSAlpha, contactable at [email protected]. We process personal data under the UK GDPR and the Data Protection Act 2018.
What we collect
When you sign in with Steam
Steam's OpenID tells us your SteamID, display name and avatar URL. That is all we receive -- we never see your Steam password, email address, or inventory credentials.
When you subscribe
Stripe processes your payment and returns a subscription identifier and status, which we store to know which plan you are on. We never receive or store your card number. Stripe is an independent controller for payment data; see the Stripe Privacy Policy.
When you use the site
We store what you create: saved trade-ups, journal entries, alert preferences, and API keys (stored only as a one-way hash -- we cannot recover the key itself). We keep a session record so you stay signed in, and we log your IP address transiently for rate limiting and abuse prevention.
If you link Discord
Linking is optional. We receive your Discord user ID to verify server membership and to deliver alerts you have asked for. We do not read your messages.
Analytics
We use PostHog to understand which pages are used. It runs cookieless by default -- no cookies and no persistent identifier are set unless you consent -- and we do not use it to build advertising profiles. We do not sell personal data, and we do not share it with advertisers.
Why we process it, and on what basis
- To provide the Service (accounts, saved data, API access) -- performance of our contract with you.
- To take payment -- performance of contract, and our legal obligation to keep tax records.
- To keep the Service secure (rate limiting, abuse prevention, fraud checks) -- our legitimate interest in a working, un-abused service.
- To measure usage -- our legitimate interest in improving the product, using data that does not identify you.
How long we keep it
Account data is kept while your account exists. Delete your account and we erase your personal data promptly, except records we must keep by law (for example, payment and tax records, typically six years). Transient security logs are kept for a short period and then discarded.
Who we share it with
Only the processors needed to run the Service: Stripe (payments), Cloudflare (security and delivery), PostHog (analytics), Discord (only if you link it), and our hosting provider. We never sell your data. We may disclose data where the law requires it.
Some processors operate outside the UK. Where they do, transfers are covered by UK adequacy regulations or standard contractual clauses.
Your rights
You have the right to access, correct, erase, restrict or object to processing, and to data portability. Two of these are automated and immediate -- from your account settings you can export all of your data in a machine-readable file, and delete your account and its personal data. For anything else, email [email protected].
If you think we have handled your data wrongly you may complain to the UK Information Commissioner's Office at ico.org.uk, though we would rather you told us first so we can fix it.
Children
The Service is not intended for anyone under 16, and we do not knowingly collect their data. If you believe a child has given us data, contact us and we will delete it.
Changes
We will update this policy as the Service changes, and the date above will change with it.