Privacy
Last updated: 28 September 2026
Short version: we collect what's needed to run your bot and bill you, we keep the sensitive parts encrypted, we don't sell anything to anyone, and we delete your credentials when you leave.
What we collect
- Contact details — the email, Discord handle or Steam profile you sign up with.
- Bot account credentials — the login and mobile-authenticator secret for the Steam account your bot runs on, plus your backpack.tf API key.
- Trading data — your bot's inventory, listings, prices, offers and trade history. This is what the dashboard is built out of.
- Billing records — what you paid and when. Card details are handled by our payment provider; we never see or store your card number.
- Server and site logs — IP address, browser and timestamps, kept briefly for security and debugging.
Why we have it
Credentials and trading data exist for one reason: to operate the bot you asked us to operate and to show you what it did. Contact details are for support and service notices. Billing records we're required to keep. Logs are for keeping the service secure and working.
In GDPR terms, we process this to perform our contract with you, to meet legal obligations (accounting), and — for security logs — on our legitimate interest in keeping the service safe.
How it's kept
- Credentials and authenticator secrets are encrypted at rest and only decrypted by the process that logs your bot in.
- Each rental is isolated: separate process, separate storage, separate credentials.
- Access is limited to the people who operate the service, and only when something needs fixing.
- Servers are in the EU.
Who else sees it
Only the services needed to make the bot work: Steam (the bot logs in and trades), backpack.tf (listings and pricing), our hosting provider, and our payment provider. We don't sell personal data, we don't share it for advertising, and we don't publish your trading figures. We'll only hand anything to authorities if the law actually requires it.
How long we keep it
- Credentials — deleted when your rental ends. You should change the password and re-key your authenticator afterwards anyway; it's your account and that's good hygiene.
- Trading history — kept for 90 days after the rental ends so you can export it, then deleted. Ask sooner and we'll delete sooner.
- Billing records — kept as long as accounting law requires (currently seven years in Sweden).
- Logs — 30 days.
Your rights
You can ask for a copy of what we hold, ask us to correct it, ask us to delete it, or object to how we use it. Ask on our Discord and we'll respond within 30 days. If you think we've handled your data badly you can complain to your national data protection authority — in Sweden that's IMY.
Cookies
This marketing site sets no cookies and stores nothing in your browser. The dashboard uses a session cookie to keep you logged in — that's it.
Children
The service isn't intended for under-16s, and we don't knowingly collect their data. If you're under 16, ask a parent before signing up for anything that costs money.
Changes and contact
If this policy changes in a way that matters, we'll tell you before it takes effect. Questions, requests or complaints: ask on our Discord.