Beta: full access needs a Steam account.Sign in with Steam
Veriloot

Privacy policy

What Veriloot keeps, why, for how long, and how to exercise your rights.

Last updated:

Who is responsible for your data

The data controller is Veriloot, entreprise individuelle, reachable at veriloot@gmail.com. Data is hosted by OVH SAS in France.

Other providers process data to run the service: a content delivery network carries connections to the site through to our server, a payment provider hosts the subscription payment form, a delivery service sends our emails, and a Steam data provider reads a signed-in account’s inventory, at that account’s request, from its SteamID. Scheduled tasks (price collection, alerts, data purges) run from a server rented in Germany: it connects to the database hosted in France and keeps a log of its runs. Analytics are described further down. These providers are named here by role; we give you the name of any one of them on request, at the contact address above.

Survey and optional contact details

Answers, comments, language and submission date help guide development. No account is required. You may voluntarily add an email or Steam profile and tick a separate, unchecked consent box. Contact details are linked to your answers and used only to discuss feedback and Veriloot testing. No newsletter or automatic message is triggered. A notification may be emailed to the controller listed above through our email delivery service, within sending limits. It contains the preset answers, language and date, without contact details or free-text comments. Older survey copies may still contain that information; the database cleanup does not erase them. Contact the controller to request their erasure.

Contact details and consent date are removed from the database after 90 days by the daily cleanup. To withdraw consent or request earlier erasure, contact the controller listed above.

The “Your beta tester feedback” form, by contrast, is tied to your Steam account: your answers, their language and date are stored per round, along with dismissals of the banner that announces it. They are included in your data export and erased with the account. It never asks for an email address: email sign-up remains the one described below.

News and skin deals by email

If the form link includes a declared campaign, its name is attached to the first accepted request and its first confirmation to measure subscriptions by campaign and language. No cross-device journey, Steam account or browsing history is matched to the address. Missing or unrecognized campaigns remain unknown. These records follow the same retention periods and access or erasure process as the subscription.

Signing up is optional and separate from the survey or Steam account. You independently select Veriloot news and skin deals using unchecked boxes. We record your email, language, choices, and the date and version of your consent. Marketing emails are eligible only after you explicitly confirm your email address. Emails, including the one asking you to confirm your address, are sent through our email delivery service, which processes the recipient address and the message content to deliver them.

Each email will include a link to stop both categories for free, without signing in or changing your SaaS subscription. Contact details provided for survey feedback are not used for these messages.

The daily cleanup deletes unconfirmed requests after 30 days, subscriptions after 365 days without renewed confirmation, and unsubscribed addresses and their records after 90 days. Unsubscribing immediately stops eligibility for emails. To access, correct or erase these records sooner, contact the controller above; email ownership must be verified because the address is not linked to your Steam account.

The contact form

The form on the Contact page sends the subject you pick, your reply email address, the username or SteamID if you provide one, your message, the page language and the time it was sent. If you are signed in, the server adds the account’s SteamID64 and Steam display name. This data is used only to answer your request. Legal basis: our legitimate interest in replying to people who write to us (art. 6(1)(f)) or, where the request concerns the subscription, steps taken at your request before entering into a contract (art. 6(1)(b)).

The message is not stored in Veriloot’s database. It is emailed to the controller’s address listed above through our email delivery service, which processes the reply address and the message content to deliver it. It then stays in that inbox, where no automatic deletion is scheduled; to have a message erased, contact the controller. To limit abuse, the server counts submissions per IP address, in memory only: the address is neither stored in the database nor attached to the message.

Price alerts by email

If you turn on email alerts on the Alerts page, we store the address you enter, encrypted, together with the channel status (to confirm, confirmed or turned off), the dates of the confirmation request and of its sending, of confirmation, of deactivation and of the last send, and the result of each alert email. The address is used only to send you the alerts you created. No alert is sent before you confirm the address through the link you receive. Legal basis: performance of the contract, for the feature you requested (art. 6(1)(b)).

Emails, including the one asking you to confirm your address, are sent through our email delivery service, which processes the recipient address and the message content to deliver them. Every alert email includes a link that turns this channel off without signing in; the address is then erased. The number of emails sent is counted to respect sending limits, with no address or account attached.

An address that is never confirmed is erased by the daily cleanup after 7 days. A confirmed address is kept until you remove it, turn the channel off or delete your account; deleting your account erases it immediately. The encrypted address is not included in your data export; it remains shown on the Alerts page when you are signed in.

Price alerts as notifications

If you turn on notifications on the Alerts page, your browser sends us a subscription specific to that device: the address of its vendor’s push service (Google for Chrome and Android, Mozilla for Firefox, Apple for Safari, Microsoft for Edge on Windows) and two keys used to encrypt messages for that device. We store it encrypted, with the name of that service, the subscription date, the date of the last accepted send and the number of consecutive failures, along with the result of each alert notification. The subscription is used only to send you the alerts you created and, when you ask for it, a test notification. Legal basis: performance of the contract, for the feature you requested (art. 6(1)(b)).

Each notification is encrypted for your device, then handed to your browser vendor’s push service, which delivers it; it contains the item name, the alert sentence and a link to the item page. We ask the service to keep it for no more than one hour if your device is offline.

A subscription is kept until you turn it off on the Alerts page, withdraw permission in your browser or device settings (the service tells us at the next send and the subscription is then erased), or delete your account, which erases it immediately. It is also erased after ten consecutive failed sends. Your data export lists, for each device, the service, the dates and the send status; the encrypted subscription address and keys are not included.

What we hold, and why

DataWhyLegal basis
Steam ID (SteamID64), persona name, avatarTo sign you in and link your inventory to your account.Performance of a contract (GDPR art. 6(1)(b))
Sessions: IP address and browserTo keep you signed in, and to let you spot a sign-in you did not make.Legitimate interest — account security (art. 6(1)(f))
Optional marketplace connections: encrypted API keys, connection status and consent datesVerify the connection and import authorised data. Recurring sync requires a separate choice; signing out of Veriloot does not delete a saved key.Performance of the requested service; separate storage and recurring-sync choices
Daily web and mobile sign-in countsMeasure service usage without extra IP addresses or browsing history. Retained for 180 days.Legitimate interest — service improvement (art. 6(1)(f))
Free plan daily item-page limit, when the item-page limit is active: account ID and a keyed fingerprint of the IP address (/64 prefix for an IPv6 address), the names of the skins opened, and the SteamID64 of other players’ inventories comparedEnforce the Free plan’s daily limit on item pages. Without an account, the limit is counted against the IP address fingerprint; with an account, against the account, and each page opened is also recorded against the fingerprint of the address used, so that signing out does not reopen the limit. These per-address records are not linked to any account. Items from your own compared inventory and their stickers are recorded there too, without counting toward the limit, so their prices and charts stay readable. The IP address is never stored in clear. Retained for the current day and the previous one (2 days, Paris time), then deleted by the daily cleanup.Performance of a contract (art. 6(1)(b)); for the IP address fingerprint, with or without an account, legitimate interest — fair access to the service (art. 6(1)(f))
Cached Steam inventoryTo show your inventory value without querying Steam on every page.Legitimate interest, bounded by a very short retention (below)
Favourites, alerts, alert triggersThe tracking features you created yourself.Performance of a contract (art. 6(1)(b))
Your purchase and sale history, if you import itTo compute your cost basis. You provide it voluntarily.Performance of a contract (art. 6(1)(b))
A purchase price and date you enter yourselfTo show your gain on an item whose purchase was never imported. You alone can see them; they feed no comparison and no ranking. Kept until you remove them, and erased with the account.Performance of a contract (art. 6(1)(b))
Subscription: payment source (site, App Store or Play Store), subscription reference, status, current periodTo know whether your subscription is running, and to restore access after a failed payment is settled.Performance of a contract (art. 6(1)(b))

Payment itself never passes through our servers: we never receive your card number. The payment provider collects it on its own pages; we only receive the information needed to manage the subscription, such as its plan, status, periods and reference.

For how long

The periods below are the ones the code actually applies: they are read from the same constant as the daily automatic purge, not copied here by hand. The last row is the exception: its period is set by law.

DataPeriodWhy this period
Cached Steam inventory24 hoursAfter that, the cache is no longer served, not even as a fallback when Steam is down: keeping it would serve no purpose. Viewing the inventory rebuilds it.
Expired or revoked sessions30 daysLong enough for someone to notice a sign-in they did not make and report it. Beyond that, the row no longer authenticates nor helps investigate.
Steam sign-in replay tokens10 minutesTwice Steam’s acceptance window. Beyond that they protect nothing.
Deleted account30 daysYour profile is anonymised and sessions revoked immediately. The Steam identifier, revocation records and billing references remain temporarily; an unresolved cancellation case may remain beyond this period, as explained below.
Accounting records and supporting documents for the subscription10 years from the end of the financial yearRequired by Article L123-22 of the French Commercial Code. Invoices themselves are issued and kept by the payment provider.

Your rights, and how to use them right now

You have rights of access, rectification, erasure, objection, restriction and portability (GDPR arts. 15–22). Two of them work straight from your account, with no delay:

  • Export your account data — the Settings screen downloads a JSON file with your profile, sessions, favourites, alerts and notifications, imported purchases, the purchase prices you entered yourself, subscriptions, inventory ranking records, marketplace connection metadata and the devices subscribed to notifications. API keys, encrypted keys, secret webhook URLs, notification subscription addresses and keys, and token digests are excluded. Email subscriptions independent of your account follow the process described in the newsletter section.
  • Delete your account — from the same screen. Deletion is immediate and irreversible: favourites, alerts, triggers, imported purchases, entered purchase prices and cached inventory, marketplace credentials, beta feedback, beta tester answers and account notifications are erased. Your profile and sessions are anonymised and every session is revoked. Account and subscription references remain until cleanup; if cancellation failed, the case needed to stop billing is kept until resolved, then for 30 days. Deleting a Steam account does not automatically unsubscribe an independent email address.

For other rights, or to complain: veriloot@gmail.com. You may also lodge a complaint with the French data protection authority (cnil.fr).

Public inventories viewed without an account

Viewing a public inventory by its Steam identifier requires no account here. It caches the inventory viewed, including that of someone who is not registered. That is precisely why this cache is kept for 24 hours and no longer. Friends’ inventory rankings also use value snapshots from public inventories viewed or synced for the ranking. These contain a SteamID64, amounts and a date, and are kept for 30 days. You can request to opt out through the controller listed above; once applied, the opt-out deletes the snapshots and prevents their recreation while it remains active.

Cookies

The site sets a session cookie (to keep you signed in), a state cookie during Steam sign-in (to prevent sign-in hijacking) and a language cookie. When you select a currency, the cst-devise cookie stores only EUR or USD for one year. If you are signed in, that choice is also saved to your account so another device can pick it up; it is included in your data export and erased with the account. If you haven’t chosen, the display currency depends on the country you connect from: Cloudflare derives it from your IP address and passes it with the request. It is only used to pick between euros and dollars; Veriloot neither stores nor logs it. These cookies are strictly necessary for the service you asked for. The traffic analytics described below set no cookie; the usage analytics, when enabled, may set some, as described below.

The videos on the home page are hosted on YouTube, a Google service. Until you click the play button, the page contacts neither YouTube nor Google: the preview is an image served by veriloot.gg, and no YouTube cookie is set. The list of channel videos and their previews are fetched by Veriloot’s server from the channel’s public YouTube feed, without any data about you. When you click, the player loads from youtube-nocookie.com, YouTube’s privacy-enhanced mode. YouTube then receives your IP address, your browser information and the site’s address without the page path, and processes playback data under its own rules. The “Watch on YouTube” link opens the video on youtube.com in a new tab.

Some links to a marketplace are affiliate links and are labelled “affiliate link”. They add a code to the address that identifies Veriloot, not you: the partner code configured for that marketplace. When you follow such a link, the marketplace knows you came from Veriloot and may attribute your purchases to that code; it processes that data under its own privacy policy. Partner reports are used to calculate commissions under the terms of each programme. Veriloot sends it no data about you: the code is the same for every visitor.

Analytics

When analytics are enabled on the site, a traffic tool hosted on our own instance counts visits to public pages and selected signed-in service pages. Page names are grouped: no SteamID, email, API key, search term or inventory content is sent. That tool also receives the site you came from when it is outside veriloot.gg, the campaign parameters of the link you followed (utm_source, utm_medium, utm_campaign, utm_content, utm_term and ref), how long you stayed on the page and how far you scrolled. No other URL parameter is sent. Administration, authentication and payment pages are excluded. No traffic-analytics cookie is added. The instance processes the IP address and browser information to produce these statistics. No permission is requested for this tool: the legal basis is our legitimate interest in measuring site traffic.

When usage analytics are enabled on the site, the tool records how pages are used: clicks, scrolling, mouse movement, selections, window size, technical errors and the structure of the page displayed. This data produces session replays and heatmaps, so we can find what gets in the way of reading or navigating. It loads without asking for your permission first: no banner or choice is shown. The legal basis we rely on is our legitimate interest in improving how the site reads and navigates.

It only loads on the home page, pricing, the platform directory and the legal pages, on an address without query parameters or fragment, and never while an account session is open or once an input field has been used on the page. The site asks it to mask page content before sending it: text, link and image addresses, and field contents. As soon as you leave these pages in the same tab, the browser blocks any further transmission to it until an allowed page is fully loaded again. The site sends it no consent signal, so it applies its default behavior, which we have not verified.

This tool comes from a provider established outside the European Union. Its European contract is with that provider’s Irish subsidiary. The provider states that it complies with the GDPR as a data controller, that it has access to this data, that the data is stored in its cloud service, and that it may transfer the data to the United States under standard contractual clauses. It also uses the IP address to determine the visitor’s location. We give you its name and privacy statement on request, at the contact address above.

According to that provider, replay data is kept for 30 days; click and heatmap data, and labeled or favorited sessions, for 9 months. It also states that it keeps a randomly selected sample of recordings for up to 9 months.

This tool may set two cookies on veriloot.gg: _clck, which keeps a pseudonymous visitor identifier for one year, and _clsk, which links page views into one session for one day. It may also store a tab identifier, _cltk, in the browser’s session storage. Its provider also documents cookies set on its own domains (CLID, MUID, ANONCHK, MR and SM). We have not verified which of these cookies and identifiers are actually set when the site sends no consent signal.

That provider states that deleting the data of one specific visitor requires deleting the whole project.

Veriloot’s TikTok account statistics

Within its private administration area, Veriloot can authorize access to its own TikTok account to monitor its posts. Visitors are not offered this connection. The data used consists of the account identifier, display name and username, follower and public video counts, and identifiers and view, like, comment and share counts for tracked videos. Observations are timestamped; no private messages or follower lists are collected.

Access and refresh tokens are stored encrypted on the server while the connection remains active. Statistical observations older than 30 days are removed by automatic cleanup jobs. This information is available only to administrators and is used to measure the performance of Veriloot’s posts; this integration does not publish videos or send messages.

The administration’s “Disconnect and delete API statistics” button deletes the tokens and TikTok observations stored by this integration and requests access revocation from TikTok. Access can also be removed through TikTok’s authorized application settings. For requests about this data, contact veriloot@gmail.com. TikTok processes data on its platform under its own privacy policy.

The Discord server

When this measurement is enabled, the bot on Veriloot’s Discord server records, for each person who joins the server: a fingerprint of their Discord ID, computed with a secret key; the channel tied to the invite they used (for example the invite posted on a social network or the one on the site, or “unknown” when the bot cannot tell); the day they joined, without the time; and, if the bot served them a /price or /drops command, the fact that it did and the time elapsed since they joined, in whole hours. For this measurement, the ID itself, the username, messages and command contents are not recorded. None of this is linked to a Veriloot account.

It is used only to learn where server members come from and whether they use the bot after joining; we only look at totals per channel, and a total based on fewer than five joins is not shown. Legal basis: our legitimate interest in measuring how well our communication channels work (art. 6(1)(f)). Each row is deleted automatically no later than 90 days after the join date. Discord also processes your data under its own rules.

To object to this measurement, email veriloot@gmail.com with your Discord ID. We use it only to recompute the fingerprint: your row is deleted, and the fingerprint is added to an exclusion list so the bot never records anything about you again, even if you leave and rejoin the server. That list holds only the fingerprint, with no channel or date, and is kept for as long as the measurement exists. Your email stays in the controller’s inbox, where no automatic deletion is scheduled; you can ask for it to be deleted at the same address.

The server’s daily “Price call” is a game with no prize: it gives points and a monthly ranking, and there is nothing to win. If you answer with the /guess command, the bot records your Discord ID, the price you entered, the time of your answer and, once the result is known, the points you scored. Your username and messages are not recorded. This data is used only to compute points and the ranking: the result posted each day in the channel shows the five best answers (a mention of the Discord account, the price entered, the points), and the /leaderboard command, whose reply only you can see, shows the month’s top ten. These mentions trigger no notification. Answers are not linked to any Veriloot account. Legal basis: our legitimate interest in running the game you chose to join (art. 6(1)(f)). Challenges and answers older than 400 days are deleted by the bot when it posts the daily challenge.

To have your answers deleted sooner, email veriloot@gmail.com with your Discord ID: all your answers are removed from the bot’s database, and you leave the ranking. Result messages already posted in the channel are not changed by this deletion; you can ask for them to be removed at the same address.

The Veriloot extension (Chrome and Firefox)

The Veriloot extension, for Chrome and Firefox, is optional. On a skin listing page, it shows the marketplace where the same item sells for less. It only runs on sixteen sites: buff.market, market.csgo.com, white.market, waxpeer.com, csfloat.com, cs.money, lis-skins.com, www.haloskins.com, skinbaron.de, tradeit.gg, skinport.com, 49skins.com, mannco.store, buff.163.com, skinswap.com and dmarket.com. On those pages, it only reads what names the item on screen: the page address, the tab or item title, the page’s structured data, the Steam Market link, the alternative text of the item image, the wear or variant shown and, on skinport.com, csfloat.com and dmarket.com, the item name in the responses the page receives from that site’s API. It doesn’t read your cookies, sign-in credentials, browsing history or other tabs. It only asks the browser for access to those sixteen sites and to Veriloot’s API, and for temporary storage (the “storage” permission) for the list of paused marketplaces described below.

For each listing you open, the extension sends two things to veriloot.gg, over HTTPS: the item name and the page’s marketplace. It sends no cookie, no account identifier and not the page address. Like any request on the Internet, it carries your IP address and the extension’s identifier. On Firefox, that identifier is drawn at random at install time and belongs to your copy of the extension; the server checks its format without recording it. The server replies with the lowest purchase price observed for the item, its marketplace and the price observed on the page’s marketplace. The API log records the method, the path, the response status, its duration and a technical request ID: neither your IP address nor the item name. To limit abuse, the server counts requests per IP address over one minute and over twenty-four hours, in memory only: the address is never written to the database or to a log, and that memory is cleared whenever the service restarts. At most once an hour, the extension also asks veriloot.gg for the list of marketplaces where Veriloot has paused its card; that request carries no information: no item name, no page address, no identifier. The request goes through the same hosting infrastructure as the site, described above. Legal basis: our legitimate interest in providing the comparison you chose to install (art. 6(1)(f)).

Nothing is written to your disk: the response is kept for one minute in the extension’s memory, so the same item isn’t requested twice, then dropped. The list of paused marketplaces is kept for one hour (five minutes if veriloot.gg didn’t answer) in the browser’s session memory (chrome.storage.session), cleared when the browser closes. Uninstalling the extension removes everything.

The button to the cheapest marketplace may be an affiliate link: it is then labeled “affiliate link” in the card and works as described in the Cookies section. Affiliation doesn’t change the order: the lowest price stays on top. The extension sets, reads and writes no cookie, changes no link on the page you’re viewing and doesn’t tell Veriloot that you follow a link. It contains no analytics. No data is sold or passed on to third parties. The use of information received complies with the Chrome Web Store User Data Policy, including the Limited Use requirements. On Firefox, the extension declares at install time, in Mozilla’s categories, the data it transmits: website content (the item name) and browsing activity (the page’s marketplace). For any question or request, email veriloot@gmail.com.