Privacy policy
What Veriloot keeps, why, for how long, and how to exercise your rights.
Last updated:
Who is responsible for your data
The data controller is Veriloot, entreprise individuelle, reachable at veriloot@gmail.com. Data is hosted by OVH SAS in France.
Other providers process data to run the service: a content delivery network carries connections to the site through to our server, a payment provider hosts the subscription payment form, a delivery service sends our emails, and a Steam data provider reads a signed-in account’s inventory, at that account’s request, from its SteamID. Scheduled tasks (price collection, alerts, data purges) run from a server rented in Germany: it connects to the database hosted in France and keeps a log of its runs. Analytics are described further down. These providers are named here by role; we give you the name of any one of them on request, at the contact address above.
Survey and optional contact details
Answers, comments, language and submission date help guide development. No account is required. You may voluntarily add an email or Steam profile and tick a separate, unchecked consent box. Contact details are linked to your answers and used only to discuss feedback and Veriloot testing. No newsletter or automatic message is triggered. A notification may be emailed to the controller listed above through our email delivery service, within sending limits. It contains the preset answers, language and date, without contact details or free-text comments. Older survey copies may still contain that information; the database cleanup does not erase them. Contact the controller to request their erasure.
Contact details and consent date are removed from the database after 90 days by the daily cleanup. To withdraw consent or request earlier erasure, contact the controller listed above.
The “Your beta tester feedback” form, by contrast, is tied to your Steam account: your answers, their language and date are stored per round, along with dismissals of the banner that announces it. They are included in your data export and erased with the account. It never asks for an email address: email sign-up remains the one described below.
The contact form
The form on the Contact page sends the subject you pick, your reply email address, the username or SteamID if you provide one, your message, the page language and the time it was sent. If you are signed in, the server adds the account’s SteamID64 and Steam display name. This data is used only to answer your request. Legal basis: our legitimate interest in replying to people who write to us (art. 6(1)(f)) or, where the request concerns the subscription, steps taken at your request before entering into a contract (art. 6(1)(b)).
The message is not stored in Veriloot’s database. It is emailed to the controller’s address listed above through our email delivery service, which processes the reply address and the message content to deliver it. It then stays in that inbox, where no automatic deletion is scheduled; to have a message erased, contact the controller. To limit abuse, the server counts submissions per IP address, in memory only: the address is neither stored in the database nor attached to the message.
Price alerts by email
If you turn on email alerts on the Alerts page, we store the address you enter, encrypted, together with the channel status (to confirm, confirmed or turned off), the dates of the confirmation request and of its sending, of confirmation, of deactivation and of the last send, and the result of each alert email. The address is used only to send you the alerts you created. No alert is sent before you confirm the address through the link you receive. Legal basis: performance of the contract, for the feature you requested (art. 6(1)(b)).
Emails, including the one asking you to confirm your address, are sent through our email delivery service, which processes the recipient address and the message content to deliver them. Every alert email includes a link that turns this channel off without signing in; the address is then erased. The number of emails sent is counted to respect sending limits, with no address or account attached.
An address that is never confirmed is erased by the daily cleanup after 7 days. A confirmed address is kept until you remove it, turn the channel off or delete your account; deleting your account erases it immediately. The encrypted address is not included in your data export; it remains shown on the Alerts page when you are signed in.
Price alerts as notifications
If you turn on notifications on the Alerts page, your browser sends us a subscription specific to that device: the address of its vendor’s push service (Google for Chrome and Android, Mozilla for Firefox, Apple for Safari, Microsoft for Edge on Windows) and two keys used to encrypt messages for that device. We store it encrypted, with the name of that service, the subscription date, the date of the last accepted send and the number of consecutive failures, along with the result of each alert notification. The subscription is used only to send you the alerts you created and, when you ask for it, a test notification. Legal basis: performance of the contract, for the feature you requested (art. 6(1)(b)).
Each notification is encrypted for your device, then handed to your browser vendor’s push service, which delivers it; it contains the item name, the alert sentence and a link to the item page. We ask the service to keep it for no more than one hour if your device is offline.
A subscription is kept until you turn it off on the Alerts page, withdraw permission in your browser or device settings (the service tells us at the next send and the subscription is then erased), or delete your account, which erases it immediately. It is also erased after ten consecutive failed sends. Your data export lists, for each device, the service, the dates and the send status; the encrypted subscription address and keys are not included.
What we hold, and why
| Data | Why | Legal basis |
|---|---|---|
| Steam ID (SteamID64), persona name, avatar | To sign you in and link your inventory to your account. | Performance of a contract (GDPR art. 6(1)(b)) |
| Sessions: IP address and browser | To keep you signed in, and to let you spot a sign-in you did not make. | Legitimate interest — account security (art. 6(1)(f)) |
| Optional marketplace connections: encrypted API keys, connection status and consent dates | Verify the connection and import authorised data. Recurring sync requires a separate choice; signing out of Veriloot does not delete a saved key. | Performance of the requested service; separate storage and recurring-sync choices |
| Daily web and mobile sign-in counts | Measure service usage without extra IP addresses or browsing history. Retained for 180 days. | Legitimate interest — service improvement (art. 6(1)(f)) |
| Free plan daily item-page limit, when the item-page limit is active: account ID and a keyed fingerprint of the IP address (/64 prefix for an IPv6 address), the names of the skins opened, and the SteamID64 of other players’ inventories compared | Enforce the Free plan’s daily limit on item pages. Without an account, the limit is counted against the IP address fingerprint; with an account, against the account, and each page opened is also recorded against the fingerprint of the address used, so that signing out does not reopen the limit. These per-address records are not linked to any account. Items from your own compared inventory and their stickers are recorded there too, without counting toward the limit, so their prices and charts stay readable. The IP address is never stored in clear. Retained for the current day and the previous one (2 days, Paris time), then deleted by the daily cleanup. | Performance of a contract (art. 6(1)(b)); for the IP address fingerprint, with or without an account, legitimate interest — fair access to the service (art. 6(1)(f)) |
| Cached Steam inventory | To show your inventory value without querying Steam on every page. | Legitimate interest, bounded by a very short retention (below) |
| Favourites, alerts, alert triggers | The tracking features you created yourself. | Performance of a contract (art. 6(1)(b)) |
| Your purchase and sale history, if you import it | To compute your cost basis. You provide it voluntarily. | Performance of a contract (art. 6(1)(b)) |
| A purchase price and date you enter yourself | To show your gain on an item whose purchase was never imported. You alone can see them; they feed no comparison and no ranking. Kept until you remove them, and erased with the account. | Performance of a contract (art. 6(1)(b)) |
| Subscription: payment source (site, App Store or Play Store), subscription reference, status, current period | To know whether your subscription is running, and to restore access after a failed payment is settled. | Performance of a contract (art. 6(1)(b)) |
Payment itself never passes through our servers: we never receive your card number. The payment provider collects it on its own pages; we only receive the information needed to manage the subscription, such as its plan, status, periods and reference.
For how long
The periods below are the ones the code actually applies: they are read from the same constant as the daily automatic purge, not copied here by hand. The last row is the exception: its period is set by law.
| Data | Period | Why this period |
|---|---|---|
| Cached Steam inventory | 24 hours | After that, the cache is no longer served, not even as a fallback when Steam is down: keeping it would serve no purpose. Viewing the inventory rebuilds it. |
| Expired or revoked sessions | 30 days | Long enough for someone to notice a sign-in they did not make and report it. Beyond that, the row no longer authenticates nor helps investigate. |
| Steam sign-in replay tokens | 10 minutes | Twice Steam’s acceptance window. Beyond that they protect nothing. |
| Deleted account | 30 days | Your profile is anonymised and sessions revoked immediately. The Steam identifier, revocation records and billing references remain temporarily; an unresolved cancellation case may remain beyond this period, as explained below. |
| Accounting records and supporting documents for the subscription | 10 years from the end of the financial year | Required by Article L123-22 of the French Commercial Code. Invoices themselves are issued and kept by the payment provider. |
Your rights, and how to use them right now
You have rights of access, rectification, erasure, objection, restriction and portability (GDPR arts. 15–22). Two of them work straight from your account, with no delay:
- Export your account data — the Settings screen downloads a JSON file with your profile, sessions, favourites, alerts and notifications, imported purchases, the purchase prices you entered yourself, subscriptions, inventory ranking records, marketplace connection metadata and the devices subscribed to notifications. API keys, encrypted keys, secret webhook URLs, notification subscription addresses and keys, and token digests are excluded. Email subscriptions independent of your account follow the process described in the newsletter section.
- Delete your account — from the same screen. Deletion is immediate and irreversible: favourites, alerts, triggers, imported purchases, entered purchase prices and cached inventory, marketplace credentials, beta feedback, beta tester answers and account notifications are erased. Your profile and sessions are anonymised and every session is revoked. Account and subscription references remain until cleanup; if cancellation failed, the case needed to stop billing is kept until resolved, then for 30 days. Deleting a Steam account does not automatically unsubscribe an independent email address.
For other rights, or to complain: veriloot@gmail.com. You may also lodge a complaint with the French data protection authority (cnil.fr).
Public inventories viewed without an account
Viewing a public inventory by its Steam identifier requires no account here. It caches the inventory viewed, including that of someone who is not registered. That is precisely why this cache is kept for 24 hours and no longer. Friends’ inventory rankings also use value snapshots from public inventories viewed or synced for the ranking. These contain a SteamID64, amounts and a date, and are kept for 30 days. You can request to opt out through the controller listed above; once applied, the opt-out deletes the snapshots and prevents their recreation while it remains active.
Analytics
When analytics are enabled on the site, a traffic tool hosted on our own instance counts visits to public pages and selected signed-in service pages. Page names are grouped: no SteamID, email, API key, search term or inventory content is sent. That tool also receives the site you came from when it is outside veriloot.gg, the campaign parameters of the link you followed (utm_source, utm_medium, utm_campaign, utm_content, utm_term and ref), how long you stayed on the page and how far you scrolled. No other URL parameter is sent. Administration, authentication and payment pages are excluded. No traffic-analytics cookie is added. The instance processes the IP address and browser information to produce these statistics. No permission is requested for this tool: the legal basis is our legitimate interest in measuring site traffic.
When usage analytics are enabled on the site, the tool records how pages are used: clicks, scrolling, mouse movement, selections, window size, technical errors and the structure of the page displayed. This data produces session replays and heatmaps, so we can find what gets in the way of reading or navigating. It loads without asking for your permission first: no banner or choice is shown. The legal basis we rely on is our legitimate interest in improving how the site reads and navigates.
It only loads on the home page, pricing, the platform directory and the legal pages, on an address without query parameters or fragment, and never while an account session is open or once an input field has been used on the page. The site asks it to mask page content before sending it: text, link and image addresses, and field contents. As soon as you leave these pages in the same tab, the browser blocks any further transmission to it until an allowed page is fully loaded again. The site sends it no consent signal, so it applies its default behavior, which we have not verified.
This tool comes from a provider established outside the European Union. Its European contract is with that provider’s Irish subsidiary. The provider states that it complies with the GDPR as a data controller, that it has access to this data, that the data is stored in its cloud service, and that it may transfer the data to the United States under standard contractual clauses. It also uses the IP address to determine the visitor’s location. We give you its name and privacy statement on request, at the contact address above.
According to that provider, replay data is kept for 30 days; click and heatmap data, and labeled or favorited sessions, for 9 months. It also states that it keeps a randomly selected sample of recordings for up to 9 months.
This tool may set two cookies on veriloot.gg: _clck, which keeps a pseudonymous visitor identifier for one year, and _clsk, which links page views into one session for one day. It may also store a tab identifier, _cltk, in the browser’s session storage. Its provider also documents cookies set on its own domains (CLID, MUID, ANONCHK, MR and SM). We have not verified which of these cookies and identifiers are actually set when the site sends no consent signal.
That provider states that deleting the data of one specific visitor requires deleting the whole project.
Veriloot’s TikTok account statistics
Within its private administration area, Veriloot can authorize access to its own TikTok account to monitor its posts. Visitors are not offered this connection. The data used consists of the account identifier, display name and username, follower and public video counts, and identifiers and view, like, comment and share counts for tracked videos. Observations are timestamped; no private messages or follower lists are collected.
Access and refresh tokens are stored encrypted on the server while the connection remains active. Statistical observations older than 30 days are removed by automatic cleanup jobs. This information is available only to administrators and is used to measure the performance of Veriloot’s posts; this integration does not publish videos or send messages.
The administration’s “Disconnect and delete API statistics” button deletes the tokens and TikTok observations stored by this integration and requests access revocation from TikTok. Access can also be removed through TikTok’s authorized application settings. For requests about this data, contact veriloot@gmail.com. TikTok processes data on its platform under its own privacy policy.
The Discord server
When this measurement is enabled, the bot on Veriloot’s Discord server records, for each person who joins the server: a fingerprint of their Discord ID, computed with a secret key; the channel tied to the invite they used (for example the invite posted on a social network or the one on the site, or “unknown” when the bot cannot tell); the day they joined, without the time; and, if the bot served them a /price or /drops command, the fact that it did and the time elapsed since they joined, in whole hours. For this measurement, the ID itself, the username, messages and command contents are not recorded. None of this is linked to a Veriloot account.
It is used only to learn where server members come from and whether they use the bot after joining; we only look at totals per channel, and a total based on fewer than five joins is not shown. Legal basis: our legitimate interest in measuring how well our communication channels work (art. 6(1)(f)). Each row is deleted automatically no later than 90 days after the join date. Discord also processes your data under its own rules.
To object to this measurement, email veriloot@gmail.com with your Discord ID. We use it only to recompute the fingerprint: your row is deleted, and the fingerprint is added to an exclusion list so the bot never records anything about you again, even if you leave and rejoin the server. That list holds only the fingerprint, with no channel or date, and is kept for as long as the measurement exists. Your email stays in the controller’s inbox, where no automatic deletion is scheduled; you can ask for it to be deleted at the same address.
The server’s daily “Price call” is a game with no prize: it gives points and a monthly ranking, and there is nothing to win. If you answer with the /guess command, the bot records your Discord ID, the price you entered, the time of your answer and, once the result is known, the points you scored. Your username and messages are not recorded. This data is used only to compute points and the ranking: the result posted each day in the channel shows the five best answers (a mention of the Discord account, the price entered, the points), and the /leaderboard command, whose reply only you can see, shows the month’s top ten. These mentions trigger no notification. Answers are not linked to any Veriloot account. Legal basis: our legitimate interest in running the game you chose to join (art. 6(1)(f)). Challenges and answers older than 400 days are deleted by the bot when it posts the daily challenge.
To have your answers deleted sooner, email veriloot@gmail.com with your Discord ID: all your answers are removed from the bot’s database, and you leave the ranking. Result messages already posted in the channel are not changed by this deletion; you can ask for them to be removed at the same address.
The Veriloot extension (Chrome and Firefox)
The Veriloot extension, for Chrome and Firefox, is optional. On a skin listing page, it shows the marketplace where the same item sells for less. It only runs on sixteen sites: buff.market, market.csgo.com, white.market, waxpeer.com, csfloat.com, cs.money, lis-skins.com, www.haloskins.com, skinbaron.de, tradeit.gg, skinport.com, 49skins.com, mannco.store, buff.163.com, skinswap.com and dmarket.com. On those pages, it only reads what names the item on screen: the page address, the tab or item title, the page’s structured data, the Steam Market link, the alternative text of the item image, the wear or variant shown and, on skinport.com, csfloat.com and dmarket.com, the item name in the responses the page receives from that site’s API. It doesn’t read your cookies, sign-in credentials, browsing history or other tabs. It only asks the browser for access to those sixteen sites and to Veriloot’s API, and for temporary storage (the “storage” permission) for the list of paused marketplaces described below.
For each listing you open, the extension sends two things to veriloot.gg, over HTTPS: the item name and the page’s marketplace. It sends no cookie, no account identifier and not the page address. Like any request on the Internet, it carries your IP address and the extension’s identifier. On Firefox, that identifier is drawn at random at install time and belongs to your copy of the extension; the server checks its format without recording it. The server replies with the lowest purchase price observed for the item, its marketplace and the price observed on the page’s marketplace. The API log records the method, the path, the response status, its duration and a technical request ID: neither your IP address nor the item name. To limit abuse, the server counts requests per IP address over one minute and over twenty-four hours, in memory only: the address is never written to the database or to a log, and that memory is cleared whenever the service restarts. At most once an hour, the extension also asks veriloot.gg for the list of marketplaces where Veriloot has paused its card; that request carries no information: no item name, no page address, no identifier. The request goes through the same hosting infrastructure as the site, described above. Legal basis: our legitimate interest in providing the comparison you chose to install (art. 6(1)(f)).
Nothing is written to your disk: the response is kept for one minute in the extension’s memory, so the same item isn’t requested twice, then dropped. The list of paused marketplaces is kept for one hour (five minutes if veriloot.gg didn’t answer) in the browser’s session memory (chrome.storage.session), cleared when the browser closes. Uninstalling the extension removes everything.
The button to the cheapest marketplace may be an affiliate link: it is then labeled “affiliate link” in the card and works as described in the Cookies section. Affiliation doesn’t change the order: the lowest price stays on top. The extension sets, reads and writes no cookie, changes no link on the page you’re viewing and doesn’t tell Veriloot that you follow a link. It contains no analytics. No data is sold or passed on to third parties. The use of information received complies with the Chrome Web Store User Data Policy, including the Limited Use requirements. On Firefox, the extension declares at install time, in Mozilla’s categories, the data it transmits: website content (the item name) and browsing activity (the page’s marketplace). For any question or request, email veriloot@gmail.com.