Privacy Policy
How Gadget Exchange collects, uses, and protects your personal information when you use our Website and Services.
Privacy Policy
Last Updated: August 27, 2026
This Privacy Policy explains what personal information Gadget Exchange collects when you use the website at gadget.exchange and the services we provide through it (together, the "Website"), why we collect it, who we share it with, how long we keep it, and what rights you have over it.
Gadget Exchange is operated by Gadget Exchange LLC, a Texas limited liability company. In this policy, "we", "us", and "our" refer to Gadget Exchange LLC. "Personal information" (or "personal data") means information that identifies you or can reasonably be linked to you.
This policy is incorporated into our Terms of Service. If you do not agree with it, please do not use the Website.
1. Who Is Responsible for Your Data
The data controller for the Website is:
- Company: Gadget Exchange LLC
- Address: 5900 Balcones Dr, Ste 100, Austin, Texas 78731, United States
- Email: [email protected]
The controller is the entity that decides why and how personal data is processed. If you have any question about this policy, or want to exercise a right described in Section 9, contact us at the address or email above, or open a support ticket from your account.
2. What We Collect
Information we receive from Steam
You sign in to the Website exclusively through Steam OpenID. We never see, receive, or store your Steam password, and there is no separate Gadget Exchange password.
When you sign in, and on later occasions while you use the Website, we receive and store from Steam:
- Your SteamID64 — the permanent numeric identifier of your Steam account. This is your account identifier on our Website.
- Your Steam display name and avatar image URL, refreshed each time you sign in.
- Your Steam account's creation date, where your profile makes it available. We use this solely as an anti-fraud signal.
- The contents of your Steam inventory for the games we support, when you use the Trade page or when we refresh your inventory to price it.
What Steam shares with us is governed by your Steam privacy settings, which you control at store.steampowered.com/account/privacysettings. If your profile or inventory is private, parts of the Website will not work for you.
Information you give us
- Steam Trade Offer URL — required before we can send or receive items. It contains a token tied to your Steam account.
- Notification email address (optional) and personal Discord webhook URL (optional), used only to deliver the notifications you switch on.
- Delivery address and billing address — country, postal code, and, where you provide them, street, city, and state or region. We use these to determine whether and how much transaction tax applies to your orders and to satisfy payment-provider requirements.
- Two-factor authentication data, if you enable it — an encrypted TOTP secret and irreversible hashes of your single-use recovery codes. We cannot read your recovery codes.
- Support tickets — the subject, every message in the thread, and anything you attach.
- Any other information you choose to send us, including feedback and correspondence.
Information generated by your use of the Website
- Wallet and transaction records — your withdrawable and non-withdrawable balances, reservations against open orders, and a full ledger of every movement in and out of your balance.
- Order, trade-offer, and item history — what you bought, what you sold, what items were delivered to or from which of our Steam accounts, when, and at what price. These records back the CSV and PDF exports you can download from your dashboard.
- Wishlist entries, giveaway entries and tickets, and your notification preferences.
- Account standing — any restriction, freeze, suspension, or closure applied to your account, and the reason recorded for it.
Information collected automatically
- IP address, including the address recorded at your most recent sign-in, and the time of that sign-in.
- Browser and device information — user agent, browser type and version, and operating system.
- Server log data — requested URL, referring URL, hostname, response status, and timestamps.
- A random device identifier stored in a cookie on your browser (see Section 3), used to recognise the same browser across sessions for fraud prevention.
- Referral attribution data — if you arrive through one of our referral links, we record the visit and, if you then create an account, which link you came from.
Information from payment and verification providers
- Deposits and cash-outs — amount, currency, method, status, timestamps, and provider-side reference identifiers. For cryptocurrency, the blockchain network, the deposit address assigned to you, the destination address you supply for a cash-out, and the transaction hashes.
- Identity verification (KYC) — where verification is required, our third-party identity provider performs the check. We receive only the status of that check and a session reference. We do not receive or store your identity documents, your photograph, or the underlying document data.
What we do not collect
We do not collect your Steam password, your Steam Guard codes, or your Steam API key. We do not store full payment card numbers — card data, where card payments are offered, is handled entirely by the payment provider. We do not run advertising trackers, advertising cookies, third-party analytics, or user profiling for marketing purposes on the Website. We do not knowingly collect information from anyone under 18.
3. Cookies and Similar Technologies
A cookie is a small data file stored by your browser. Some cookies last only for the session; others persist until they expire or you delete them. The Website uses only cookies that are necessary to operate it and to keep it secure. We do not use advertising or third-party analytics cookies.
We use cookies for the following purposes:
- Signing you in — keeping your session active after you authenticate through Steam, so you do not have to sign in again on every page. The session ends when you sign out, or when it expires a set period after you signed in.
- Security — protecting requests and forms against cross-site request forgery and other attacks.
- Fraud prevention — recognising a returning browser so that we can detect abuse of the Website. The value stored is a random identifier and holds no personal details about you by itself.
- Referral attribution — where you arrive through one of our referral links, recording which link you came from so a later signup can be attributed to it, and counting each browser only once in visit statistics. These are set only if you arrive through such a link.
All of the above are necessary for the Website to work or to keep it secure. Our CDN and security provider, Cloudflare (see Section 6), may set its own necessary cookies to route traffic, filter malicious requests, and mitigate attacks.
The Website also uses your browser's local storage to remember whether you prefer the light or dark interface. That preference is never sent to our servers.
We process necessary cookies on the basis of our legitimate interest in providing a functioning, secure Website (Art. 6(1)(f) GDPR) and, where they are required to deliver a service you requested, on the basis of contract performance (Art. 6(1)(b) GDPR). Where the law requires consent for a particular cookie, we ask for it and you can withdraw it at any time.
You can configure your browser to warn you about cookies, to accept them only in specific cases, to refuse them, or to delete them when the browser closes. If you block the cookies described above you will not be able to sign in or use the Website.
4. Why We Use Your Data, and Our Legal Bases
We use your personal information for the purposes below. Where the GDPR applies to you, the legal basis is stated alongside each purpose.
- To provide the Website and your account — signing you in, showing your inventory, pricing items, executing purchases and sales, delivering items through Steam trade offers, maintaining your balance and history. Legal basis: performance of a contract (Art. 6(1)(b) GDPR).
- To process deposits and cash-outs and to maintain the ledger of your balance. Legal basis: performance of a contract (Art. 6(1)(b) GDPR); compliance with a legal obligation (Art. 6(1)(c) GDPR).
- To calculate and collect transaction taxes using your delivery and billing address. Legal basis: compliance with a legal obligation (Art. 6(1)(c) GDPR).
- To verify your identity where required for a payment method, a cash-out, or by law. Legal basis: compliance with a legal obligation (Art. 6(1)(c) GDPR); legitimate interest in preventing fraud (Art. 6(1)(f) GDPR).
- To prevent fraud, abuse, money laundering, and account takeover, and to keep the Website secure — see Section 5. Legal basis: legitimate interest in protecting the Website, our stock, and our users (Art. 6(1)(f) GDPR); compliance with a legal obligation (Art. 6(1)(c) GDPR).
- To secure your account — two-factor authentication, recovery codes, sign-in records, and security incident records. Legal basis: legitimate interest in security (Art. 6(1)(f) GDPR); performance of a contract (Art. 6(1)(b) GDPR).
- To provide support — reading and answering your tickets. Legal basis: performance of a contract (Art. 6(1)(b) GDPR) where your request concerns a transaction; otherwise legitimate interest in handling enquiries effectively (Art. 6(1)(f) GDPR), or your consent (Art. 6(1)(a) GDPR) where we asked for it.
- To send notifications you switched on — by email or to your Discord webhook. Legal basis: your consent (Art. 6(1)(a) GDPR), withdrawable at any time by turning the channel off or removing the address.
- To run giveaways you enter. Legal basis: performance of a contract (Art. 6(1)(b) GDPR).
- To measure referral links — counting unique visits and attributing signups. Legal basis: legitimate interest in understanding where our users come from (Art. 6(1)(f) GDPR).
- To operate and improve the Website — diagnosing errors, monitoring performance and capacity, and maintaining aggregate operational statistics. Legal basis: legitimate interest in a reliable, error-free service (Art. 6(1)(f) GDPR).
- To comply with the law and to establish, exercise, or defend legal claims — including responding to lawful requests from authorities. Legal basis: compliance with a legal obligation (Art. 6(1)(c) GDPR); legitimate interest (Art. 6(1)(f) GDPR).
Where we ask for your consent, you may withdraw it at any time. Withdrawing consent does not affect the lawfulness of processing carried out before the withdrawal.
5. Fraud Prevention and Automated Decisions
Because real value moves through the Website, we operate security and anti-fraud controls. For that purpose we process technical information about how your account is used — including the network addresses you connect from, information about your browser and device, records of sign-ins and security events, and your activity on the Website.
Some of the resulting decisions are made automatically, and they can have a real effect on you: a feature such as cashing out or a particular payment method may be limited, or an account may be suspended, frozen, or closed. We do not publish the details of how these controls work, because doing so would tell the people abusing the Website exactly what to avoid.
You have the right to ask for a human review of any automated decision that restricts your account, to express your point of view, and to contest the decision. Contact us or open a support ticket and a member of our team will look at it.
For support and investigation purposes our staff can view your account and, under an internal control, access the Website as your account in order to reproduce a problem you have reported. Every such access is logged.
6. Who We Share Your Data With
We do not sell your personal information, and we do not share it for cross-context behavioural advertising. We disclose it only in the circumstances below, and only to the extent necessary.
Service providers (processors) who act on our instructions:
- Hetzner Online GmbH, Germany — hosting of our servers and databases. Your data is stored on infrastructure operated by this provider under a data processing agreement.
- Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA — content delivery, DNS, and protection against malicious traffic. Because traffic between your browser and the Website is routed through Cloudflare's network, Cloudflare processes connection data such as your IP address and request metadata for those purposes. Cloudflare's privacy policy: cloudflare.com/privacypolicy/
- Our identity verification provider — to run a KYC check where one is required. We receive only the outcome and a session reference; your documents go to the provider, not to us.
- Our email delivery provider — to send the email notifications you switched on.
- Infrastructure and network providers supporting the operation of our servers and our Steam connectivity.
Independent companies that decide for themselves how they handle your data. These are not our processors: they receive or hold data in their own right and act as controllers of it under their own privacy policies, which you should read.
- Valve Corporation (Steam) — the operator of Steam. Signing in, your Steam profile and inventory, and the trade offers used to deliver items all run through Steam. What Steam shares with us is governed by your Steam privacy settings, and what Valve does with your data is governed by Valve, not by us. Steam's privacy policy: store.steampowered.com/privacy_agreement/
- Payment and cryptocurrency providers, including our card payment provider and our cryptocurrency payment gateway — to process deposits and cash-outs. They receive the data necessary to execute and reconcile the transaction.
- Discord Inc. — only where you supply a personal Discord webhook URL for notifications, or where you use our Discord verification flow. In that case we transmit the notification content to the webhook you supplied, and we may store your Discord user identifier.
Other disclosures:
- Legal and regulatory — where we are required to disclose data by law, court order, or a valid request from a public authority, or where disclosure is necessary to establish, exercise, or defend legal claims, to enforce our Terms of Service, or to protect the rights, property, or safety of Gadget Exchange, our users, or others.
- Fraud and abuse — we may report items obtained illegitimately, and the accounts involved, to Valve Corporation or to law enforcement.
- Business transfer — if Gadget Exchange or the Website is merged, acquired, reorganised, or sold, your data may be transferred as part of that transaction. We will require the recipient to honour this policy or notify you of any material change.
Where a service provider processes personal data on our behalf, we put a data processing agreement in place requiring them to process it only on our instructions and in line with applicable data protection law.
7. International Transfers
We are established in the United States and our providers are located in the United States, the European Union, and elsewhere. Using the Website therefore involves transferring your personal data across borders, including to the United States.
Where personal data of individuals in the European Economic Area, the United Kingdom, or Switzerland is transferred to a country that has not been recognised as providing an adequate level of protection, we rely on appropriate safeguards, principally the Standard Contractual Clauses approved by the European Commission, and, where the recipient is certified, the EU-U.S. Data Privacy Framework and its UK Extension and Swiss-U.S. counterpart.
You may request a copy of the safeguards we rely on by contacting us.
8. How Long We Keep Your Data
We keep personal data only as long as necessary for the purposes it was collected for, unless a longer period is required or permitted by law.
- Account, wallet, order, trade, and ledger records are kept for the life of your account and afterwards for as long as required to meet tax, accounting, and anti-money-laundering retention obligations, and to establish, exercise, or defend legal claims.
- Support tickets are archived automatically once they have been resolved or closed and left untouched for a set period, after which they no longer appear on your account.
- Security and fraud-prevention records are kept for as long as necessary to protect the Website against repeat abuse.
- Server logs are retained for a limited operational period and then removed or rotated out.
- Notification addresses and preferences are kept until you remove them.
- Identity verification status is kept for the period required by applicable financial-crime law.
Where data is no longer needed for any purpose and no retention obligation applies, we delete it or irreversibly anonymise it.
9. Your Rights
Depending on where you live, you may have some or all of the following rights over your personal data:
- Access — to be told whether we process data about you and to receive a copy of it, together with information about its source, its recipients, and the purposes it is used for.
- Rectification — to have inaccurate data corrected and incomplete data completed.
- Erasure — to have your data deleted where there is no overriding reason for us to keep it.
- Restriction — to have processing limited, for example while you contest the accuracy of data, where processing is unlawful but you do not want the data erased, where we no longer need the data but you need it for a legal claim, or while an objection under Art. 21(1) GDPR is being weighed.
- Portability — to receive the data you gave us, or that we process automatically on the basis of your consent or a contract, in a common machine-readable format, and to have it transmitted to another controller where technically feasible.
- Objection — to object at any time to processing based on our legitimate interests, on grounds relating to your particular situation.
- Withdrawal of consent — to withdraw consent at any time, without affecting the lawfulness of processing before the withdrawal.
- Human review of automated decisions, as described in Section 5.
- Complaint — to lodge a complaint with a supervisory authority, in particular in the country where you live, where you work, or where the alleged infringement occurred. This right exists alongside any other legal remedy.
A note on direct marketing. If we ever process your data for direct marketing, you have the right to object at any time, including to any profiling connected with it, and we will stop using your data for that purpose.
If you are in the United States, depending on your state you may also have the right to know what personal information we collect and disclose, to obtain a copy of it, to correct it, to delete it, to limit the use of sensitive personal information, and not to be discriminated against for exercising those rights. We do not sell personal information and we do not share it for cross-context behavioural advertising.
To exercise a right, contact us at [email protected] or open a support ticket. We may need to verify your identity before we act — normally by confirming that the request comes from the Steam account in question. We answer within the period the applicable law requires, and we do not charge for a first, reasonable request.
Some of your history cannot be deleted on request where we are legally required to keep it, for example transaction and tax records, or where it is needed to prevent fraud on the Website.
10. Security
We take the protection of your personal data seriously and handle it as confidential.
- All traffic between your browser and the Website is encrypted with TLS. You can recognise this by the
https://prefix and the lock icon in your browser. Payment traffic is likewise encrypted. - Sensitive secrets are encrypted at rest, including two-factor authentication secrets and our payment-gateway credentials. Recovery codes are stored only as irreversible hashes.
- Access to production data by our staff is restricted, permission-controlled, and logged, and administrative sign-in requires two-factor authentication.
- We monitor for and record security incidents, and we apply rate limiting and abuse controls across the Website.
You can further protect your own account by enabling two-factor authentication, keeping Steam Guard active, and never sharing your Steam credentials or your recovery codes with anyone. We will never ask you for your Steam password, your Steam Guard codes, your API key, or a seed phrase.
No method of transmitting or storing data is completely secure. Transmission over the Internet, including by email, can never be fully protected against third-party access, and we cannot guarantee absolute security.
11. Children
The Website is not intended for anyone under 18, and our Terms of Service require you to be at least 18 to use it. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact us and we will delete it.
12. Changes to This Policy
We may update this Privacy Policy to reflect changes in the Website, in our providers, or in the law. When we do, we post the revised policy on this page and update the "Last Updated" date at the top. Where a change is material, we will make reasonable efforts to notify you. Please review this page from time to time.
13. Contact Us
For any question about this policy or about how we handle your personal data:
- Company: Gadget Exchange LLC
- Address: 5900 Balcones Dr, Ste 100, Austin, Texas 78731, United States
- Email: [email protected]
You can also open a support ticket from your account, which lets us connect your request to your account without any further verification step.