StormStats legal

Privacy policy

Last updated July 26, 2026

What we collect

When you sign in, we store your SteamID64, display name, session data, and account preferences. When you use analysis features, we may store provider responses, historical snapshots, searches, watchlists, comparisons, teams, processing jobs, and subscription state. IP addresses are hashed before operational logging.

Why we process it

We use this data to authenticate you, provide requested analytics, maintain historical charts, enforce plan limits, prevent abuse, process legitimate demos, support billing, and secure the service.

Provider boundaries

Steam and FACEIT data is requested through supported official APIs. Private profiles and unavailable values are respected. Stripe processes payment details; StormStats does not store full card numbers.

Retention and deletion

Provider cache entries expire automatically. Historical snapshots remain while needed for the service or until account deletion, subject to lawful retention obligations. Account deletion removes account-owned records through database cascades.

Your controls

You can export stored data, change profile visibility and notification preferences, unlink access by deleting your account, or contact the operator for access and correction requests.

Cookies

StormStats uses essential session, OpenID nonce, and CSRF cookies. Non-essential analytics or advertising cookies are not enabled in the default deployment, so no consent banner is shown.

Security

Sessions use secure HTTP-only cookies, state-changing requests require CSRF validation, authorization is checked on the server, and secrets are never shipped in frontend bundles.