effective 25 August 2026

Privacy policy

What VACWatch collects, where it comes from, who it goes to, and how to get it removed.

the short version

VACWatch records public Steam ban data so people can look it up. That means we hold information about two different groups: people who sign up for an account, and people whose public Steam profiles we track. Most privacy policies only cover the first. This one covers both, because the second group never agreed to anything.

if you have an account

We collect and store:

  • 01Your email address, display name, and avatar — from Discord if you sign in that way, or from you directly if you register with an email and password. Passwords are stored hashed, never in plain text.
  • 02Discord access and refresh tokens, so we can confirm your identity and check whether you share a server with our bot. We only ever use these for VACWatch features.
  • 03Your Discord user ID and username, and whether you have opted in to direct-message ban alerts.
  • 04Your profile details — username, biography, and whether you have marked your profile private — plus any Steam accounts you claim as your own and the list of accounts you follow.
  • 05Subscription and billing status, if you pay for a membership. Card details are handled by our payment provider and never reach our servers.
  • 06Session records, including IP address and browser user agent, used to keep you signed in and to spot abuse.
if we track your steam account

You do not need a VACWatch account for us to hold a record about you. If someone looks up or follows a Steam account, we store a copy of what Steam publishes for it and keep it updated. That record can include the SteamID, current and previous persona names, avatar, profile URL, country and state, account creation date, Steam level, recent playtime, and VAC, game, and economy ban counts and dates. Where a matching Faceit account exists, we may also store its nickname, skill level, and ban information.

All of it comes from Steam's and Faceit's public APIs. We do not attempt to identify anyone beyond the account, and we do not collect real names, addresses, or contact details. We keep name history specifically because a ban record is not much use if the account can be renamed to escape it.

If you are in a jurisdiction with data protection laws such as the UK or EU GDPR, our basis for this is legitimate interest in maintaining a public record of game ban data. You have the right to object. Seeyour choices below.

who else sees it

We do not sell your data or share it for advertising. We use these providers to run the service:

CloudflareHosting, CDN, image storage, caching. All traffic passes through Cloudflare.
TursoThe database holding accounts, tracked lists, and Steam records.
DiscordSign-in, and ban alerts sent to you by direct message or posted to a channel.
Steam (Valve)Source of all profile and ban data. We read from Steam; we send it no personal data about you.
FaceitSource of supplementary competitive-account data for tracked Steam accounts.
GuapocadoBilling and subscriptions. Receives your user id, name, and email.
PostHogProduct analytics — how pages and features are used.
Google Tag ManagerLoads analytics tags. Production only.

These providers operate internationally, so your data may be processed outside Australia. We may also disclose information where we are legally required to.

cookies and analytics

We set a session cookie to keep you signed in, and a preference cookie remembering your light or dark theme. Neither is used for advertising.

We use PostHog for product analytics and Google Tag Manager to load it. These record page views and feature usage, and may set their own cookies. Analytics tags load only in production. You can block them with a browser extension or tracker-blocking setting without losing any VACWatch functionality.

how long we keep it

Account data is kept while your account exists. Delete your account and we remove your profile, tracked list, and Discord connection.

Tracked Steam records are kept indefinitely, because a ban history that expires defeats the purpose of the site. When Steam reports an account no longer exists, we quarantine it and re-check before removing it, so a temporary Steam outage cannot wipe a record.

your choices
  • 01Claim your Steam account. If a tracked account is yours, connect it to a VACWatch account to prove ownership and manage how it appears.
  • 02Make your profile private.Available in account settings once you have claimed an account.
  • 03Turn off Discord alerts. Opt out of direct messages, or disconnect Discord entirely, from your account settings.
  • 04Delete your account. This removes your account data. It does not automatically remove a tracked Steam record, which is a separate request.
  • 05Ask for access, correction, or removal.Email privacy@vac.watch. Tell us the SteamID, and how you can demonstrate the account is yours. We will respond within a reasonable time and will explain our reasoning if we decline.
security

Traffic is encrypted in transit, passwords are hashed, and access to production systems is restricted. No service can promise perfect security, and we do not.

children

VACWatch is not intended for children under 13, and we do not knowingly create accounts for them. If you believe a child has registered, contact us and we will remove the account.

changes and contact

We may update this policy. Material changes will be noted on this page with a new effective date. Questions, requests, or complaints go toprivacy@vac.watch.

VACWatch is not affiliated with, endorsed by, or sponsored by Valve Corporation, Faceit, or Discord.