Skip to content

Privacy Policy

By AssetPayUpdated Read as Markdown

Effective Date: August 9, 2026

Introduction

This policy explains what data AssetPay collects, what we use it for, how long we keep it, and who else it reaches.

It covers two groups. Merchants are the platforms that integrate our gateway; we are the data controller for their account and billing records. End users are the people who deposit skins through a merchant's checkout. For most end-user data the merchant decides why the processing happens, which makes them the controller and us a processor acting on their instructions under a Data Processing Agreement.

Who we are

AssetPay Oy, Business Registration No. 3537599-6, registered in Finland, is the data controller for the processing described in this policy.

Information we collect

Information you give us

  • Name and email address
  • Account credentials, including multi-factor authentication settings
  • Steam account identity and inventory data needed to price and execute a trade
  • Trade, settlement and payout records
  • Support correspondence
  • Communication preferences

Information collected automatically

When you use the platform we record technical details about the request:

  • IP address
  • Browser type and operating system
  • Access times
  • Pages viewed

GDPR requires us to name a lawful basis for each purpose rather than process data generally. Ours are:

What we processWhyLegal basis
Account details and credentialsCreating, securing and administering your accountContract, Art. 6(1)(b)
Steam identity, inventory and trade recordsPricing items, executing trades and settling valueContract, Art. 6(1)(b)
Accounting, settlement and AML recordsMeeting statutory bookkeeping and anti-money-laundering dutiesLegal obligation, Art. 6(1)(c)
Technical logs and device dataSecurity, fraud prevention, abuse detection and debuggingLegitimate interests, Art. 6(1)(f)
Support correspondenceAnswering and resolving your requestsContract and legitimate interests
Product and marketing emailSending updates you asked to receiveConsent, Art. 6(1)(a)

Where we rely on legitimate interests, we have weighed those interests against your rights and you can object at any time; see Your rights. Where we rely on consent, you can withdraw it at any time without affecting processing that already happened.

How long we keep it

We keep merchant account records for as long as the merchant relationship is active. Trade, ledger and accounting records are kept after that because Finnish accounting and anti-money-laundering legislation requires it. Technical logs are kept for a shorter operational window and then deleted or aggregated.

Data security

We implement appropriate technical and organizational security measures to protect personal data against unauthorized access, alteration, disclosure or destruction.

  • Encryption of sensitive records
  • Regular security audits
  • Access controls and authentication
  • Secure storage infrastructure
  • Employee training on privacy protection

Data sharing and sub-processors

We do not sell your personal data. We share it with:

  • Service providers and sub-processors who help us operate the platform
  • Legal authorities where the law requires it
  • Business partners, where you have consented

We engage third-party sub-processors under a written Data Processing Agreement. They may only act on our instructions and are bound by confidentiality and security obligations.

Our current sub-processors:

  • Vercel — application hosting and content delivery
  • Cloudflare — bot protection on authentication forms (Turnstile)
  • Mintlify — documentation hosting (/docs)

The sub-processor page sets out what data reaches each of them and where they operate. Merchants can request a dated copy of that list and our DPA by contacting support@assetpay.gg.

International data transfers

Some of the sub-processors above operate outside the European Economic Area. Where personal data is transferred out of the EEA, we rely on the European Commission's Standard Contractual Clauses, or on an adequacy decision covering the destination country.

Your rights

Under GDPR you have the right to:

  • Access the personal data we hold about you, and receive a copy of it
  • Rectify inaccurate or incomplete data
  • Erasure of your data, where we have no overriding legal duty to keep it
  • Restrict processing while a dispute about accuracy or lawfulness is resolved
  • Portability — receive your data in a structured, machine-readable format, or have it sent to another controller
  • Object to processing based on legitimate interests, including profiling
  • Withdraw consent at any time, where consent is the basis we rely on

To exercise any of these, email support@assetpay.gg from the address associated with your account. We will respond within one month, as GDPR requires.

If you are an end user who deposited skins through a merchant's site, send your request to that merchant first. They are the controller for that processing, and we will act on their instruction.

Complaints

If you think we have handled your data unlawfully, you can complain to your local supervisory authority. In Finland that is the Office of the Data Protection Ombudsman (Tietosuojavaltuutetun toimisto), tietosuoja.fi. You can also complain to the authority in your own country of residence.

Cookies

We use a small number of cookies. assetpay-auth records that you have signed in so the app can route you to the merchant dashboard; it carries no personal data itself. Cloudflare Turnstile sets its own cookies when it runs a bot check on the authentication forms.

You can control cookie preferences through your browser settings, though blocking the authentication cookie will prevent sign-in from working.

Children's privacy

The platform is not intended for anyone under 18, and we do not knowingly collect personal data from children. If you believe a child has given us data, contact us and we will delete it.

Changes to this policy

We may update this policy. If a change materially affects how we handle your data, we will post the new version here and update the effective date above. Merchants under contract will be notified directly.

Contact

Questions about this policy, or about a request under it, go to support@assetpay.gg.


Last updated: August 9, 2026