Privacy Policy
Effective Date: August 9, 2026
Introduction
This policy explains what data AssetPay collects, what we use it for, how long we keep it, and who else it reaches.
It covers two groups. Merchants are the platforms that integrate our gateway; we are the data controller for their account and billing records. End users are the people who deposit skins through a merchant's checkout. For most end-user data the merchant decides why the processing happens, which makes them the controller and us a processor acting on their instructions under a Data Processing Agreement.
Who we are
AssetPay Oy, Business Registration No. 3537599-6, registered in Finland, is the data controller for the processing described in this policy.
- Privacy contact: support@assetpay.gg
Information we collect
Information you give us
- Name and email address
- Account credentials, including multi-factor authentication settings
- Steam account identity and inventory data needed to price and execute a trade
- Trade, settlement and payout records
- Support correspondence
- Communication preferences
Information collected automatically
When you use the platform we record technical details about the request:
- IP address
- Browser type and operating system
- Access times
- Pages viewed
Why we process it, and on what legal basis
GDPR requires us to name a lawful basis for each purpose rather than process data generally. Ours are:
| What we process | Why | Legal basis |
|---|---|---|
| Account details and credentials | Creating, securing and administering your account | Contract, Art. 6(1)(b) |
| Steam identity, inventory and trade records | Pricing items, executing trades and settling value | Contract, Art. 6(1)(b) |
| Accounting, settlement and AML records | Meeting statutory bookkeeping and anti-money-laundering duties | Legal obligation, Art. 6(1)(c) |
| Technical logs and device data | Security, fraud prevention, abuse detection and debugging | Legitimate interests, Art. 6(1)(f) |
| Support correspondence | Answering and resolving your requests | Contract and legitimate interests |
| Product and marketing email | Sending updates you asked to receive | Consent, Art. 6(1)(a) |
Where we rely on legitimate interests, we have weighed those interests against your rights and you can object at any time; see Your rights. Where we rely on consent, you can withdraw it at any time without affecting processing that already happened.
How long we keep it
We keep merchant account records for as long as the merchant relationship is active. Trade, ledger and accounting records are kept after that because Finnish accounting and anti-money-laundering legislation requires it. Technical logs are kept for a shorter operational window and then deleted or aggregated.
Data security
We implement appropriate technical and organizational security measures to protect personal data against unauthorized access, alteration, disclosure or destruction.
- Encryption of sensitive records
- Regular security audits
- Access controls and authentication
- Secure storage infrastructure
- Employee training on privacy protection
Data sharing and sub-processors
We do not sell your personal data. We share it with:
- Service providers and sub-processors who help us operate the platform
- Legal authorities where the law requires it
- Business partners, where you have consented
We engage third-party sub-processors under a written Data Processing Agreement. They may only act on our instructions and are bound by confidentiality and security obligations.
Our current sub-processors:
- Vercel — application hosting and content delivery
- Cloudflare — bot protection on authentication forms (Turnstile)
- Mintlify — documentation hosting (
/docs)
The sub-processor page sets out what data reaches each of them and where they operate. Merchants can request a dated copy of that list and our DPA by contacting support@assetpay.gg.
International data transfers
Some of the sub-processors above operate outside the European Economic Area. Where personal data is transferred out of the EEA, we rely on the European Commission's Standard Contractual Clauses, or on an adequacy decision covering the destination country.
Your rights
Under GDPR you have the right to:
- Access the personal data we hold about you, and receive a copy of it
- Rectify inaccurate or incomplete data
- Erasure of your data, where we have no overriding legal duty to keep it
- Restrict processing while a dispute about accuracy or lawfulness is resolved
- Portability — receive your data in a structured, machine-readable format, or have it sent to another controller
- Object to processing based on legitimate interests, including profiling
- Withdraw consent at any time, where consent is the basis we rely on
To exercise any of these, email support@assetpay.gg from the address associated with your account. We will respond within one month, as GDPR requires.
If you are an end user who deposited skins through a merchant's site, send your request to that merchant first. They are the controller for that processing, and we will act on their instruction.
Complaints
If you think we have handled your data unlawfully, you can complain to your local supervisory authority. In Finland that is the Office of the Data Protection Ombudsman (Tietosuojavaltuutetun toimisto), tietosuoja.fi. You can also complain to the authority in your own country of residence.
Cookies
We use a small number of cookies. assetpay-auth records that you have signed in so the app can route you to the merchant dashboard; it carries no personal data itself. Cloudflare Turnstile sets its own cookies when it runs a bot check on the authentication forms.
You can control cookie preferences through your browser settings, though blocking the authentication cookie will prevent sign-in from working.
Children's privacy
The platform is not intended for anyone under 18, and we do not knowingly collect personal data from children. If you believe a child has given us data, contact us and we will delete it.
Changes to this policy
We may update this policy. If a change materially affects how we handle your data, we will post the new version here and update the effective date above. Merchants under contract will be notified directly.
Contact
Questions about this policy, or about a request under it, go to support@assetpay.gg.
Last updated: August 9, 2026