Draft — owner/legal review required before production launch.
Privacy Policy
1. Scope and choices
Dogshit Players is preparing an opt-in Steam membership service. During the registration preview, Steam OpenID proves control of your account, and accepting the current documents permits retrieval of your own public Steam metadata for your private member area. Your registration is not a public directory entry. Any later public directory or structured-rating release requires a new consent version and your fresh acceptance before publication.
2. Data the service stores
- the permanent SteamID64 verified by Steam OpenID;
- public Steam display name, public profile URL, public avatar URL, current vanity segment, synchronization time, and selected historical public display/vanity aliases;
- membership tier and profile state, including deactivation, suspension, and deletion-request timestamps;
- the accepted consent, privacy, and rating-terms versions, acceptance time, choices, and any withdrawal time;
- if ratings are introduced in a later separately consented membership release: structured rating values, category, target and author membership references, invalidation state, and timestamps; ratings are unavailable in the registration preview;
- cryptographic hashes for short-lived OpenID state, server sessions, and CSRF protection—not the raw server-side tokens;
- necessary moderation actions and deletion-processing records, including restricted reasons and the administrator identity supplied by Static Web Apps authentication.
The service does not ask for or store a Steam password, private Steam login/account name, email from Steam, friends, inventory, game history, or ban history. Public search does not contact Steam or an external resolver.
3. Use and public disclosure
During the registration preview, you can view your own Steam-linked registration in the member area, and authorized administrators can use restricted membership and deletion tools. An internal Active status does not make your preview registration public. Public search, public profiles, and rating output remain unavailable. Session data, consent records, suspension reasons, and moderation details are not public.
4. Sources and processors
Account ownership is asserted by Steam OpenID. After consent or an explicit member refresh, the backend requests only that verified member’s public summary from Valve’s Steam Web API. Microsoft Azure hosts the Static Web App, Function, Key Vault, and SQL database. Steam data and external services are provided as-is and may be unavailable or inaccurate.
Support messages sent to support@dogshitplayers.org are routed by Cloudflare to a mailbox hosted by Google. Include only the information needed for your request. Do not send passwords, authentication codes, API keys, or session cookies.
5. Location and transfers
The repository’s production parameters configure the application, Function, Key Vault, and Azure SQL primary resources in Azure West Europe (Netherlands). The owner must confirm the live deployment before launch. Microsoft-managed support, resilience, diagnostic, and backup processing may involve operational or retained copies under the owner’s Azure configuration and agreements; this draft makes no guarantee that every transient or backup copy stays in one country.
6. Retention
OpenID correlation state is short-lived and single use. Member sessions expire under the configured session lifetime and can be revoked earlier. Public profile metadata and aliases remain while needed for active membership or a documented operational/legal reason. Consent history is retained to show which version governed participation. A deactivation hides the profile but is not deletion. A deletion request immediately hides the profile, revokes sessions, and removes ratings authored by or received by the member; administrator completion removes the remaining member-linked application data while retaining only a redacted moderation audit. Azure backups and operational copies expire under the configured platform retention rather than immediately.
7. Member controls
Members can deactivate, request deletion, and sign out. Manual profile refresh is unavailable during the registration preview; metadata is retrieved as part of the consent flow. Suspension and moderation questions use the contact process below. Reactivation requires fresh Steam authentication, current consent, and a successful own-profile metadata retrieval.
8. Security
The service uses HTTPS in deployed environments, managed identities, Key Vault, parameterized SQL, opaque hashed sessions, CSRF checks, bounded local search, least-privilege administrative roles, and audit records. No service can promise absolute security.
9. Contact and version changes
For privacy, account support, moderation appeals, and deletion questions, contact support@dogshitplayers.org. The responsible operator and the remaining launch facts identified above must still be confirmed before this draft is published as the operative policy. Material policy changes receive a new configured version. A later public membership release requires fresh consent; preview registration alone never permits automatic publication.