Draft — owner/legal review required before production launch.

Privacy Policy

Launch blocker: This implementation-ready draft is not legal advice. The owner must confirm the responsible operator, contact address, lawful bases, retention periods, and Microsoft contractual details before accepting members.

1. Scope and choices

Dogshit Players is preparing an opt-in Steam membership service. During the registration preview, Steam OpenID proves control of your account, and accepting the current documents permits retrieval of your own public Steam metadata for your private member area. Your registration is not a public directory entry. Any later public directory or structured-rating release requires a new consent version and your fresh acceptance before publication.

2. Data the service stores

The service does not ask for or store a Steam password, private Steam login/account name, email from Steam, friends, inventory, game history, or ban history. Public search does not contact Steam or an external resolver.

3. Use and public disclosure

During the registration preview, you can view your own Steam-linked registration in the member area, and authorized administrators can use restricted membership and deletion tools. An internal Active status does not make your preview registration public. Public search, public profiles, and rating output remain unavailable. Session data, consent records, suspension reasons, and moderation details are not public.

4. Sources and processors

Account ownership is asserted by Steam OpenID. After consent or an explicit member refresh, the backend requests only that verified member’s public summary from Valve’s Steam Web API. Microsoft Azure hosts the Static Web App, Function, Key Vault, and SQL database. Steam data and external services are provided as-is and may be unavailable or inaccurate.

Support messages sent to support@dogshitplayers.org are routed by Cloudflare to a mailbox hosted by Google. Include only the information needed for your request. Do not send passwords, authentication codes, API keys, or session cookies.

5. Location and transfers

The repository’s production parameters configure the application, Function, Key Vault, and Azure SQL primary resources in Azure West Europe (Netherlands). The owner must confirm the live deployment before launch. Microsoft-managed support, resilience, diagnostic, and backup processing may involve operational or retained copies under the owner’s Azure configuration and agreements; this draft makes no guarantee that every transient or backup copy stays in one country.

6. Retention

OpenID correlation state is short-lived and single use. Member sessions expire under the configured session lifetime and can be revoked earlier. Public profile metadata and aliases remain while needed for active membership or a documented operational/legal reason. Consent history is retained to show which version governed participation. A deactivation hides the profile but is not deletion. A deletion request immediately hides the profile, revokes sessions, and removes ratings authored by or received by the member; administrator completion removes the remaining member-linked application data while retaining only a redacted moderation audit. Azure backups and operational copies expire under the configured platform retention rather than immediately.

7. Member controls

Members can deactivate, request deletion, and sign out. Manual profile refresh is unavailable during the registration preview; metadata is retrieved as part of the consent flow. Suspension and moderation questions use the contact process below. Reactivation requires fresh Steam authentication, current consent, and a successful own-profile metadata retrieval.

8. Security

The service uses HTTPS in deployed environments, managed identities, Key Vault, parameterized SQL, opaque hashed sessions, CSRF checks, bounded local search, least-privilege administrative roles, and audit records. No service can promise absolute security.

9. Contact and version changes

For privacy, account support, moderation appeals, and deletion questions, contact support@dogshitplayers.org. The responsible operator and the remaining launch facts identified above must still be confirmed before this draft is published as the operative policy. Material policy changes receive a new configured version. A later public membership release requires fresh consent; preview registration alone never permits automatic publication.