Short version
ggto.win is a Steam looking-for-group board and player-to-player trade board with XP, badges, weekly tickets, leaderboards, Steam key rewards, and trade reputation. We collect the Steam, listing, contact, feedback, report, reward, and safety data needed to run those features.
We do not ask for your Steam password. Steam login happens on Steam. We do not sell personal data. We do not store payment data, private Steam messages, Steam inventory contents, friend lists, bans, or your personal full owned-game history.
Steam login
Steam acts as the OpenID provider. After you approve login, Steam returns your 64-bit SteamID. ggto.win uses that ID to create your local account session.
Steam login does not give ggto.win your Steam username or password.
Steam profile data we store
When you sign in, we call Steam Web API GetPlayerSummaries so listings can show a real Steam profile. We may store:
- SteamID
- Steam display name
- Steam profile URL
- Steam avatar URLs
- persona state and profile visibility state
- country code, account creation time, and last logoff if Steam returns them
- sync, create, and update timestamps
Public library sync
If you press Sync public library, we call Steam Web API GetOwnedGames for games visible through your Steam privacy settings. Steam may return AppIDs, game names, and playtime.
ggto.win only uses that response to add popular game records to the site game index. We do not store your personal owned-game list or your playtime linked to your account.
Steam game artwork
For game images, we may use public Steam image URLs and Steam Store app details by AppID. This is game catalogue data, not personal account data.
We may cache public game image URLs so pages load reliably when older Steam CDN artwork is missing.
LFG post data
When you create a listing, we store the fields you submit: game, title, region, timezone, language, availability, optional date range, voice preference, voice tools, party size, skill level, playstyle, mode or role, notes, status, expiry, and timestamps.
Open listings are public and can appear on search pages, game pages, player pages, and search engines. Closed or expired listings stop appearing in normal search, but may remain stored for account history and site integrity review until deleted.
Trade listings
When you create a trade listing, we store the fields you submit: game, offer/want type, title, have text, want text, notes, status, expiry, and timestamps.
Trade listings are public and can appear on trade pages, player pages, and search engines while open. Trades are completed on Steam between users. ggto.win is not a middleman and is not responsible for trade outcomes.
Real-money trade terms are not allowed. If you include money-related terms, we may remove them from the listing text.
Trade offer URL
If you paste a Steam trade offer URL on your account page, we store it so other users can open the Send trade offer button from your trade listings.
This URL is optional and can be removed at any time from your account page.
Trade feedback, reputation, and reports
After two users interact through a trade listing, they can leave feedback about the other user. We store rating, comment, listing reference, and timestamps. Feedback contributes to public reputation signals.
Users can also report bad actors. Reports are stored for admin review, along with reporter, reported user, listing reference, report type, details, and status.
Public pages
Your Steam display name, avatar, profile link, open LFG posts, visible badges, level, and weekly leaderboard position may be public. Completed giveaway winner history may show winner display name, avatar, reward label, campaign, and public ticket context for completed draws.
Reward codes, Steam keys, private admin notes, moderation notes, and unrevealed giveaway inventory are not public.
Contact events
When a signed-in player clicks a contact action, we store the post ID, sender SteamID, receiver SteamID, selected action, and timestamp. This helps measure interest and keep the site reliable.
If the same signed-in player reopens the same LFG contact link later, we may open Steam again without creating another contact record or awarding extra XP.
Actual conversation happens on Steam. ggto.win does not read, send, or store Steam messages.
Share buttons
Owner share buttons create a public LFG URL and optional invite text. If your browser supports native sharing, your browser, operating system, or chosen app handles the share. ggto.win does not receive the destination app or the people you share with.
If native sharing is unavailable, the site copies the public LFG URL to your clipboard when your browser permits it.
Rewards, XP, and badges
If you use reward features, we store activity events such as LFG posts, contact clicks, closed posts, public library sync actions, XP changes, weekly ticket counts, challenge progress, badges, reward grants, and reveal timestamps.
Reward logs help protect giveaway fairness, prevent duplicate claims, and reduce reward misuse. Steam keys are stored encrypted before reveal and are only shown to the signed-in account that earned or won them.
We may store limited safety and moderation records when needed to keep rewards fair and reliable.
Fair giveaway checks
We use strict checks to keep giveaways fair, smooth, and resistant to misuse. These checks may consider account activity, reward activity, contact activity, form security results, and moderation status.
We do not publish exact review methods because that would make them easier to bypass.
Cookies and sessions
We use a secure session cookie to keep you logged in and protect forms. Session data is kept for up to 30 days unless you log out sooner.
We also use Google Analytics cookies to understand which pages work well and which pages need improvement. This analytics data is about site usage and performance, not your Steam account.
Google Analytics
ggto.win uses Google Analytics 4 to understand page views, traffic sources, devices, approximate location, and site usage so we can improve pages and site functionality.
We may link Google Analytics with Google Ads to measure ad performance and conversions such as sign-ins and posts. These conversions measure on-site actions and do not grant access to your Steam account.
Google Analytics is not used to access your Steam account and is not linked to your Steam login. We do not send SteamIDs, Steam profile URLs, Steam display names, or custom user IDs to Google Analytics.
Google says Analytics IP masking is built in for Google Analytics properties and IP addresses are not logged or stored. Google Analytics may still process browser, device, page, referrer, event, and approximate location data.
Who processes data
Core site data is stored and served through Cloudflare-hosted infrastructure. Cloudflare may also process safety checks when enabled. Steam processes Steam login, Steam Web API, and public Steam Store app data. Google processes Google Analytics data. Discord processes data if you use the floating support link.
Your choices
- Log out to delete the active session cookie from your browser.
- Close your own LFG posts from your account page.
- Use Steam privacy settings to control what Steam returns through public profile and library APIs.
- Use browser cookie controls or Google's Analytics opt-out add-on to reduce Analytics collection.
- Contact support through Discord to request account, reward, or post deletion where we can safely honor the request.
Security
Secrets stay server-side. We use standard protections for login sessions and form submissions.
No internet service is risk-free, so avoid putting sensitive personal data in public LFG notes.
Reference links