Browser Extension Privacy Policy
Effective Date: 25th September 2026
This policy describes how the CS2 Skin Compare - Skinstrack browser extension (version 4.0, for Chromium-based browsers) handles data. It covers what the extension reads, what it stores on your device, what it sends to our servers and to Steam, and which permissions it requests and why. The lists below match the extension manifest exactly. If you have questions not answered here, reach out via our Discord or email before installing.
1. What the Extension Does
The extension shows CS2 skin prices and values on Steam and on CS2 marketplaces so you can price, compare and trade your items without leaving the page:
- Steam inventory - a value bar (market value, Steam value, items priced, most valuable items), price labels on item tiles, float, paint seed, Doppler phase, trade lock and sticker details in the item panel, extra sort orders, and an optional reminder for when a trade-locked item becomes tradable.
- Steam Market - on CS2 listing pages a panel compares the Steam price with the lowest marketplace price, each listing row shows its float and seed, and a small toolbar adds a float filter, a float sort and a listings per page selector.
- Steam trade offers - in a trade offer window the extension shows item prices and the value of what you give and receive. On your trade offers list it shows the same per offer, a summary, a sort by profit and warnings for risky offers (you give items and receive nothing, a large loss, mostly unpriced items, a trade hold, or a partner whose name matches one of your friends but is a different account). A trade offer link can carry a
my_itemparameter that pre-selects one of your items in the offer window; you still review and send the offer yourself. - Trade offer alerts (optional) - when you turn this on, the extension checks your incoming offers every 2 minutes, shows the number of active offers on the toolbar icon and sends a browser notification for each new offer.
- Marketplace price badges - on supported CS2 marketplaces the extension reads item names from the page and adds a badge with the Skinstrack price breakdown for that item.
- Inventory sync - from the popup you can send your CS2 inventory to your Skinstrack account, once or automatically every 24 hours.
The extension never sends, accepts or declines a trade offer, never buys, sells or lists an item and never places a bid or an order. Everything it adds to a page is read-only apart from pre-selecting an item in a trade offer window you opened yourself.
2. Permissions Requested
Required permissions, requested at install:
- storage - keeps your settings and the local data listed in section 4 in
chrome.storage.local. Nothing is written to Chrome sync storage. - alarms - schedules the optional 24 hour inventory sync, the optional 2 minute trade offer check and the trade unlock reminders you set. Turning a feature off clears its alarm.
- tabs - finds or opens your Steam inventory tab when you click Sync inventory in the popup, and opens the offer or item when you click a notification.
Optional permissions, requested only when you turn the matching feature on in the popup settings, and revocable at any time from the Chrome extensions page:
- notifications - browser notifications for new incoming trade offers and for trade unlock reminders. They are never used for promotions or announcements.
- api.steampowered.com - lets the extension ask Steam for your trade offers (see section 7). Needed for the trade offers list values and for trade offer alerts.
3. Websites the Extension Runs On
The extension has host permissions for these domains and runs content scripts only on the listed pages:
- steamcommunity.com - inventory pages, CS2 Steam Market listing pages, trade offer windows and the trade offers list.
- api.skinstrack.com - our API (section 5).
- buff.163.com, csfloat.com, cs.money, dmarket.com, market.csgo.com - marketplace price badges.
- api.frankfurter.app - exchange rates (section 6).
On marketplace pages the extension reads item names and listing prices from the page only. It does not read your account details, order history, wallet balance or any other information on those sites.
4. Data Stored on Your Device
Everything below lives in chrome.storage.local or session storage on your device and is removed when you uninstall the extension:
- Steam ID - your 64-bit Steam ID, resolved from your profile URL on install and on browser startup.
- Settings - which features are on, your display currency (picked up once from your Steam wallet currency), and the auto sync preference.
- Inventory summary - the last calculated market and Steam value of your inventory and the last sync time, shown in the popup.
- Daily activity - two counters reset each day: items checked and potential savings.
- Caches - price lookups for 15 minutes, exchange rates for 8 hours, and, while you use the trade offers page, your Steam friends list for 1 hour so the friend-name warning can run locally.
- Steam access token - when the trade offers feature or trade offer alerts are on, the short-lived web session token Steam issues to your logged-in browser is stored so the extension can ask Steam for your offers. It is only ever sent to Steam, never to Skinstrack or anyone else, and it expires on its own.
- Trade offer and reminder state - the ids of offers you were already notified about, and the items you asked to be reminded about.
5. Data Sent to Skinstrack
The extension talks to api.skinstrack.com for these purposes:
- Price lookups - the item names (
market_hash_name, plus the Doppler phase or sticker and charm names when shown) of the items visible on the page are sent and the current prices come back. Every request carries the extension version and, when known, your Steam ID as an identifier used for abuse prevention and usage limits. If you are signed in to skinstrack.com in the same browser profile, your session cookie is included so the popup can show your account and plan. - Inventory sync - when you click Sync inventory or enable auto sync, the extension reads your CS2 inventory from Steam using your existing Steam session and sends the item names, counts and trade lock dates to your Skinstrack account. This requires you to be signed in at skinstrack.com; otherwise nothing is sent.
We do not send asset ids, inspect links, float values, stickers on your items, your trade offers, your trade partners, your friends list or your Steam access token. Trade offer values and warnings are computed on your device from prices fetched by item name. Synced inventory data is stored under your account and governed by the same privacy and terms rules as the main Skinstrack service.
Use of information received from the extension adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements.
6. Third-Party Network Requests
- api.frankfurter.app - a free, open exchange rate API. The extension fetches USD conversion rates so prices can be shown in your display currency. It is a plain GET request with no identifiers.
The extension does not embed advertising scripts, analytics SDKs or any other third-party tracking code, and it loads no code from the network.
7. Steam Data Access
All requests to Steam use your existing browser session, the same way Steam's own pages do. The extension never reads or stores your password, Steam Guard codes or cookies.
- Profile - one request to
steamcommunity.com/my/on install and on browser startup to resolve your Steam ID, and, when trade offer features are on, to read the web session token described in section 4. - Inventory - the Steam inventory JSON for your CS2 items, used for the value bar, the item details and the sync.
- Trade offers - with the optional api.steampowered.com permission, your active trade offers and their item descriptions.
- Friends and partner names - on your trade offers list, your friends page and the public mini profile of an offer partner who is not your friend, so the friend-name warning can compare display names on your device.
- Market listings- when you change the listings per page, the same listing request Steam's page makes, with a different page size.
8. Marketplace Links and Referral Codes
Buy links and marketplace rows in the extension open throughapi.skinstrack.com/v1/redirect, which forwards you to the marketplace listing and may add a Skinstrack referral or affiliate code to the link. This happens only when you click a link. Referral codes never change the price you pay, and Skinstrack may receive a commission from the marketplace. The extension never links to case-opening, gambling or betting sites.
9. What We Don't Do
- We do not read or store your passwords, Steam Guard codes or session cookies.
- We do not send, accept or decline trade offers, and we do not buy, sell or list items.
- We do not ask for or create a Steam Web API key.
- We do not sell, share or rent your data to third parties.
- We do not run any code outside the listed host permissions and we load no remote code.
- We do not use Chrome sync storage; all local data stays on your device.
- We do not send notifications for anything other than the offer and reminder events you turned on.
10. Removing the Extension
Uninstalling the extension removes all locally stored data immediately, including the Steam access token. Inventory data previously synced to your Skinstrack account remains on our servers as part of your account and can be deleted by deleting your account or contacting us directly.
11. Updates to This Policy
If we change what data the extension accesses or how we handle it, we will update the effective date above and post a notice on our Discord. Material changes, such as a new site the extension runs on or new categories of data sent to our servers, will also be described in the Chrome Web Store release notes for that version. Continued use of the extension after a policy update means you accept the new terms.
Questions about this policy can be directed to our Discord community or by email. Links to both are available on the main skinstrack.com homepage.