Legal
Privacy Policy
Last updated: February 2026
1. Introduction
SKINS24 ("we," "us," or "our") is the operator of www.skins24.co.uk, a digital marketplace dedicated to CS2 cosmetic items. This Privacy Policy describes how we gather, utilise, share, and safeguard your personal information when you interact with our platform. We are fully committed to upholding your privacy in compliance with the General Data Protection Regulation (GDPR) and all other relevant data protection legislation.
By making use of our platform, you confirm that you have reviewed and understood the contents of this Privacy Policy.
2. Information We Collect
Account Information: When you authenticate through Steam OAuth, we obtain your Steam ID, display name, and profile avatar. Your Steam password is never transmitted to or stored by us.
Transaction Data: We maintain records of purchases conducted on our platform, encompassing order specifics, item details, transaction values, and timestamps. Your payment card credentials are handled solely by our PCI DSS certified payment processor and never reside on our infrastructure.
Technical Data: We automatically capture your IP address, browser type and version, operating system, device identifiers, referral URLs, and pages viewed. This information is gathered via server logs and analytical tools.
Communication Data: Should you reach out to our support team, we retain the substance of your correspondence together with any details you voluntarily share.
3. How We Use Your Information
Your personal information is used for the following purposes: establishing and managing your account; processing transactions and delivering purchased items via Steam trade offers; responding to support enquiries and providing assistance; identifying and preventing fraud, money laundering, and other prohibited conduct; meeting legal obligations under EU tax and accounting regulations; enhancing platform functionality, analysing usage trends, and improving the user experience; and issuing transactional notifications regarding your purchases and account activity.
We do not employ your personal information for behavioural advertising or user profiling. Marketing communications are only sent where you have provided explicit opt-in consent, and you may revoke that consent at any time.
4. Legal Basis for Processing
We rely on the following lawful grounds for processing your personal data, as set out by the GDPR:
Contract Performance: Processing that is necessary to deliver on our commitments when you purchase items or engage with our services.
Legitimate Interests: Processing undertaken for fraud prevention, platform security, and service enhancement, provided these interests do not override your fundamental rights.
Legal Obligations: Processing that is mandated by applicable legislation, including anti-money laundering rules and tax reporting duties.
Consent: Processing founded on your explicit agreement, such as marketing emails and non-essential cookies.
5. Data Sharing
We disclose your data only to the following categories of recipients, and strictly to the extent required:
Steam / Valve Corporation: Your Steam ID is used to verify your identity and to execute item trades.
BitSkins: Transaction information is shared to enable item procurement and delivery.
Payment Processor: Payment details are transmitted directly to our authorised payment service provider for transaction authorisation and settlement.
Infrastructure Providers: We utilise cloud hosting and content delivery networks that may process data on our behalf, subject to robust data processing agreements.
Legal Authorities: We may release information where compelled by law or in response to valid legal requests.
We never sell your personal information to third parties.
6. Data Retention
We hold your personal data only for as long as it is needed to achieve the objectives described in this policy or as mandated by law. Account information is kept for the life of your account plus 6 years thereafter. Transaction records are preserved for 7 years in accordance with EU tax and accounting requirements. Server and technical logs are retained for 90 days. Support-related correspondence is kept for 3 years.
Once the relevant retention period expires, your data is securely destroyed or irreversibly anonymised.
7. Data Security
We maintain suitable technical and organisational safeguards to shield your personal data from unauthorised access, modification, disclosure, or loss. These safeguards include TLS encryption for all data in transit, encryption at rest for stored information, role-based access controls and authentication protocols, and periodic security reviews.
If a data breach occurs that could endanger your rights and freedoms, we will report it to the appropriate supervisory authority within 72 hours and notify affected individuals without undue delay, in accordance with the GDPR.
8. Your Rights
Under the GDPR, you are entitled to the following rights in relation to your personal data: the right to obtain a copy of the data we hold about you; the right to have inaccurate or incomplete data corrected; the right to request deletion of your data, subject to any legal retention obligations; the right to limit processing in specific circumstances; the right to receive your data in a structured, commonly used, machine-readable format; the right to challenge processing conducted on the basis of legitimate interests; and the right to revoke consent at any time where processing relies on consent.
To invoke any of these rights, please write to legal@skins24.co.uk. We will address your request within 30 days of receipt.
9. International Data Transfers
Your data is principally processed within the European Union. Where it is necessary to transfer data to countries outside the EU — for instance, to Steam/Valve in the United States — we ensure that appropriate protective measures are in place, including Standard Contractual Clauses endorsed by the European Commission.
10. Children's Privacy
Our services are not designed for or directed at individuals under 18 years of age. We do not intentionally collect personal data from minors. Should we discover that a minor has submitted personal information to us, we will take prompt action to remove that data from our systems.
11. Changes to This Policy
We may revise this Privacy Policy periodically to reflect developments in our practices or in applicable law. Significant changes will be communicated by email or through a conspicuous notice on our website. The "Last updated" date at the top of this page indicates when the most recent revision was made.
For questions about this policy, contact us at legal@skins24.co.uk