Privacy Policy
This Privacy Policy explains how Blackpine s.r.o., the company that operates SkinRogue, processes your personal data when you browse skinrogue.com, create an account, sign in with Steam, contact us or buy Counter-Strike 2 skins. We process personal data in accordance with Regulation (EU) 2016/679 (the General Data Protection Regulation, “GDPR”) and Czech Act No. 110/2019 Coll., on the Processing of Personal Data.
- Controller: Blackpine s.r.o., Prague, Czech Republic.
- We use your data to deliver skins to your Steam inventory, run your account, take payment and meet our legal obligations.
- We never sell your personal data.
- Card details are handled by our payment service provider — we never see or store full card numbers.
- You can access, correct, erase or export your data and object to processing at any time.
- You may lodge a complaint with the Czech Office for Personal Data Protection.
01Who is responsible for your data
The controller of your personal data is Blackpine s.r.o., a limited liability company incorporated under the laws of the Czech Republic, with its registered office at 1512/22 Podskalská, Nové Město, 128 00 Prague 2, Czech Republic, Company ID (IČO) 30008603, registered in the Commercial Register maintained by the Municipal Court in Prague under File No. C 455773 (“we”, “us” or “SkinRogue”).
You can contact us about anything related to your personal data by email at info@skinrogue.com or by post at our registered office. We have not appointed a data protection officer; privacy requests are handled directly by our team.
02Scope of this policy
This policy applies to the processing of personal data of visitors, account holders and customers of skinrogue.com (the “Website”) and of anyone who communicates with us. It does not apply to third-party websites and services, including Steam, which is operated by Valve Corporation under its own privacy policy.
03Personal data we process
| Category | What it includes | Source |
|---|---|---|
| Identification & contact data | Name, username, email address, billing address and phone number (if provided) | You |
| Account data | Login credentials (passwords are stored only in hashed form), account settings and wishlist | You |
| Steam data | SteamID, public Steam profile name and avatar, Steam trade URL | You; Steam, when you sign in with Steam |
| Order & transaction data | Items ordered, prices, order history, invoices, and withdrawal, refund and complaint records | You; us |
| Payment data | Payment method, transaction reference and payment status. Card data are processed solely by the payment service provider | Payment service provider |
| Communication data | Content of emails, contact form messages and complaint correspondence | You |
| Technical data | IP address, browser and device type, date and time of access, pages requested, server and error logs | Automatically |
| Cookie & attribution data | Cookie identifiers, your consent choices and — only with your consent — how you reached the Website, such as the referring site or campaign | Automatically |
We do not intentionally process special categories of personal data within the meaning of Article 9 GDPR, and we ask you not to send them to us.
04Why we process your data and on what legal basis
| Purpose | Legal basis | Retention |
|---|---|---|
| Concluding and performing the contract, including delivering skins to your Steam inventory and customer support | Performance of a contract — Art. 6(1)(b) GDPR | For the duration of the contract and up to 4 years afterwards |
| Creating and managing your account, including sign-in with Steam | Performance of a contract — Art. 6(1)(b) GDPR | While your account is active; deleted or anonymised within 30 days of closure, unless the law requires longer retention |
| Processing payments, preventing fraud and securing transactions | Performance of a contract, legal obligation and our legitimate interest in preventing fraud — Art. 6(1)(b), (c) and (f) GDPR | Up to 4 years after the transaction, or until any dispute is resolved |
| Issuing and keeping invoices and accounting records | Legal obligation — Art. 6(1)(c) GDPR, in particular Act No. 563/1991 Coll., on Accounting, and Czech tax legislation | For the periods required by law, up to 10 years |
| Handling withdrawals, refunds and complaints, and establishing, exercising or defending legal claims | Legal obligations under the Civil Code and the Consumer Protection Act, and our legitimate interest — Art. 6(1)(c) and (f) GDPR | Up to 4 years after the matter is closed |
| Answering enquiries sent by email or through the contact form | Performance of a contract (where the enquiry concerns an order) or legitimate interest — Art. 6(1)(b) or (f) GDPR | Up to 2 years after the enquiry is closed |
| Operating and securing the Website, preventing abuse and fixing errors | Legitimate interest — Art. 6(1)(f) GDPR | Server logs are kept for a limited period (see below) |
| Order attribution — understanding how visitors find us | Consent — Art. 6(1)(a) GDPR and Section 89(3) of Act No. 127/2005 Coll. | Session only; see our Cookies Policy |
| Offering similar products to existing customers by email | Legitimate interest — Art. 6(1)(f) GDPR and Section 7(3) of Act No. 480/2004 Coll.; you can unsubscribe at any time | Until you object |
| Newsletters and other marketing communications to non-customers | Consent — Art. 6(1)(a) GDPR | Until you withdraw your consent |
Where we rely on legitimate interests, we have balanced them against your interests, rights and freedoms. You can ask us for more information about this assessment.
05Is providing your data required?
Data marked as required at registration or checkout are necessary to conclude and perform the contract; without them we cannot accept your order or deliver your items. Providing any other data is voluntary.
06Sign in with Steam
If you choose “Sign in with Steam”, you are redirected to Steam, which is operated by Valve Corporation. Valve authenticates you and shares your SteamID and public profile information with us. We never receive your Steam password. Valve’s processing of your data is governed by the Steam privacy policy.
07Who receives your data
We share personal data only where necessary and only with the following categories of recipients:
- payment service providers that process card and wallet payments (Visa, Mastercard, Google Pay, Apple Pay);
- hosting, IT, email and infrastructure providers that operate the Website on our behalf;
- Valve Corporation, to authenticate you via Steam and to deliver items through Steam trade offers;
- professional advisers, such as accountants, auditors and lawyers, who are bound by confidentiality;
- public authorities and courts, such as tax authorities, the Czech Trade Inspection Authority or law enforcement authorities, where the law requires us to do so; and
- a successor in the event of a merger, acquisition or sale of our business, subject to this policy.
Service providers acting as processors process your data only on our instructions and under a data processing agreement meeting the requirements of Article 28 GDPR. We never sell your personal data.
08Transfers outside the European Economic Area
Some recipients, such as Valve Corporation or certain payment and IT providers, may process personal data outside the European Economic Area, including in the United States. We transfer personal data outside the EEA only where the law allows it: on the basis of an adequacy decision of the European Commission (including the EU–US Data Privacy Framework for certified recipients), standard contractual clauses approved by the European Commission or, where applicable, a derogation under Article 49 GDPR, for example where the transfer is necessary to perform a contract you have requested. You can ask us for information about the safeguards we rely on.
09How long we keep your data
We keep personal data only for as long as necessary for the purposes described above, as set out in the table. These periods reflect in particular the three-year general limitation period under Section 629 of the Czech Civil Code and our statutory accounting and tax obligations. Server logs are kept for a limited period, typically 10 days, unless longer retention is needed to investigate a security incident. When data are no longer needed, we delete or anonymise them securely.
10How we protect your data
We use appropriate technical and organisational measures to protect personal data, including encrypted connections (TLS/HTTPS), hashed passwords, access restricted on a need-to-know basis, regular software updates and backups, and payment processing by PCI DSS compliant providers. If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we notify the supervisory authority and, where required, you, in accordance with Articles 33 and 34 GDPR.
11Your rights
Under the GDPR you have the right to:
- access your personal data and obtain a copy of them (Art. 15);
- have inaccurate data rectified (Art. 16);
- have your data erased (Art. 17);
- restrict the processing of your data (Art. 18);
- receive your data in a structured, machine-readable format and have them transmitted to another controller — data portability (Art. 20);
- object to processing based on legitimate interests and, at any time, to direct marketing (Art. 21);
- withdraw your consent at any time, without affecting the lawfulness of processing carried out before its withdrawal (Art. 7(3)); and
- not be subject to a decision based solely on automated processing that produces legal effects concerning you or similarly significantly affects you (Art. 22).
To exercise your rights, email info@skinrogue.com. We may ask you to verify your identity. We respond free of charge within one month of receiving your request. Where necessary, taking into account the complexity and number of requests, this period may be extended by two further months; we will inform you of any extension and the reasons for it.
You have the right to lodge a complaint with the supervisory authority, the Office for Personal Data Protection (Úřad pro ochranu osobních údajů), Pplk. Sochora 27, 170 00 Prague 7, Czech Republic, uoou.gov.cz. You may also turn to the supervisory authority in the EU Member State where you live or work or where the alleged infringement took place.
12Automated decision-making
To protect our customers and us against payment fraud, orders may be screened automatically. Such checks may delay an order or flag it for manual review, but we do not take decisions producing legal or similarly significant effects solely by automated means. You can always ask for human review, express your point of view and contest the decision.
13Children
The Website is intended only for persons aged 18 and over. We do not knowingly collect personal data of minors. If we learn that we have done so, we delete the data without undue delay.
14Changes to this policy
We may update this Privacy Policy to reflect changes in the law or in the way we process personal data. The current version is always available on this page together with its date. We will inform you of significant changes by email or by a notice on the Website.
15Contact
For any questions about this Privacy Policy or your personal data, contact us at info@skinrogue.com or write to Blackpine s.r.o., 1512/22 Podskalská, Nové Město, 128 00 Prague 2, Czech Republic.
- Legal name
- Blackpine s.r.o.
- Registered office
- 1512/22 Podskalská, Nové Město, 128 00 Prague 2, Czech Republic
- Company ID (IČO)
- 30008603
- Commercial Register
- File No. C 455773, Municipal Court in Prague
- info@skinrogue.com