Last updated15 September 2026 OperatorBlackpine s.r.o. Governing lawCzech Republic

This Privacy Policy explains how Blackpine s.r.o., the company that operates SkinRogue, processes your personal data when you browse skinrogue.com, create an account, sign in with Steam, contact us or buy Counter-Strike 2 skins. We process personal data in accordance with Regulation (EU) 2016/679 (the General Data Protection Regulation, “GDPR”) and Czech Act No. 110/2019 Coll., on the Processing of Personal Data.

At a glance
  • Controller: Blackpine s.r.o., Prague, Czech Republic.
  • We use your data to deliver skins to your Steam inventory, run your account, take payment and meet our legal obligations.
  • We never sell your personal data.
  • Card details are handled by our payment service provider — we never see or store full card numbers.
  • You can access, correct, erase or export your data and object to processing at any time.
  • You may lodge a complaint with the Czech Office for Personal Data Protection.

01Who is responsible for your data

The controller of your personal data is Blackpine s.r.o., a limited liability company incorporated under the laws of the Czech Republic, with its registered office at 1512/22 Podskalská, Nové Město, 128 00 Prague 2, Czech Republic, Company ID (IČO) 30008603, registered in the Commercial Register maintained by the Municipal Court in Prague under File No. C 455773 (“we”, “us” or “SkinRogue”).

You can contact us about anything related to your personal data by email at info@skinrogue.com or by post at our registered office. We have not appointed a data protection officer; privacy requests are handled directly by our team.

02Scope of this policy

This policy applies to the processing of personal data of visitors, account holders and customers of skinrogue.com (the “Website”) and of anyone who communicates with us. It does not apply to third-party websites and services, including Steam, which is operated by Valve Corporation under its own privacy policy.

03Personal data we process

Category What it includes Source
Identification & contact data Name, username, email address, billing address and phone number (if provided) You
Account data Login credentials (passwords are stored only in hashed form), account settings and wishlist You
Steam data SteamID, public Steam profile name and avatar, Steam trade URL You; Steam, when you sign in with Steam
Order & transaction data Items ordered, prices, order history, invoices, and withdrawal, refund and complaint records You; us
Payment data Payment method, transaction reference and payment status. Card data are processed solely by the payment service provider Payment service provider
Communication data Content of emails, contact form messages and complaint correspondence You
Technical data IP address, browser and device type, date and time of access, pages requested, server and error logs Automatically
Cookie & attribution data Cookie identifiers, your consent choices and — only with your consent — how you reached the Website, such as the referring site or campaign Automatically

We do not intentionally process special categories of personal data within the meaning of Article 9 GDPR, and we ask you not to send them to us.

Purpose Legal basis Retention
Concluding and performing the contract, including delivering skins to your Steam inventory and customer support Performance of a contract — Art. 6(1)(b) GDPR For the duration of the contract and up to 4 years afterwards
Creating and managing your account, including sign-in with Steam Performance of a contract — Art. 6(1)(b) GDPR While your account is active; deleted or anonymised within 30 days of closure, unless the law requires longer retention
Processing payments, preventing fraud and securing transactions Performance of a contract, legal obligation and our legitimate interest in preventing fraud — Art. 6(1)(b), (c) and (f) GDPR Up to 4 years after the transaction, or until any dispute is resolved
Issuing and keeping invoices and accounting records Legal obligation — Art. 6(1)(c) GDPR, in particular Act No. 563/1991 Coll., on Accounting, and Czech tax legislation For the periods required by law, up to 10 years
Handling withdrawals, refunds and complaints, and establishing, exercising or defending legal claims Legal obligations under the Civil Code and the Consumer Protection Act, and our legitimate interest — Art. 6(1)(c) and (f) GDPR Up to 4 years after the matter is closed
Answering enquiries sent by email or through the contact form Performance of a contract (where the enquiry concerns an order) or legitimate interest — Art. 6(1)(b) or (f) GDPR Up to 2 years after the enquiry is closed
Operating and securing the Website, preventing abuse and fixing errors Legitimate interest — Art. 6(1)(f) GDPR Server logs are kept for a limited period (see below)
Order attribution — understanding how visitors find us Consent — Art. 6(1)(a) GDPR and Section 89(3) of Act No. 127/2005 Coll. Session only; see our Cookies Policy
Offering similar products to existing customers by email Legitimate interest — Art. 6(1)(f) GDPR and Section 7(3) of Act No. 480/2004 Coll.; you can unsubscribe at any time Until you object
Newsletters and other marketing communications to non-customers Consent — Art. 6(1)(a) GDPR Until you withdraw your consent

Where we rely on legitimate interests, we have balanced them against your interests, rights and freedoms. You can ask us for more information about this assessment.

05Is providing your data required?

Data marked as required at registration or checkout are necessary to conclude and perform the contract; without them we cannot accept your order or deliver your items. Providing any other data is voluntary.

06Sign in with Steam

If you choose “Sign in with Steam”, you are redirected to Steam, which is operated by Valve Corporation. Valve authenticates you and shares your SteamID and public profile information with us. We never receive your Steam password. Valve’s processing of your data is governed by the Steam privacy policy.

07Who receives your data

We share personal data only where necessary and only with the following categories of recipients:

  • payment service providers that process card and wallet payments (Visa, Mastercard, Google Pay, Apple Pay);
  • hosting, IT, email and infrastructure providers that operate the Website on our behalf;
  • Valve Corporation, to authenticate you via Steam and to deliver items through Steam trade offers;
  • professional advisers, such as accountants, auditors and lawyers, who are bound by confidentiality;
  • public authorities and courts, such as tax authorities, the Czech Trade Inspection Authority or law enforcement authorities, where the law requires us to do so; and
  • a successor in the event of a merger, acquisition or sale of our business, subject to this policy.

Service providers acting as processors process your data only on our instructions and under a data processing agreement meeting the requirements of Article 28 GDPR. We never sell your personal data.

08Transfers outside the European Economic Area

Some recipients, such as Valve Corporation or certain payment and IT providers, may process personal data outside the European Economic Area, including in the United States. We transfer personal data outside the EEA only where the law allows it: on the basis of an adequacy decision of the European Commission (including the EU–US Data Privacy Framework for certified recipients), standard contractual clauses approved by the European Commission or, where applicable, a derogation under Article 49 GDPR, for example where the transfer is necessary to perform a contract you have requested. You can ask us for information about the safeguards we rely on.

09How long we keep your data

We keep personal data only for as long as necessary for the purposes described above, as set out in the table. These periods reflect in particular the three-year general limitation period under Section 629 of the Czech Civil Code and our statutory accounting and tax obligations. Server logs are kept for a limited period, typically 10 days, unless longer retention is needed to investigate a security incident. When data are no longer needed, we delete or anonymise them securely.

10How we protect your data

We use appropriate technical and organisational measures to protect personal data, including encrypted connections (TLS/HTTPS), hashed passwords, access restricted on a need-to-know basis, regular software updates and backups, and payment processing by PCI DSS compliant providers. If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we notify the supervisory authority and, where required, you, in accordance with Articles 33 and 34 GDPR.

11Your rights

Under the GDPR you have the right to:

  • access your personal data and obtain a copy of them (Art. 15);
  • have inaccurate data rectified (Art. 16);
  • have your data erased (Art. 17);
  • restrict the processing of your data (Art. 18);
  • receive your data in a structured, machine-readable format and have them transmitted to another controller — data portability (Art. 20);
  • object to processing based on legitimate interests and, at any time, to direct marketing (Art. 21);
  • withdraw your consent at any time, without affecting the lawfulness of processing carried out before its withdrawal (Art. 7(3)); and
  • not be subject to a decision based solely on automated processing that produces legal effects concerning you or similarly significantly affects you (Art. 22).

To exercise your rights, email info@skinrogue.com. We may ask you to verify your identity. We respond free of charge within one month of receiving your request. Where necessary, taking into account the complexity and number of requests, this period may be extended by two further months; we will inform you of any extension and the reasons for it.

Right to lodge a complaint

You have the right to lodge a complaint with the supervisory authority, the Office for Personal Data Protection (Úřad pro ochranu osobních údajů), Pplk. Sochora 27, 170 00 Prague 7, Czech Republic, uoou.gov.cz. You may also turn to the supervisory authority in the EU Member State where you live or work or where the alleged infringement took place.

12Automated decision-making

To protect our customers and us against payment fraud, orders may be screened automatically. Such checks may delay an order or flag it for manual review, but we do not take decisions producing legal or similarly significant effects solely by automated means. You can always ask for human review, express your point of view and contest the decision.

13Children

The Website is intended only for persons aged 18 and over. We do not knowingly collect personal data of minors. If we learn that we have done so, we delete the data without undue delay.

14Changes to this policy

We may update this Privacy Policy to reflect changes in the law or in the way we process personal data. The current version is always available on this page together with its date. We will inform you of significant changes by email or by a notice on the Website.

15Contact

For any questions about this Privacy Policy or your personal data, contact us at info@skinrogue.com or write to Blackpine s.r.o., 1512/22 Podskalská, Nové Město, 128 00 Prague 2, Czech Republic.

Company details
SkinRogue is operated by Blackpine s.r.o.
Legal name
Blackpine s.r.o.
Registered office
1512/22 Podskalská, Nové Město, 128 00 Prague 2, Czech Republic
Company ID (IČO)
30008603
Commercial Register
File No. C 455773, Municipal Court in Prague