Cookie Policy
Skins Dealer · Cookie Policy · v1.0 · Effective 29 July 2026
| Field | Value |
| Operator | Pebletex OÜ |
| Company number | 17367621 |
| Registered office | Telliskivi tn 60a/5, Põhja-Tallinna linnaosa, 10412 Tallinn, Harju maakond, Estonia |
| Trading name / brand | Skins Dealer |
| Website | https://skins-dealer.com |
| Contact email | info@skins-dealer.com |
| Support / complaints | info@skins-dealer.com; Monday to Friday, 09:00-17:00 Eastern European Time / Eastern European Summer Time, excluding public holidays in Estonia |
| Governing law | Laws of Estonia, subject to mandatory consumer protections |
| Document version | v1.0 |
| Effective date | 29 July 2026 |
| Important: Necessary cookies support security, sessions, checkout and consent choices. Analytics, preference and marketing technologies are activated only after the consent required by law, and you may change that choice through the website’s cookie controls. |
1. Introduction and scope
This Cookie Policy explains how Skins Dealer uses cookies, local storage, pixels, software development kit functions and similar technologies on skins-dealer.com. It should be read with the Privacy Policy.
The policy applies to the public website, account area and checkout pages controlled by Pebletex OÜ. A Payment Provider or Supported Platform may set its own technologies under its own notice.
2. What cookies and similar technologies are
A cookie is a small text file stored by a browser. Local storage performs a similar function with different technical characteristics. Pixels and tags can record that a page or message was loaded. Server-side identifiers may link a browser session to security and transaction records.
Technologies may be session-based and expire when the browser closes, or persistent and remain for a stated period. First-party technologies are set for the Skins Dealer domain; third-party technologies are provided by another service.
3. Why we use cookies
We use technologies to keep sessions secure, prevent cross-site request forgery, remember consent, route checkout, retain selected preferences, detect abuse and maintain service reliability.
With consent, we may measure aggregate website performance, understand navigation, remember optional settings and evaluate marketing. We do not use non-essential technologies as a condition of buying a Digital Item.
4. Cookie categories
The category table describes the operational purpose of each group. The inventory below lists representative names used by the Service design; the live consent tool is the controlling source for technologies active on a particular device.
Cookie categories
| Category | Purpose | Consent required | Effect if disabled |
| Strictly necessary | Security, session, checkout, fraud controls and consent recording | No, where legally exempt as necessary | Login, checkout or preference recording may fail |
| Functional / preferences | Remember optional language, interface and account choices | Yes, unless essential to a requested function | Selections may need to be re-entered |
| Analytics / performance | Measure traffic, errors and feature performance in aggregate | Yes | Core Service remains available; measurement is reduced |
| Marketing | Measure campaigns or present relevant promotions | Yes | Core Service remains available; promotions are less tailored |
5. Lawful basis and consent
European cookie rules generally require prior consent for technologies that are not strictly necessary. Necessary storage is used to provide the service or communication you request and to maintain security. Non-essential categories remain disabled until a valid choice is recorded.
Consent is freely given, specific and withdrawable. Refusing analytics or marketing does not increase the price or prevent ordinary checkout. A new choice may be requested after a reasonable period or when the inventory materially changes.
6. Cookie inventory and technology details
Technology labels and provider details may differ according to the production configuration. The table therefore identifies controlled technology classes and maximum ordinary lifetimes; the live consent interface and browser storage are the controlling sources for technologies active on a particular device.
Cookie and technology inventory
| Technology class | Type | Purpose | Typical duration | Responsible party |
| Session identifier | Strictly necessary; first party | Maintains authenticated and checkout session | Session | Skins Dealer / hosting provider |
| Request-integrity token | Strictly necessary; first party | Protects forms and account actions from forged requests | Session | Skins Dealer / hosting provider |
| Consent preference record | Strictly necessary; first party | Stores category choices, policy version and consent timestamp | Up to 12 months | Skins Dealer / consent provider |
| Interface preference storage | Functional; first party | Remembers optional language, interface and catalogue preferences | Up to 6 months | Skins Dealer |
| Device-risk identifier | Strictly necessary; provider-linked | Supports payment authentication, fraud screening and abuse controls | Provider-defined; ordinarily no longer than 13 months | Payment / fraud-prevention provider |
| Aggregate analytics identifier | Analytics; first party or provider-linked | Measures page performance, errors and aggregate navigation after consent | Up to 13 months | Configured analytics provider |
| Campaign attribution identifier | Marketing; provider-linked | Attributes consenting campaign visits and conversions | Up to 90 days | Configured marketing provider |
| Basket state storage | Strictly necessary; first party | Retains the selected item during checkout | Until checkout completion or up to 24 hours | Skins Dealer / hosting provider |
7. Third-party cookies and embedded services
Payment interfaces, fraud checks, support tools and embedded content may create third-party requests. Necessary payment technologies may operate when you actively open checkout. Optional analytics or marketing services operate only after the required consent.
Third parties may combine information under their own terms where they act independently. We select providers for a defined function and limit the data shared where reasonably possible.
8. Managing preferences
Use the cookie banner or “Cookie settings” control to accept, reject or change non-essential categories. Browser settings can also block or delete storage, but broad blocking may disrupt login, security and checkout.
Withdrawing consent prevents future optional processing on the device after the settings update. It does not invalidate processing carried out before withdrawal. You may need to repeat the choice on another browser, device or private-browsing session.
9. Retention and review
Each technology expires according to the inventory or is deleted earlier when you clear browser data. Server records linked to security, transactions or consent are retained under the Privacy Policy rather than solely by cookie lifetime.
We review the inventory after material releases, provider changes and at least every six months. Obsolete technologies are removed, durations are checked and the consent interface is updated before new optional categories are activated.
10. Do-Not-Track and browser signals
Some browsers send Do-Not-Track signals, but there is no uniform industry interpretation. We therefore use the consent interface as the primary control for optional cookies.
Where a legally recognised opt-out signal applies, we will honour it for the processing within its scope. A signal does not disable storage that is strictly necessary for security or a requested transaction.
11. Children and age
The Service is for users aged 18 or older. We do not design cookie-based profiling for children or knowingly use children’s data for targeted advertising.
If an underage user has accessed the Service, a parent or responsible adult may contact us so that the Account and associated optional identifiers can be reviewed.
12. International data flows
Technology providers may operate infrastructure outside Estonia or the European Economic Area. Where personal data is transferred internationally, the safeguards described in the Privacy Policy apply.
Cookie consent does not itself replace a required transfer safeguard. Provider configuration and contracts are assessed separately.
13. Changes
We may update this policy and inventory when the website, providers, law or consent standards change. The effective date identifies the current version.
A material new optional purpose requires a new consent choice where the law requires. Existing necessary storage may be updated to maintain security or compatibility.
14. Contact
Questions about cookies or consent may be sent to info@skins-dealer.com or by post to Pebletex OÜ, Telliskivi tn 60a/5, Põhja-Tallinna linnaosa, 10412 Tallinn, Harju maakond, Estonia.
Include the browser, device and approximate date of the issue, but do not send passwords or full payment details.
Operational Maintenance Checklist
Review control
| Control | Frequency / trigger | Evidence | Required action |
| Automated technology scan | Before release and monthly | Scan export and detected storage list | Classify new technology before activation |
| Consent-banner test | Before release and quarterly | Screenshots and network test | Confirm optional requests are blocked before consent |
| Inventory reconciliation | Every six months | Approved inventory version | Update names, providers, purposes and durations |
| Provider review | On onboarding or material change | Contract, privacy and transfer review | Restrict scope or replace provider if needed |
| Withdrawal test | Quarterly | Recorded test result | Confirm future optional requests stop after withdrawal |
| Publication review | After any material change | Version and effective date | Publish updated policy and request renewed consent where required |
Schedule 1. Consent and Technology Governance
This schedule describes the controls used to keep cookie and similar-technology deployment aligned with user choices, security needs and the published inventory.
Consent event records
When an optional technology requires consent, the consent interface should record the decision, the categories selected, the policy version, a timestamp and a pseudonymous browser or device identifier. These records are used to demonstrate that a choice was obtained and to honour later withdrawal. They are not used to reconstruct full browsing histories. A renewed choice may be requested after a material purpose change, a significant inventory change or expiry of the applicable consent period.
Necessary storage and checkout continuity
Strictly necessary technologies may preserve session integrity, remember a basket, route traffic, prevent cross-site request forgery, maintain load-balancer affinity and keep a checkout state long enough to complete an Order. Blocking them can prevent sign-in, payment authorisation, fraud screening or delivery-status display. Their use is limited to providing the service requested by the user, securing the Website or meeting an applicable legal obligation; they are not repurposed for optional behavioural advertising.
Payment and fraud-prevention technologies
Payment providers and fraud-prevention vendors may set or read identifiers during checkout to authenticate a user, apply Strong Customer Authentication where required, detect repeated attempts, identify automated abuse and correlate a transaction with a risk event. The provider controls the technical lifetime of its own identifiers within its documented rules. Skins Dealer limits the data sent to what is needed for payment and security, and does not receive a user’s complete card number or card security code.
Preference withdrawal mechanics
Withdrawing consent stops future use of the affected optional category from the point at which the preference is processed. It does not retroactively invalidate processing carried out under a valid earlier choice, and it may not erase identifiers already placed by a third party until they expire or are deleted through that provider or the browser. Users should therefore use both the Website preference control and browser or device controls when they want the broadest practical reset.
Browser changes and identifier loss
A preference may appear to reset after cookies are cleared, a browser profile is replaced, private-browsing mode is used, a device is changed or a consent identifier cannot be read. In those cases, the Website may present the choice again. Separate browsers and devices maintain separate preference states unless an authenticated preference mechanism explicitly synchronises them. Users should make their selection on each relevant environment.
Inventory verification and deployment control
Before a new script, tag, software development kit or embedded feature is released, its owner, provider, purpose, data elements, duration, category and activation condition should be documented. Optional technology should remain disabled until the applicable consent signal exists. Periodic scans and manual checks should compare the deployed environment with the published inventory, remove obsolete tags and verify that rejected categories do not fire except where a narrowly defined necessary function applies.
Incident handling
A technology that behaves outside its approved purpose, activates before consent, transmits unexpected data or cannot be disabled should be suspended where technically feasible and referred for privacy and security review. The review should identify affected users and periods, determine whether notification or remedial consent is required, correct the configuration and preserve proportionate evidence. A cookie complaint is handled together with any related access, erasure or objection request under the Privacy Policy.
User diagnostic route
For a consent or cookie malfunction, the user should identify the browser and version, device type, approximate time, preference selected and the page on which the issue occurred. Screenshots may help, provided they do not show passwords, authentication codes or complete payment data. Support may ask the user to test a fresh session, clear a specific site identifier or disable a conflicting extension before escalation to the relevant technology provider.
Skins Dealer · Cookie Policy · v1.0 · Effective 29 July 2026. The version made available through the Website is the controlling customer-facing version.
