Cookie Policy

Skins Dealer · Cookie Policy · v1.0 · Effective 29 July 2026

FieldValue
OperatorPebletex OÜ
Company number17367621
Registered officeTelliskivi tn 60a/5, Põhja-Tallinna linnaosa, 10412 Tallinn, Harju maakond, Estonia
Trading name / brandSkins Dealer
Websitehttps://skins-dealer.com
Contact emailinfo@skins-dealer.com
Support / complaintsinfo@skins-dealer.com; Monday to Friday, 09:00-17:00 Eastern European Time / Eastern European Summer Time, excluding public holidays in Estonia
Governing lawLaws of Estonia, subject to mandatory consumer protections
Document versionv1.0
Effective date29 July 2026
Important: Necessary cookies support security, sessions, checkout and consent choices. Analytics, preference and marketing technologies are activated only after the consent required by law, and you may change that choice through the website’s cookie controls.

1. Introduction and scope

This Cookie Policy explains how Skins Dealer uses cookies, local storage, pixels, software development kit functions and similar technologies on skins-dealer.com. It should be read with the Privacy Policy.

The policy applies to the public website, account area and checkout pages controlled by Pebletex OÜ. A Payment Provider or Supported Platform may set its own technologies under its own notice.

2. What cookies and similar technologies are

A cookie is a small text file stored by a browser. Local storage performs a similar function with different technical characteristics. Pixels and tags can record that a page or message was loaded. Server-side identifiers may link a browser session to security and transaction records.

Technologies may be session-based and expire when the browser closes, or persistent and remain for a stated period. First-party technologies are set for the Skins Dealer domain; third-party technologies are provided by another service.

3. Why we use cookies

We use technologies to keep sessions secure, prevent cross-site request forgery, remember consent, route checkout, retain selected preferences, detect abuse and maintain service reliability.

With consent, we may measure aggregate website performance, understand navigation, remember optional settings and evaluate marketing. We do not use non-essential technologies as a condition of buying a Digital Item.

4. Cookie categories

The category table describes the operational purpose of each group. The inventory below lists representative names used by the Service design; the live consent tool is the controlling source for technologies active on a particular device.

Cookie categories

CategoryPurposeConsent requiredEffect if disabled
Strictly necessarySecurity, session, checkout, fraud controls and consent recordingNo, where legally exempt as necessaryLogin, checkout or preference recording may fail
Functional / preferencesRemember optional language, interface and account choicesYes, unless essential to a requested functionSelections may need to be re-entered
Analytics / performanceMeasure traffic, errors and feature performance in aggregateYesCore Service remains available; measurement is reduced
MarketingMeasure campaigns or present relevant promotionsYesCore Service remains available; promotions are less tailored

5. Lawful basis and consent

European cookie rules generally require prior consent for technologies that are not strictly necessary. Necessary storage is used to provide the service or communication you request and to maintain security. Non-essential categories remain disabled until a valid choice is recorded.

Consent is freely given, specific and withdrawable. Refusing analytics or marketing does not increase the price or prevent ordinary checkout. A new choice may be requested after a reasonable period or when the inventory materially changes.

6. Cookie inventory and technology details

Technology labels and provider details may differ according to the production configuration. The table therefore identifies controlled technology classes and maximum ordinary lifetimes; the live consent interface and browser storage are the controlling sources for technologies active on a particular device.

Cookie and technology inventory

Technology classTypePurposeTypical durationResponsible party
Session identifierStrictly necessary; first partyMaintains authenticated and checkout sessionSessionSkins Dealer / hosting provider
Request-integrity tokenStrictly necessary; first partyProtects forms and account actions from forged requestsSessionSkins Dealer / hosting provider
Consent preference recordStrictly necessary; first partyStores category choices, policy version and consent timestampUp to 12 monthsSkins Dealer / consent provider
Interface preference storageFunctional; first partyRemembers optional language, interface and catalogue preferencesUp to 6 monthsSkins Dealer
Device-risk identifierStrictly necessary; provider-linkedSupports payment authentication, fraud screening and abuse controlsProvider-defined; ordinarily no longer than 13 monthsPayment / fraud-prevention provider
Aggregate analytics identifierAnalytics; first party or provider-linkedMeasures page performance, errors and aggregate navigation after consentUp to 13 monthsConfigured analytics provider
Campaign attribution identifierMarketing; provider-linkedAttributes consenting campaign visits and conversionsUp to 90 daysConfigured marketing provider
Basket state storageStrictly necessary; first partyRetains the selected item during checkoutUntil checkout completion or up to 24 hoursSkins Dealer / hosting provider

7. Third-party cookies and embedded services

Payment interfaces, fraud checks, support tools and embedded content may create third-party requests. Necessary payment technologies may operate when you actively open checkout. Optional analytics or marketing services operate only after the required consent.

Third parties may combine information under their own terms where they act independently. We select providers for a defined function and limit the data shared where reasonably possible.

8. Managing preferences

Use the cookie banner or “Cookie settings” control to accept, reject or change non-essential categories. Browser settings can also block or delete storage, but broad blocking may disrupt login, security and checkout.

Withdrawing consent prevents future optional processing on the device after the settings update. It does not invalidate processing carried out before withdrawal. You may need to repeat the choice on another browser, device or private-browsing session.

9. Retention and review

Each technology expires according to the inventory or is deleted earlier when you clear browser data. Server records linked to security, transactions or consent are retained under the Privacy Policy rather than solely by cookie lifetime.

We review the inventory after material releases, provider changes and at least every six months. Obsolete technologies are removed, durations are checked and the consent interface is updated before new optional categories are activated.

10. Do-Not-Track and browser signals

Some browsers send Do-Not-Track signals, but there is no uniform industry interpretation. We therefore use the consent interface as the primary control for optional cookies.

Where a legally recognised opt-out signal applies, we will honour it for the processing within its scope. A signal does not disable storage that is strictly necessary for security or a requested transaction.

11. Children and age

The Service is for users aged 18 or older. We do not design cookie-based profiling for children or knowingly use children’s data for targeted advertising.

If an underage user has accessed the Service, a parent or responsible adult may contact us so that the Account and associated optional identifiers can be reviewed.

12. International data flows

Technology providers may operate infrastructure outside Estonia or the European Economic Area. Where personal data is transferred internationally, the safeguards described in the Privacy Policy apply.

Cookie consent does not itself replace a required transfer safeguard. Provider configuration and contracts are assessed separately.

13. Changes

We may update this policy and inventory when the website, providers, law or consent standards change. The effective date identifies the current version.

A material new optional purpose requires a new consent choice where the law requires. Existing necessary storage may be updated to maintain security or compatibility.

14. Contact

Questions about cookies or consent may be sent to info@skins-dealer.com or by post to Pebletex OÜ, Telliskivi tn 60a/5, Põhja-Tallinna linnaosa, 10412 Tallinn, Harju maakond, Estonia.

Include the browser, device and approximate date of the issue, but do not send passwords or full payment details.

Operational Maintenance Checklist

Review control

ControlFrequency / triggerEvidenceRequired action
Automated technology scanBefore release and monthlyScan export and detected storage listClassify new technology before activation
Consent-banner testBefore release and quarterlyScreenshots and network testConfirm optional requests are blocked before consent
Inventory reconciliationEvery six monthsApproved inventory versionUpdate names, providers, purposes and durations
Provider reviewOn onboarding or material changeContract, privacy and transfer reviewRestrict scope or replace provider if needed
Withdrawal testQuarterlyRecorded test resultConfirm future optional requests stop after withdrawal
Publication reviewAfter any material changeVersion and effective datePublish updated policy and request renewed consent where required

Schedule 1. Consent and Technology Governance

This schedule describes the controls used to keep cookie and similar-technology deployment aligned with user choices, security needs and the published inventory.

Consent event records

When an optional technology requires consent, the consent interface should record the decision, the categories selected, the policy version, a timestamp and a pseudonymous browser or device identifier. These records are used to demonstrate that a choice was obtained and to honour later withdrawal. They are not used to reconstruct full browsing histories. A renewed choice may be requested after a material purpose change, a significant inventory change or expiry of the applicable consent period.

Necessary storage and checkout continuity

Strictly necessary technologies may preserve session integrity, remember a basket, route traffic, prevent cross-site request forgery, maintain load-balancer affinity and keep a checkout state long enough to complete an Order. Blocking them can prevent sign-in, payment authorisation, fraud screening or delivery-status display. Their use is limited to providing the service requested by the user, securing the Website or meeting an applicable legal obligation; they are not repurposed for optional behavioural advertising.

Payment and fraud-prevention technologies

Payment providers and fraud-prevention vendors may set or read identifiers during checkout to authenticate a user, apply Strong Customer Authentication where required, detect repeated attempts, identify automated abuse and correlate a transaction with a risk event. The provider controls the technical lifetime of its own identifiers within its documented rules. Skins Dealer limits the data sent to what is needed for payment and security, and does not receive a user’s complete card number or card security code.

Preference withdrawal mechanics

Withdrawing consent stops future use of the affected optional category from the point at which the preference is processed. It does not retroactively invalidate processing carried out under a valid earlier choice, and it may not erase identifiers already placed by a third party until they expire or are deleted through that provider or the browser. Users should therefore use both the Website preference control and browser or device controls when they want the broadest practical reset.

Browser changes and identifier loss

A preference may appear to reset after cookies are cleared, a browser profile is replaced, private-browsing mode is used, a device is changed or a consent identifier cannot be read. In those cases, the Website may present the choice again. Separate browsers and devices maintain separate preference states unless an authenticated preference mechanism explicitly synchronises them. Users should make their selection on each relevant environment.

Inventory verification and deployment control

Before a new script, tag, software development kit or embedded feature is released, its owner, provider, purpose, data elements, duration, category and activation condition should be documented. Optional technology should remain disabled until the applicable consent signal exists. Periodic scans and manual checks should compare the deployed environment with the published inventory, remove obsolete tags and verify that rejected categories do not fire except where a narrowly defined necessary function applies.

Incident handling

A technology that behaves outside its approved purpose, activates before consent, transmits unexpected data or cannot be disabled should be suspended where technically feasible and referred for privacy and security review. The review should identify affected users and periods, determine whether notification or remedial consent is required, correct the configuration and preserve proportionate evidence. A cookie complaint is handled together with any related access, erasure or objection request under the Privacy Policy.

User diagnostic route

For a consent or cookie malfunction, the user should identify the browser and version, device type, approximate time, preference selected and the page on which the issue occurred. Screenshots may help, provided they do not show passwords, authentication codes or complete payment data. Support may ask the user to test a fresh session, clear a specific site identifier or disable a conflicting extension before escalation to the relevant technology provider.

Skins Dealer · Cookie Policy · v1.0 · Effective 29 July 2026. The version made available through the Website is the controlling customer-facing version.