Privacy Policy
Skins Dealer · Privacy Policy · v1.0 · Effective 29 July 2026
| Field | Value |
| Operator | Pebletex OÜ |
| Company number | 17367621 |
| Registered office | Telliskivi tn 60a/5, Põhja-Tallinna linnaosa, 10412 Tallinn, Harju maakond, Estonia |
| Trading name / brand | Skins Dealer |
| Website | https://skins-dealer.com |
| Contact email | info@skins-dealer.com |
| Support / complaints | info@skins-dealer.com; Monday to Friday, 09:00-17:00 Eastern European Time / Eastern European Summer Time, excluding public holidays in Estonia |
| Governing law | Laws of Estonia, subject to mandatory consumer protections |
| Document version | v1.0 |
| Effective date | 29 July 2026 |
| Important: This policy explains how Pebletex OÜ uses personal data for accounts, payments, fraud prevention, delivery of digital skins and support. Full payment-card data is handled in the Payment Provider’s secure environment rather than stored by Skins Dealer. |
1. Introduction and scope
This Privacy Policy applies when you visit skins-dealer.com, create or use an Account, purchase a Digital Item, communicate with support or otherwise interact with the Skins Dealer Service. It explains what personal data we process, why we use it, who receives it, how long it is kept and the rights available to you.
Pebletex OÜ processes data in accordance with the European Union General Data Protection Regulation and applicable Estonian data-protection law. Separate terms may apply to independent third-party platforms and Payment Providers, which process data under their own notices.
2. Data controller and contact
Pebletex OÜ, company number 17367621, is the controller of personal data processed for operation of the Service. Its registered office is Telliskivi tn 60a/5, Põhja-Tallinna linnaosa, 10412 Tallinn, Harju maakond, Estonia.
Privacy questions and rights requests may be sent to info@skins-dealer.com. No separate data protection officer has been appointed because the present processing activities do not require one; privacy responsibility remains with the operator’s management.
3. Age position
The Service is intended only for persons aged 18 or older and is not directed to children. We do not knowingly permit a child to create an Account or purchase Digital Items.
Where age, payment authority or account control is doubtful, we may request proportionate verification or refuse the transaction. If we learn that a child’s data has been submitted, we will restrict the Account and delete or anonymise the data unless retention is legally required.
4. Categories of personal data
We process only data reasonably connected to storefront operation, transaction security, digital fulfilment and legal compliance. The table below describes the principal categories and the ordinary source of each category.
Personal data categories
| Category | Examples | Source | Purpose |
| Account and identity | Name, email, account ID, age confirmation, country and login records | You; account systems | Create and secure the Account; establish eligibility; communicate |
| Transaction and billing | Order reference, amount, currency, billing country, payment status, masked card details | You; Payment Provider | Process payment, keep records, handle refunds and disputes |
| Delivery and entitlement | Game/platform identifier, destination account, item selected, transfer status, timestamps | You; Supported Platform | Deliver the Digital Item and prove fulfilment |
| Technical and usage | IP address, device, browser, session, security events, consent preferences | Device and website | Security, fraud prevention, operation and consent management |
| Support and communications | Messages, attachments, complaint details, responses and call notes | You; support channels | Resolve requests, complaints, defects and payment issues |
| Compliance and risk | Verification results, sanctions/fraud indicators, chargeback evidence | You; service providers; public sources | Prevent abuse, meet legal duties and defend claims |
| Marketing preferences | Consent, unsubscribe status, campaign interaction | You; email systems | Send and manage optional marketing communications |
5. Sources of personal data
Most data comes directly from you when you register, pay, nominate a destination account or contact support. Technical data is generated when the website and security systems operate. Payment status and masked account information are returned by the Payment Provider, while delivery responses may be returned by the Supported Platform.
We may also receive fraud, sanctions, device-risk or dispute information from service providers and publicly available sources. We do not purchase consumer profiles for unrelated advertising.
6. How we use personal data
We use personal data to provide the Service, authenticate users, display and accept Orders, obtain payment authorisation, deliver Digital Items, maintain entitlement records, answer support requests and administer refunds or cancellations.
We also use data to secure accounts, detect stolen payment methods, prevent duplicate claims, investigate platform manipulation, comply with tax and accounting duties, establish or defend legal claims, improve reliability and measure website performance where consent permits.
We do not use transaction data to make unrelated lending, insurance or employment decisions. We do not sell personal data for money.
7. Lawful bases for processing
The lawful basis depends on the purpose. Contract is used where processing is necessary to accept and fulfil an Order. Legal obligation applies to accounting, tax, regulatory and valid authority requests. Legitimate interests support proportionate security, fraud prevention, service improvement and claims management. Consent is used for non-essential cookies and optional direct marketing.
Lawful bases
| Processing activity | Lawful basis | Notes |
| Account creation and authentication | Performance of a contract | Needed to provide account-based purchasing and delivery |
| Order, payment status and fulfilment | Performance of a contract | Includes destination account and entitlement evidence |
| Accounting and tax records | Legal obligation | Retained for statutory financial-record periods |
| Fraud, abuse and security monitoring | Legitimate interests; legal obligation where applicable | Balanced against user rights; focused on transaction and platform risk |
| Refunds, complaints and legal claims | Contract; legitimate interests; legal obligation | Needed to resolve disputes and preserve evidence |
| Necessary cookies | Contract and legitimate interests | Required for sessions, security, checkout and consent choices |
| Analytics and marketing cookies | Consent | Not activated until valid consent where required |
| Email marketing | Consent or lawful existing-customer basis where available | Every message contains an unsubscribe route |
8. Payments and checkout
Payment-card details are entered into the Payment Provider’s hosted or secured payment interface. Pebletex OÜ receives transaction identifiers, status, amount, currency, risk results and limited masked details needed for support and reconciliation, but does not intend to store full card numbers or card security codes.
The Payment Provider may process data as an independent controller or processor depending on the activity. Strong customer authentication, three-domain secure checks and issuer decisions may involve the card issuer and payment networks.
9. Cookies and similar technologies
The website uses necessary storage to maintain sessions, security and consent choices. Functional, analytics or marketing technologies are used only in accordance with the Cookie Policy and the consent settings presented to you.
You can withdraw non-essential consent without affecting the lawfulness of prior processing. Disabling necessary storage may prevent secure checkout or account login.
10. Sharing of personal data
We share data with Payment Providers, hosting and content-delivery providers, fraud-prevention services, communications and support providers, analytics providers used with consent, professional advisers and the Supported Platform where required to deliver or verify an item.
Recipients receive only the data reasonably needed for their function and are subject to contractual, professional or legal duties. We may disclose data to a competent authority, court, card scheme or acquirer where the request is lawful or necessary to protect rights and investigate fraud.
A corporate reorganisation may involve transfer of relevant records subject to confidentiality and applicable data-protection requirements.
11. International transfers
Some providers may process data outside Estonia or the European Economic Area. Where European data-protection law requires safeguards, we use an adequacy decision, standard contractual clauses or another lawful transfer mechanism, together with supplementary measures where appropriate.
The destination account may be operated by a global game platform. Its independent processing is governed by its own privacy notice and chosen account region.
12. Data retention
We retain data for no longer than necessary for the stated purpose, legal duties, fraud prevention and dispute defence. Periods may be extended where a complaint, investigation, litigation hold or authority request remains open. Data is then deleted, anonymised or securely isolated.
Retention schedule
| Data category | Retention period | Trigger / criterion |
| Account profile | Active account plus 24 months | Closure or last meaningful activity, unless a dispute remains |
| Order, payment and tax records | 7 years | End of the financial year of the transaction |
| Delivery and entitlement evidence | 7 years | Completion, refund or reversal of the Order |
| Fraud and security logs | 24 months | Collection or closure of the relevant investigation |
| Support tickets and complaints | 3 years | Final resolution of the request |
| Chargeback and legal-claim files | Until final resolution plus 3 years | Final scheme, court or settlement outcome |
| Marketing consent records | Duration of consent plus 3 years | Withdrawal or last campaign interaction |
| Cookie consent choice | Up to 12 months | Last consent decision, then renewed as required |
13. Data security
We use access controls, encryption in transit, restricted administrative privileges, logging, backups, vulnerability management and provider due diligence appropriate to the nature of the Service. Payment data is segregated through the Payment Provider’s environment.
No online system is entirely risk-free. You should use a unique password, enable available multifactor authentication and report suspicious access promptly. We assess personal-data incidents and notify affected persons and authorities where the law requires.
14. Your privacy rights
Subject to applicable conditions, you may request access, correction, erasure, restriction, portability or objection, and may withdraw consent. You may also object to direct marketing at any time and lodge a complaint with the Estonian Data Protection Inspectorate or another competent supervisory authority.
A request should identify you, the relevant Account and the right exercised. We may seek proportionate verification and may refuse or charge for manifestly unfounded or excessive requests only where the law permits. Responses are normally provided within one month, with lawful extensions explained.
15. Marketing communications
Optional marketing is sent only where a lawful basis exists. Consent is separate from purchase and can be withdrawn through the unsubscribe link or by contacting us. Transaction, security and policy messages are service communications and may continue while relevant.
We do not use sensitive profiling to target marketing. Suppression records may be retained to respect an unsubscribe request.
16. Automated decision-making and profiling
Fraud and security tools may generate risk indicators or recommend manual review. They consider transaction, device, account and delivery signals. A high-risk result may delay or prevent an Order, but significant adverse decisions are subject to human review where required by law.
You may contact support to provide context or challenge an incorrect result. We do not conduct automated decision-making that produces legal or similarly significant effects solely for advertising.
17. Third-party services and links
The Service may link to a game platform, Payment Provider or external information source. Those parties determine their own processing and terms. Review their notices before providing data or enabling account connections.
A third-party link is not an endorsement of all content or practices. We are responsible for our own processing and for processors acting on our documented instructions.
18. Changes to this policy
We may update this policy to reflect legal, technical, provider or service changes. The version and effective date identify the current text. Material changes will be highlighted through the website, Account or email where appropriate.
Older transaction records remain governed by the law and retention rules applicable to them; a policy update does not remove an accrued privacy right.
19. How to contact us or submit a request
Send privacy requests to info@skins-dealer.com or by post to Pebletex OÜ, Telliskivi tn 60a/5, Põhja-Tallinna linnaosa, 10412 Tallinn, Harju maakond, Estonia. State the Account email, the right requested and enough detail to locate the relevant data.
Do not include full card details, passwords or security codes. Complaints about an Order should use the same contact but clearly identify the Order reference so that privacy and transaction workflows can be coordinated.
Schedule 1. Practical Retention Guide
- Closing an Account stops ordinary access but does not immediately erase transaction, tax, fraud or dispute records that must be retained.
- A valid erasure request removes data that is no longer needed; legally required records are restricted to the permitted purpose.
- A pending refund, chargeback or platform investigation pauses deletion of the evidence necessary to reach and defend the outcome.
- Marketing consent can be withdrawn immediately; a minimal suppression record may remain so that the preference is respected.
- When a provider relationship ends, data is returned, deleted or retained only under documented legal requirements.
Skins Dealer · Privacy Policy · v1.0 · Effective 29 July 2026. The version made available through the Website is the controlling customer-facing version.
