Privacy Policy

Skins Dealer · Privacy Policy · v1.0 · Effective 29 July 2026

FieldValue
OperatorPebletex OÜ
Company number17367621
Registered officeTelliskivi tn 60a/5, Põhja-Tallinna linnaosa, 10412 Tallinn, Harju maakond, Estonia
Trading name / brandSkins Dealer
Websitehttps://skins-dealer.com
Contact emailinfo@skins-dealer.com
Support / complaintsinfo@skins-dealer.com; Monday to Friday, 09:00-17:00 Eastern European Time / Eastern European Summer Time, excluding public holidays in Estonia
Governing lawLaws of Estonia, subject to mandatory consumer protections
Document versionv1.0
Effective date29 July 2026
Important: This policy explains how Pebletex OÜ uses personal data for accounts, payments, fraud prevention, delivery of digital skins and support. Full payment-card data is handled in the Payment Provider’s secure environment rather than stored by Skins Dealer.

1. Introduction and scope

This Privacy Policy applies when you visit skins-dealer.com, create or use an Account, purchase a Digital Item, communicate with support or otherwise interact with the Skins Dealer Service. It explains what personal data we process, why we use it, who receives it, how long it is kept and the rights available to you.

Pebletex OÜ processes data in accordance with the European Union General Data Protection Regulation and applicable Estonian data-protection law. Separate terms may apply to independent third-party platforms and Payment Providers, which process data under their own notices.

2. Data controller and contact

Pebletex OÜ, company number 17367621, is the controller of personal data processed for operation of the Service. Its registered office is Telliskivi tn 60a/5, Põhja-Tallinna linnaosa, 10412 Tallinn, Harju maakond, Estonia.

Privacy questions and rights requests may be sent to info@skins-dealer.com. No separate data protection officer has been appointed because the present processing activities do not require one; privacy responsibility remains with the operator’s management.

3. Age position

The Service is intended only for persons aged 18 or older and is not directed to children. We do not knowingly permit a child to create an Account or purchase Digital Items.

Where age, payment authority or account control is doubtful, we may request proportionate verification or refuse the transaction. If we learn that a child’s data has been submitted, we will restrict the Account and delete or anonymise the data unless retention is legally required.

4. Categories of personal data

We process only data reasonably connected to storefront operation, transaction security, digital fulfilment and legal compliance. The table below describes the principal categories and the ordinary source of each category.

Personal data categories

CategoryExamplesSourcePurpose
Account and identityName, email, account ID, age confirmation, country and login recordsYou; account systemsCreate and secure the Account; establish eligibility; communicate
Transaction and billingOrder reference, amount, currency, billing country, payment status, masked card detailsYou; Payment ProviderProcess payment, keep records, handle refunds and disputes
Delivery and entitlementGame/platform identifier, destination account, item selected, transfer status, timestampsYou; Supported PlatformDeliver the Digital Item and prove fulfilment
Technical and usageIP address, device, browser, session, security events, consent preferencesDevice and websiteSecurity, fraud prevention, operation and consent management
Support and communicationsMessages, attachments, complaint details, responses and call notesYou; support channelsResolve requests, complaints, defects and payment issues
Compliance and riskVerification results, sanctions/fraud indicators, chargeback evidenceYou; service providers; public sourcesPrevent abuse, meet legal duties and defend claims
Marketing preferencesConsent, unsubscribe status, campaign interactionYou; email systemsSend and manage optional marketing communications

5. Sources of personal data

Most data comes directly from you when you register, pay, nominate a destination account or contact support. Technical data is generated when the website and security systems operate. Payment status and masked account information are returned by the Payment Provider, while delivery responses may be returned by the Supported Platform.

We may also receive fraud, sanctions, device-risk or dispute information from service providers and publicly available sources. We do not purchase consumer profiles for unrelated advertising.

6. How we use personal data

We use personal data to provide the Service, authenticate users, display and accept Orders, obtain payment authorisation, deliver Digital Items, maintain entitlement records, answer support requests and administer refunds or cancellations.

We also use data to secure accounts, detect stolen payment methods, prevent duplicate claims, investigate platform manipulation, comply with tax and accounting duties, establish or defend legal claims, improve reliability and measure website performance where consent permits.

We do not use transaction data to make unrelated lending, insurance or employment decisions. We do not sell personal data for money.

7. Lawful bases for processing

The lawful basis depends on the purpose. Contract is used where processing is necessary to accept and fulfil an Order. Legal obligation applies to accounting, tax, regulatory and valid authority requests. Legitimate interests support proportionate security, fraud prevention, service improvement and claims management. Consent is used for non-essential cookies and optional direct marketing.

Lawful bases

Processing activityLawful basisNotes
Account creation and authenticationPerformance of a contractNeeded to provide account-based purchasing and delivery
Order, payment status and fulfilmentPerformance of a contractIncludes destination account and entitlement evidence
Accounting and tax recordsLegal obligationRetained for statutory financial-record periods
Fraud, abuse and security monitoringLegitimate interests; legal obligation where applicableBalanced against user rights; focused on transaction and platform risk
Refunds, complaints and legal claimsContract; legitimate interests; legal obligationNeeded to resolve disputes and preserve evidence
Necessary cookiesContract and legitimate interestsRequired for sessions, security, checkout and consent choices
Analytics and marketing cookiesConsentNot activated until valid consent where required
Email marketingConsent or lawful existing-customer basis where availableEvery message contains an unsubscribe route

8. Payments and checkout

Payment-card details are entered into the Payment Provider’s hosted or secured payment interface. Pebletex OÜ receives transaction identifiers, status, amount, currency, risk results and limited masked details needed for support and reconciliation, but does not intend to store full card numbers or card security codes.

The Payment Provider may process data as an independent controller or processor depending on the activity. Strong customer authentication, three-domain secure checks and issuer decisions may involve the card issuer and payment networks.

9. Cookies and similar technologies

The website uses necessary storage to maintain sessions, security and consent choices. Functional, analytics or marketing technologies are used only in accordance with the Cookie Policy and the consent settings presented to you.

You can withdraw non-essential consent without affecting the lawfulness of prior processing. Disabling necessary storage may prevent secure checkout or account login.

10. Sharing of personal data

We share data with Payment Providers, hosting and content-delivery providers, fraud-prevention services, communications and support providers, analytics providers used with consent, professional advisers and the Supported Platform where required to deliver or verify an item.

Recipients receive only the data reasonably needed for their function and are subject to contractual, professional or legal duties. We may disclose data to a competent authority, court, card scheme or acquirer where the request is lawful or necessary to protect rights and investigate fraud.

A corporate reorganisation may involve transfer of relevant records subject to confidentiality and applicable data-protection requirements.

11. International transfers

Some providers may process data outside Estonia or the European Economic Area. Where European data-protection law requires safeguards, we use an adequacy decision, standard contractual clauses or another lawful transfer mechanism, together with supplementary measures where appropriate.

The destination account may be operated by a global game platform. Its independent processing is governed by its own privacy notice and chosen account region.

12. Data retention

We retain data for no longer than necessary for the stated purpose, legal duties, fraud prevention and dispute defence. Periods may be extended where a complaint, investigation, litigation hold or authority request remains open. Data is then deleted, anonymised or securely isolated.

Retention schedule

Data categoryRetention periodTrigger / criterion
Account profileActive account plus 24 monthsClosure or last meaningful activity, unless a dispute remains
Order, payment and tax records7 yearsEnd of the financial year of the transaction
Delivery and entitlement evidence7 yearsCompletion, refund or reversal of the Order
Fraud and security logs24 monthsCollection or closure of the relevant investigation
Support tickets and complaints3 yearsFinal resolution of the request
Chargeback and legal-claim filesUntil final resolution plus 3 yearsFinal scheme, court or settlement outcome
Marketing consent recordsDuration of consent plus 3 yearsWithdrawal or last campaign interaction
Cookie consent choiceUp to 12 monthsLast consent decision, then renewed as required

13. Data security

We use access controls, encryption in transit, restricted administrative privileges, logging, backups, vulnerability management and provider due diligence appropriate to the nature of the Service. Payment data is segregated through the Payment Provider’s environment.

No online system is entirely risk-free. You should use a unique password, enable available multifactor authentication and report suspicious access promptly. We assess personal-data incidents and notify affected persons and authorities where the law requires.

14. Your privacy rights

Subject to applicable conditions, you may request access, correction, erasure, restriction, portability or objection, and may withdraw consent. You may also object to direct marketing at any time and lodge a complaint with the Estonian Data Protection Inspectorate or another competent supervisory authority.

A request should identify you, the relevant Account and the right exercised. We may seek proportionate verification and may refuse or charge for manifestly unfounded or excessive requests only where the law permits. Responses are normally provided within one month, with lawful extensions explained.

15. Marketing communications

Optional marketing is sent only where a lawful basis exists. Consent is separate from purchase and can be withdrawn through the unsubscribe link or by contacting us. Transaction, security and policy messages are service communications and may continue while relevant.

We do not use sensitive profiling to target marketing. Suppression records may be retained to respect an unsubscribe request.

16. Automated decision-making and profiling

Fraud and security tools may generate risk indicators or recommend manual review. They consider transaction, device, account and delivery signals. A high-risk result may delay or prevent an Order, but significant adverse decisions are subject to human review where required by law.

You may contact support to provide context or challenge an incorrect result. We do not conduct automated decision-making that produces legal or similarly significant effects solely for advertising.

17. Third-party services and links

The Service may link to a game platform, Payment Provider or external information source. Those parties determine their own processing and terms. Review their notices before providing data or enabling account connections.

A third-party link is not an endorsement of all content or practices. We are responsible for our own processing and for processors acting on our documented instructions.

18. Changes to this policy

We may update this policy to reflect legal, technical, provider or service changes. The version and effective date identify the current text. Material changes will be highlighted through the website, Account or email where appropriate.

Older transaction records remain governed by the law and retention rules applicable to them; a policy update does not remove an accrued privacy right.

19. How to contact us or submit a request

Send privacy requests to info@skins-dealer.com or by post to Pebletex OÜ, Telliskivi tn 60a/5, Põhja-Tallinna linnaosa, 10412 Tallinn, Harju maakond, Estonia. State the Account email, the right requested and enough detail to locate the relevant data.

Do not include full card details, passwords or security codes. Complaints about an Order should use the same contact but clearly identify the Order reference so that privacy and transaction workflows can be coordinated.

Schedule 1. Practical Retention Guide

  • Closing an Account stops ordinary access but does not immediately erase transaction, tax, fraud or dispute records that must be retained.
  • A valid erasure request removes data that is no longer needed; legally required records are restricted to the permitted purpose.
  • A pending refund, chargeback or platform investigation pauses deletion of the evidence necessary to reach and defend the outcome.
  • Marketing consent can be withdrawn immediately; a minimal suppression record may remain so that the preference is respected.
  • When a provider relationship ends, data is returned, deleted or retained only under documented legal requirements.

Skins Dealer · Privacy Policy · v1.0 · Effective 29 July 2026. The version made available through the Website is the controlling customer-facing version.