Adatvédelmi tájékoztató
In force from 1 September 2026
Last updated: 1 September 2026
Ez a dokumentum magyarul nem érhető el. A hivatalos angol fordítást olvassa; a kötelező erejű változat a lengyel.
Digital Traders sp. z o.o. adopts this Privacy Policy as operator of SellYourSkins.com. It is in force from 1 September 2026, 00:00 (the "Effective Date") and governs processing carried out from that moment. Processing carried out earlier by the previous operator of the service stays governed by that operator's Privacy Policy of 7 March 2024.
The Polish version is the binding version and the basis of interpretation. The English version is our official translation. Versions in the remaining languages of the Website are convenience translations. If the version published in the language in which the Website is displayed to you is more favourable to you as a consumer, you may rely on it; the risk of an error in a translation we published is ours.
At a glance
A short extraction from the sections named in each point.
Who processes your data: Digital Traders sp. z o.o., Warsaw, KRS 0001253066. We buy Virtual Items from you in our own name and for our own account; we are not a marketplace and we do not hold your funds. privacy@sellyourskins.com (sec. 1).
What we collect and why: Steam, contact, transaction, payout, verification, technical, program, preference and communication data, to run your Account and pay you what is due, run our programs, prevent fraud, diagnose errors in the Website, verify every transaction before payout and screen sanctions lists, meet tax and accounting duties and, with your consent, send marketing e-mails and review invitations and load analytics tools (sec. 3 and 4).
Your country decides the payout methods available to you: the methods shown to you follow your country, which we take from your IP address and which you may change yourself on the sell page. The country you select is your own declaration, and an untrue declaration may cause the payout to be rejected. We aim to keep at least one method available in every supported country; availability also depends on the payment service providers. Currency and language proposals you can always override (sec. 4, rows 2a and 2b).
What is automatic and what is not: Quotes are generated automatically, and a payout above our limits, published or internal, is held automatically. Release of such a hold, and every refusal to conclude a Sale, cancellation, bonus withdrawal and Account block, is decided by our staff (sec. 5).
What is public: public Website statistics show a masked identifier, the item and the value. Your Steam display name and avatar appear only if you switch that on yourself (sec. 4, row 5).
Marketing: marketing e-mails, abandoned-sale reminders and Trustpilot invitations need your prior, separate consent, never your acceptance of the Terms of Service (sec. 4, rows 9 and 10).
Cookies and your device: analytics tools load only after you give consent, and rejecting is as easy as accepting. The referral code from a link you followed we store without asking for consent, because it is necessary to apply the code you request that way. Separately, to detect multi-accounting and abuse we compute, on our server side, signals of your browser and device from the data your browser itself sends with every request; you may object (sec. 10).
Who else sees your data: the payment service provider that executes the payout you chose, Valve (Steam) for login, inventory and trade offers, our support-chat and e-mail providers, and, only after you give consent, our analytics providers. We do not sell personal data (sec. 6).
Data outside the EEA: the providers executing your payouts are established in the EEA, with one exception, Payset in the United Kingdom, which is covered by a European Commission adequacy decision. Recipients in the United States are covered by the EU-U.S. Data Privacy Framework, with Standard Contractual Clauses as the fallback should certification lapse. The Steam connection relies on the contract-performance derogation in Art. 49(1)(b) GDPR (sec. 7). Our error monitoring runs on infrastructure inside the European Union (sec. 6.5).
How long we keep data: transaction and accounting records at least 5 years, verification and anti-fraud records 5 years, claims and audit files 6 years (sec. 8).
What deletion does and does not do: you delete your Account yourself. We erase or replace identifying data, delete the error reports tagged with your Steam ID, keep the records we must keep, and keep a keyed identifier so that an existing block and benefits you already used survive re-registration. What remains is pseudonymized, not anonymous (sec. 9.4).
Your rights: access, rectification, erasure, restriction, portability, objection, withdrawal of consent, and a complaint to a supervisory authority in any EEA country (sec. 9 and 15).
1. Controller and contact
1.1. From the Effective Date, the controller of personal data within the meaning of the GDPR for your personal data processed in connection with the website sellyourskins.com and its subpages (the "Website") and the services provided through it is Digital Traders spółka z ograniczoną odpowiedzialnością, seated in Warsaw (the "Administrator", "we", "us").
1.2. Our registration data: ul. Stefana Batorego 18/108, 02-591 Warszawa, Poland; District Court for the Capital City of Warsaw in Warsaw, XII Commercial Division, KRS 0001253066; NIP 7011322455; share capital PLN 5,000.00.
1.3. Write to us about personal data at privacy@sellyourskins.com or admin@digitaltraders.io, or by post to the address in section 1.2 marked "Personal data".
1.4. We have appointed no Data Protection Officer; the contacts in section 1.3 handle every data-protection matter.
1.5. The change of operator of the Website affects your data as follows. 1.5.1. We operate the Website in our own name and under our own Terms of Service, and we are the controller of the personal data of that operation, in particular your Account data and the data of Sales concluded from 1 September 2026, 00:00. The delimitation is technical: it is decided by the transaction timestamp recorded in the service database. 1.5.2. The previous operator, SKINFINITY.GG (company registration number 386079755), performs and settles transactions concluded on or before 31 August 2026, on the terms in force then, and is the controller of its own settlement, accounting and compliance records of those transactions, under its Privacy Policy of 7 March 2024. Address requests about those transactions, data-protection requests included, to it, through the change-of-operator page of the Website. If you send such a request to us, we will tell you and, where possible, pass it on. 1.5.3. The service database holds records of transactions concluded before the Effective Date. We process them for four purposes of our own and no others:
a) showing you your own transaction history in your Account; the basis is Art. 6(1)(b) GDPR once you have accepted the Terms of Service and, until you do, Art. 6(1)(f), that is our and your legitimate interest in keeping your access to your history continuous;
b) reading, once, the Bonus Level, experience points and referral values recorded as at 31 August 2026, to set the starting values of our own new benefit program (Art. 6(1)(f));
c) enforcing a block in force (Art. 6(1)(f));
d) enforcing the one-time character of benefits already used (Art. 6(1)(f)).
Against each of the purposes based on Art. 6(1)(f) you may object under section 9.2, and you will receive a summary of our balancing test by writing to privacy@sellyourskins.com. 1.5.4. We and the previous operator are separate controllers. Each of us processes the records of transactions concluded before the Effective Date for its own purposes, described in sections 1.5.2 and 1.5.3 respectively, and neither of us processes those records on the other's behalf.
2. Scope
2.1. This Privacy Policy applies to every natural person whose personal data we process in connection with the Website, whether you browse it, hold an Account, sell Virtual Items to us, take part in our programs or prize giveaways, contact us, or reach us through a referral ("Users", "you").
2.2. Capitalized terms not defined in this Privacy Policy have the meaning given in the Terms of Service.
2.3. You need no personal data to view the public pages. Logging in, receiving Quotes, concluding Sales and receiving payouts require the data we mark as required. Without it we cannot provide the feature concerned.
3. Categories of personal data we process
3.1. Depending on how you use the Website, we process:
| # | Category | Data |
|---|---|---|
| (a) | Steam profile data | SteamID64, Steam display name, avatar, Steam level, Steam account creation date, Trade URL, contents of your public Steam inventory |
| (b) | Contact data | e-mail address; e-mail delivery and abuse-report status (delivered, bounced, marked as spam) reported by our e-mail delivery provider |
| (c) | Transaction data | Virtual Items sold, Quotes and applied bonuses, amounts and currencies, applied exchange rates, transaction statuses and timestamps, Wallet and balance history |
| (d) | Payout data (by method chosen) | name and surname, e-mail address, telephone number, payment card number and card BIN data (brand, type, issuer country and currency), IBAN, bank account details and per-country bank identifiers, national identification numbers where the payout provider requires them for a given country (CPF, CUIT/CUIL, RUT, CLABE, national ID number) |
| (e) | Verification data (only where verification under the Terms of Service requires it) | name and surname, date of birth, address, telephone number, identity document data, sanctions-screening results, and for Users covered by Section 7.13 of the Terms of Service also the PESEL number |
| (f) | Technical data | IP address, the country and the approximate city derived from it, browser and device information, device recognition (fingerprinting) signals (section 10.6), cookie and similar identifiers, server logs (date and time of access, pages viewed, error events), error reports generated when the Website malfunctions (section 6.5), authentication and security logs (login attempts: SteamID, IP address, timestamp) |
| (g) | Program data | Bonus Level and experience points, codes applied and the log of every application attempt, successful or not, referral relations, referral commissions and their history, masked identifiers of referred Users shown to Referrers, entries in prize giveaways and campaigns |
| (h) | Preference data | interface language, display currency, the payout country you select on the sell page, public-statistics visibility, marketing and reminder e-mail settings |
| (i) | Communication data | your correspondence with our support and complaints channels, records of service messages sent to you, and their metadata |
| (j) | Push notification data | web push subscription tokens, if you enable push notifications |
| (k) | Pseudonymized anti-abuse identifier | a keyed cryptographic hash (HMAC-SHA256) of your SteamID, kept after Account deletion to re-apply an existing Account block and to stop repeated use of one-time benefits, in particular the Welcome Bonus |
3.2. We do not knowingly process special categories of personal data (Art. 9 GDPR), and we ask you not to put such data in correspondence with us.
3.3. We collect identity-document copies only where they are strictly necessary, because a verification cannot be completed by less intrusive means.
3.4. We use verification data (category (e)) only for verification, sanctions compliance, fraud prevention, compliance with legal obligations and the defence of legal claims, never for marketing and never for the programs in section 4, rows 3 and 4.
4. Purposes and legal bases of processing
4.1. We process your personal data for the following purposes and on the following legal bases. Article references are to the GDPR unless another act is named.
| # | Purpose | Data (sec. 3.1) | Legal basis |
|---|---|---|---|
| 1 | Running your Account, generating Quotes, concluding and performing Sales, operating the Wallet (Terms of Service, Section 8), executing payouts, including the Steam Trade Protection Hold, and sending you transaction, service and legal messages | (a), (b), (c), (d), (h), (i), and the technical data in (f) needed to run your session | Art. 6(1)(b): performance of a contract |
| 2a | Determining which payout methods are available to you, from your country (payment-rail availability, card-issuer restrictions, sanctions and provider rules), and reading the first digits (BIN) of your payout card to determine the currency in which a payout to that card can be executed. We take your country from your IP address, and you may also select it yourself from the drop-down list on the sell page | (d), (f), (h) | Art. 6(1)(b): it decides what we can lawfully and technically pay you, and how |
| 2b | Proposing a display currency and interface language from the same country signal, and converting displayed values into the currency you choose. The currency selector and the language switcher override these proposals | (f), (h) | Art. 6(1)(f): presenting a usable, locally relevant service |
| 3 | Running the bonus, loyalty and referral programs: experience points, Bonus Levels, applying Bonus Codes and referral codes, calculating and paying referral commissions, keeping the code-application log | (a), (b), (c), (g) | Art. 6(1)(b). Anti-abuse checks within these programs: Art. 6(1)(f) |
| 4 | Running prize giveaways and promotional campaigns you take part in: entries, winner selection, notification, crediting prizes | (a), (b), (c), (g) | Art. 6(1)(b); tax and record-keeping duties: Art. 6(1)(c) |
| 5 | Public Website statistics, for example recent Sales and leaderboards. By default they show a masked identifier, the item and the value. Your Steam display name and avatar appear only if you switch that on in Account settings, and you can switch it off again at any time | (a), (c) | Art. 6(1)(f) for the masked form: presenting Website activity. Art. 6(1)(a), your consent, for your Steam display name and avatar |
| 6 | Fraud prevention and security: detecting market manipulation and manifestly mispriced transactions, transaction-risk analysis, detecting multi-accounting, bot activity and program abuse, device recognition (section 10.6), logging login attempts, investigating incidents, and, after Account deletion, using the identifier in section 3.1(k) to re-apply an existing block and stop repeated use of one-time benefits | (a), (c), (f), (g), (k) | Art. 6(1)(f): preventing fraud and abuse (Recital 47). Write to privacy@sellyourskins.com for a summary of our balancing test |
| 6a | Diagnosing malfunctions of the Website and keeping it technically stable: error reports sent by your browser to our monitoring provider, which contain your Steam ID and are therefore linked to you as the identified holder of the Account (section 6.5) | (a), (f) | Art. 6(1)(f): keeping the service you use working, and finding and fixing faults in it |
| 7 | Verifying every transaction before payout under our AML/KYC and Anti-Fraud Policy of 27 July 2026, screening against the sanctions lists of the European Union and the United Nations and against the Polish list kept under the Act of 13 April 2022 on special solutions for counteracting support for aggression against Ukraine and for the protection of national security (Dz.U. 2022 poz. 835, as amended), and meeting the requirements of the payment service providers we engage | (a), (b), (c), (d), (e), (f) | Art. 6(1)(c) for the restrictive measures binding on us, in particular Council Regulations (EU) No 269/2014 and (EU) No 833/2014 and the Act of 13 April 2022. Otherwise Art. 6(1)(f): preventing fraud and sanctions exposure |
| 7a | Performance of our duties as income-tax remitter towards Users who have declared Polish tax residence and have not made the business-activity statement (Terms of Service, Section 7.13): withholding and remitting the advance, preparing and filing the PIT-4R return and the PIT-11 information | (b), (e): first and last name, PESEL number, home address | Art. 6(1)(c): legal obligation under tax law |
| 8 | Other legal obligations: accounting regulations and tax law, handling complaints, responding to lawful requests of public authorities | (b), (c), (d), (e), (i) | Art. 6(1)(c) |
| 9 | Direct marketing by e-mail: newsletter, promotions and abandoned-sale reminders, with simple profiling to tailor offers, for example a Bonus Code proposed from your activity | (b), (c), (g), (h) | Art. 6(1)(a): your consent, as art. 398 read with art. 400 of the Act of 12 July 2024, Electronic Communications Law (PKE), requires. You may withdraw it at any time |
| 10 | Inviting you to review the service on Trustpilot after a completed payout (section 4.3) | (b), (c) | Art. 6(1)(a) read with art. 398 PKE: the same marketing consent as row 9. Without it no invitation is triggered |
| 11 | Storing information on your device and accessing information already stored there, beyond the storage and access exempt from consent under section 10 | (f) | Your consent under art. 399 read with art. 400 PKE and Art. 6(1)(a); see section 10 |
| 12 | Web push notifications about your transaction and payout status | (j) | Art. 6(1)(b): part of the service you asked for. The consent given in the browser covers the storage on your device (art. 399 PKE, a service you requested) and you can revoke it in your browser |
| 13 | Establishing, exercising and defending legal claims, including the Sale audit records defined in the Terms of Service (Section 12.10), BIN checks, verification decisions and authentication events | (a), (c), (d), (e), (f), (g), (i) | Art. 6(1)(f): protection of legal claims |
Where the basis is Art. 6(1)(f), you may object under section 9.2.
4.2. You give the marketing consent for rows 9 and 10 by ticking a box, unchecked by default, where you enter your e-mail address, or through the toggle in your Account profile. We never infer it from your acceptance of the Terms of Service or from your use of the Website. Abandoned-sale reminders count as marketing and we send them only where consent was given. We record the date and source of each consent and each withdrawal and, at the moment of acceptance, also the version of the documents shown to you (Art. 7(1) GDPR).
4.3. The invitation in row 10 works as follows. After a completed payout by selected methods we send Trustpilot your payout e-mail address and the fact of the transaction, so that it can send you one invitation to review the service. We send nothing further and no more than one invitation per transaction, and each invitation carries its own opt-out.
4.4. Service, legal and transactional messages, such as transaction and payout status e-mails, refund notices and notices of changes to the Terms of Service or to this Privacy Policy, are not marketing and need no marketing consent. We send them under Art. 6(1)(b) or Art. 6(1)(c) GDPR.
5. Automated decision-making and profiling
5.1. The following runs automatically. 5.1.1. Quotes for your Virtual Items are generated fully automatically, by comparing data from external price sources. 5.1.2. Automated systems raise fraud and manipulation flags, on the logic described in section 5.2, for the decisions taken with human involvement described in section 5.4. 5.1.3. Verification and payout data are screened automatically against the sanctions lists named in section 4.1, row 7. Our staff review the alerts. 5.1.4. Your country is detected from your IP address for the purposes in section 4.1, rows 2a and 2b, unless you select a country yourself on the sell page, in which case we use the country you selected. 5.1.5. A payout above the limits published on the Website, or above limits we apply internally for security reasons, is held automatically before release.
5.2. The detection logic compares the Quote against the cash market value of the item determined from independent price sources (Terms of Service, section 12.2), and analyses account relationships, transaction patterns (transactions between related Steam accounts, wash trading on reference markets, exploitation of price-feed outages, bots, multiple accounts) and technical signals, including device recognition. A flag or an automatic hold may lead to a measure under section 5.4: refusal to conclude a Sale, a temporary payout hold, cancellation of a Sale with full restitution, refusal or withdrawal of a bonus, or an Account block.
5.3. The generation of a Quote is not a decision within the meaning of Art. 22 GDPR. Quotes are produced identically for all Users, from the same price sources and under the same rules described in sections 5.1.1 and 5.2, and they contain no assessment of you as a person, of your characteristics or of your behaviour. If you disagree with a Quote, you do not have to accept it; you may also contest it through the complaint procedure provided in the Terms of Service (response within 14 days) or by writing to privacy@sellyourskins.com, and a member of our staff will then consider your case.
5.4. The measures below are not solely automated decisions. Every transaction undergoes verification during the Decision Period before the offer is accepted and, where applicable, before payout (Terms of Service, section 13.2), and that verification may include manual review. 5.4.1. A limit rule may impose a payout hold automatically (section 5.1.5). Whether the hold is released or maintained is always decided by a member of our staff. 5.4.2. The declining of a sale offer, cancellation of a concluded Sale, refusal or withdrawal of an earned bonus, and suspension or blocking of an Account are always taken or confirmed by a member of our staff, on the flag or alert and the logged evidence. They are not solely automated decisions within the meaning of Art. 22 GDPR. 5.4.3. We tell you of every such measure, its outcome, the reason for it, including the trigger relied on, and the complaint procedure open to you. Where the Terms of Service allow us to withhold detail, on the grounds and within the limits stated there (Terms of Service, section 14.3), we tell you as much as we lawfully can and preserve the full record for the competent authorities and courts.
5.5. Neither the detection of your country nor your own selection of it is an assessment of you personally. Payout-method availability depends on the payout country, for the reasons in section 4.1, row 2a, and we aim to keep at least one payout method available in every supported country; availability also depends on the payment service providers and sanctions law.
6. Recipients of your data
6.1. We do not sell personal data and we do not disclose it for anyone else's marketing purposes. We disclose it only as far as necessary, to the recipients named below. A processor acts only on our documented instructions and may not use your data for its own purposes. An independent controller decides for itself, within the law, how it uses what it receives, under its own privacy policy.
| Recipient | Role | Purpose |
|---|---|---|
| Payment service providers we engage to execute payouts, currently ZEN.com (card payouts), PayPal, Revolut, Wise, Payoneer and Payset (sec. 6.2 and 7) | Independent controllers for the payment leg each of them executes | Executing your payout: the method you chose, through the transfer channel we selected |
| Neutrino API | Processor | BIN lookup: brand, type, issuer country and currency of your payout card (sec. 4.1, row 2a) |
| Valve Corporation (Steam) | Independent controller | Steam login (OpenID), reading your public profile and inventory, sending and receiving trade offers |
| steamwebapi.com (Sellrock UG (haftungsbeschrankt), Nuremberg) | Separate controller | Receives your SteamID64 and Trade URL for the pricing and tradability checking of Virtual Items; we base the disclosure on our legitimate interest (Art. 6(1)(f)) |
| Cloudflare, Inc. and, as fallback, IPinfo (ipinfo.io) | Processors | Infrastructure, content delivery, security, determining the country from the IP address |
| Sentry (Functional Software, Inc.), on infrastructure in the European Union (the ingest.de.sentry.io endpoint) | Processor | Error and performance monitoring and receiving application logs, on the data described in section 6.5, which includes your Steam ID |
| Twilio Inc. (SendGrid service) | Processor | Sending transactional and, with your consent, marketing e-mails; reporting delivery, bounce and abuse-report status to us |
| Microsoft Corporation (Microsoft Clarity) | Processor | Session recordings and heatmaps, only after your consent to the analytics category (sec. 10.3) |
| Google LLC (Google Analytics 4, Google Tag Manager) | Processor for the measurement we commission; independent controller for the purposes Google reserves | Usage statistics, only after your consent to the analytics category, with Consent Mode v2 defaulting to denied |
| Intercom, Inc. | Processor | Support chat, loaded only when you open it (sec. 10.4), on the data described in section 6.6 |
| Trustpilot A/S | Processor for the invitation in sec. 4.3; independent controller for the review platform | Review invitations and the review widget |
| Push services of your browser vendor (Google FCM, Mozilla Autopush, Apple Push) | Independent controllers or processors of the delivery leg | Delivering the push notifications you enabled |
| Hosting, IT infrastructure and content platform providers (including Payload CMS, WordPress hosting for the blog) | Processors | Server hosting, backups, maintenance, serving FAQ, wiki and blog content |
| Referrers, and the general public of Users and visitors | Recipients of limited data | Referrers: only masked identifiers and commission amounts concerning Users they referred (sec. 12.4). The public: public Website statistics in masked form (sec. 4.1, row 5) |
| The previous operator of the service | Separate controller of its own records | Only data of transactions concluded before the Effective Date and of their settlements (sec. 1.5) |
| Professional advisers (legal, accounting, audit) and public authorities | Advisers: processors or independent controllers, as applicable. Authorities: independent controllers | Advisers: compliance, accounting, claims handling. Authorities: only on a lawful request or where the law requires disclosure |
| The competent tax office | Independent controller | Tax returns and information (PIT-4R, PIT-11) concerning Users covered by Section 7.13 of the Terms of Service |
6.2. The table names the payment service providers we engage as at the date this Privacy Policy comes into force. We may engage further ones within the same category (Art. 13(1)(e) GDPR), and this does not change this Privacy Policy. Write to privacy@sellyourskins.com to learn the current membership of this or any other category named in the table.
6.3. The price- and market-data providers we use for Quotes supply us with item and market data; we send them no personal data.
6.4. Each of our processors is bound by a data processing agreement meeting the requirements of Art. 28 GDPR, concluded within the terms of service of that processor or separately.
6.5. Sentry monitors errors and performance for us, and the following applies to it. When the Website malfunctions, your browser sends an error report to Sentry, which processes it for us on infrastructure in the European Union (the ingest.de.sentry.io endpoint). Application logs generated as the Website runs also go to Sentry, under the same regime. The report contains your Steam ID as the user identifier, technical data about the session (browser, operating system, the address of the page concerned, and the trail of clicks that led to the error) and an approximate location, country and city, derived from your IP address at the moment the event is received. The IP address itself is not stored (the sendDefaultPii option is switched off). Because the Steam ID is attached, these reports are linked to you as the identified holder of the Account (basis: section 4.1, row 6a; retention: section 8.1; deletion: section 9.4.1). Session replay, meaning the recording of what happens on your screen, is not enabled in our monitoring.
6.6. When you open the support chat, Intercom receives your user identifier, your Steam ID, your e-mail address, your name and surname and the date your Account was created, together with an identity verification signature (HMAC) we compute, which stops anyone else opening a chat in your name. It also receives your Steam Trade URL. The Trade URL is not an ordinary identifier but a functional token that allows a trade offer to be sent to your Steam account.
7. Transfers of data outside the European Economic Area
7.1. The payment service providers we engage to execute payouts are, with one exception stated in section 7.2, established in the European Economic Area: PayPal (Europe) S.a r.l. et Cie, S.C.A. in Luxembourg, Revolut Bank UAB in Lithuania, Wise Europe SA in Belgium, UAB ZEN.COM in Lithuania, and Payoneer Europe Limited in Ireland. Disclosure of data to these recipients is not a transfer outside the EEA. The PayPal and Payoneer corporate groups also process data in the United States; they do so as separate controllers, on the terms described in their privacy policies.
7.2. Pay Set Limited, seated in London (Payset), is the only payment service provider we engage established outside the EEA. The transfer basis is the adequacy decision of the European Commission for the United Kingdom.
7.3. Recipients in the United States, in particular Cloudflare, Inc., Twilio Inc. (SendGrid service), Microsoft Corporation, Google LLC and Intercom, Inc., receive data under the adequacy decision based on the EU-U.S. Data Privacy Framework, for a recipient certified under that framework at the time of the transfer. If the recipient's certification lapses or the decision ceases to apply, the transfer basis is the Standard Contractual Clauses adopted by the European Commission, supplemented where a transfer impact assessment identifies further technical and organizational measures as necessary.
7.4. For the data exchange inherent in the Steam login, in the reading of your inventory and in the trade offers you initiate, the disclosure takes place between us and Valve Corporation as two independent controllers, at your initiative and to perform the contract concluded at your request (Art. 49(1)(b) GDPR, where no other instrument covers the transfer).
7.5. For every other recipient outside the EEA we apply the Standard Contractual Clauses adopted by the European Commission.
7.6. Write to privacy@sellyourskins.com for a copy of the safeguards applicable to a given transfer, or for information on where they are available, and to learn the current transfer basis for a named recipient.
8. Retention periods
8.1. We keep personal data no longer than the purposes in section 4 require:
| Data | Retention period |
|---|---|
| Account, preference and program data (3.1(a), (g), (h)), including the referral relation, e-mail delivery status and push subscription tokens | While you hold the Account; the referral relation concerning a referred User, while that User's Account exists. On Account deletion, identifying data is erased or replaced at once under section 9.4, together with the delivery status and push tokens (tokens we also delete when you unsubscribe), and only the records listed below remain. If the Account is closed for inactivity under the Terms of Service, until claims can no longer be brought, as a rule 6 years, ending on the last day of the calendar year (art. 118 of the Civil Code) |
| Transaction, payout and accounting data, including giveaway prizes and referral commissions | 5 years from the beginning of the year following the financial year they relate to (art. 74 ust. 2 and 3 of the Accounting Act) and, where tax law requires it, until the tax liability prescribes, that is 5 years from the end of the calendar year in which the payment deadline fell (art. 86 § 1 read with art. 70 § 1 of the Tax Ordinance). The later date controls |
| Tax-remitter documentation (PIT-11 and PIT-4R data, copies of returns and information) | 5 years from the end of the calendar year in which the tax payment deadline fell (tax law; Art. 6(1)(c) GDPR) |
| Verification and anti-fraud records (outcomes, sanctions-screening results, related documentation) | 5 years, the period set by our AML/KYC and Anti-Fraud Policy of 27 July 2026, on our legitimate interest in fraud prevention and the protection of claims (Art. 6(1)(f) GDPR) |
| Identity-document copies (3.1(e)) | Deleted or irreversibly redacted promptly once no longer necessary, as a rule no later than 3 months from the completion of the verification; only its fact, date and result remain, for the 5 years above. Where the verification reveals a violation or supports a claim, the records join the claims files below |
| Claims, complaint and audit files (the Sale audit records defined in the Terms of Service, Section 12.10, BIN checks, verification decisions and any log preserved as evidence in a specific incident, complaint or claim) | Until claims can no longer be brought, as a rule 6 years (art. 118 of the Civil Code) |
| Authentication and security logs (login attempts) and device recognition signals (3.1(f)) | 12 months, unless preserved in the claims or incident files above |
| Server logs (access and error logs) and the error reports and performance events in our monitoring system (sec. 6.5) | 90 days, unless preserved in the incident or claims files above. Reports containing your Steam ID are additionally deleted the moment you delete your Account, as the clearing step of the Account deletion procedure (section 9.4.1); where that step has not yet run through the provider's systems, the reports concerned are deleted promptly, as a rule within a few days of the deletion of the Account |
| Anti-abuse identifier (3.1(k)) | The block limb: while the block is in force, and no longer than 5 years from Account deletion; if the block is lifted or expires, the identifier is deleted. The one-time-benefit limb: 3 years from Account deletion |
| Code-application log, and support and communication data (3.1(i)) outside complaint files | 3 years; for communication data, counted from the end of the correspondence |
| Marketing data | Until you withdraw consent or object |
| Records of consent, withdrawal and objection (date, source, clause or document version) | 6 years from the event recorded, as evidence before UODO, UKE and the courts |
| Cookies and similar identifiers | The lifetimes stated in section 10 |
8.2. Where several periods apply to the same record, the longest controls. After it ends, we delete the data or remove its identifying elements.
9. Your rights
9.1. You have the right to: 9.1.1. access your data and obtain a copy (Art. 15 GDPR); 9.1.2. rectification of inaccurate or incomplete data (Art. 16 GDPR); 9.1.3. erasure of data, to the extent Art. 17 GDPR allows it; 9.1.4. restriction of processing (Art. 18 GDPR); 9.1.5. data portability (Art. 20 GDPR); 9.1.6. withdraw consent at any time where processing rests on consent (section 4.1, rows 5, 9, 10 and 11), without affecting the lawfulness of processing carried out before the withdrawal.
9.2. You have the right to object under Art. 21 GDPR. Where we process your data on our legitimate interests, you may object at any time on grounds relating to your particular situation. This covers section 4.1, rows 2b, 3 (the anti-abuse limb), 5 (the masked public statistics), 6, 6a, 7 (the Art. 6(1)(f) limb) and 13. We then stop processing for that purpose unless we demonstrate compelling legitimate grounds for the processing overriding your interests, rights and freedoms, or the data is necessary to establish, exercise or defend legal claims.
9.3. If you object to direct marketing, you need give no reason and we always comply. You can also switch marketing e-mails off with the toggle in your Account profile or with the unsubscribe link included in every such e-mail. If you hold no Account and want your address excluded from review invitations, write to privacy@sellyourskins.com.
9.4. You can delete your Account yourself in your Account profile, with immediate effect, or ask us to delete it by e-mail. 9.4.1. On deletion we erase or replace with neutral values your SteamID, name and surname, avatar, Trade URL, e-mail address, IP data, country and similar identifying data. We delete push subscriptions, pending reminders, notifications and newsletter entries outright, and we deactivate referral codes. The deletion procedure also includes a clearing step in our error monitoring system: the error reports described in section 6.5 are tagged with your Steam ID as the user identifier, that identifier is what makes them findable, and we use it to delete them. Where the clearing step has not yet run through the provider's systems, the reports concerned are deleted promptly, in accordance with section 8.1. 9.4.2. We keep the records section 8 requires or entitles us to keep, in particular transaction and accounting records. They must identify the transaction and its counterparty to serve the accounting and tax obligations they exist for, so the identifying data in them stays as long as those obligations run. 9.4.3. If an Account block is in force, we keep a record of the block and the keyed identifier in section 3.1(k), so that the block and the one-time character of benefits already used stay effective despite re-registration. 9.4.4. What remains after deletion is pseudonymized, not anonymous. We keep a keyed identifier that lets us recognize a returning blocked Account, so the GDPR keeps applying to those records and your rights keep applying to you, within the limits following from section 8 and Art. 17(3) GDPR. 9.4.5. Your right to erasure does not depend on the state of your Wallet. Nothing is forfeited: before deletion we pay out any remaining balance, including amounts below the minimum payout, and any transaction in progress is settled in accordance with the Terms of Service; the Account is deleted once that settlement is complete. On deletion you may complete a short exit survey; we store it with no link to you and use it only as aggregate statistics, so please do not enter personal data in its free-text field.
9.5. Send requests to privacy@sellyourskins.com, or by post to the address in section 1.2 marked "Personal data". We answer without undue delay, and no later than one month from receiving the request. For complex or numerous requests we may extend that period by two months, and we tell you within the first month, with reasons.
9.6. If we have reasonable doubts about the identity of the person making a request, we may ask for information to confirm it, for example confirmation from the e-mail address linked to the Account or a login through Steam.
9.7. Exercising your rights is free. If requests are manifestly unfounded or excessive, in particular because of their repetitive character, we may charge a reasonable fee or refuse to act, giving reasons.
10. Cookies, device storage and device recognition
10.1. The Website stores information on your device and accesses information already stored there, using cookies (small text files) and similar technologies, such as sessionStorage entries. Under art. 399 of the Act of 12 July 2024, Electronic Communications Law (PKE), we do this without your consent only where it is necessary to transmit a communication or to deliver a service you explicitly requested; sections 10.4 and 10.5 list every such item. Everything else, analytics included, happens only with your consent, given to the standard art. 400 PKE requires, which is the GDPR standard of consent.
10.2. On your first visit, and whenever new consent is needed, the Website shows a consent banner. It asks before anything happens: no consent-based cookie is set and no consent-based script is loaded until you give consent, and continued browsing, scrolling or inaction is never consent. 10.2.1. You accept or reject each category separately, and rejecting is as easy as accepting, with the reject option at the same level as the accept option. 10.2.2. The cookie-settings link in the footer of the Website reopens the banner at any time, where you withdraw or change your choices as easily as you made them. Refusing consent to storage other than necessary does not block access to the Website.
10.3. The consent banner distinguishes the necessary category (sections 10.4 and 10.5) from the categories requiring your consent: analytics and marketing.
10.3.1. The analytics category covers the following tools.
| Tool | Provider | Purpose | Cookies | Lifetime |
|---|---|---|---|---|
| Microsoft Clarity | Microsoft Corporation | Session recordings and heatmaps showing how the Website is used | _clck, _clsk | _clck up to 12 months; _clsk 1 day |
| Google Analytics 4 | Google LLC | Aggregate usage statistics | _ga, _ga_* | up to 24 months |
| Google Tag Manager | Google LLC | Loading the tags above in line with your consent | no own persistent cookies | no lifetime applies, as it writes no cookie of its own |
Google Consent Mode v2 defaults all consent signals to "denied". Google tags receive consent signals only after you give consent and only to its extent. In session recordings, form fields are masked and recording is disabled on the payout and verification screens, so payout details, identity-document data and national identification numbers are never captured.
10.4. The support chat loads only at your request. The Intercom chat does not load with the page. It loads when you open it, and opening it is your request for that service, so the storage needed to run it is exempt from consent under art. 399 PKE. Intercom then sets its own cookies (names beginning with intercom-, for example intercom-id-*, intercom-session-*, intercom-device-id-*, with a lifetime of up to 9 months) to keep your conversation continuous. If you never open the chat, no Intercom cookie is set.
10.5. We use the storage below without your consent, as art. 399 ust. 3 PKE permits:
| Name | Type and purpose | Lifetime | Properties |
|---|---|---|---|
| PHPSESSID | Strictly necessary: keeps your session and login state | session | httpOnly |
| cc_cookie | Strictly necessary: stores the cookie choices you made in the banner | up to 12 months | first-party |
| __cf_bm, cf_clearance | Strictly necessary: security and bot-traffic management | __cf_bm approx. 30 minutes; cf_clearance up to 1 year | set by Cloudflare on our domain |
| I18N_LOCALE | Functional, at your request: remembers the interface language you selected | 6 months | first-party |
| ref_code | Functional, at your request: stores the referral code or Bonus Code from a link you followed, or a code you applied, until it is applied to your Sale | 90 days | first-party |
| ref_visit_logged | Functional: prevents the same visit from a referral link being counted more than once | 30 days | first-party |
| sys_ref_banner_dismissed | Functional: remembers that you dismissed the referral banner | sessionStorage (until the tab or session ends) | stays on your device |
We write ref_code when you follow a referral link or apply a code. It stores the Bonus Code or the referral code so that the code can be applied to your Sale and, for a referral code, so that the commission can be attributed to the Referrer. This is information necessary to deliver a service you explicitly request by following a link carrying a code or by applying a code (art. 399 PKE), so we do not ask for consent to write it. If you do not want the code applied, you can delete this cookie in your browser settings or simply not use the referral link.
10.6. Device recognition works as follows. To detect multi-accounting, bot activity and abuse of the bonus and referral programs, we compute a technical device identifier on our server side, from the data your browser itself sends with every request: request headers, including user-agent data and language settings, and network-level attributes. We run no script in your browser that reads device characteristics, and we do not access information stored in your device for this purpose. We never use these signals for advertising, marketing profiles or audience measurement. The processing rests on Art. 6(1)(f) GDPR (section 4.1, row 6), and you may object under section 9.2.
10.7. We load embedded third-party components, such as the Trustpilot review widget, so that they store nothing on your device before you interact with them. Where such a component would store or read more than the strictly necessary, we ask for your consent first.
10.8. You can also manage, delete or block cookies in your browser settings; some features of the Website may then stop working correctly.
11. Minors
11.1. The Website is intended only for persons at least 18 years old. We do not knowingly process children's personal data and we do not knowingly direct any service or any communication to them.
11.2. The date of birth collected during verification (section 3.1(e)) also confirms that you meet the age requirement.
11.3. If we establish that an Account belongs to a person under 18, we act under the Terms of Service. While the Account is suspended we process the minor's data only to maintain the Account, to settle the items held and the amounts owed, to document the case and to prevent the Account being recreated, and we send no marketing messages or reminders. Settlement may require the involvement of a parent or another statutory representative, whose contact and identification data we then process for that purpose alone, on Art. 6(1)(c) and Art. 6(1)(f) GDPR.
11.4. If you believe a person under 18 has given us personal data, write to privacy@sellyourskins.com and we will act without undue delay.
12. Referral data concerning third parties
12.1. If you reached us through someone's referral link or someone's code, this section 12 is our Art. 14 GDPR notice on the referral relation.
12.2. We process the code, the fact and time of your visit and, once you log in, the link between your Account and the Referrer's Account, to attribute your Sales, calculate the Referrer's commission and determine your eligibility for the Welcome Bonus (section 4.1, row 3). The source of the referral relation is the Referrer, who shared the link or code with you. All other information about you reaches us from you.
12.3. We inform you at first contact: a banner tells you that a referral code is pending, and this Privacy Policy is available to you before you log in.
12.4. Referrers do not see your identity. A Referrer sees only masked identifiers of referred Users, for example a partially hidden nickname and SteamID, with commission amounts.
13. Sources of your data
13.1. We obtain personal data: 13.1.1. directly from you, when you use the Website, apply codes, enter payout details, change settings or contact us; 13.1.2. from Steam (Valve) and, at your request, from steamwebapi.com, your profile and inventory data, publicly accessible on Steam, retrieved when you log in through Steam and use the Website; 13.1.3. from the payment service providers we engage, confirmations and statuses of the payouts they execute for you; 13.1.4. from Neutrino API, the brand, type, issuer country and issuer currency of your payout card, derived from its first digits; 13.1.5. from Twilio Inc. (SendGrid), the delivery, bounce and spam-report status of e-mails sent to you; 13.1.6. from infrastructure providers, the country derived from your IP address (Cloudflare, with ipinfo.io as fallback); 13.1.7. from Referrers, the referral relation described in section 12; 13.1.8. from the service database maintained before the Effective Date, the records of transactions concluded before 1 September 2026 and the program values recorded as at 31 August 2026, which we process only for the purposes and on the bases stated in section 1.5.3.
13.2. For section 13.1.8, the categories concerned are those in section 3.1(a), (c) and (g), and the recipients, retention periods and rights are those set out in sections 6, 8 and 9. We informed you of the change of operator by e-mail on 18 August 2026 and on the change-of-operator page of the Website.
14. Security and data breach handling
14.1. We apply technical and organizational measures appropriate to the risk: encryption in transit (TLS), access limited to personnel who need it for their tasks, network-level protections, separation of environments, event logging and monitoring, backups, and contractual security obligations imposed on our processors.
14.2. We document every personal data breach and, where Art. 33 GDPR so requires, notify it to the President of the Personal Data Protection Office. Where the breach is likely to result in a high risk to your rights and freedoms, we notify you as well and tell you what you can do to limit its effects (Art. 34 GDPR).
15. Complaints to the supervisory authority
15.1. If you consider that our processing infringes the GDPR, you may lodge a complaint with a supervisory authority: Prezes Urzędu Ochrony Danych Osobowych (President of the Personal Data Protection Office), ul. Stawki 2, 00-193 Warszawa, Poland, www.uodo.gov.pl.
15.2. If you live or work in another country of the European Economic Area, or the infringement took place in such a country, you may lodge the complaint with that country's supervisory authority (Art. 77(1) GDPR).
16. Changes to this Privacy Policy
16.1. The current version is always available at an unchanged address on the Website, showing the date from which it is in force. Previous versions are published alongside it, each showing the dates between which it applied.
16.2. We inform you of material changes, in particular those concerning purposes, legal bases, recipients or your rights, by e-mail to the address linked to your Account or by a clear notice on the Website, before the changes take effect.
Document previously in force
Until 31 August 2026 the Website was operated by SKINFINITY.GG (business register number 386079755). The document below belongs to that trader and governs the transactions concluded up to that date, which that trader performs and settles (Section 3.2). We publish it so that you can reach it.
- SKINFINITY.GG Privacy Policy of 7 March 2024in force until 31 August 2026
Dokumentumverzió: 2026-09-01