Privacy Policy
Last updated: 17 August 2026
1. Introduction
1.1
This Privacy Policy explains how we collect, use, store, share and protect personal data when you visit https://prestigeskins.store (the “Site”), create an account, place an order, or otherwise interact with us.
1.2
The Site is operated by DUVIAN LTD, a company registered in England and Wales under company number 17393283, whose registered address is at Suite Ra01, 195-197 Wood Street, London, United Kingdom, E17 3NU. We trade as PrestigeSkins.
1.3
For the purposes of the UK General Data Protection Regulation (“UK GDPR”) and the Data Protection Act 2018 (“DPA 2018”), DUVIAN LTD is the controller of the personal data described in this Policy. This means we decide why and how your personal data is processed.
1.4
The registered address address given above is a registered address for the service of formal legal documents only. It is not a shop, showroom or customer-facing office, and it cannot accept visitors or deliveries relating to orders. All customer correspondence should be sent to contactform@prestigeskins.store.
1.5
We sell cosmetic in-game items (“skins”) for Counter-Strike 2, which are delivered digitally to your Steam account by trade. Understanding how our service works helps explain why we need certain data — in particular your Steam account identifiers, which are technically necessary to deliver what you have bought.
2. Scope of this Policy
2.1
This Policy applies to personal data we process about:
- (a) visitors to the Site;
- (b) registered account holders;
- (c) customers and prospective customers;
- (d) people who contact us with an enquiry, complaint or legal notice.
2.2
This Policy does not apply to third-party services that we do not control. In particular, your use of Steam is governed by Valve Corporation’s own terms and privacy policy. When you send or accept a trade on Steam, Valve processes your data as an independent controller. We have no access to your Steam password or Steam Guard credentials and will never ask for them.
2.3
The Site may contain links to third-party websites. We are not responsible for the privacy practices of those websites, and we encourage you to read their privacy notices before providing them with any personal data.
3. Age restriction
3.1
Our services are intended solely for individuals aged 18 or over. We do not knowingly collect personal data from anyone under 18.
3.2
If we become aware that we hold personal data relating to a person under 18, we will delete it without undue delay, subject to any overriding legal obligation to retain records (for example, records of a transaction that must be kept for tax purposes). If you believe a person under 18 has provided us with personal data, please contact us at contactform@prestigeskins.store.
4. Personal data we collect
4.1
We collect the following categories of personal data.
| Category | Examples of data | Source |
|---|---|---|
| Identity and account data | Username, display name, password (stored only in hashed form), account preferences, account creation date | Provided by you |
| Contact data | Email address; postal address or country where required for tax or verification purposes | Provided by you |
| Steam and delivery data | SteamID (64-bit), Steam trade URL, Steam profile display name and public profile information, trade offer identifiers, trade status and timestamps, trade hold or cooldown information | Provided by you and returned by the Steam platform |
| Order and transaction data | Items ordered, order reference, price in EUR, date and time, order status, delivery confirmation, refund and cancellation records, cancellation-waiver acknowledgement | Generated by us; provided by you |
| Payment data | Payment method type, partial card identifiers (such as last four digits and card brand), transaction reference, authorisation outcome, currency and amount, billing name and billing address | Provided by you to our payment provider and shared with us in limited form |
| Communications data | Emails and support messages you send us, our replies, complaint records, notes of the handling of your case | Provided by you; generated by us |
| Technical and usage data | IP address, approximate location derived from IP (country or region level), browser type and version, operating system and device type, referring URL, pages viewed, time and duration of visits, error logs, session identifiers | Collected automatically |
| Fraud and risk data | Risk scores or flags returned by our payment provider or fraud-screening tools, records of chargebacks or disputes, records of prohibited conduct, evidence gathered when investigating suspicious activity | Generated by us; provided by third parties |
| Marketing data | Marketing preferences, consent records (including date, time and method of consent), suppression or unsubscribe records | Provided by you; generated by us |
4.2
We do not knowingly collect special category data (data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic or biometric data, health data, or data concerning sex life or sexual orientation), nor criminal offence data. Please do not send us such data. If you do so voluntarily — for example, in the free text of a support message — we will delete it as soon as reasonably practicable unless we need it to handle your query.
4.3
We do not require or store your Steam password, Steam Guard codes, mobile authenticator credentials, or full payment card numbers. Full card details are entered directly with our payment provider and are never held on our systems.
4.4
If you choose not to provide certain data, we may be unable to provide the service. In particular, without a valid Steam trade URL we cannot deliver items you have purchased, and without an email address we cannot send you order confirmations or handle a complaint.
5. How we use your personal data and our lawful bases
5.1
Under the UK GDPR we must have a lawful basis for each purpose for which we process your personal data. The table below sets out our purposes and the corresponding lawful basis.
| Purpose | Data used | Lawful basis (UK GDPR Article 6) |
|---|---|---|
| Creating and administering your account | Identity, contact, technical | Contract — Art. 6(1)(b): necessary to take steps at your request and to perform our contract with you |
| Processing your order and forming the contract of sale | Identity, contact, order, payment | Contract — Art. 6(1)(b) |
| Delivering purchased items to your Steam account by trade | Steam and delivery, order | Contract — Art. 6(1)(b) |
| Taking payment and managing refunds, cancellations and chargebacks | Payment, order, contact | Contract — Art. 6(1)(b); and Legal obligation — Art. 6(1)(c) where a refund is required by consumer law |
| Providing customer support and responding to enquiries | Contact, communications, order | Contract — Art. 6(1)(b) where it concerns an order; otherwise Legitimate interests — Art. 6(1)(f): responding to people who contact us |
| Handling complaints and disputes, including alternative dispute resolution | Communications, order, identity | Legal obligation — Art. 6(1)(c) under the Alternative Dispute Resolution for Consumer Disputes (Competent Authorities and Information) Regulations 2015; and Legitimate interests — Art. 6(1)(f): resolving disputes fairly and defending legal claims |
| Preventing, detecting and investigating fraud, including payment fraud, stolen accounts and chargeback abuse | Fraud and risk, payment, technical, Steam and delivery | Legitimate interests — Art. 6(1)(f): protecting our business, our customers and our payment providers from fraud and financial crime |
| Keeping the Site secure, diagnosing faults, preventing abuse and automated scraping | Technical, usage | Legitimate interests — Art. 6(1)(f): network and information security |
| Keeping accounting and tax records | Order, payment, identity, contact | Legal obligation — Art. 6(1)(c) under the Companies Act 2006 and UK tax legislation |
| Verifying that customers are 18 or over | Identity, account | Legal obligation — Art. 6(1)(c) where applicable; and Legitimate interests — Art. 6(1)(f): operating an age-restricted service responsibly |
| Sending order-related (transactional) emails such as confirmations and delivery notices | Contact, order | Contract — Art. 6(1)(b) |
| Sending marketing emails about our products and offers | Contact, marketing | Consent — Art. 6(1)(a); or Legitimate interests — Art. 6(1)(f) where the “soft opt-in” in regulation 22 of PECR applies (see clause 9) |
| Analytics and understanding how the Site is used | Technical, usage | Consent — Art. 6(1)(a) (consent is obtained through our cookie banner before any non-essential cookie or similar technology is set) |
| Establishing, exercising or defending legal claims | Any relevant category | Legitimate interests — Art. 6(1)(f): protecting our legal position; and Legal obligation — Art. 6(1)(c) where we must comply with a court order or lawful request |
5.2
Legitimate interests assessments. Where we rely on legitimate interests, we have considered whether our interests are overridden by your interests, rights and freedoms, and we have concluded that they are not. You have the right to object to processing based on legitimate interests (see clause 11.1(f)). You may request a summary of our legitimate interests assessment for a particular purpose by contacting us.
5.3
Change of purpose. We will only use your personal data for the purposes for which we collected it, unless we reasonably consider that we need to use it for another compatible purpose. If we need to use your data for an unrelated purpose, we will tell you and explain the lawful basis on which we can do so.
6. Automated decision-making and profiling
6.1
We do not make decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you, within the meaning of Article 22 of the UK GDPR, other than as described in clause 6.2.
6.2
Automated fraud screening — described honestly. Orders are screened for fraud and payment risk. This screening involves automated checks carried out by us and by our payment provider, which may consider factors such as: the payment method used; mismatches between billing and technical data; the age and history of your account; the value and pattern of your orders; previously recorded chargebacks or disputes; and characteristics of the Steam account to which delivery is requested. This process may result in an order being automatically declined, held for manual review, or flagged for additional verification.
6.3
Where an order is automatically declined or held, this is a decision about a single transaction. It does not create a legal status, a credit record or a permanent bar, and we do not build a general profile of you for any wider purpose. Nevertheless, so that you are treated fairly:
- (a) you may contact us at contactform@prestigeskins.store to ask why an order was declined or held;
- (b) you may ask for the decision to be reviewed by a member of our team (human intervention);
- (c) you may express your point of view and contest the decision;
- (d) any payment already taken for a declined order will be refunded or the authorisation released.
6.4
We may not always be able to disclose the detailed rules used to detect fraud, because doing so would undermine their effectiveness and would prejudice the prevention and detection of crime. We will, however, always give you as much information as we reasonably can.
6.5
We do not use your personal data for automated advertising profiling or for behavioural advertising by third parties without your consent.
7. Who we share your personal data with
7.1
We share personal data only where it is necessary, and only with recipients who are required to keep it secure. Recipients fall into the following categories.
| Recipient category | Purpose of sharing | Role |
|---|---|---|
| our payment service providers and any other payment service provider we use | Processing payments, refunds, chargebacks and fraud screening | Independent controller and/or processor, depending on the activity |
| our hosting provider | Hosting the Site, databases and backups | Processor |
| our email service provider | Sending transactional and (where consented) marketing email | Processor |
| our analytics provider | Website analytics, where you have consented | Processor |
| our infrastructure and security providers | Content delivery, caching, denial-of-service protection and bot mitigation | Processor |
| Valve Corporation (Steam) | Necessarily, in order to send a trade offer to your Steam account | Independent controller |
| Professional advisers — lawyers, accountants, auditors and insurers | Legal advice, accounts, audit, insurance claims | Independent controllers or processors, as applicable |
| Law enforcement, regulators, courts and government bodies | Where we are required by law, or where disclosure is necessary to establish, exercise or defend legal claims | Independent controllers |
| A purchaser or successor of our business or assets | Business reorganisation, merger or sale | Independent controller |
7.2
Where a recipient acts as our processor, we put in place a written contract complying with Article 28 of the UK GDPR requiring them to process personal data only on our documented instructions and to apply appropriate security measures.
7.3
We do not sell your personal data, and we do not share it with third parties for their own independent marketing purposes.
7.4
A note on Steam. To deliver an item we must send a trade offer to the Steam account identified by the trade URL you give us. The trade offer, and the information visible within it, is handled by Valve Corporation under its own policies. Some information about your Steam account (such as your display name and inventory) may be publicly visible on Steam depending on the privacy settings you have chosen there. We do not control those settings.
8. International transfers
8.1
Some of our service providers, and the Steam platform itself, are located outside the United Kingdom, including in the United States and the European Economic Area. Where personal data is transferred outside the UK, we ensure an appropriate level of protection is in place by relying on one of the following safeguards:
- (a) UK adequacy regulations — the receiving country, territory or sector is covered by adequacy regulations made by the Secretary of State under section 17A of the DPA 2018 (this includes transfers to EEA countries);
- (b) the International Data Transfer Agreement (IDTA) issued by the Information Commissioner, or the International Data Transfer Addendum to the European Commission’s Standard Contractual Clauses, together with a transfer risk assessment; or
- (c) another lawful transfer mechanism or derogation permitted by Chapter V of the UK GDPR, including where the transfer is necessary for the performance of a contract with you (Article 49(1)(b)) — which is the position when a trade offer must be routed through the Steam platform in order to deliver your purchase.
8.2
You may request further information about the safeguards applied to a particular transfer, and a copy of the relevant clauses (with commercially confidential terms redacted), by contacting us at contactform@prestigeskins.store.
9. Marketing and electronic communications
9.1
Transactional messages. We will always send you emails that are necessary to perform our contract with you — for example order confirmations, delivery notices, refund confirmations and important service or security notices. These are not marketing and you cannot opt out of them while you hold an account or an open order.
9.2
Marketing messages. We will only send you marketing email where:
- (a) you have given us your consent to do so; or
- (b) the “soft opt-in” in regulation 22(3) of the Privacy and Electronic Communications (EC Directive) Regulations 2003 (“PECR”) applies — that is, we obtained your contact details in the course of a sale or negotiations for a sale, the marketing relates to our own similar products, and you were given a simple means of refusing at the time and in every message.
9.3
Withdrawing consent. You can opt out at any time, free of charge, by clicking the unsubscribe link in any marketing email or by emailing contactform@prestigeskins.store. We will action your request promptly. Withdrawing consent does not affect the lawfulness of processing carried out before withdrawal.
9.4
When you unsubscribe, we retain a minimal record of your email address on a suppression list. This is necessary so that we can honour your request and avoid contacting you again; we do not use the suppression list for any other purpose.
9.5
Cookies and similar technologies are covered by regulation 6 of PECR and are explained in our Cookies Policy.
10. How long we keep your personal data
10.1
We keep personal data only for as long as necessary for the purposes for which it was collected, including to satisfy legal, accounting or reporting requirements. Our standard retention periods are set out below.
| Record type | Retention period | Rationale |
|---|---|---|
| Order, transaction and payment records | 6 years from the end of the accounting period in which the transaction occurred | Companies Act 2006 (sections 386–388) and UK tax record-keeping requirements |
| Trade delivery records and cancellation-waiver acknowledgements | 6 years from the date of the order | Evidence of contract performance and of the consumer’s express consent under the Consumer Contracts Regulations 2013; general limitation period under the Limitation Act 1980 |
| Account data (where no orders have been placed) | Life of the account, plus 12 months after closure or after 24 months of inactivity | Allows account reactivation; avoids retaining dormant data indefinitely |
| Customer support correspondence | 24 months from the date of last contact | Service quality and query history |
| Complaint files | 6 years from closure of the complaint | Limitation Act 1980; regulatory and ADR requirements |
| Fraud, chargeback and prohibited-conduct records | 6 years from the relevant event | Fraud prevention and defence of legal claims |
| Marketing consent records | For as long as consent is relied upon, plus 24 months | Demonstrating compliance with UK GDPR Article 7(1) |
| Suppression (unsubscribe) list | Retained for as long as we operate, unless you ask otherwise | Necessary to honour your opt-out |
| Server, security and error logs | 90 days | Security monitoring and fault diagnosis |
| Analytics data | 26 months, in pseudonymised or aggregated form wherever possible | Understanding Site performance |
| Backups | Overwritten on a rolling cycle of 30 days | Business continuity |
10.2
Where data is deleted from live systems, residual copies may persist in backups until those backups are overwritten in the ordinary cycle. During that period the data is not used for any active purpose.
10.3
Where we no longer need to identify you, we may anonymise your data so that it can no longer be associated with you, and use that anonymised information indefinitely for statistical purposes without further notice to you.
11. Your rights
11.1
Under the UK GDPR you have the following rights, which you may exercise free of charge:
- (a) Right of access (Article 15) — to be told whether we process your personal data and, if so, to receive a copy of it together with information about how it is used.
- (b) Right to rectification (Article 16) — to have inaccurate personal data corrected and incomplete data completed.
- (c) Right to erasure (Article 17) — to ask us to delete your personal data where, for example, it is no longer necessary for the purpose, you withdraw consent and there is no other lawful basis, or it has been unlawfully processed. This right is not absolute and does not apply where we must keep the data to comply with a legal obligation or to establish, exercise or defend legal claims.
- (d) Right to restriction of processing (Article 18) — to ask us to suspend the processing of your personal data in certain circumstances, for example while we verify its accuracy.
- (e) Right to data portability (Article 20) — to receive the personal data you have provided to us in a structured, commonly used and machine-readable format, and to have it transmitted to another controller where technically feasible. This applies to data processed by automated means on the basis of consent or contract.
- (f) Right to object (Article 21) — to object at any time to processing based on our legitimate interests. We will stop unless we can demonstrate compelling legitimate grounds which override your interests, rights and freedoms, or the processing is for the establishment, exercise or defence of legal claims. You may object to direct marketing at any time and we will always stop.
- (g) Rights relating to automated decision-making (Article 22) — see clause 6.
- (h) Right to withdraw consent (Article 7(3)) — where we rely on consent, you may withdraw it at any time. This does not affect the lawfulness of processing before withdrawal.
11.2
How to exercise your rights. Please email contactform@prestigeskins.store, stating clearly which right you wish to exercise and providing enough information for us to locate your records (for example, the email address associated with your account, and any relevant order references).
11.3
Identity verification. We may ask you for information to confirm your identity before acting on a request. This is a security measure to ensure that personal data is not disclosed to anyone who has no right to receive it. We will ask only for what is proportionate.
11.4
Timescale. We will respond without undue delay and in any event within one month of receiving your request. Where a request is complex, or where you have made a number of requests, we may extend this period by up to a further two months. If we do, we will tell you within one month of receiving your request and explain why.
11.5
Fees and refusals. We do not charge a fee for exercising your rights. However, if a request is manifestly unfounded or excessive, we may charge a reasonable administrative fee or refuse to act. If we refuse, we will explain why and tell you about your right to complain to the ICO and to seek a judicial remedy.
12. Data security
12.1
We have implemented appropriate technical and organisational measures under Article 32 of the UK GDPR to protect personal data against unauthorised or unlawful processing and against accidental loss, destruction or damage. These measures include: encryption of data in transit using TLS; access controls and role-based permissions; the use of hashed password storage; segregation of administrative access; logging and monitoring; regular software updates and patching; and restricting access to personal data to those who need it to do their job.
12.2
No method of transmission over the internet or method of electronic storage is completely secure. While we take all reasonable steps to protect your personal data, we cannot guarantee absolute security.
12.3
Your responsibilities. You are responsible for keeping your account credentials confidential, for enabling and maintaining Steam Guard on your Steam account, and for not sharing your trade URL publicly except where necessary. We will never ask you for your password, your Steam Guard codes, or your mobile authenticator seed. Any message that asks for these is fraudulent and should be reported to us.
12.4
Breach notification. Where a personal data breach is likely to result in a risk to your rights and freedoms, we will notify the Information Commissioner’s Office without undue delay and, where feasible, within 72 hours of becoming aware of it, in accordance with Article 33. Where the breach is likely to result in a high risk, we will also notify you without undue delay in accordance with Article 34.
13. Cookies and similar technologies
13.1
The Site uses cookies and similar technologies. Non-essential cookies are set only with your consent, obtained through our cookie banner, in accordance with regulation 6 of PECR and the consent standard in the UK GDPR.
13.2
Full details of the categories of cookies we use, and how to give or withdraw your consent, are set out in our separate Cookies Policy, which forms part of this Privacy Policy.
14. Changes to this Policy
14.1
We may update this Policy from time to time to reflect changes in our practices, our service, or in the law. The “Last updated” date at the top of this page shows when it was last revised.
14.2
Where a change is material — for example, if we begin processing your personal data for a new purpose or on a new lawful basis — we will bring it to your attention by a prominent notice on the Site and, where we hold your email address and it is appropriate to do so, by email. Where a change requires your consent, we will obtain it before the change takes effect.
14.3
We recommend that you review this Policy periodically.
15. Complaints and the Information Commissioner’s Office
15.1
If you are unhappy with how we have handled your personal data or a request you have made, please tell us first at contactform@prestigeskins.store. We take such concerns seriously and will investigate under our Complaints Policy.
15.2
You also have the right to lodge a complaint with the Information Commissioner’s Office (ICO), the UK supervisory authority for data protection, at any time. You do not need to complain to us first.
Information Commissioner’s Office Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF, United Kingdom Helpline: 0303 123 1113 Website: https://ico.org.uk
15.3
You also have the right to an effective judicial remedy under Article 79 of the UK GDPR and section 167 of the DPA 2018, and you may be entitled to compensation for damage suffered as a result of an infringement under Article 82 and section 168.
15.4
Our.
16. Contact us
Any questions about this Privacy Policy, or any request to exercise your data protection rights, should be sent to the contact point below.
DUVIAN LTD (trading as PrestigeSkins) Registered in England and Wales, company number 17393283 Registered address: Suite Ra01, 195-197 Wood Street, London, United Kingdom, E17 3NU Email: contactform@prestigeskins.store Website: https://prestigeskins.store The registered address is for the service of formal documents only. It is not open to visitors.
We have not appointed a statutory Data Protection Officer, as we are not required to do so under Article 37 of the UK GDPR. Responsibility for data protection matters sits with the Data Protection Lead, contactable at the email address above.