Privacy Policy
Effective date: 23 July 2026 · Last updated: 23 July 2026
This Privacy Policy explains how Axevyron OÜ collects, uses, shares and protects personal data when you visit skintory.store, sign in with Steam, contact our support team or purchase in-game virtual items from us.
1. Who we are
Axevyron OÜ (trading as “Skintory”, referred to in this Policy as “we”, “us” or “our”) operates the website skintory.store (the “Website”) and the related online store through which we sell in-game virtual items for Counter-Strike 2 (the “Services”).
For the purposes of the General Data Protection Regulation (Regulation (EU) 2016/679, the “GDPR”), we are the data controller of the personal data described in this Policy.
| Company name | Axevyron OÜ |
|---|---|
| Registry code | 17545790 |
| Registered address | Tööstuse tn 48, Põhja-Tallinna linnaosa, 10416 Tallinn, Harju maakond, Estonia |
| privacy@skintory.store | |
| Website | https://skintory.store |
We have not appointed a Data Protection Officer, as we are not required to do so under Article 37 of the GDPR. All privacy enquiries should be sent to the email address above.
2. Scope of this Policy
This Policy applies to all personal data we process about visitors to the Website, registered account holders, customers and people who contact us. It does not apply to third-party services that we do not control, including Steam and the payment providers you may use to pay for an order. Those services process your data under their own privacy policies, and we encourage you to read them.
3. Personal data we collect
3.1 Data you provide to us
- Order data — the items you buy, order number, order date, order total and order status.
- Steam trade URL — the trade link you enter at checkout so that we can deliver the item to your Steam inventory.
- Contact data — your email address and any other information you choose to include when you write to our support team or use a contact form on the Website.
- Billing data — the billing details required to issue an invoice and to complete the payment, where applicable.
- Marketing data — your email address if you voluntarily subscribe to our newsletter.
3.2 Data we receive from Steam
If you sign in using Steam, authentication is performed by Valve Corporation through the OpenID protocol. We never see or receive your Steam password. Steam provides us with a limited set of public profile data, which typically includes:
- your Steam ID (a unique numeric identifier);
- your Steam profile name and avatar image;
- the public URL of your Steam profile.
We use this data to create and identify your account on the Website and to associate your orders with the correct Steam account.
3.3 Data collected automatically
- Technical data — IP address, browser type and version, operating system, device type, screen resolution, language and time zone settings.
- Usage data — pages viewed, items viewed, referring page, date and time of access, and interactions with the Website.
- Cookie data — information stored in cookies and similar technologies, as described in our Cookies Policy.
- Server logs — our hosting infrastructure records requests made to the Website for security, diagnostic and abuse-prevention purposes.
3.4 Data we receive from third parties
- Payment service providers — confirmation that a payment has succeeded, failed or been refunded, together with a transaction reference and, in some cases, a masked identifier of the payment instrument. We do not receive or store your full card number, CVV or banking credentials.
- Item supply partners — confirmation of item purchase, delivery status and trade offer results from the trading platforms we use to source and deliver items.
- Anti-bot and security providers — risk signals used to distinguish genuine users from automated traffic.
3.5 Sensitive data
We do not intentionally collect special categories of personal data (such as data revealing health, political opinions, religious beliefs or biometric data). Please do not send us such information.
4. Why we use your data and our legal bases
We only process personal data where we have a lawful basis to do so under Article 6 of the GDPR.
| Purpose | Categories of data | Legal basis |
|---|---|---|
| Creating and administering your account, authenticating you via Steam | Steam ID, profile name, avatar, profile URL, email | Performance of a contract (Art. 6(1)(b)) |
| Processing orders, purchasing items on your behalf and delivering them to your Steam inventory | Order data, Steam ID, trade URL, payment confirmation | Performance of a contract (Art. 6(1)(b)) |
| Taking payment and processing refunds | Order data, billing data, transaction references | Performance of a contract (Art. 6(1)(b)) |
| Providing customer support and handling complaints and refund claims | Contact data, order data, correspondence | Performance of a contract (Art. 6(1)(b)); legitimate interests (Art. 6(1)(f)) |
| Keeping accounting records and issuing invoices | Order data, billing data, transaction references | Compliance with a legal obligation (Art. 6(1)(c)) |
| Preventing fraud, chargeback abuse, money laundering and unauthorised access | Technical data, usage data, order data, Steam ID | Legitimate interests (Art. 6(1)(f)); legal obligation (Art. 6(1)(c)) |
| Securing and maintaining the Website, diagnosing faults and improving performance | Technical data, usage data, server logs | Legitimate interests (Art. 6(1)(f)) |
| Sending newsletters and promotional messages | Email address, marketing preferences | Consent (Art. 6(1)(a)) |
| Setting non-essential cookies | Cookie data, technical data | Consent (Art. 6(1)(a)) |
| Establishing, exercising or defending legal claims | Any of the above, as relevant | Legitimate interests (Art. 6(1)(f)) |
Where we rely on legitimate interests, we have assessed that our interests are not overridden by your rights and freedoms. You may object to such processing at any time (see section 10).
5. Steam integration and trade data
Delivery of the items you purchase is only technically possible if we can send a Steam trade offer to your account. This requires your Steam ID and a valid Steam trade URL. If you do not provide a valid trade URL, or if your Steam account is subject to a trade restriction, we will not be able to complete your order.
To display accurate item information such as float value, exterior, rarity and applied stickers, we may transmit an item inspection link to a specialised third-party inspection service. Inspection links relate to the in-game item, not to you personally, but they may be associated with a listing that you subsequently purchase.
Skintory is not affiliated with, endorsed by, sponsored by or otherwise associated with Valve Corporation. Your use of Steam is governed by the Steam Subscriber Agreement and the Valve Privacy Policy.
6. Marketing communications
We will only send you marketing emails if you have subscribed to them. Every marketing email contains an unsubscribe link, and you may also withdraw your consent at any time by writing to privacy@skintory.store. Withdrawing consent does not affect the lawfulness of processing carried out before the withdrawal.
Transactional messages — such as order confirmations, delivery notifications, refund notices and security alerts — are a necessary part of the service and are not marketing. You cannot opt out of these while you have an active order or account.
7. Who we share your data with
We do not sell your personal data and we do not share it for third-party advertising purposes. We disclose personal data only to the following categories of recipients, and only to the extent necessary:
| Recipient category | Purpose of disclosure |
|---|---|
| Hosting and infrastructure providers | Operating the Website, storing data, backups |
| Payment service providers | Taking payment, processing refunds, fraud screening |
| Item trading platforms and supply partners | Sourcing the item you ordered and delivering it to your Steam inventory |
| Item inspection and pricing services | Retrieving item attributes and current market prices |
| Email delivery and newsletter providers | Sending transactional and, where consented, marketing emails |
| Security and anti-bot providers | Protecting the Website against automated abuse and attacks |
| Professional advisers and accountants | Bookkeeping, tax compliance, legal advice |
| Public authorities and courts | Where disclosure is required by law or necessary to establish or defend legal claims |
All processors acting on our behalf are bound by written agreements that meet the requirements of Article 28 of the GDPR. If our business is transferred, merged or restructured, personal data may be transferred to the acquiring entity, subject to the protections described in this Policy.
8. International transfers
Our processing takes place primarily within the European Economic Area (EEA). Some of our service providers — in particular certain payment, email and security providers — may process data outside the EEA. Where this occurs, we ensure an appropriate safeguard is in place, which will normally be:
- an adequacy decision adopted by the European Commission under Article 45 of the GDPR; or
- Standard Contractual Clauses approved by the European Commission under Article 46 of the GDPR, supplemented where necessary by additional technical and organisational measures.
You may request further information about the safeguards applied to a specific transfer by contacting us.
9. How long we keep your data
| Data | Retention period |
|---|---|
| Account data | For as long as your account remains active, and for 12 months after your last activity or after you request deletion, whichever is earlier |
| Order, transaction and accounting records | 7 years from the end of the relevant financial year, as required by the Estonian Accounting Act |
| Support correspondence | 24 months from the closure of the enquiry |
| Fraud and abuse records | Up to 5 years, where necessary to prevent repeat abuse and to defend legal claims |
| Marketing consent records and newsletter data | Until you withdraw consent, plus 3 years to evidence the consent |
| Server logs | Up to 12 months |
| Cookies | As set out in our Cookies Policy |
Where we are required to keep certain records for statutory periods, we will retain them even if you ask us to delete your account, and we will restrict processing to that legal purpose only.
10. Your rights
Subject to the conditions set out in the GDPR, you have the following rights:
- Access — to obtain confirmation of whether we process your data, and a copy of it (Art. 15).
- Rectification — to have inaccurate data corrected and incomplete data completed (Art. 16).
- Erasure — to have your data deleted where one of the grounds in Article 17 applies.
- Restriction — to have processing limited in the circumstances described in Article 18.
- Data portability — to receive the data you provided to us in a structured, commonly used and machine-readable format, and to have it transmitted to another controller where technically feasible (Art. 20).
- Objection — to object at any time to processing based on legitimate interests, and to object at any time and without justification to processing for direct marketing (Art. 21).
- Withdrawal of consent — to withdraw consent at any time, without affecting the lawfulness of processing carried out beforehand (Art. 7(3)).
To exercise any of these rights, write to privacy@skintory.store. We will respond within one month of receiving your request. That period may be extended by up to two further months where the request is complex or where we have received a number of requests, in which case we will inform you within the first month. We may ask you for information to verify your identity before acting on a request.
11. Automated decision-making
We do not carry out automated decision-making that produces legal effects concerning you or similarly significantly affects you within the meaning of Article 22 of the GDPR. Automated checks may be used to screen orders for fraud indicators, but an order will not be cancelled solely on that basis without human review where you ask us to reconsider.
12. Security
We implement appropriate technical and organisational measures to protect personal data against unauthorised or unlawful processing and against accidental loss, destruction or damage. These include encryption of data in transit using TLS, access controls and role separation, regular software updates, protection against automated abuse, and restricted administrative access.
No method of transmission or storage is completely secure. If a personal data breach occurs that is likely to result in a high risk to your rights and freedoms, we will notify you and the competent supervisory authority in accordance with Articles 33 and 34 of the GDPR.
13. Children
The Services are intended for users aged 18 and over. We do not knowingly collect personal data from children. If you believe that a child has provided us with personal data, please contact us and we will delete it without undue delay.
14. Third-party links
The Website may contain links to third-party websites, including Steam, social media platforms and content creators’ channels. We are not responsible for the privacy practices of those websites, and this Policy does not apply to them.
15. Changes to this Policy
We may update this Policy from time to time to reflect changes in our practices, our service providers or applicable law. The version in force is always the one published on this page, and the “last updated” date at the top indicates when it was last revised. Where a change is material, we will provide reasonable advance notice by email or through a prominent notice on the Website.
16. Contact and complaints
If you have any question about this Policy or about how we handle your personal data, please contact us first:
| Axevyron OÜ | Registry code 17545790 |
|---|---|
| Address | Tööstuse tn 48, Põhja-Tallinna linnaosa, 10416 Tallinn, Harju maakond, Estonia |
| privacy@skintory.store |
You also have the right to lodge a complaint with a supervisory authority, in particular in the EU Member State of your habitual residence, place of work or place of the alleged infringement. Our lead supervisory authority is:
Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon)
Tatari 39, 10134 Tallinn, Estonia
Email: info@aki.ee · Website: www.aki.ee