Where we rely on
legitimate interests, we balance our interests against your rights and freedoms. Our legitimate interests include operating a secure digital-skins marketplace, preventing fraud and abuse, protecting users, enforcing our terms, supporting payment integrity, improving our services, and defending legal claims.
Where we rely on consent, you may withdraw consent at any time. Withdrawal does not affect processing that occurred before withdrawal.6. Payment-card and card-scheme data protectionBecause we accept card payments, we work with payment service providers, acquirers, card networks, issuing banks, fraud-prevention tools, and authentication providers.
To support payment security and card-scheme requirements, we may process and share relevant transaction data for:
- card authorization and settlement;
- 3-D Secure authentication;
- fraud screening and transaction monitoring;
- refunds, reversals, chargebacks, and dispute resolution;
- prevention of unauthorized transactions;
- compliance with Visa, Mastercard, acquirer, processor, and PCI DSS requirements;
- audit, reconciliation, and reporting;
- detection and prevention of illegal, deceptive, or abusive activity.
We do not sell cardholder data. We do not use cardholder data for unrelated marketing. We do not request or store CVV/CVC codes after authorization. Where we receive card metadata, such as last four digits or card brand, we use it only for payment confirmation, customer support, fraud prevention, dispute handling, and legal/accounting purposes.
7. Fraud prevention and risk scoringDigital skins can be targeted by account takeover, stolen payment cards, stolen items, bots, refund abuse, chargeback abuse, market manipulation, sanctions evasion, and other forms of fraud. To protect users and our business, we may use manual and automated checks.
These checks may consider:
- account age and history;
- transaction value and frequency;
- Steam profile and trade history;
- payment method and billing information;
- device, browser, IP address, VPN/proxy indicators, and approximate location;
- failed login attempts;
- chargebacks, refunds, or disputes;
- sanctions, fraud, or compliance signals;
- links between accounts, devices, payment methods, or Steam profiles.
These checks may result in additional verification, delayed delivery, blocked transactions, withdrawal limits, account restrictions, or account closure. You may contact us at
support@gamepunk.net to request human review of a decision where required by applicable law.
8. Cookies and similar technologiesWe use cookies, pixels, local storage, SDKs, and similar technologies.
8.1 Essential cookiesThese are required for the website to work. They may support:
- login and authentication;
- shopping cart and checkout;
- fraud prevention;
- security;
- load balancing;
- cookie-consent preferences.
8.2 Analytics cookiesThese help us understand how users interact with the website, identify errors, and improve performance. Where required by law, we use analytics cookies only with your consent.
8.3 Marketing cookiesThese may help us measure advertising, prevent ad fraud, personalize offers, or retarget users. We use these only where permitted by law and, where required, with your consent.
You may control cookies through your browser settings. Blocking some cookies may affect website functionality.
9. Marketing communicationsWe may send you marketing emails, offers, promotions, or updates if you consent or where permitted by law for existing customers.
You can unsubscribe at any time by clicking the unsubscribe link in our emails or contacting us at support@gamepunk.net. We may still send non-marketing messages, such as security alerts, order confirmations, payment updates, account notices, and legal notices.
10. Who we share personal data withWe may share personal data with the following categories of recipients:
- payment service providers;
- acquiring banks, issuing banks, card networks, and 3-D Secure providers;
- fraud-prevention, risk, chargeback, and dispute-management providers;
- KYC, identity-verification, age-verification, sanctions-screening, and compliance providers;
- cloud hosting, infrastructure, security, and content-delivery providers;
- analytics and performance-monitoring providers;
- email, SMS, push-notification, and customer-support providers;
- accounting, tax, legal, audit, and professional advisers;
- logistics or digital-delivery service providers, where applicable;
- other users, only where necessary for marketplace features, transaction completion, dispute handling, or legal compliance;
- regulators, courts, law enforcement, financial intelligence units, tax authorities, card-scheme bodies, payment processors, and other authorities where required or permitted by law;
- potential buyers, investors, successors, or advisers in connection with a merger, acquisition, restructuring, financing, or sale of business assets.
We require processors to process personal data only under our instructions and to implement appropriate security measures.
11. International transfersWe may transfer personal data outside your country, including outside the EEA, the United Kingdom, or Switzerland, where our service providers, payment partners, fraud-prevention providers, hosting providers, or group companies are located.
Where required, we use appropriate safeguards, such as:
- adequacy decisions;
- Standard Contractual Clauses;
- UK International Data Transfer Agreement or UK Addendum;
- data-processing agreements;
- technical and organizational safeguards;
- supplementary measures where appropriate.
You may contact us for more information about international-transfer safeguards.
12. Data retentionWe keep personal data only for as long as necessary for the purposes described in this Privacy Policy, including providing the service, complying with law, resolving disputes, preventing fraud, enforcing agreements, and maintaining payment records.
13. SecurityWe use technical and organizational measures designed to protect personal data, including as appropriate:
- encryption in transit;
- access controls;
- authentication and authorization controls;
- logging and monitoring;
- network and application security controls;
- secure development practices;
- vulnerability management;
- backup and recovery controls;
- staff confidentiality obligations;
- vendor due diligence;
- payment processing through PCI DSS-compliant providers.
No system is perfectly secure. You are responsible for keeping your account credentials, email account, Steam account, Steam Guard, devices, and trade confirmations secure.
14. Your rightsSubject to applicable law, you may have the right to:
- access your personal data;
- correct inaccurate or incomplete data;
- request deletion of your data;
- restrict processing;
- object to processing based on legitimate interests;
- object to direct marketing;
- receive your data in a portable format;
- withdraw consent where processing is based on consent;
- request human review of certain automated decisions where required by law;
- lodge a complaint with a data-protection supervisory authority.
To exercise your rights, contact us at support@gamepunk.net. We may ask for information to verify your identity before responding.
We usually respond within one month, unless the request is complex or we receive multiple requests, in which case we may extend the response period where permitted by law.
You also have the right to complain to your local supervisory authority. For EEA users, this may be the authority in the country where you live, work, or believe an infringement occurred.
15. Account deletionYou may request account deletion by contacting support@gamepunk.net.
Deletion may not be immediate or complete where we need to retain data for:
- pending transactions;
- unresolved disputes;
- chargebacks or refunds;
- fraud prevention;
- legal claims;
- sanctions or compliance records;
- tax, accounting, or audit obligations;
- payment-card and acquirer requirements.
Where deletion is not possible, we will restrict or minimize retained data where appropriate.
16. Children and age restrictionsOur service is intended only for users who are at least
[18 / 16 / applicable age] years old and legally able to enter into binding contracts.
We do not knowingly collect personal data from children below the applicable age. If we learn that a child has provided personal data without valid authorization, we will take appropriate steps to delete or restrict the data and close the account where required.
We may request age verification where needed to comply with law, payment requirements, platform safety rules, or our terms.
17. Prohibited use and compliance checksWe may process data to detect, prevent, investigate, or take action against:
- stolen accounts or stolen skins;
- unauthorized payment methods;
- chargeback abuse;
- bot activity or scraping;
- money laundering or sanctions evasion;
- fraud, deception, or market manipulation;
- violation of our Terms of Service;
- activity prohibited by our payment processors, acquirers, Visa, Mastercard, or applicable law.
This may include sharing relevant information with payment partners, card networks, banks, fraud-prevention providers, law enforcement, regulators, or affected users where lawful and necessary.
18. Third-party links and servicesOur website may link to third-party websites or services, including Steam, payment providers, identity-verification providers, social media platforms, analytics tools, or advertising partners.
Their privacy practices are governed by their own privacy notices. We are not responsible for third-party privacy practices.
19. Changes to this Privacy PolicyWe may update this Privacy Policy from time to time. We will post the updated version on our website and update the “Last updated” date.
If changes are material, we may notify you by email, account notice, website banner, or other appropriate means.
20. Contact usFor privacy questions, requests, or complaints, contact: support@gamepunk.net