Privacy Policy

Last updated: 23 May 2026

How we collect, use, and protect your personal data

1. Controller

The controller for the personal data processing described in this Privacy Policy is:

Rentaskin Sp. z o.o. Jana i Jędrzeja Śniadeckich 20D/7 35-006 Rzeszów, Poland Email: [email protected]

Privacy contact for data requests and rights: [email protected].

We do not process special categories of personal data (Article 9 GDPR) such as health data, racial or ethnic origin, political opinions, or biometric data.

2. Overview of Personal Data Processing

We process personal data to operate the Platform, manage user accounts, enable Steam authentication, process rentals, deliver and return Skins, process payments, send transactional emails, provide support, prevent fraud and abuse, comply with legal obligations, and improve Platform security and reliability.

We apply the principle of data minimisation: we collect and retain only the personal data that is necessary for the specific purpose. We do not sell personal data. We do not use personal data for third-party advertising without your consent.

Detailed records of our processing activities are available on request. To request a copy, contact [email protected].

3. Account and Registration Data

When you create an account or interact with the Platform, we process the following categories of personal data:

  • Account identifiers: Steam account ID, platform-internal user ID, account creation and update timestamps.
  • Contact information: Email address, email-verification status.
  • Steam profile data: Steam display name, Steam avatar image URL, Steam profile URL (received via Steam OpenID at login).
  • Steam Trade URL: The Steam trade offer URL you provide and which is required to deliver and return rented Skins.
  • Legal consent records: Version and timestamp of accepted Terms, Privacy Policy, age confirmation, and withdrawal waiver consent.
  • Account status data: Account role, suspension status, security flags.

Purpose: Creating and managing user accounts, authenticating users, providing the rental service, delivering and returning Skins, preventing misuse, documenting consent, complying with legal obligations.

Legal basis: Performance of contract (Art. 6(1)(b) GDPR); compliance with legal obligations (Art. 6(1)(c)); legitimate interests in Platform security and fraud prevention (Art. 6(1)(f)); consent for specific consent-based processing (Art. 6(1)(a)).

Retention: Account data is retained for the duration of the active account and deleted or anonymised after account closure, except where retention is required by law, for dispute resolution, fraud prevention, or other legitimate purposes.

4. Steam Authentication and Trade URL

We use Steam OpenID (via the next-auth-steam provider) to authenticate users. When you log in, Steam confirms your identity and provides public Steam profile data (Steam ID, display name, avatar URL, profile URL). We do not request or store your Steam password.

Your Steam Trade URL is required to deliver rented Skins via Steam trade offers and to process returns. It is stored on the Platform and can be updated at any time in your profile settings.

For fraud prevention purposes, our backend performs a server-side account-status check with the Steam Web API at the time of checkout (checking trade eligibility). The result is used to allow or block checkout and is not stored permanently beyond what is necessary to process the transaction.

Legal basis: Performance of contract (Art. 6(1)(b)) and legitimate interests in fraud prevention (Art. 6(1)(f)).

5. Rental and Transaction Data

In connection with rental and lending transactions, we process the following categories:

  • Rental records: user identifiers, item identifiers, rental period, rental price, service fee, currency, status.
  • Payment records: Stripe checkout session references, payment status, refund status, chargeback status.
  • Delivery and return records: trade offer identifiers, trade status, delivery and return timestamps.
  • Support notes relating to specific transactions.

Purpose: Executing rentals, managing delivery and return, calculating fees, processing payments, providing support, preventing fraud, complying with tax and accounting obligations, and defending legal claims.

Legal basis: Performance of contract (Art. 6(1)(b)); legal obligations including tax and accounting (Art. 6(1)(c)); legitimate interests in fraud prevention and legal defence (Art. 6(1)(f)).

Retention: Transaction records are retained for the statutory retention period required for tax, accounting, and legal purposes.

6. Payment Processing — Stripe

Payments on the Platform are processed by Stripe (Stripe Payments Europe, Ltd. or the applicable Stripe group entity. When you proceed to checkout, you are directed to a Stripe-hosted or Stripe-embedded payment flow. Full card numbers are entered directly into Stripe's secure payment fields and are not stored on our servers.

We receive from Stripe the information necessary to confirm payment, link a successful payment to the correct rental, handle refunds, and manage support and dispute resolution. This includes payment status, checkout session identifiers, and transaction amounts.

Stripe may also process data for its own fraud prevention, risk management, anti-money laundering, and compliance purposes, acting as an independent controller for those activities. Please refer to Stripe's own privacy documentation for details: stripe.com/privacy.

Stripe Connect (upcoming). When the lender feature is activated, lender payouts will be processed through Stripe Connect. At that point, lenders will be required to complete Stripe Connect onboarding, which involves Stripe collecting and processing identity, bank account, tax, and compliance information. Until lender features are live, no Stripe Connect data is processed.

Legal basis: Performance of contract (Art. 6(1)(b)); legal obligations relating to tax, AML, and fraud prevention (Art. 6(1)(c)); legitimate interests (Art. 6(1)(f)).

7. Transactional Email — Resend

We use Resend (an EU-capable transactional email service) to send emails required to operate the service, including email verification codes, waitlist confirmations, and support replies.

Data transmitted to Resend includes your email address and the content of the transactional message. Verification codes are stored in hashed form (SHA-256) on our servers and are valid only for a short period.

Legal basis: Performance of contract (Art. 6(1)(b)); legitimate interests (Art. 6(1)(f)) for security and service functionality.

Retention: Transactional email logs are retained only as long as necessary for operational and support purposes, typically not more than 90 days.

8. Hosting and Infrastructure

The Platform and its backend services (including the content management system and database) are hosted on Railway, operating from a Netherlands-based server region within the European Union. Standard infrastructure data such as request logs and IP addresses are processed transiently in connection with normal hosting operations.

Skin and game-asset images displayed on the Platform are served via Cloudflare's content delivery network as a proxy for Steam's image servers. No personal data beyond transient IP-address data is processed in this context.

Legal basis: Legitimate interests in providing a reliable and secure Platform (Art. 6(1)(f)).

Retention: Infrastructure and access logs are retained for a short rolling window and automatically deleted thereafter (typically 30–90 days).

9. Cookies and Analytics

We use cookies, localStorage, and similar technologies. These fall into the following categories:

Strictly necessary

Required for core Platform functionality: login session (next-auth.session-token — httpOnly, secure), OAuth callback flow, checkout continuity, and consent preference storage (rentaskin_consent_v1 in localStorage). These cannot be disabled without breaking essential functions.

Legal basis: Legitimate interests / service operation (ePrivacy consent exception for strictly necessary technologies).

Analytics (consent required)

Where you have given consent, we use Google Tag Manager (container GTM-MB3HSL68) to load Google Analytics 4 for traffic and checkout funnel analysis, and PostHog (EU endpoint at eu.posthog.com, accessed via our own /ingest proxy) for product usage analytics. Both operate under Consent Mode v2 with analytics storage defaulting to denied until consent is given. Consent can be withdrawn at any time using the button at the bottom of this page.

Legal basis: Consent (Art. 6(1)(a) GDPR; ePrivacy Directive).

Marketing (reserved — not currently active)

The marketing consent category is reserved for future use. No marketing pixels, tracking scripts, or advertising identifiers are currently loaded on the Platform.

Legal basis: Consent (Art. 6(1)(a) GDPR; ePrivacy Directive) — will apply when and if this category is activated.

You can manage and withdraw your cookie and analytics consent at any time. Your consent choice is stored locally and applied via Google Consent Mode. Withdrawal stops future non-essential tracking; it does not affect processing that occurred before withdrawal.

10. Recipients of Personal Data

We disclose personal data only where necessary and legally permitted. Categories of recipients include:

  • Stripe — payment processing; Stripe Payments Europe, Ltd. (Ireland) and Stripe group entities for fraud and compliance.
  • Railway — hosting and infrastructure (EU, Netherlands).
  • Resend — transactional email delivery.
  • Google — analytics via GTM/GA4 (after consent only); subject to Google's data processing terms and SCCs.
  • PostHog — product analytics (EU endpoint, after consent only).
  • Cloudflare — image proxy and CDN for Steam-hosted assets.
  • Steam / Valve — authentication and trade functionality; Steam ID used for OpenID login and trade-offer delivery.
  • Professional advisers — tax advisors, legal advisors, and auditors where necessary.
  • Public authorities — tax authorities, law enforcement, courts, or regulators where legally required.

We do not sell personal data to third parties.

Full and up-to-date records of our data processors, including data processing agreements, are available on request at [email protected].

11. International Data Transfers

Our primary infrastructure is hosted within the EU (Railway, Netherlands). Where we use providers that process data outside the EU or EEA, or that are headquartered outside the EU/EEA, we ensure appropriate safeguards are in place:

  • Stripe (Ireland, EU) — EU-based primary processing; additional Stripe group transfers covered by adequacy or SCCs as applicable.
  • Google (GA4/GTM) — Alphabet Inc. is a US entity. Transfers to the US are covered by EU Standard Contractual Clauses (SCCs) under Google's data processing terms.
  • PostHog — EU endpoint (eu.posthog.com); data processed within the EU.
  • Steam / Valve Corporation — US entity; Steam OpenID authentication and trade API calls involve transfers to Valve's US infrastructure. These are covered by SCCs where applicable and are limited to the minimum data necessary for the service.
  • Resend — transactional email; EU data processing available; transfer mechanism to be confirmed before publication.

Copies of applicable transfer mechanisms are available on request at [email protected].

12. Retention Periods

We retain personal data only for as long as necessary for the relevant purpose:

  • Account data: Retained while your account is active and deleted or anonymised after account closure, except where retention is required by law or for dispute resolution.
  • Rental and transaction records: Retained for the statutory tax and accounting retention period applicable under Polish law (currently understood to be 5 years — to be confirmed by a tax advisor before publication).
  • Support communications: Retained for a reasonable period after the matter is resolved to allow for follow-up, dispute handling, and legal defence (currently planned as 3 years — to be confirmed under Polish law).
  • Infrastructure and access logs: Retained for a short rolling window (30–90 days depending on type) and automatically deleted.
  • Consent records: Retained for 12 months from the date of consent, or longer where required for legal compliance.
  • Email verification codes: Retained only for the validity period of the code (minutes to hours) and deleted on use or expiry.

13. Your Rights

Under the GDPR, you have the following rights in relation to your personal data, subject to applicable conditions and exceptions:

  • Right of access (Art. 15): Request a copy of the personal data we hold about you.
  • Right to rectification (Art. 16): Request correction of inaccurate or incomplete data.
  • Right to erasure (Art. 17): Request deletion of your personal data where the legal basis for processing no longer applies.
  • Right to restriction (Art. 18): Request that we restrict processing of your data in certain circumstances.
  • Right to data portability (Art. 20): Receive your data in a structured, machine-readable format where processing is based on contract or consent.
  • Right to object (Art. 21): Object to processing based on legitimate interests. We will cease processing unless we demonstrate compelling legitimate grounds.
  • Right to withdraw consent: Withdraw consent at any time where processing is based on consent, without affecting the lawfulness of processing before withdrawal.

To exercise any of these rights, contact us at [email protected]. We will respond within one month of receiving your request (extendable by two months where necessary due to the complexity or number of requests).

If you believe your data protection rights have been violated, you may lodge a complaint with the Polish data protection supervisory authority:

Prezes Urzędu Ochrony Danych Osobowych (UODO) Website: uodo.gov.pl

EU/EEA residents may also contact the supervisory authority in their country of residence.

14. Data Security

We apply technical and organisational security measures to protect personal data against unauthorised access, loss, misuse, alteration, or disclosure. Measures include:

  • TLS encryption for all data transmission between browser and server.
  • Role-based access control and authentication controls for backend systems.
  • Email verification codes stored in hashed form (SHA-256) rather than plaintext.
  • Full card numbers (PAN) are never stored on our servers — payment is handled entirely through Stripe's PCI-DSS-compliant payment infrastructure.
  • Access logging and monitoring for administrative functions.
  • Regular access reviews and security assessments.

No method of transmission or storage is completely secure. If we become aware of a personal data breach, we will assess the risk and notify the competent supervisory authority and affected users where required by the GDPR (Arts. 33–34).

15. Minors

The Platform is intended exclusively for persons who are at least 18 years old. We do not knowingly collect personal data from minors. If we become aware that a minor has created an account or used the Platform, we will delete the account and associated personal data unless retention is required for legal claims, fraud prevention, accounting, or legal obligations.

16. Automated Decision-Making

We may use automated systems for fraud prevention, risk scoring, payment checks, and abuse detection to support account security and Platform integrity. These systems inform human review decisions rather than making final decisions autonomously.

No decision with a legal or similarly significant effect on you is made solely by automated processing without human review. Article 22 GDPR (right to not be subject to solely automated decisions) is therefore not engaged. If the Platform's systems are updated to include solely automated significant decisions, this policy will be updated accordingly and appropriate safeguards implemented.

17. Changes to This Privacy Policy

We may update this Privacy Policy to reflect changes in our data processing activities, provider setup, legal requirements, or Platform functionality. Material changes will be communicated to registered users where required. The current version will always be available at rentaskin.gg/privacy.

Cookie Preferences

You can change or withdraw your cookie and analytics consent at any time. Clicking the button below clears your stored consent choice and reloads the page to show the consent banner again.