Privacy Policy
Last updated: 19 September 2026
How we collect, use, and protect your personal data
1. Controller
The controller for the personal data processing described in this Privacy Policy is:
Rentaskin Sp. z o.o. Jana i Jędrzeja Śniadeckich 20D/7 35-006 Rzeszów, Poland KRS: 0001243787 · NIP: 5170471557 Email: [email protected]
Privacy contact for data requests and rights: [email protected].
We have not appointed a Data Protection Officer because we are not legally required to do so under Art. 37 GDPR. The privacy contact above is the primary point of contact for all data protection matters.
We do not process special categories of personal data (Article 9 GDPR) such as health data, racial or ethnic origin, political opinions, or biometric data.
2. Overview of Personal Data Processing
We process personal data to operate the Platform, manage user accounts, enable Steam authentication, process rentals, deliver and return Skins, process payments, determine and remit value added tax, operate the Supplier programme and Supplier payouts, send transactional emails, run giveaways, provide support, prevent fraud and abuse, comply with legal obligations, and improve Platform security and reliability.
We apply the principle of data minimisation: we collect and retain only the personal data that is necessary for the specific purpose. We do not sell personal data. We do not use personal data for third-party advertising without your consent.
Detailed records of our processing activities are available on request. To request a copy, contact [email protected].
3. Account and Registration Data
When you create an account or interact with the Platform, we process the following categories of personal data:
- Account identifiers: Steam account ID, platform-internal user ID, account creation and update timestamps.
- Contact information: Email address, email-verification status.
- Steam profile data: Steam display name, Steam avatar image URL, Steam profile URL (received via Steam OpenID at login).
- Steam Trade URL: The Steam trade offer URL you provide and which is required to deliver and return rented Skins.
- Legal consent records: Version and timestamp of accepted Terms, Privacy Policy, Supplier Agreement, age confirmation, withdrawal waiver, and giveaway terms.
- Account status data: Account role, suspension status, security flags.
- Availability alerts: The Skins or Bundles for which you have asked to be notified when they become available.
- Discord link data (optional): Discord user ID, username, avatar, link timestamp, and whether you are a member of the RentaSkin Discord server, if you choose to connect Discord (see Section 8).
- Supplier data (optional): Skins you submit from your public Steam inventory, listing offers and your decisions on them, and your Stripe Connect account reference, if you use the Supplier feature.
Purpose: Creating and managing user accounts, authenticating users, providing the rental and Supplier services, delivering and returning Skins, preventing misuse, documenting consent, complying with legal obligations.
Legal basis: Performance of contract (Art. 6(1)(b) GDPR); compliance with legal obligations (Art. 6(1)(c)); legitimate interests in Platform security and fraud prevention (Art. 6(1)(f)); consent for specific consent-based processing (Art. 6(1)(a)).
Is providing this data mandatory? A Steam account, a verified email address, the age confirmation, and a valid Steam Trade URL are necessary to conclude and perform a rental contract; without them we cannot provide the service. Discord linking, availability alerts, and the Supplier feature are optional.
Retention: Account data is retained for the duration of the active account and deleted or anonymised after account closure, except where retention is required by law, for dispute resolution, fraud prevention, or other legitimate purposes.
4. Steam Authentication and Trade URL
We use Steam OpenID (via the next-auth-steam provider) to authenticate users. When you log in, Steam confirms your identity and provides public Steam profile data (Steam ID, display name, avatar URL, profile URL). We do not request or store your Steam password.
Your Steam Trade URL is required to deliver rented Skins via Steam trade offers and to process returns. It is stored on the Platform and can be updated at any time in your profile settings.
For fraud prevention purposes, our backend performs a server-side account-status check with the Steam Web API at the time of checkout (checking trade eligibility). The result is used to allow or block checkout and is not stored permanently beyond what is necessary to process the transaction.
If you use the Supplier feature, we read the public CS2 inventory of your Steam account to let you select Skins for submission.
Legal basis: Performance of contract (Art. 6(1)(b)) and legitimate interests in fraud prevention (Art. 6(1)(f)).
5. Rental, Supplier, and Transaction Data
In connection with rental and Supplier transactions, we process the following categories:
- Rental records: user identifiers, item identifiers, rental period, rental price, processing fee, currency, status.
- Payment records: Stripe checkout session and customer references, payment status, refund status (including early-return refunds), chargeback status.
- Billing and tax records: the billing address you enter at checkout (country, postal code, and any further address lines you provide), the VAT rate and amount applied, and the tax-location evidence determined by our payment provider (billing country, card-issuer country, and IP-derived country).
- Delivery and return records: trade offer identifiers, trade status, delivery and return timestamps, trade reversal confirmations.
- Supplier records: listing offers, revenue share, rental earnings, payout amounts and status, withdrawal requests, and bot setup cost deductions.
- Support notes relating to specific transactions.
Purpose: Executing rentals, managing delivery and return, calculating fees and Supplier revenue shares, processing payments and payouts, determining the VAT applicable in your country and reporting it under the EU One-Stop-Shop scheme, providing support, preventing fraud, complying with tax and accounting obligations, and defending legal claims.
Legal basis: Performance of contract (Art. 6(1)(b)); legal obligations including tax and accounting (Art. 6(1)(c)); legitimate interests in fraud prevention and legal defence (Art. 6(1)(f)).
Retention: Transaction records are retained for the statutory retention period required for tax, accounting, and legal purposes (see Section 13).
6. Payment Processing — Stripe
Payments on the Platform are processed by Stripe (Stripe Payments Europe, Ltd. or the applicable Stripe group entity). When you proceed to checkout, you are directed to a Stripe-embedded payment flow. Full card numbers are entered directly into Stripe's secure payment fields and are not stored on our servers.
We receive from Stripe the information necessary to confirm payment, link a successful payment to the correct rental, handle refunds, and manage support and dispute resolution. This includes payment status, checkout session and customer identifiers, transaction amounts, and the VAT rate, VAT amount, and billing country determined for the transaction.
VAT determination and receipts. Stripe collects your billing address at checkout and uses it together with other location indicators (such as the country of your card issuer and your IP address) to determine the VAT applicable in your country, as required by EU VAT rules for electronically supplied services. Stripe also sends the payment receipt showing the VAT amount to your email address on our behalf. Legal basis: compliance with legal obligations (Art. 6(1)(c) GDPR) and performance of contract (Art. 6(1)(b)).
Stripe may also process data for its own fraud prevention, risk management, anti-money laundering, and compliance purposes, acting as an independent controller for those activities. Please refer to Stripe's own privacy documentation for details: stripe.com/privacy.
Stripe Connect (Suppliers). Supplier payouts are processed through Stripe Connect. To receive payouts, Suppliers complete Stripe Connect onboarding, during which Stripe collects identity, bank account, tax, and compliance information. Stripe acts as controller for its own verification and compliance processing. We receive only the Stripe account identifier, onboarding status, and payout status; we do not store your bank details.
Legal basis: Performance of contract (Art. 6(1)(b)); legal obligations relating to tax, AML, and fraud prevention (Art. 6(1)(c)); legitimate interests (Art. 6(1)(f)).
7. Transactional Email — Resend
We use Resend to send emails required to operate the service, including email verification codes, waitlist confirmations, and support replies.
Data transmitted to Resend includes your email address and the content of the transactional message. Verification codes are stored in hashed form (SHA-256) on our servers and are valid only for a short period.
Resend processes data in the United States; see Section 12 for the transfer safeguards.
Legal basis: Performance of contract (Art. 6(1)(b)); legitimate interests (Art. 6(1)(f)) for security and service functionality.
Retention: Transactional email logs are retained only as long as necessary for operational and support purposes, typically not more than 90 days.
8. Discord Linking and Giveaways
You may optionally connect your Discord account to take part in giveaways and community features. We use Discord OAuth to receive your Discord user ID, username, and avatar, and we check through the Discord API whether you are a member of the RentaSkin Discord server. We record link, relink, and unlink events for abuse prevention.
If you enter a giveaway, we store your entry, the requirements you confirmed (for example following or liking a post), and the Discord identifiers needed to contact you if you win. Winners are contacted by Discord direct message and have the response time stated in the giveaway terms to reply.
Discord Inc. (United States) receives your Discord ID in the course of these checks; see Section 12. Discord's own processing is governed by Discord's privacy policy.
Legal basis: Consent and performance of the giveaway terms (Art. 6(1)(a) and (b)); legitimate interests in preventing duplicate or fraudulent entries (Art. 6(1)(f)).
Retention: Giveaway entries are retained until the giveaway is closed and the winner confirmed, plus the period needed for dispute handling and legal obligations. Discord link data is retained until you unlink Discord or delete your account.
9. Hosting and Infrastructure
The Platform and its backend services (including the content management system and database) are hosted on Railway, operating from a Netherlands-based server region within the European Union. Standard infrastructure data such as request logs and IP addresses are processed transiently in connection with normal hosting operations.
Website traffic to rentaskin.gg is routed through Cloudflare, which provides DNS, content delivery, caching, and security (including DDoS protection). Cloudflare processes IP addresses and request metadata for these purposes. Cloudflare also provides us with the country of your connection, which we use only to preselect a display currency (see Section 10).
Short-lived operational state (checkout reservations, rate-limit counters, and job queues used to process rentals and trades) is held in Redis Cloud, hosted in the European Union.
Skin and game-asset images displayed on the Platform are loaded from Valve's Steam content delivery network. No personal data beyond transient IP-address data is processed in this context.
Legal basis: Legitimate interests in providing a reliable and secure Platform (Art. 6(1)(f)).
Retention: Infrastructure and access logs are retained for a short rolling window and automatically deleted thereafter (typically 30–90 days).
10. Cookies and Analytics
We use cookies, localStorage, and similar technologies. These fall into the following categories:
Strictly necessary
Required for core Platform functionality: login session (next-auth.session-token — httpOnly, secure), OAuth callback flow, Discord login state (rs_discord_oauth_state, short-lived), checkout continuity, currency preference (rs_currency), and consent preference storage (rentaskin_consent_v1 in localStorage). These cannot be disabled without breaking essential functions.
Your approximate country, derived from your IP address by our CDN provider, is used once to preselect a display currency. You can change the currency at any time.
Legal basis: Legitimate interests / service operation (ePrivacy consent exception for strictly necessary technologies).
Analytics (consent required)
Where you have given consent, we use Google Tag Manager (container GTM-MB3HSL68) to load Google Analytics 4 for traffic and checkout funnel analysis. It operates under Consent Mode v2 with analytics storage defaulting to denied until consent is given. Consent can be withdrawn at any time in your profile or using the button at the bottom of this page.
Legal basis: Consent (Art. 6(1)(a) GDPR; ePrivacy Directive).
Marketing (consent required)
Where you have given marketing consent, we activate the TikTok Pixel (TikTok Technology Limited, Ireland, and TikTok Inc., United States) to measure the effectiveness of our TikTok advertising and to reach CS2 players with relevant ads. The pixel may process your IP address, device and browser information, pages visited, and events such as page views or a completed Supplier submission. The pixel script is loaded with tracking disabled and is only activated after you consent. For the collection and transmission of data through the pixel, we and TikTok are joint controllers; TikTok is solely responsible for its subsequent processing, which is described in TikTok's privacy policy. Consent can be withdrawn at any time in your profile or using the button at the bottom of this page.
Legal basis: Consent (Art. 6(1)(a) GDPR; ePrivacy Directive).
You can manage and withdraw your cookie, analytics, and marketing consent at any time. Your consent choice is stored locally and applied via Google Consent Mode and the TikTok consent API. Withdrawal stops future non-essential tracking; it does not affect processing that occurred before withdrawal.
11. Recipients of Personal Data
We disclose personal data only where necessary and legally permitted. Categories of recipients include:
- Stripe — payment processing, VAT determination, payment receipts, and Supplier payouts; Stripe Payments Europe, Ltd. (Ireland) and Stripe group entities for fraud and compliance.
- Tax authorities — VAT reporting under the EU One-Stop-Shop scheme (aggregated per country; no personal data is transmitted in the return itself, but records must be made available on request).
- Railway — hosting and infrastructure (EU, Netherlands).
- Cloudflare — DNS, content delivery, and security for all website traffic.
- Redis Cloud — short-lived operational state (EU).
- Resend — transactional email delivery.
- Google — analytics via GTM/GA4 (after consent only); subject to Google's data processing terms and SCCs.
- TikTok — advertising measurement via TikTok Pixel (after marketing consent only).
- Discord — account linking and server-membership checks (only if you connect Discord).
- Steam / Valve — authentication, inventory reading, and trade functionality; Steam ID used for OpenID login and trade-offer delivery.
- Professional advisers — tax advisors, legal advisors, and auditors where necessary.
- Public authorities — tax authorities, law enforcement, courts, or regulators where legally required.
We do not sell personal data to third parties.
Full and up-to-date records of our data processors, including data processing agreements, are available on request at [email protected].
12. International Data Transfers
Our primary infrastructure is hosted within the EU (Railway, Netherlands; Redis Cloud, EU). Where we use providers that process data outside the EU or EEA, or that are headquartered outside the EU/EEA, we ensure appropriate safeguards are in place:
- Stripe (Ireland, EU) — EU-based primary processing; additional Stripe group transfers covered by the EU-US Data Privacy Framework or EU Standard Contractual Clauses (SCCs) as applicable.
- Cloudflare (United States) — global edge network; transfers covered by Cloudflare's Data Processing Addendum with SCCs.
- Resend (United States) — transactional email; transfers covered by Resend's Data Processing Addendum with SCCs and the EU-US Data Privacy Framework where applicable.
- Google (GA4/GTM) — Alphabet Inc. is a US entity. Transfers to the US are covered by SCCs under Google's data processing terms.
- TikTok — TikTok Technology Limited (Ireland) with transfers to TikTok Inc. (United States) and other group entities, covered by SCCs under TikTok's data processing terms.
- Discord Inc. (United States) — transfers covered by the EU-US Data Privacy Framework or SCCs as applicable; limited to your Discord ID and the membership check.
- Steam / Valve Corporation — US entity; Steam OpenID authentication, inventory reads, and trade API calls involve transfers to Valve's US infrastructure. These are limited to the minimum data necessary for the service.
Copies of applicable transfer mechanisms are available on request at [email protected].
13. Retention Periods
We retain personal data only for as long as necessary for the relevant purpose:
- Account data: Retained while your account is active and deleted or anonymised after account closure, except where retention is required by law or for dispute resolution.
- Rental, payout, and transaction records: Retained for 5 years from the end of the calendar year in which the transaction took place, as required by Polish tax and accounting law.
- VAT records under the EU One-Stop-Shop scheme (billing country, tax-location evidence, VAT rate and amount): Retained for 10 years from the end of the year in which the transaction took place, as required by Art. 369k of the EU VAT Directive.
- Support communications: Retained for up to 3 years after the matter is closed to allow for follow-up, dispute handling, and the defence of legal claims.
- Giveaway entries and Discord link events: As described in Section 8.
- Infrastructure and access logs: Retained for a short rolling window (30–90 days depending on type) and automatically deleted.
- Cookie consent choice: Stored in your browser until you change it, clear it, or it is renewed after a policy change. Records of your acceptance of the Terms and Privacy Policy are kept for the lifetime of your account and for the period needed to demonstrate compliance.
- Email verification codes: Retained only for the validity period of the code (minutes) and deleted on use or expiry.
14. Your Rights
Under the GDPR, you have the following rights in relation to your personal data, subject to applicable conditions and exceptions:
- Right of access (Art. 15): Request a copy of the personal data we hold about you.
- Right to rectification (Art. 16): Request correction of inaccurate or incomplete data.
- Right to erasure (Art. 17): Request deletion of your personal data where the legal basis for processing no longer applies.
- Right to restriction (Art. 18): Request that we restrict processing of your data in certain circumstances.
- Right to data portability (Art. 20): Receive your data in a structured, machine-readable format where processing is based on contract or consent.
- Right to object (Art. 21): Object to processing based on legitimate interests. We will cease processing unless we demonstrate compelling legitimate grounds.
- Right to withdraw consent: Withdraw consent at any time where processing is based on consent, without affecting the lawfulness of processing before withdrawal.
To exercise any of these rights, contact us at [email protected]. We will respond within one month of receiving your request (extendable by two months where necessary due to the complexity or number of requests).
If you believe your data protection rights have been violated, you may lodge a complaint with the Polish data protection supervisory authority:
Prezes Urzędu Ochrony Danych Osobowych (UODO) Website: uodo.gov.pl
EU/EEA residents may also contact the supervisory authority in their country of residence.
15. Data Security
We apply technical and organisational security measures to protect personal data against unauthorised access, loss, misuse, alteration, or disclosure. Measures include:
- TLS encryption for all data transmission between browser and server.
- Role-based access control and authentication controls for backend systems.
- Email verification codes stored in hashed form (SHA-256) rather than plaintext.
- Full card numbers (PAN) and bank details are never stored on our servers — payments and payouts are handled entirely through Stripe's PCI-DSS-compliant infrastructure.
- Access logging and monitoring for administrative functions.
- Rate limiting and abuse controls on authentication, checkout, giveaway, and Supplier actions.
- Regular access reviews and security assessments.
No method of transmission or storage is completely secure. If we become aware of a personal data breach, we will assess the risk and notify the competent supervisory authority and affected users where required by the GDPR (Arts. 33–34).
16. Minors
The Platform is intended exclusively for persons who are at least 18 years old. We do not knowingly collect personal data from minors. If we become aware that a minor has created an account or used the Platform, we will delete the account and associated personal data unless retention is required for legal claims, fraud prevention, accounting, or legal obligations.
17. Automated Decision-Making
We use automated checks for fraud prevention, payment checks, and abuse detection. For example, a checkout is automatically declined if Steam reports that your account cannot currently trade, if your Trade URL is invalid, or if rate limits are exceeded. These checks protect the Platform and other users and can be reviewed on request: contact [email protected] and a member of our team will review the decision.
No decision with a legal or similarly significant effect on you (such as account termination or a payout refusal) is made solely by automated processing without human review. Article 22 GDPR is therefore not engaged for such decisions. If the Platform's systems are updated to include solely automated significant decisions, this policy will be updated accordingly and appropriate safeguards implemented.
18. Changes to This Privacy Policy
We may update this Privacy Policy to reflect changes in our data processing activities, provider setup, legal requirements, or Platform functionality. Material changes will be communicated to registered users on their next login, where you will be asked to review and accept the updated policy. The current version will always be available at rentaskin.gg/privacy.
Cookie Preferences
You can change or withdraw your cookie and analytics consent at any time. Clicking the button below clears your stored consent choice and reloads the page to show the consent banner again.