PRIVACY POLICY
Effective Date: 14/02/2025
This Privacy Policy explains how Ventarcus OÜ (Company Number: 17173615, Registered Address: Harju maakond, Tallinn, Kesklinna linnaosa, F. R. Faehlmanni tn 5, 10125) (“NoScope.GG", “we", “us", “our") collects, uses, and protects personal data in connection with the website NoScope.GG (the “Website") and related services (the “Services").
Contact email (including Data Protection Officer contact):
[email protected]
This Privacy Policy is issued in accordance with:
- Regulation (EU) 2016/679 (General Data Protection Regulation – GDPR);
- Applicable Estonian data protection legislation;
- Relevant EU consumer protection and payment regulations.
1. Data Controller
The data controller responsible for processing your personal data is:
Ventarcus OÜ
Company Number: 123
Registered Address: DEMO_ADDRESS
Email: [email protected]
2. Categories of Personal Data We Collect
We collect personal data directly from you, automatically through your use of the Services, and from third parties such as payment providers.
2.1 Account & Authentication Data
When you log in via Steam:
- Steam ID
- Steam username
- Steam profile information (as made available by you)
- Avatar/profile image
- Steam trade URL
- Authentication tokens
2.2 Transaction Data
- Coin purchases
- Skin purchases and transfers
- Transaction amounts
- Payment status
- Internal transaction identifiers
- IP address at time of transaction
2.3 Payment Data
Payments are processed by third-party payment service providers. We may receive:
- Payment confirmation
- Partial payment method identifiers (e.g., last 4 digits of card)
- Billing country
- Risk indicators from payment providers
We do not store full payment card details.
2.4 Technical & Usage Data
- IP address
- Device information
- Browser type and version
- Operating system
- Log files
- Access timestamps
- Session identifiers
- Cookie identifiers
2.5 Risk & Compliance Data
For fraud prevention and compliance purposes, we may process:
- Risk scores
- Transaction monitoring results
- Geolocation data
- Identity verification documents (if required)
- Sanctions screening results
2.6 Communications
- Support requests
- Email correspondence
- Verification responses
3. Purposes and Legal Bases for Processing
We process personal data only where a valid legal basis exists under GDPR Article 6.
3.1 Contract Performance (Art. 6(1)(b) GDPR)
- Creating and managing accounts
- Processing Coin purchases
- Delivering skins
- Providing customer support
- Managing transactions
3.2 Legal Obligations (Art. 6(1)(c) GDPR)
- Anti-money laundering compliance (where applicable)
- Sanctions screening
- Fraud reporting
- Accounting and tax obligations
3.3 Legitimate Interests (Art. 6(1)(f) GDPR)
- Fraud detection and prevention
- Transaction monitoring and risk scoring
- Chargeback management
- Platform security
- Service improvement
- Enforcement of Terms of Service
We ensure that our legitimate interests do not override your fundamental rights and freedoms.
3.4 Consent (Art. 6(1)(a) GDPR)
- Non-essential cookies
- Marketing communications (if applicable)
Consent may be withdrawn at any time.
4. Transaction Monitoring & Risk Management
To comply with card network rules, EU law, and fraud prevention requirements, we operate automated and manual monitoring systems.
These systems may:
- Assign risk scores to transactions;
- Detect suspicious behavior patterns;
- Trigger identity verification;
- Temporarily suspend transactions or accounts.
Automated decision-making may occur where necessary to prevent fraud. Where legally required, you have the right to request human review of such decisions.
5. Age Verification
NoScope.GG is strictly limited to users aged 18 or older.
We may conduct age or identity verification on a risk-based basis. This may involve requesting government-issued identification or other documentation.
6. Cookies & Tracking Technologies
We use:
- Essential cookies (authentication, security);
- Functional cookies;
- Analytics cookies (where consent is required);
- Fraud-prevention cookies.
A separate Cookie Policy or consent banner provides additional details.
7. Data Sharing
We may share personal data with:
7.1 Payment Providers
For transaction processing and fraud detection.
7.2 Identity Verification Providers
When verification is required.
7.3 Hosting & IT Service Providers
For infrastructure and security services.
7.4 Legal & Regulatory Authorities
Where required by law or regulatory obligation.
We do not sell personal data.
8. International Data Transfers
Where personal data is transferred outside the European Economic Area (EEA), we ensure appropriate safeguards, including:
- EU Standard Contractual Clauses;
- Transfers to countries with adequacy decisions;
- Other GDPR-compliant safeguards.
9. Data Retention
We retain personal data only as long as necessary for:
- Contract performance;
- Legal compliance;
- Fraud prevention;
- Dispute resolution.
Typical retention periods:
- Account data: retained while account is active and up to 5 years thereafter for legal and fraud-prevention purposes;
- Transaction records: retained in accordance with accounting laws (typically 7 years);
- Verification documents: retained only as long as required for compliance.
10. Your Rights Under GDPR
You have the following rights:
- Right of access (Art. 15 GDPR)
- Right to rectification (Art. 16 GDPR)
- Right to erasure (“right to be forgotten") (Art. 17 GDPR)
- Right to restriction of processing (Art. 18 GDPR)
- Right to data portability (Art. 20 GDPR)
- Right to object (Art. 21 GDPR)
- Right to withdraw consent
- Right not to be subject solely to automated decision-making (Art. 22 GDPR), where applicable
Requests may be submitted to:
[email protected]
We may request identity verification before fulfilling requests.
11. Data Security
We implement appropriate technical and organizational measures, including:
- Encryption in transit (TLS);
- Secure hosting environments;
- Access controls;
- Monitoring systems;
- Payment processor compliance (e.g., PCI-DSS where applicable).
No system can guarantee absolute security.
12. Complaints
If you believe your data protection rights have been violated, you may:
- Contact us at [email protected]
- Lodge a complaint with the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon) or your local EU supervisory authority.
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time.
Material changes will be communicated via the Website. Continued use of the Services after updates constitutes acceptance of the revised Policy.
14. Contact Information
For all privacy-related inquiries:
Data Protection Officer (DPO): [email protected]