PRIVACY POLICY

Effective Date: 14/02/2025

This Privacy Policy explains how Ventarcus OÜ (Company Number: 17173615, Registered Address: Harju maakond, Tallinn, Kesklinna linnaosa, F. R. Faehlmanni tn 5, 10125) (“NoScope.GG", “we", “us", “our") collects, uses, and protects personal data in connection with the website NoScope.GG (the “Website") and related services (the “Services").

Contact email (including Data Protection Officer contact):
[email protected]

This Privacy Policy is issued in accordance with:

  • Regulation (EU) 2016/679 (General Data Protection Regulation – GDPR);
  • Applicable Estonian data protection legislation;
  • Relevant EU consumer protection and payment regulations.

1. Data Controller

The data controller responsible for processing your personal data is:

Ventarcus OÜ
Company Number: 123
Registered Address: DEMO_ADDRESS
Email: [email protected]


2. Categories of Personal Data We Collect

We collect personal data directly from you, automatically through your use of the Services, and from third parties such as payment providers.

2.1 Account & Authentication Data

When you log in via Steam:

  • Steam ID
  • Steam username
  • Steam profile information (as made available by you)
  • Avatar/profile image
  • Steam trade URL
  • Authentication tokens

2.2 Transaction Data

  • Coin purchases
  • Skin purchases and transfers
  • Transaction amounts
  • Payment status
  • Internal transaction identifiers
  • IP address at time of transaction

2.3 Payment Data

Payments are processed by third-party payment service providers. We may receive:

  • Payment confirmation
  • Partial payment method identifiers (e.g., last 4 digits of card)
  • Billing country
  • Risk indicators from payment providers

We do not store full payment card details.

2.4 Technical & Usage Data

  • IP address
  • Device information
  • Browser type and version
  • Operating system
  • Log files
  • Access timestamps
  • Session identifiers
  • Cookie identifiers

2.5 Risk & Compliance Data

For fraud prevention and compliance purposes, we may process:

  • Risk scores
  • Transaction monitoring results
  • Geolocation data
  • Identity verification documents (if required)
  • Sanctions screening results

2.6 Communications

  • Support requests
  • Email correspondence
  • Verification responses

3. Purposes and Legal Bases for Processing

We process personal data only where a valid legal basis exists under GDPR Article 6.

3.1 Contract Performance (Art. 6(1)(b) GDPR)

  • Creating and managing accounts
  • Processing Coin purchases
  • Delivering skins
  • Providing customer support
  • Managing transactions

3.2 Legal Obligations (Art. 6(1)(c) GDPR)

  • Anti-money laundering compliance (where applicable)
  • Sanctions screening
  • Fraud reporting
  • Accounting and tax obligations

3.3 Legitimate Interests (Art. 6(1)(f) GDPR)

  • Fraud detection and prevention
  • Transaction monitoring and risk scoring
  • Chargeback management
  • Platform security
  • Service improvement
  • Enforcement of Terms of Service

We ensure that our legitimate interests do not override your fundamental rights and freedoms.

3.4 Consent (Art. 6(1)(a) GDPR)

  • Non-essential cookies
  • Marketing communications (if applicable)

Consent may be withdrawn at any time.


4. Transaction Monitoring & Risk Management

To comply with card network rules, EU law, and fraud prevention requirements, we operate automated and manual monitoring systems.

These systems may:

  • Assign risk scores to transactions;
  • Detect suspicious behavior patterns;
  • Trigger identity verification;
  • Temporarily suspend transactions or accounts.

Automated decision-making may occur where necessary to prevent fraud. Where legally required, you have the right to request human review of such decisions.


5. Age Verification

NoScope.GG is strictly limited to users aged 18 or older.

We may conduct age or identity verification on a risk-based basis. This may involve requesting government-issued identification or other documentation.


6. Cookies & Tracking Technologies

We use:

  • Essential cookies (authentication, security);
  • Functional cookies;
  • Analytics cookies (where consent is required);
  • Fraud-prevention cookies.

A separate Cookie Policy or consent banner provides additional details.


7. Data Sharing

We may share personal data with:

7.1 Payment Providers

For transaction processing and fraud detection.

7.2 Identity Verification Providers

When verification is required.

7.3 Hosting & IT Service Providers

For infrastructure and security services.

7.4 Legal & Regulatory Authorities

Where required by law or regulatory obligation.

We do not sell personal data.


8. International Data Transfers

Where personal data is transferred outside the European Economic Area (EEA), we ensure appropriate safeguards, including:

  • EU Standard Contractual Clauses;
  • Transfers to countries with adequacy decisions;
  • Other GDPR-compliant safeguards.

9. Data Retention

We retain personal data only as long as necessary for:

  • Contract performance;
  • Legal compliance;
  • Fraud prevention;
  • Dispute resolution.

Typical retention periods:

  • Account data: retained while account is active and up to 5 years thereafter for legal and fraud-prevention purposes;
  • Transaction records: retained in accordance with accounting laws (typically 7 years);
  • Verification documents: retained only as long as required for compliance.

10. Your Rights Under GDPR

You have the following rights:

  • Right of access (Art. 15 GDPR)
  • Right to rectification (Art. 16 GDPR)
  • Right to erasure (“right to be forgotten") (Art. 17 GDPR)
  • Right to restriction of processing (Art. 18 GDPR)
  • Right to data portability (Art. 20 GDPR)
  • Right to object (Art. 21 GDPR)
  • Right to withdraw consent
  • Right not to be subject solely to automated decision-making (Art. 22 GDPR), where applicable

Requests may be submitted to:
[email protected]

We may request identity verification before fulfilling requests.


11. Data Security

We implement appropriate technical and organizational measures, including:

  • Encryption in transit (TLS);
  • Secure hosting environments;
  • Access controls;
  • Monitoring systems;
  • Payment processor compliance (e.g., PCI-DSS where applicable).

No system can guarantee absolute security.


12. Complaints

If you believe your data protection rights have been violated, you may:

  1. Contact us at [email protected]
  2. Lodge a complaint with the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon) or your local EU supervisory authority.

13. Changes to This Privacy Policy

We may update this Privacy Policy from time to time.

Material changes will be communicated via the Website. Continued use of the Services after updates constitutes acceptance of the revised Policy.


14. Contact Information

For all privacy-related inquiries:

Data Protection Officer (DPO): [email protected]