Privacy Policy
This notice explains what personal data SkinWinKing processes, why we use it and which choices and rights are available to you.
Last updated: 24 August 20261. Data controller
The operator identified in the Legal Notice is the controller for customer accounts, orders, support and store communications. Questions or privacy requests may be sent through the Support page. Final company and direct privacy contact details will be added before commercial launch.
2. Data we collect
We may process account details such as name, email address, password hash and sign-in provider identifiers; order, cart, invoice and payment status data; product keys linked to an order; support messages; language and cookie preferences; and security data such as IP address, timestamps, device information and audit events. We do not store full payment card numbers.
3. Purposes and legal bases
Data is used to create and secure accounts, process orders, deliver digital products, provide support, prevent fraud, meet accounting and legal duties, and improve service reliability. The legal bases may include performance of a contract, compliance with law, legitimate interests in security and service operation, and consent for optional cookies or marketing.
4. Recipients and processors
Data may be shared only as necessary with hosting and database providers such as Vercel and Neon, authentication providers selected by the user, payment providers, transactional email services, and product suppliers such as Kinguin for fulfilment. Each provider receives only the information needed for its role.
5. International transfers
Some providers may process data outside the European Economic Area. Where required, transfers rely on an adequacy decision, Standard Contractual Clauses or another lawful safeguard. Provider details will be kept current in this notice as production services are activated.
6. Retention
Account data is retained while the account is active. Order and transaction records are retained for the period required by accounting, tax, fraud-prevention and consumer-protection law. Support and security logs are kept only as long as reasonably necessary. Data is deleted or anonymised when the relevant purpose and retention duty end.
7. Security
We use access controls, encrypted transport, password hashing, secret management, audit logging and encryption for sensitive digital-key material. No online system can guarantee absolute security; suspected incidents are investigated and notifications are made when legally required.
8. Your rights
Depending on the circumstances, you may request access, correction, deletion, restriction, portability or objection, and may withdraw consent at any time without affecting earlier lawful processing. You may also complain to the Croatian Personal Data Protection Agency (AZOP) or the competent authority in your country.
9. Cookies and local storage
Necessary storage supports login, cart, security and language preferences. Optional analytics and marketing storage is disabled until consent is given. Preferences can be changed from Cookie settings in the footer. See the Cookie Policy for details.
10. Children and automated decisions
The store is not directed to children who cannot lawfully enter a purchase contract. We do not knowingly use solely automated decisions that produce legal or similarly significant effects without appropriate information and safeguards.
11. Changes to this notice
Material changes will be shown on this page with a revised date. Where required, users will receive additional notice or be asked for renewed consent.