Policies

Cookie Policy

Last updated: 31 July 2026

1. Introduction

This Cookie Policy explains how CONDEO LTD uses cookies and similar storage and access technologies when you visit or use conskins.com and related ConSkins services.

It explains:

  • what cookies and similar technologies are;
  • why we use them;
  • which technologies require your consent;
  • which technologies may be used without consent;
  • how third parties may use such technologies;
  • how long information may remain on your device;
  • how you can manage or withdraw your choices; and
  • how to contact us about our use of these technologies.

This Cookie Policy should be read together with the ConSkins Privacy Policy.

2. Service Provider

The ConSkins service is operated by:

CONDEO LTD
Company number: 17225871
Registered office: Dept 6790, 196 High Road, Wood Green, London, United Kingdom, N22 8HH
Email: info@conskins.com

Website: conskins.com

In this Policy, “ConSkins”, “we”, “us” and “our” mean CONDEO LTD.

3. Scope of This Policy

This Policy applies to cookies and similar technologies used through:

  • conskins.com;
  • the ConSkins Account interface;
  • the ConSkins Balance and payment interface;
  • Digital Item catalogue and Order pages;
  • Steam linking and delivery functionality;
  • customer support features;
  • cookie preference tools; and
  • other ConSkins-controlled online interfaces.

External services, including Steam and payment services, may use their own cookies or similar technologies under their own privacy and cookie notices.

4. What Are Cookies?

Cookies are small text files placed on your browser or device when you visit a website.

Cookies may allow a website to:

  • recognise a browser or device;
  • maintain a login session;
  • remember preferences;
  • secure transactions;
  • prevent fraud;
  • understand how the website is used;
  • measure performance;
  • personalise functionality; or
  • support advertising where permitted.

Cookies may contain identifiers and other technical information. They do not ordinarily contain complete payment card details or readable passwords.

5. Similar Storage and Access Technologies

This Policy also applies to technologies that store information on, or access information from, your browser or device, including:

  • local storage;
  • session storage;
  • software development kits;
  • pixels;
  • tags;
  • scripts;
  • browser cache identifiers;
  • device identifiers;
  • web beacons;
  • embedded content;
  • link identifiers; and
  • device or browser signals used for security and fraud prevention.

References to “cookies” in this Policy include these similar technologies unless the context requires otherwise.

6. First-Party and Third-Party Cookies

6.1 First-party cookies

First-party cookies are placed through the ConSkins domain and are generally controlled by ConSkins.

They may be used to:

  • maintain Account sessions;
  • remember consent choices;
  • protect forms and payments;
  • maintain security;
  • remember Website preferences; and
  • provide requested functionality.

6.2 Third-party cookies

Third-party cookies are placed or controlled by another organisation whose service is integrated into or accessed through ConSkins.

Third parties may include:

  • payment service providers;
  • fraud-prevention providers;
  • identity verification providers;
  • Steam or Valve;
  • hosting and security providers;
  • consent management providers;
  • analytics providers; and
  • advertising providers where enabled.

Third parties may determine their own purposes and retention periods for some processing.

7. Session and Persistent Cookies

7.1 Session cookies

Session cookies normally expire when you close your browser or when the relevant session ends.

They may be used for:

  • authentication;
  • checkout;
  • security;
  • fraud prevention;
  • form protection; and
  • temporary Website functionality.

7.2 Persistent cookies

Persistent cookies remain on your device for a defined period or until you remove them.

They may be used to:

  • remember cookie preferences;
  • recognise a trusted device;
  • remember language or display settings;
  • measure Website use; and
  • maintain other permitted preferences.

We will not retain a cookie for longer than is reasonably necessary for its stated purpose.

8. Legal Framework

Our use of cookies and similar technologies is governed by applicable privacy and electronic communications rules, including:

  • the Privacy and Electronic Communications Regulations 2003;
  • the UK GDPR;
  • the Data Protection Act 2018; and
  • other applicable data protection and privacy laws.

Where a technology does not fall within a legal exception, we will obtain consent before storing information on or accessing information from your device.

Where personal data is processed, we will also identify an appropriate lawful basis under applicable data protection law.

9. Cookies That May Be Used Without Consent

Depending on their exact purpose and configuration, we may use certain technologies without prior consent where an applicable legal exception applies.

These may include technologies used solely for:

  • transmitting a communication;
  • providing a service expressly requested by you;
  • authenticating and maintaining your Account session;
  • protecting the Website, Account or payment process;
  • preventing fraud;
  • maintaining a shopping or Order session;
  • remembering your cookie choices;
  • collecting limited statistical information to improve the Service, where all conditions of the applicable statistical exception are met;
  • adapting Website appearance or functionality to your preference, where all conditions of the applicable appearance exception are met; or
  • another exempt purpose permitted by law.

An exception applies only to the particular exempt purpose.

If the same technology is also used for a non-exempt purpose, we will obtain consent unless another lawful exception applies.

10. Strictly Necessary Technologies

Strictly necessary technologies are essential to provide functionality that you request.

They may be used to:

  • create and maintain secure Account sessions;
  • authenticate login;
  • prevent unauthorised access;
  • protect forms against cross-site request forgery;
  • remember items during checkout;
  • maintain payment and Order state;
  • process Balance Top-Ups;
  • connect requested Steam functionality;
  • deliver Digital Items;
  • remember privacy and cookie choices;
  • prevent fraudulent transactions;
  • apply security rate limits;
  • detect malicious traffic; and
  • maintain Website availability.

You cannot disable strictly necessary technologies through the ConSkins Cookie Preferences tool because the relevant functionality may not work without them.

You may still block them through your browser, but doing so may prevent the Website or Account from functioning correctly.

11. Security and Fraud-Prevention Technologies

We may use storage and access technologies to protect:

  • ConSkins Accounts;
  • registered email addresses;
  • ConSkins Balance;
  • payments;
  • Orders;
  • Steam linking;
  • Steam Trade Offers;
  • refunds;
  • support functions; and
  • the Website generally.

These technologies may help us identify:

  • suspicious login attempts;
  • stolen payment credentials;
  • unusual payment activity;
  • automated abuse;
  • multiple related Accounts;
  • malicious traffic;
  • session hijacking;
  • phishing;
  • account compromise;
  • attempts to bypass restrictions; and
  • other security threats.

Security technologies may use information such as:

  • IP address;
  • browser type;
  • device information;
  • session identifier;
  • login history;
  • transaction information;
  • approximate location;
  • security events; and
  • fraud-risk indicators.

Where these technologies are essential to secure a service requested by you, they may be used without consent.

They will not be used for unrelated advertising without the required consent.

12. Functional and Preference Technologies

Functional technologies may remember choices such as:

  • language;
  • region;
  • currency display;
  • catalogue display settings;
  • recently viewed Digital Items;
  • interface preferences;
  • accessibility settings; and
  • other Website customisation.

Some short-lived preference technologies may fall within an applicable appearance exception where they are used solely to adapt or improve the Website according to your preference.

Where we rely on that exception, we will:

  • provide clear information;
  • limit the use to the permitted purpose; and
  • provide a simple and free way to object.

Where the exception does not apply, we will request consent before using the technology.

13. Statistical and Analytics Technologies

We may use limited statistical technologies to understand:

  • which pages are visited;
  • how users navigate the Website;
  • whether pages load correctly;
  • which features are used;
  • where errors occur;
  • general device and browser categories;
  • aggregated Website performance; and
  • how the Service may be improved.

Where analytics are used solely to collect statistical information for improving the ConSkins Service and all conditions of the applicable statistical exception are met, prior consent may not be required.

Where we rely on that exception, we will:

  • provide clear information;
  • limit the technology to statistical purposes;
  • avoid using the information for advertising or unrelated profiling;
  • provide a simple and free way to object; and
  • apply appropriate privacy safeguards.

Where an analytics technology is used for broader tracking, profiling, advertising, cross-service measurement or another non-exempt purpose, it will not be activated before the required consent is obtained.

14. Advertising and Marketing Technologies

ConSkins may use advertising or marketing technologies only where they are enabled and the required consent has been obtained.

Such technologies may be used to:

  • measure advertising performance;
  • limit repeated advertising;
  • understand whether an advertisement led to a Website visit;
  • create or use advertising audiences;
  • personalise advertising;
  • track interactions across websites or services; or
  • support campaign reporting.

Advertising and marketing technologies are not strictly necessary for the operation of ConSkins.

They will remain disabled unless you actively consent where consent is required.

You may withdraw your consent at any time.

15. Account Authentication Technologies

When you log in, ConSkins may use technologies to:

  • confirm that you are authenticated;
  • maintain the secure session;
  • remember that authentication was completed;
  • prevent repeated login requests;
  • detect suspicious access; and
  • log you out after inactivity or security events.

Blocking these technologies may prevent access to your Account.

16. ConSkins Balance and Payment Technologies

When you top up or use your ConSkins Balance, ConSkins and the relevant Payment Provider may use cookies or similar technologies to:

  • maintain the payment session;
  • authenticate the transaction;
  • apply 3D Secure;
  • prevent duplicate submissions;
  • detect payment fraud;
  • identify suspicious activity;
  • remember transaction state;
  • process a refund;
  • respond to a Chargeback; and
  • comply with payment-security requirements.

Some payment technologies are necessary to complete the payment that you request.

A Payment Provider may also use technologies under its own privacy and cookie terms.

17. Steam-Related Technologies

When you link or interact with Steam, Valve or Steam may use cookies and similar technologies on its own domains to:

  • maintain Steam login;
  • authenticate the Steam Account;
  • manage Steam security;
  • display Account information;
  • manage Steam Trade Offers; and
  • provide other Steam functionality.

Steam-controlled technologies are governed by Valve’s own privacy and cookie practices.

ConSkins does not receive your Steam password through ordinary Steam linking.

18. Identity Verification Technologies

Where identity, age or payment ownership verification is required, a verification provider may use technologies to:

  • maintain the verification session;
  • protect document submission;
  • prevent fraud;
  • support camera or liveness functionality;
  • remember verification progress;
  • prevent repeated submissions; and
  • secure communication with its systems.

Such providers may operate their own domains and privacy notices.

19. Consent Management Technologies

ConSkins may use a consent management tool to:

  • display the cookie banner;
  • record your selections;
  • remember accepted and rejected categories;
  • store the date and version of the consent notice;
  • demonstrate that consent was obtained;
  • allow you to revise your choices; and
  • prevent repeated banners during the relevant preference period.

The consent preference record is necessary to respect and demonstrate your choices.

20. Cookie and Technology Schedule

The table below describes the principal technologies that may be used through ConSkins.

Exact technical identifiers may vary depending on the production environment, provider configuration and security setup. The live Cookie Preferences interface should display the current identifier, provider, purpose and duration for active non-essential technologies.

Technology or identifierProviderPurposeCategoryTypical durationConsent or exception
Account session identifier — deployment-specific nameConSkinsMaintains a secure logged-in Account sessionStrictly necessarySession or up to 30 daysStrictly necessary
Authentication token — deployment-specific nameConSkinsConfirms authentication and prevents repeated loginStrictly necessarySession or up to 30 daysStrictly necessary
CSRF or form-security token — deployment-specific nameConSkinsProtects forms and transactions against unauthorised requestsStrictly necessarySessionStrictly necessary
Cookie preference record — deployment-specific nameConSkins or consent providerStores cookie and privacy selectionsStrictly necessaryUp to 6 monthsStrictly necessary to remember choices
Checkout and Order state — deployment-specific nameConSkinsMaintains the selected item, Balance deduction and Order processStrictly necessarySession or up to 24 hoursStrictly necessary
Security and rate-limit identifier — deployment-specific nameConSkins or security providerDetects malicious traffic, automated abuse and Account attacksStrictly necessary or security purposeSession to 12 months, depending on risk purposeStrictly necessary where essential
Language or display preference — deployment-specific nameConSkinsRemembers language, currency display or interface preferenceFunctionalSession to 12 monthsAppearance exception with opt-out, or consent
Recently viewed items — deployment-specific nameConSkinsRemembers Digital Items recently viewed on the deviceFunctionalUp to 30 daysAppearance exception with opt-out, or consent
Payment authentication cookies — provider-specific namesPayment ProviderMaintains the payment session, applies authentication and prevents fraudStrictly necessary for requested paymentSession to provider-defined periodStrictly necessary where essential to payment
3D Secure cookies or device identifiers — provider-specific namesPayment Provider, card issuer or authentication providerAuthenticates a Top-Up and assesses payment riskStrictly necessary for requested paymentSession to provider-defined periodStrictly necessary where essential
Steam authentication cookies — Steam-controlled namesValve or SteamMaintains Steam login and requested Steam functionalityThird-party essential functionalitySteam-definedControlled by Steam; may be necessary for requested interaction
Identity verification session cookies — provider-specific namesVerification providerSecures and maintains an identity or age verification sessionStrictly necessary for requested verificationSession to provider-defined periodStrictly necessary where verification is requested
Limited first-party analytics identifier — provider-specific name, if enabledConSkins or analytics providerProduces statistical information to improve the WebsiteAnalyticsSession to 13 monthsStatistical exception with simple opt-out where all conditions are met, otherwise consent
Third-party analytics identifiers — provider-specific names, if enabledAnalytics providerMeasures Website use and performanceAnalyticsProvider-defined, ordinarily up to 24 monthsPrior consent unless an exception clearly applies
Advertising conversion identifiers — provider-specific names, if enabledAdvertising providerMeasures advertising performance and conversionsMarketingProvider-defined, ordinarily up to 13 monthsPrior consent
Advertising audience or remarketing identifiers — provider-specific names, if enabledAdvertising providerSupports personalised advertising or audience creationMarketingProvider-definedPrior consent

21. Live Cookie Preferences Information

The Cookie Preferences interface may contain more detailed and current information about active technologies, including:

  • technical cookie name;
  • provider;
  • domain;
  • purpose;
  • category;
  • whether the cookie is first-party or third-party;
  • duration;
  • consent status; and
  • a link to relevant third-party information.

Where the live Cookie Preferences information and the general table in this Policy differ because of a recent technical update, the live interface should identify the technologies active in the current production environment.

We will update this Policy where the change is material.

22. Optional Services Not Currently Enabled

A technology described in this Policy does not necessarily mean that the related optional provider or feature is currently active.

Optional analytics, marketing, embedded content or advertising technologies will apply only where:

  • the relevant service has been implemented;
  • the technology is active on the Website; and
  • any required consent or exception conditions have been satisfied.

23. Consent Banner

When required, ConSkins will display a consent interface that allows you to:

  • accept optional technologies;
  • reject optional technologies;
  • select individual categories;
  • receive information about the purposes;
  • access third-party information; and
  • save your preferences.

Rejecting optional cookies should be as clear and accessible as accepting them.

We will not treat continued browsing, silence or inactivity as valid consent where an active opt-in is required.

24. Granular Choices

Where consent is required, choices may be divided into categories such as:

  • strictly necessary;
  • functional;
  • analytics;
  • marketing; and
  • other optional technologies.

Strictly necessary technologies will remain active.

Optional categories will not be pre-selected where consent requires an affirmative choice.

25. Withdrawal of Consent

You may withdraw or change consent at any time through the Cookie Preferences link available on the Website.

Withdrawing consent will:

  • stop future use of the relevant non-essential technologies;
  • update the preference record; and
  • remove or disable relevant technologies where technically possible and legally required.

Withdrawal does not make earlier processing unlawful where valid consent existed at the time.

Withdrawing consent should be as easy as giving it.

26. Objecting to Exempt Statistical or Preference Technologies

Where ConSkins relies on a statistical or appearance exception instead of consent, we will provide a simple and free way to object.

You may object through:

  • the Cookie Preferences interface;
  • an opt-out control associated with the relevant feature; or
  • another clearly identified mechanism.

After a valid objection, the relevant technology will no longer be used for that exempt purpose on the applicable browser or device, subject to the technical limitations explained to you.

27. Consent Records

We may retain records showing:

  • the consent or objection selected;
  • the date and time;
  • the version of the notice;
  • the categories selected;
  • the browser or device identifier associated with the preference; and
  • subsequent changes or withdrawal.

These records are used to:

  • respect your choices;
  • demonstrate compliance;
  • investigate complaints; and
  • avoid repeatedly requesting the same preference.

Consent records will be protected and retained only for an appropriate period.

28. Refreshing Cookie Choices

We may ask you to review your choices again where:

  • material purposes change;
  • new non-essential providers are introduced;
  • the consent categories change;
  • the previous preference expires;
  • legal requirements change;
  • the consent record can no longer be reliably linked to the device; or
  • another refresh is reasonably necessary.

As a general operational approach, ConSkins may refresh cookie choices approximately every six months, although the appropriate interval may vary according to the nature of the technologies and any changes made.

29. Multiple Devices and Browsers

Cookie preferences are generally stored on the browser or device used to make the selection.

You may need to set your preferences again when you:

  • use another device;
  • use another browser;
  • use a private browsing session;
  • clear browser data;
  • block the preference cookie;
  • reinstall the browser; or
  • access the Website through an embedded browser.

30. Browser Controls

Most browsers allow you to:

  • view cookies;
  • delete cookies;
  • block all cookies;
  • block third-party cookies;
  • block cookies from particular websites;
  • clear local storage; and
  • receive a notification before a cookie is placed.

Browser settings vary.

Blocking all cookies may prevent:

  • Account login;
  • Balance Top-Ups;
  • checkout;
  • Order processing;
  • Steam linking;
  • support functionality;
  • cookie preferences; and
  • other requested features

from working correctly.

Browser controls do not necessarily prevent all similar technologies, such as local storage, pixels, scripts or device signals.

31. Global Privacy and Browser Signals

ConSkins may recognise supported browser or device privacy signals where technically and legally appropriate.

However, browser settings or privacy signals may not always communicate a sufficiently specific choice for every cookie category or purpose.

Where a separate consent interface is required, you should use the ConSkins Cookie Preferences tool to record your choices.

32. Do Not Track

Some browsers transmit a “Do Not Track” signal.

There is no single universally adopted technical standard determining how every online service should respond to that signal.

ConSkins will respond to legally recognised and technically supported preference mechanisms where required.

You should use the Cookie Preferences interface for the clearest control over ConSkins optional technologies.

33. Cookie Walls

ConSkins will not ordinarily require you to consent to optional advertising or analytics cookies merely to access core Website functionality.

Certain requested features may require a specific technology to operate.

Where a technology is genuinely necessary for the feature you request, we will explain the effect of disabling it.

34. Embedded Content

The Website may contain content or functionality provided by another organisation.

Examples may include:

  • Steam authentication;
  • payment interfaces;
  • identity verification tools;
  • customer support widgets;
  • videos;
  • social content; or
  • other embedded features.

An embedded provider may store or access information when:

  • the page loads;
  • you interact with the feature;
  • you log in;
  • you submit information; or
  • the relevant feature is activated.

Where the technology is not exempt, we will seek consent before activating it.

Feature-led consent may be requested when you choose to use a specific optional feature.

35. External Links

A link from ConSkins to an external website does not mean that ConSkins controls the external website’s cookies.

When you follow an external link, the destination website may place its own cookies under its own policies.

You should review the destination website’s privacy and cookie information.

36. Payment Provider Cookies

Payment Providers may use cookies or device information to:

  • authenticate a payment;
  • prevent fraud;
  • comply with payment network rules;
  • apply 3D Secure;
  • maintain the payment session; and
  • process refunds or disputes.

Where you are redirected to a Payment Provider’s domain, that provider controls the technologies used on that domain.

Payment functionality may not operate if essential payment cookies are blocked.

37. Steam and Valve Cookies

When you are redirected to or interact with Steam, Valve may use technologies under its own policies.

These may support:

  • Steam login;
  • Account authentication;
  • session security;
  • Steam Guard;
  • Account preferences; and
  • Steam Trade functionality.

ConSkins does not control the duration or purpose of cookies set exclusively by Valve on Steam-controlled domains.

38. Security and Device Recognition

ConSkins may recognise a browser or device for security purposes.

Security device recognition may help:

  • detect unusual login attempts;
  • identify compromised sessions;
  • prevent repeated payment fraud;
  • apply transaction limits;
  • protect the Balance;
  • identify automated attacks; and
  • protect Steam Trade delivery.

Security information will not be used for unrelated personalised advertising without the required consent.

39. Device Fingerprinting

ConSkins will not use device fingerprinting for advertising or cross-service tracking without an appropriate legal basis and any required consent.

Limited device or browser signals may be used for security and fraud prevention where reasonably necessary and proportionate.

Such signals may include:

  • browser version;
  • operating system;
  • screen characteristics;
  • language;
  • time zone;
  • IP information;
  • device configuration; and
  • security indicators.

Further information about security processing is provided in the Privacy Policy.

40. Analytics Safeguards

Where analytics technologies are used, ConSkins may apply safeguards such as:

  • limiting data collection;
  • shortening retention periods;
  • avoiding unnecessary cross-site tracking;
  • disabling advertising features;
  • aggregating reports;
  • masking or truncating IP addresses where supported;
  • restricting provider access;
  • preventing secondary use where contractually possible; and
  • providing consent or opt-out controls.

41. International Transfers

Third-party cookie and technology providers may process information outside the United Kingdom.

Where personal data is transferred internationally, ConSkins will use an appropriate safeguard where required, such as:

  • an applicable adequacy regulation;
  • the UK International Data Transfer Agreement;
  • the UK Addendum to the European Commission’s Standard Contractual Clauses;
  • binding corporate rules;
  • an applicable legal exception; or
  • another permitted mechanism.

Further information is provided in the Privacy Policy.

42. Personal Data Collected Through Cookies

Depending on the technology, information collected may include:

  • IP address;
  • cookie identifier;
  • session identifier;
  • Account status;
  • browser and device information;
  • operating system;
  • approximate location;
  • language;
  • pages viewed;
  • buttons selected;
  • referring page;
  • error information;
  • consent choices;
  • transaction status;
  • security events; and
  • advertising interactions where consented.

We process this information in accordance with the Privacy Policy.

43. Retention

Cookie retention periods depend on their purposes.

We will:

  • use session cookies only for the necessary session period;
  • set reasonable expiry periods for persistent cookies;
  • review provider defaults;
  • avoid indefinite retention;
  • remove technologies that are no longer required; and
  • update the Cookie Preferences information when material changes occur.

Third-party providers may apply their own retention periods as described in their notices.

44. Security

We take reasonable measures to protect information collected through cookies and similar technologies.

Measures may include:

  • secure cookie attributes;
  • encrypted connections;
  • restricted access;
  • session expiry;
  • rotation of identifiers;
  • monitoring;
  • provider controls;
  • pseudonymisation; and
  • data minimisation.

Cookies should not be treated as a secure place to store readable passwords or complete payment card details.

45. Your Data Protection Rights

Where information collected through cookies constitutes personal data, you may have rights including:

  • access;
  • correction;
  • deletion;
  • restriction;
  • objection;
  • data portability;
  • withdrawal of consent; and
  • complaint to a competent supervisory authority.

These rights are subject to applicable conditions and exemptions.

Further information is provided in the Privacy Policy.

46. Contacting Us

Questions or complaints about cookies and similar technologies should be sent to:

info@conskins.com

Please include:

  • the browser or device used;
  • the relevant cookie or technology, where known;
  • the date of the issue;
  • a description of the concern;
  • screenshots, where useful; and
  • the resolution requested.

Do not send passwords, Steam Guard codes or complete payment card details.

47. Complaints

You may complain to ConSkins if you believe that:

  • non-essential cookies were activated without a valid basis;
  • your rejection was not respected;
  • you could not withdraw consent;
  • the Cookie Preferences interface did not work;
  • a third party was not identified;
  • information was unclear; or
  • personal data collected through cookies was misused.

We will handle data protection complaints in accordance with the Privacy Policy.

You may also have the right to complain to the United Kingdom Information Commissioner’s Office or another competent supervisory authority.

48. Changes to This Policy

We may update this Policy to reflect:

  • changes to Website functionality;
  • new or removed providers;
  • changes to payment or Steam integrations;
  • changes to cookie names;
  • new analytics or marketing technologies;
  • security improvements;
  • changes in law or regulatory guidance; or
  • corrections and clarifications.

The current version will be published on the Website with a revised “Last updated” date.

Where a change materially affects an existing consent, we will request fresh consent where required.

49. Relationship with Other Policies

This Cookie Policy should be read together with:

  • the Terms and Conditions;
  • the Privacy Policy;
  • the ConSkins Balance, Payments & Pricing Policy;
  • the Digital Item Delivery & Steam Trade Policy;
  • the Acceptable Use, Fraud Prevention & Account Security Policy; and
  • the KYC & Sanctions Policy.

50. Contact Details

CONDEO LTD
Company number: 17225871
Registered office: Dept 6790, 196 High Road, Wood Green, London, United Kingdom, N22 8HH
Email: info@conskins.com