CSMarket

Legal

Privacy Notice

Last updated: 11 September 2026

1. Who we are

1.1 The controller of your personal data is SECURESTRIVE INNOVATIONS LTD, company no. 16815410, registered office 167-169 Great Portland Street, 5th Floor, London, England, W1W 5PF, United Kingdom ("we", "us", "the Operator"). We operate CS Market at https://cs-market.co.

1.2 For data-protection queries you may contact us at [email protected]. We are not required to appoint a Data Protection Officer under Article 37 UK GDPR but we operate a dedicated privacy inbox.

2. What we mean by personal data

Personal data means any information about an identified or identifiable natural person, as defined in the UK GDPR and the EU GDPR.

3. What personal data we collect and why

We collect and process the following categories of personal data:

  • Identity and contact data (name, e-mail, phone, country of residence) - to create and administer your account.
  • Steam account identifier and public inventory data - to verify ownership and to route Item Transfers.
  • Verification data (identity document, address evidence, source-of-funds documents) - collected and held by the Payment Institution, referenced by us only by verification status.
  • Transaction data (Orders, Item metadata, prices, payout events, chargebacks) - to operate the Platform and defend disputes.
  • Payment data (masked card number, IBAN, card push-to-card destination) - held and processed by the Payment Institution; we only see tokenised references.
  • Device and log data (IP address, user-agent, session ID, device fingerprint) - to protect the Platform against fraud, account takeover and bot abuse.
  • Communications (support tickets, dispute messages) - to handle disputes and provide support.
  • Marketing preferences and consent logs - to send only communications you have agreed to receive.

4. Lawful bases

  • Contract (Article 6(1)(b) UK GDPR) - to provide the Platform, execute Orders and issue payouts.
  • Legal obligation (Article 6(1)(c)) - to comply with UK company law, tax law and any obligations imposed on the Payment Institution that require us to co-operate.
  • Legitimate interests (Article 6(1)(f)) - to prevent fraud, secure the Platform, defend chargebacks and improve the service. We balance these against your rights and interests.
  • Consent (Article 6(1)(a)) - for optional cookies and marketing communications; you can withdraw consent at any time.

5. How we share personal data

  • With the Payment Institution ([Payment Institution - Acquirer / EMI partner to be inserted]) - for KYC, KYB, sanctions screening, safeguarding of Client Funds, pay-ins, payouts (including card push-to-card via Visa Direct or Mastercard Send) and chargeback handling. The Payment Institution acts as an independent controller for those purposes.
  • With Valve Corporation (Steam) - to route Item Transfers via Steam's trade API; we share only the minimum data required (Steam ID, trade offer details).
  • With cloud infrastructure, hosting, analytics, e-mail delivery, anti-fraud and log providers - as processors under written data-processing agreements.
  • With professional advisers (legal, accounting, audit) - under a duty of confidentiality.
  • With law-enforcement, courts, regulators - where legally required or in response to a valid legal process.
  • With a successor entity in the event of a merger, acquisition or reorganisation - subject to appropriate safeguards.

We do not sell personal data and do not use it for automated decision-making that produces legal or similarly significant effects on you.

6. International transfers

Some processors are based outside the UK / EEA. Where we transfer personal data internationally, we rely on UK adequacy regulations, the UK International Data Transfer Agreement (IDTA), the UK Addendum to the EU Standard Contractual Clauses, or another lawful transfer mechanism. A copy of the transfer safeguard is available on request.

7. Retention

  • Account and transaction data - kept for the life of the account plus six (6) years after closure, to satisfy tax, accounting and limitation-period obligations.
  • AML / sanctions records - held by the Payment Institution for at least five (5) years after the end of the business relationship as required by MLR 2017.
  • Dispute defence data (chargeback evidence, Item Transfer logs, IP logs) - kept for at least eighteen (18) months from the date of the Order.
  • Marketing consents - kept until you withdraw consent, plus a reasonable audit period.
  • Server access logs - typically ninety (90) days, subject to security-incident investigation.

8. Security

We implement industry-standard controls aligned to ISO 27001 / NIST CSF: encryption in transit and at rest, per-tenant isolation for messages and Deliverables, least-privilege access, hardened build pipeline, secrets management, quarterly access reviews, and a documented incident-response plan meeting the seventy-two (72)-hour ICO breach-notification requirement.

9. Your rights

Subject to conditions and exemptions in law, you have the right to (i) access your personal data, (ii) rectify inaccurate data, (iii) erasure, (iv) restrict processing, (v) object to processing, (vi) data portability, (vii) withdraw consent where processing is based on consent, and (viii) lodge a complaint with the Information Commissioner's Office (ICO) at https://ico.org.uk or with your local supervisory authority.

To exercise your rights, contact [email protected]. We respond within one month (extendable by two further months for complex requests, with notice).

10. Cookies

We use cookies and similar technologies as described in the Cookie Policy. Strictly necessary cookies are set by default; all other categories require your consent.

11. Age

The Platform is not directed at children. Users must be at least eighteen (18) years old. We do not knowingly collect personal data from children; if we discover we have, we delete it without undue delay.

12. Changes to this notice

We may amend this notice from time to time. Where changes are material, we will notify you in-Platform or by e-mail. The current version and its date are shown at the top of this notice.

13. Registered details

SECURESTRIVE INNOVATIONS LTD, company no. 16815410, registered office 167-169 Great Portland Street, 5th Floor, London, England, W1W 5PF, United Kingdom. Contact: [email protected].