[ OPS-01 ] rift.market
RIFT

Privacy Policy

> rift/legal/privacy · last updated 2026-04-01

1.

data controller

DEK KEY OÜ ("Rift") is the data controller. Contact: privacy@rift.market.

2.

what we collect

datasourcepurpose
Steam ID, display nameSteam OpenIDAccount creation & auth
Email addressOnboarding formReceipts, alerts, support
Trade URLOnboarding formSkin delivery via Steam
Discord handleOptional inputSupport escalation
IP address, user agentAutomaticSecurity & fraud prevention
Payment card (tokenized)PCI-DSS payment providerWallet top-ups
Order historyPlatform activityService delivery & disputes
3.

how we use your data

  • Process purchases and deliver items
  • Send transactional emails (receipts, trade updates)
  • Prevent fraud and comply with our legal obligations
  • Improve the platform (anonymous analytics only)
4.

data sharing

  • DMarket — to execute skin trades (Steam ID + trade URL)
  • Our PCI-DSS-compliant payment provider — to process card payments (tokenized card data)
  • Law enforcement — when required by law

We never sell, rent, or share your data for advertising purposes.

5.

data retention

Account data is retained while your account is active. Order records are kept for 7 years for legal compliance. You can request deletion at any time — we will erase all non-legally-required data within 30 days.

6.

your rights

  • Access — request a copy of your data
  • Rectification — correct inaccurate information
  • Erasure — delete your account and data
  • Portability — export your data in machine-readable format
  • Objection — opt out of non-essential processing

Email privacy@rift.market to exercise any right. We respond within 30 days.

7.

cookies

See our Cookie Policy for details on what cookies we use and how to manage them.

8.

changes

We will notify you of material changes via email 14 days before they take effect.