Two kinds of personal data pass through Ctrade: the small amount needed to run an account, and the identity documents we are obliged to collect before paying anyone. This page explains both, in the order they happen.
01
Controller and contact
The controller for the data described here is OWNER INPUT REQUIRED, at OWNER INPUT REQUIRED. Data protection questions go to OWNER INPUT REQUIRED.
Whether a data protection officer has been appointed: OWNER INPUT REQUIRED. Until the operator confirms this, the support address is the single point of contact.
02
When you open an account
We store your email address, a hash of your password, the date you registered and whether your email has been confirmed. We keep this because there is no way to run a signed-in account without it — the legal basis is performance of the contract.
If you add Steam trade details so we can send you items, those are stored against your account and used for nothing else.
03
When you trade
Orders, sell requests, balance movements and the reference of every transaction are recorded. This is both contractual and an accounting obligation: we cannot delete a settled order on request, because we have to be able to show what money moved and why.
Support messages you send are stored with the address you gave, so a later reply has context.
04
When you pass identity checks
For a sale or a withdrawal we collect your full name, date of birth, citizenship, country of residence, tax identification number, an identity document and a proof of address. The legal basis is our own legal obligation as a business that pays out money.
Documents are stored in a private bucket that is not reachable from the public internet. Reads are authorised per request and only staff reviewing your case can open them.
Retention for identity records is OWNER INPUT REQUIRED; the operator must set this to the period required by its jurisdiction before this deployment handles real applicants.
05
What we never collect
Card numbers do not reach our servers. Card payments are handled by the payment provider and we keep only the last four digits and the card brand so you can tell your cards apart.
We do not run advertising trackers, we do not sell data, and we do not build profiles for anyone else.
06
Who else sees your data
Our hosting and database provider, our transactional email provider, and the payment provider each process data on our instructions under a processing agreement. They see only what their function needs.
We disclose data to an authority when we are legally required to, and we will tell you unless the law forbids it.
07
Your rights
You can ask for a copy of your data, correct it, ask us to delete what we are not obliged to keep, object to a particular use, or ask for your data in a portable form. Write to the support address and we will answer within one month.
Where a legal retention period applies — identity records and accounting data — we will tell you the period rather than delete the record early.
You can also complain to a supervisory authority. The competent authority depends on the operator's jurisdiction: OWNER INPUT REQUIRED.
08
Security and transfers
Traffic is encrypted in transit, documents sit in private storage, and access to the production database is limited to the accounts that need it. Every administrative action on your account is written to an internal audit log.
Data is hosted in the European Union. Any transfer outside it would rely on the standard contractual clauses; current transfers: OWNER INPUT REQUIRED.