Effective Date: 9 June 2026
Noventra Tech Ltd, operating lootnex.com (“LootNex,” “we,” “us,” or “our”), is committed to protecting the privacy of everyone who uses our platform. This Privacy Policy sets out what personal data we collect, why we collect it, how long we keep it, and what rights you hold over it — all in plain terms.
LootNex is a platform for buying and selling CS2 cosmetic items, including knives, gloves, agents, rifles, pistols, and other in-game skins and wearables. The nature of our service requires us to handle certain personal and financial data to process orders, verify identity, and transfer Items to your Steam inventory. We handle that data carefully and only as described here.
This policy applies to all visitors, registered users, sellers, and buyers on lootnex.com. By using the platform, you confirm that you have read and understood this Privacy Policy.
1. Who Is Responsible for Your Data
Noventra Tech Ltd is the Data Controller for all personal data collected through lootnex.com, registered in England and Wales under company number 17256413.
Registered address:
61 Bridge Street, Kington, United Kingdom, HR5 3DJ
General support: info@lootnex.com
Website: lootnex.com
2. How We Collect Your Data
Personal data reaches us through three routes:
- Directly from you — when you register an account, complete a purchase, list an Item for sale, request a payout, fill in any form on the platform, or contact our support team.
- Automatically — through cookies, server logs, and analytics tools that activate as you navigate lootnex.com. This captures technical and behavioural data about how the platform is used.
- From third parties — including payment processors and acquiring banks (transaction and fraud data), identity verification providers (KYC/AML documentation), and Valve Corporation via the Steam API (inventory status, trade eligibility, and trade offer outcomes).
3. What Personal Data We Collect
The categories of data we collect depend on how you use LootNex:
Identity and contact details:
- Full name, email address, date of birth, billing address, and any other information you provide during account creation or checkout.
Steam and trading data:
- Your Steam username, Steam ID, linked Trade URL, inventory visibility status, and the history of trade offers associated with your account — all required to deliver purchased Items to your Steam inventory.
Transaction and order records:
- Details of every order placed or listing created on the platform, including Item type and quality tier (e.g., knife, glove, agent skin, rifle skin), price, payment confirmation, payout records, and current transaction status.
Payment data:
- Payment method details are handled exclusively by our authorised third-party payment service providers under PCI DSS standards. Noventra Tech Ltd does not store, access, or process full card numbers or sensitive payment credentials.
Identity verification (KYC/AML) data:
- Government-issued identification documents, proof of address, date of birth confirmation, and any supplementary documentation required to satisfy our AML compliance obligations prior to processing payouts or high-value transactions.
Technical and usage data:
- IP address, browser type and version, operating system, device identifiers, referral source, pages visited, session duration, and cookie identifiers — collected automatically each time you use the platform.
Support and communications data:
- Records of all correspondence between you and LootNex, including support tickets, email exchanges, and any messages submitted through the platform.
4. Why We Process Your Data
We process personal data only where a lawful basis exists under UK GDPR. Our processing purposes are:
- Account management — to create, authenticate, and maintain your LootNex account securely.
- Order fulfilment and Item delivery — to process purchases and coordinate the transfer of CS2 cosmetic Items to your Steam inventory via trade offer.
- Payout processing — to verify seller eligibility, conduct required identity checks, and transfer sale proceeds to the seller’s designated payment method.
- Fraud prevention and platform security — to detect, investigate, and prevent fraudulent transactions, unauthorised account access, market manipulation, and other harmful conduct on the platform.
- Legal and regulatory compliance — to fulfil obligations under applicable AML/CTF legislation, financial record-keeping requirements, tax law, and payment scheme rules imposed by Visa, Mastercard, and our acquiring banks.
- Customer support — to handle enquiries, resolve disputes, and assist with account or transaction issues.
- Platform improvement and analytics — to monitor performance, analyse usage patterns, and develop and enhance LootNex’s features and services.
- Marketing communications — to send promotional content where you have explicitly consented. You may withdraw consent and unsubscribe at any time; transactional and security notifications will continue regardless.
- Enforcement of Terms — to investigate breaches of our Terms and Conditions and protect the rights and interests of LootNex and our users.
5. How We Protect Your Data
We apply technical and organisational security measures proportionate to the sensitivity of the data we hold, including:
- Encryption of all data in transit using industry-standard TLS/SSL protocols.
- Role-based access controls ensuring personal data is accessible only to authorised LootNex personnel on a strict need-to-know basis.
- Regular internal security reviews and infrastructure monitoring.
- Contractual obligations imposed on all third-party processors requiring equivalent security standards.
No digital system is entirely immune to risk. You remain responsible for keeping your account credentials confidential. If you suspect any unauthorised access to your account, notify us immediately at info@lootnex.com.
6. Who We Share Your Data With
We do not sell, rent, or trade your personal data to any third party for their own commercial purposes. Data is shared only in the following circumstances:
- Payment service providers and acquiring banks — for transaction processing, authentication, fraud screening, AML checks, and chargeback handling.
- Identity verification providers — for KYC and AML compliance checks required before payouts or high-value transactions are approved.
- Valve Corporation / Steam — to the extent strictly necessary to complete Steam trade offers and verify Item inventory eligibility.
- Technology and operational service providers — including hosting infrastructure, analytics platforms, email delivery, and customer support tools, all operating under data processing agreements that prohibit independent use of your data.
- Regulatory authorities and law enforcement — where legally required or where disclosure is necessary to protect the safety, rights, or property of LootNex, our users, or third parties.
- Professional advisers — solicitors, accountants, and auditors, under professional obligations of confidentiality.
All third-party data processors are contractually bound to handle your information solely for the purpose for which it was shared and in accordance with applicable data protection law.
7. Automated Decision-Making
Certain transactions on LootNex may be subject to automated processing by payment processors, acquiring banks, or fraud detection systems. These automated checks assess factors such as transaction risk, device fingerprinting, identity verification outcomes, and AML compliance indicators. The outcome may result in a transaction being approved, declined, or flagged for manual review.
Where an automated decision materially affects you — for example, a declined payout or blocked purchase — you have the right to request human review of that decision. To do so, contact info@lootnex.com with the relevant transaction details and we will review your case within 5 business days.
8. Cookies and Tracking Technologies
LootNex uses cookies and similar tracking technologies to keep the platform operational, remember your preferences, and analyse how users interact with our services.
We use four categories of cookies:
- Strictly necessary — essential for core platform functions such as session management, login authentication, and security. These cannot be disabled without affecting platform usability.
- Analytical and performance — used to understand traffic patterns, identify errors, and measure the effectiveness of platform features (e.g., anonymised analytics via tools such as Google Analytics).
- Functional — used to remember your settings and personalise your experience on lootnex.com.
- Marketing — used to deliver relevant promotional content where you have given explicit consent.
You may manage your cookie preferences at any time via your browser settings or through our cookie preferences centre where available. Disabling certain cookies may limit access to some platform features.
9. How Long We Keep Your Data
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected and to comply with our legal obligations:
- Account and transaction records — retained for a minimum of 6 years from the date of the relevant transaction, in compliance with financial record-keeping requirements under English law.
- KYC and AML verification records — retained for a minimum of 5 years from the conclusion of the business relationship, or longer where required by applicable financial regulation.
- Customer support correspondence — retained for up to 3 years, or longer where a dispute or legal matter remains unresolved.
- Marketing consent records — retained until consent is withdrawn, plus a reasonable period to demonstrate compliance with our consent obligations.
- Technical and analytics data — stored in accordance with the respective lifetimes of each cookie or tool, or until deleted via your browser settings.
Upon expiry of the applicable retention period, personal data is securely deleted or anonymised in line with our internal data disposal procedures.
10. International Data Transfers
Your data is primarily stored and processed within the United Kingdom. Where our payment providers, identity verification partners, or technology infrastructure providers operate internationally, data may be transferred outside the UK or EEA.
In all such cases, we ensure appropriate safeguards are in place, which may include:
- Transfers to countries recognised by the UK Government as providing an adequate level of data protection.
- Use of UK-approved International Data Transfer Agreements (IDTAs) or Standard Contractual Clauses (SCCs).
- Other legally recognised transfer mechanisms as appropriate to the circumstances.
For further information about the safeguards applicable to any specific transfer, contact info@lootnex.com.
11. Your Rights
Under UK GDPR, you hold the following rights in relation to your personal data held by LootNex:
- Right of access — to request a copy of the personal data we hold about you (a Subject Access Request).
- Right to rectification — to request correction of inaccurate or incomplete data without undue delay.
- Right to erasure — to request deletion of your data where it is no longer required for the purposes for which it was collected, subject to our legal retention obligations.
- Right to restrict processing — to request that we limit our use of your data in certain defined circumstances.
- Right to data portability — to receive your data in a structured, machine-readable format and, where technically feasible, to have it transferred to another controller.
- Right to object — to object to processing carried out on the basis of our legitimate interests.
- Right to withdraw consent — where processing is consent-based, you may withdraw at any time without affecting the lawfulness of prior processing.
- Rights regarding automated decisions — to request human review of any automated decision that materially affects you, as described in Section 7.
Submit rights requests to info@lootnex.com. We will acknowledge your request within 2 business days and respond in full within one calendar month as required by UK GDPR.
If you are dissatisfied with our handling of your data, you have the right to lodge a complaint with the Information Commissioner’s Office (ICO) — the UK’s independent data protection authority — at www.ico.org.uk or by calling 0303 123 1113.
12. Children’s Data
LootNex is designed exclusively for users aged 18 and over. We do not knowingly collect or process personal data from individuals under the age of 18. If you have reason to believe that a minor has submitted personal data to LootNex, please contact us immediately at info@lootnex.com. We will take prompt steps to identify and permanently delete such data from our systems upon verification.
13. Changes to This Policy
We review and update this Privacy Policy periodically to reflect changes in law, regulatory guidance, platform features, or our internal data practices. Where changes are material, we will notify you by email or via a prominent notice on lootnex.com no less than 7 days before the revised policy takes effect.
The current version of this policy is always available at lootnex.com/privacy, with the effective date displayed at the top. Continued use of LootNex after the effective date of any revision constitutes your acceptance of the updated policy.
14. Contact and Data Protection Enquiries
For questions, requests, or concerns relating to this Privacy Policy or the way LootNex processes your personal data, please reach out to us:
Noventra Tech Ltd
61 Bridge Street, Kington, United Kingdom, HR5 3DJ
Company Registration No: 17256413
General Support: info@lootnex.com
Website: lootnex.com
We aim to acknowledge all privacy-related enquiries within 2 business days and to resolve all complaints within 30 calendar days.
© 2026 Noventra Tech Ltd — lootnex.com — All Rights Reserved