Skip to content

PRIVACY POLICY

Last Revision: May 29, 2026

This Privacy Policy describes how your private details are handled, archived, and distributed when you access our interface, purchase Virtual Goods, reach out to our team, or otherwise submit information through our network. It also covers crucial disclosures regarding your individual data rights. If you supply information on behalf of a separate party, you are required to advise them of these processing terms and point them toward this layout.

Company Information

The Data Controller is NOVATRIX LTD.

Unless stated otherwise, the terms used in this Privacy Policy have the same meanings as those in our Terms and Conditions. Please read this policy carefully.

1. Categories of Collected Information and Operational Objectives

1.1 Account Registration & Customer Profiles: Establishing a registered profile requires customers to supply a first name, surname, phone contact, email address, and a password. We process this data to manage customer profiles, operate platform tools, and protect network parameters. We retain the right to execute localized technology reviews to verify user coordinates for security compliance. If these checks reveal conflicting data or connections from Restricted Countries, profile creation or order completion may be rejected. Users are strictly limited to a single profile and must not deploy VPN services while browsing the interface. Legal Basis: Performance of a Contract.

1.2 Identity Verification & Regulatory Compliance: Our team may demand supplementary confirmation documents—including official identity card scans, proof of payment instruments, account authorization files, or alternative communication records. Customers are required to submit these verification scans within three (3) business days. Failure to supply these records within the window may result in registration denial or purchase termination accompanied by a complete refund. Legal Basis: Legal Obligation and Legitimate Interest (Fraud Prevention).

1.3 Platform Traffic Logs & Analytical Metrics: We collect information detailing how users interact with our storefront, classified as Usage Data. This dataset covers your IP address, browser type, specific sub-pages visited, time and date markers, time spent per screen, and unique device serial codes. We review this data to optimize layout performance, generate general statistics, and block unauthorized security entry. Legal Basis: Legitimate Interest (Service Improvement and Platform Security).

1.4 Promotional Outbound Marketing: If you explicitly opt-in to our updates, we will transmit newsletters and advertising materials regarding our service catalog. Legal Basis: Informed Consent (which can be revoked at any moment).

2. Cookie Management and Tracking Frameworks

Websites deploy cookies—small text strings saved to customer hardware—to maximize layout efficiency and customize user experiences. Under applicable legislation, strictly necessary cookies can be stored automatically to support basic web performance. All other tracking tools require your explicit permission.

3.1 We deploy the following tracking categories across our domain:

  • Strictly necessary. Cookies required for core shop features such as authentication, cart persistence, checkout, and remembering your consent choice. The website cannot function properly without these cookies.
  • Statistics. Analytical cookies that help us understand visitor behavior by gathering usage metrics anonymously without identifying individuals.
  • Marketing. Marketing cookies are used to track visitors across websites. The intention is to display ads that are relevant and engaging for the individual user and thereby more valuable for publishers and third party advertisers.

3.2 The operational lifespan of our cookies falls into two distinct categories:

  • Persistent: Tracking files that remain stored on your system for a pre-set expiration period or until manually cleared. For instance, selecting "Remember Me" during login keeps your session active via a persistent cookie for up to two weeks.
  • Session-Based: Temporary tracking tools that are instantly wiped from your machine the moment you close your web browser.

3. Integrated Third-Party Web Technologies

Our ecosystem integrates tracking technologies deployed by trusted external service brands originating from domains other than ghostsskin.com. We use these files for outside advertising campaigns and general analytics. Third-party analysis providers help us evaluate website trends to improve your experience, while external marketing cookies deliver targeted advertising to your feed on other platforms. We do not maintain direct backend management over these tracking tools, which are governed entirely by the privacy policies of their respective external providers.

3.1 In addition to standard cookies, we deploy equivalent alternative tracking systems:

  • Pixel Tags & Web Beacons: Invisible tracking graphics containing unique markers that tell us when a user visits our storefront or opens an email communication.
  • Local Caching: We utilize HTML5 Local Storage to cache functional elements directly within your web browser to improve interface load speeds and store layout selections.

3.2 Customizing Your Tracking Profiles

You retain the full right to accept or decline non-essential cookies. You can adjust or withdraw your tracking permissions at any time using Cookie settings in the footer or by reading our Cookie policy at /legal/cookies. We use gathered information strictly for its stated purposes unless we notify you of an unrelated processing need supported by a valid legal framework. We may process data without your awareness or consent only if explicitly demanded or permitted by law.

4. Advanced Data Processing and Third-Party Disclosures

4.1 External Service Providers: We may transfer data to IT hosting platforms, KYC/identity confirmation vendors, and specialized corporate advisors (such as lawyers and accountants) operating under our strict operational directions. We control and remain fully responsible for your information.

4.2 Independent Data Controllers: If you transfer data directly to third-party entities, they act as independent data controllers. We hold zero liability for their processing activities; please check their standalone privacy statements.

4.3 Payment Infrastructure Gateways: Your payment card data is processed directly by compliant external transactional gateways adhering to PCI-DSS framework protocols; our System never gathers or stores your full financial credentials. Core transactional metadata is scrubbed once the underlying order finalizes.

4.4 Marketing Dispatches: If selected on our Website, you will receive weekly newsletters and ads regarding our services, which you can remove yourself from at any time using the unsubscribe link located in the footer of our emails.

4.5 Cross-Border Information Transfers: Data may be shared internally within our corporate branches, affiliates, and integrated partner companies to satisfy the purposes detailed in this policy. Personal information collected inside the European Economic Area (EEA) may be transferred to servers outside the EEA. To protect these datasets, we implement European Commission-approved Standard Contractual Clauses (SCCs), enforce binding corporate rules, or obtain explicit user consent.

4.6 Aggregated Analytics: We generate anonymized, aggregated datasets to evaluate platform usage trends and update our features. This anonymous data may be utilized or commercially shared without restriction.

4.7 Corporate Restructuring & Legal Enforcement: Your personal data may be shared or transferred during corporate mergers, asset acquisitions, bankruptcy restructuring, or business dissolution proceedings. We may also disclose your data to satisfy judicial orders, enforce active user agreements, defend against liability claims, protect public safety, or address fraudulent transactions.

4.8 Cross-Device Identification: We link your independent devices to provide a cohesive user experience. We cooperate with third-party tracking partners using statistical modeling to identify multi-device usage for site security, advertising campaign measurement, and targeted promotional placement (subject to explicit consent).

4.9 Automated Decision-Making (“ADM”) & AI Systems: ADM applies when systemic conclusions (including profiling) significantly impact an individual or carry legal consequences without human intervention. We do not deploy ADM protocols for high-impact decisions unless you provide explicit consent, the process is sanctioned by legislation, or it is required to execute an active customer contract. We use automated tools to generate custom service recommendations, block platform features when prohibited conduct is caught, and minimize fraudulent chargeback actions. Automated AI chat systems handle baseline user support requests with your permission, and AI engines may suggest text strings or translation fixes via trusted partners. Your information is safeguarded and processed only to run these workflows; you can request human assistance at any time by messaging support.

5. Information Storage Lifespans

We apply the following retention parameters to your data:

Data may be kept longer if necessary to protect legitimate interests, handle legal disputes, or fulfill legal obligations.

6. Technical Security and Data Protection Safeguards

Our Website utilizes 256-bit SSL encryption tunnels to lock down the transfer of customer data, and we continuously implement the latest software and security measures to minimize potential vulnerabilities. Automated daily server scans are deployed to spot malicious exploits or unauthorized penetration attempts. Our infrastructure is housed within secure, physically guarded facilities to block entry by unauthorized actors.

While we apply industry-standard technical and administrative measures to lock down your data, the internet is not completely safe, and no network storage framework can be guaranteed to be immune from breaches. Although we take extensive security steps, we cannot supply an absolute guarantee of total safety.

7. Individual Privacy Rights and Controls

For residents of the United Kingdom or the European Union (acting as data subjects whose personal information is collected, stored and processed), specific protections are guaranteed under the GDPR, UK GDPR, and the Data Protection Act 2018.

You maintain the following explicit entitlements:

  • The Right of Access: You can demand formal confirmation regarding whether your personal profile is actively being processed. If it is, you have the right to inspect that information along with detailed disclosures concerning the core purposes of the processing, the specific data categories involved, the identities of third parties who have received or will receive the data, and the expected timeframe for data retention (or the metric used to calculate that duration).
  • Copy Restrictions: If you request a physical or digital duplicate of your personal datasets, we will provide it only if you present valid proof of identity and the release does not compromise the rights and privacy freedoms of other users.
  • The Right to Erasure ("Right to be Forgotten"): You can demand that we scrub your personal profiles from our systems without delay. We will comply with this deletion request where the datasets are no longer required for their original stated purpose, you withdraw your processing consent (and no alternative legal ground supports the data usage), you object to the processing and no overriding legitimate corporate reasons exist, the data was processed unlawfully, or deletion is required by law.
  • The Right to Data Portability: You can request to receive the personal information you supplied to us in a structured, standard, machine-readable format. You have the right to transfer this dataset to an alternative company where processing depends on your consent or an active contract, and the processing runs via automated means.
  • The Right to Withdraw Consent: You can revoke your explicit data processing permissions at any moment. Revoking consent does not impact the legality of any data processing executed before your withdrawal notice.
  • The Right to Lodge a Complaint: You can file a formal complaint with a data protection supervisory authority, specifically inside the EU Member State of your primary residence, your workplace, or the location where the alleged data infraction occurred. For issues arising inside the United Kingdom, please direct your complaints to the Information Commissioner’s Office (ICO).

You can exercise the above rights by contacting our support team via the email address: general@ghostsskin.com.

8. Policy Updates

We regularly evaluate our compliance profiles and reserve the absolute right to rewrite or adjust this Privacy Policy to align with shifting regulatory demands. Clarifications and structural changes go into effect the exact moment they are posted on our Website. We encourage you to review this document periodically to stay informed about our data handling updates.