Privacy Policy
This Privacy Policy explains how Blue Horizon Sp. z o.o. (“Karambase”, “we”, “us” or “our”) collects, uses, stores and protects your personal data when you visit karambase.com (the “Website”) and use our services. We are committed to processing your personal data lawfully, fairly and transparently in accordance with Regulation (EU) 2016/679 (the “GDPR”) and applicable Polish law.
Data Controller: Blue Horizon Sp. z o.o.
KRS: 0001250411 · NIP: 7831957098
Registered address: Półwiejska 17/26, 61-888 Poznań, Poland
Privacy contact: support@karambase.com
1. Information We Collect
We collect personal data that you provide to us, data generated through your use of the Website, and data received from third parties when you choose to connect them. Specifically:
Information you provide
- Contact details — email address and any information you submit through contact forms, support requests or newsletter sign-ups.
- Order information — the items you purchase, order references and your communications with our support team.
Information from Steam (Steam Sign-In)
- When you sign in with Steam, Valve provides us with your SteamID, public profile name, avatar and trade URL. We use this solely to identify your account and deliver purchased items to your Steam inventory. We never receive your Steam password.
Payment information
- Payments are processed by regulated third-party payment providers (supporting Visa, Mastercard, Google Pay and Apple Pay). We do not store full card numbers on our servers; our providers handle card data under the PCI-DSS standard. We retain transaction identifiers, amounts, dates and status for accounting and fraud-prevention purposes.
Technical and usage data
- IP address, browser type and version, device and operating system, referring pages, pages viewed, and interaction data, collected through cookies and similar technologies (see our Cookies Policy).
2. How and Why We Use Your Data
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Creating and managing your account; signing you in via Steam | Performance of a contract (Art. 6(1)(b)) |
| Processing orders, payments and delivering items to your Steam inventory | Performance of a contract (Art. 6(1)(b)) |
| Providing customer support and responding to enquiries | Performance of a contract / legitimate interests (Art. 6(1)(b), (f)) |
| Fraud prevention, securing the Website and ensuring platform integrity | Legitimate interests (Art. 6(1)(f)) |
| Complying with accounting, tax and other legal obligations | Legal obligation (Art. 6(1)(c)) |
| Sending marketing communications and newsletters | Consent (Art. 6(1)(a)) — withdrawable at any time |
| Analytics and improving our services | Consent / legitimate interests (Art. 6(1)(a), (f)) |
3. Sharing Your Data
We do not sell your personal data. We share it only with:
- Payment providers — to authorise and process your payments and prevent fraud.
- Valve Corporation (Steam) — to authenticate your sign-in and deliver items to your inventory.
- Service providers — hosting, email, analytics and customer-support tools that process data on our behalf under appropriate data-processing agreements.
- Authorities — where we are legally required to do so, or to establish, exercise or defend legal claims.
4. International Transfers
Your data is primarily processed within the European Economic Area (EEA). Where a provider processes data outside the EEA, we ensure an adequate level of protection through mechanisms such as European Commission adequacy decisions or Standard Contractual Clauses.
5. How Long We Keep Your Data
We retain personal data only for as long as necessary for the purposes set out above: account data for the lifetime of your account; transaction and accounting records for the period required by Polish tax law (generally 5 years); and support correspondence for as long as needed to resolve your matter and a reasonable period thereafter. When data is no longer needed, we delete or anonymise it.
6. Your Rights
Under the GDPR you have the right to: access your data; rectify inaccurate data; request erasure (“right to be forgotten”); restrict or object to processing; data portability; and withdraw consent at any time (without affecting prior processing). To exercise any right, contact us at support@karambase.com. You also have the right to lodge a complaint with the Polish supervisory authority, the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych, UODO), ul. Stawki 2, 00-193 Warsaw.
7. Security
We implement appropriate technical and organisational measures to protect your data, including encryption in transit (TLS), access controls, and the use of PCI-DSS-compliant payment processors. No method of transmission or storage is completely secure, but we continually work to safeguard your information.
8. Cookies
We use cookies and similar technologies to operate the Website, remember your preferences, and (with your consent) measure performance and personalise content. For full details and to manage your choices, see our Cookies Policy.
9. Children
The Website is intended for users aged 18 and over. We do not knowingly collect data from anyone under 18. If you believe a minor has provided us data, please contact us and we will delete it.
10. Changes to This Policy
We may update this Privacy Policy from time to time. The “Last updated” date above reflects the latest version. Material changes will be communicated through the Website.
11. Contact Us
For any privacy question or request, contact us at support@karambase.com or by post at the registered address above.