Privacy policy
What ONESTAND knows about you, why it is needed and how to exercise your rights.
1. Who is responsible for your data
ONESTAND processes personal data to provide this service. This policy covers visitors and account holders, including Google and Steam sign-in, balance top-ups, case openings and marketplace withdrawals.
For questions about your personal data, use the Support section. Include your ONESTAND user ID and describe your request. Never share your password, session cookies or complete payment-card details.
Support2. What data we receive
- Account data from Google or Steam: provider account identifier, display name and avatar. We assign an internal account ID and store account dates, currency, balance and status. Authentication takes place on the provider website; ONESTAND does not receive your password.
- Service activity: saved case names and settings, case openings and their results, acquired and sold items, balance movements, payment amounts, methods, currencies, references and statuses. Payment and delivery providers return information about the progress and result of your transactions.
- Withdrawal information: your Standoff 2 player ID, assigned ONESTAND avatar and confirmation that it is installed in the game, selected skin and its pattern when applicable, listing prices, request statuses and operator notes needed to identify and process your withdrawal.
- Technical data: IP address, session identifiers, request times, browser and device information transmitted with requests, and service or error logs. When you contact us, we receive your correspondence, contact details and any supporting information you choose to provide.
You can browse public pages without signing in. A Google or Steam identity is needed for an account; payment information is needed for a RUB top-up; your Standoff 2 player profile and listing details are needed for a withdrawal. Card details are entered on the payment provider checkout.
3. Purposes and legal grounds
The legal grounds and your rights depend on the law applicable to your data. References to the GDPR below apply where that regulation governs the processing.
- Providing the service and taking steps you request before a transaction (GDPR Article 6(1)(b)): authenticate your Google or Steam account, maintain your balance and history, process openings and sales, arrange payments and delivery, and resolve service enquiries.
- Legitimate interests (Article 6(1)(f)): use account, transaction and technical data to protect accounts, prevent fraud and abuse, investigate errors and defend legal claims. Our interest is a secure and reliable service. The public activity feed described below serves our interest in showing recent service activity. These interests must be balanced against your rights; you may object.
- Legal obligations (Article 6(1)(c)): retain records required by applicable accounting or tax rules, respond to binding lawful requests and handle data protection requests. This ground applies only where a legal obligation requires the processing.
Where an optional purpose requires consent, it must be requested separately and may be withdrawn. Reading this policy, signing in or accepting the user agreement does not itself grant consent to advertising or unrelated processing. Withdrawing consent does not affect earlier lawful processing or processing based on another legal ground.
4. Public activity
The live drop feed is visible to other visitors. It can show your account display name and avatar together with the item received and its displayed value. Signed-in players can also view your ONESTAND profile: account ID, Steam ID when available, registration date and prizes. Saved case names and settings can be viewed by other visitors. This information can be copied by others. Your balance, payment history and Standoff 2 withdrawal profile are not displayed in the public feed. To object to publication of your personal data, contact support using section 1.
5. Who receives data
- Google and Steam / Valve: authentication, profile information and account images. Each provider handles your use of its platform under its own privacy policy.
- GAMEMONEY and the payment method provider you select: payment processing and status confirmation. Payment requests include your IP address, account or payment recipient identifier, invoice reference, amount, currency and selected method. The checkout provider handles the payment details you enter there under its own terms.
- Standoff 2 marketplace and the operators processing withdrawals: your player identifier, avatar, listing details and purchase status are used to identify and purchase the correct listing.
- Jivo: customer support chat. When chat is enabled and you are signed in, its widget can load when you hover over or focus the Support button, or open the chat. This sends your IP address and browser request information to Jivo. If you use the chat, Jivo receives the messages and details you submit to support.
- Hosting, network protection and content delivery providers, including Cloudflare where traffic passes through it, process technical request data to deliver and protect the site. Loading external avatar and item images also sends your IP address and request information to the image host. Authorised personnel and service providers may access data for their assigned tasks; advisers and competent authorities may receive it when needed for legal obligations or claims.
6. International processing
Authentication, payment and infrastructure providers may process data outside your country, including outside the European Economic Area. A transfer subject to GDPR must have a lawful transfer mechanism, such as an applicable adequacy decision or appropriate safeguards, including standard contractual clauses where required. You may request information about the countries, recipients and safeguards relevant to your data, and a copy of applicable safeguards, through the Support section linked in section 1.
7. Cookies and browser storage
- The first-party session cookie keeps you signed in. It has a lifetime of up to 7 days and is removed when you successfully sign out. Blocking it prevents authenticated features from working.
- Temporary sign-in cookies protect the Google or Steam sign-in flow. They expire within 10 minutes.
- The visitor cookie stores a random identifier for up to 365 days so the online visitor counter can recognise the same browser across requests. It is not used for advertising. You can remove it in your browser settings.
- Temporary session storage remembers the language and return page for Google or Steam sign-in. The return marker is consumed on re-entry, is accepted only within 15 minutes and is also cleared when the browser ends the tab session.
- Local storage keeps your sound settings, animation speed and keyboard shortcut preference in this browser until you change them or clear site data. Case settings are included in the page URL; saved cases are stored with your account on the server. The browser may also cache application files, fonts and images. Clearing site data removes local settings and cached files; it does not delete your account, saved cases or transaction history on the server.
You can manage cookies and site storage in your browser settings. ONESTAND does not currently include advertising trackers or optional audience analytics. If optional tracking is introduced, information and any legally required choice must be provided before it starts. External payment and authentication pages have their own storage practices.
8. How long data is kept
Account and trade details are kept while needed to maintain your account and fulfil your requested operations. Payment, balance, opening and delivery records may need to be kept after account closure until outstanding operations and disputes are resolved and the applicable accounting, tax and legal-claim retention requirements expire. The relevant record and obligation determine the period; closing an account does not necessarily require immediate erasure of every transaction.
Correspondence is kept for handling the request and any related claim. Technical and security logs are kept for diagnosing incidents, preventing abuse and investigating disputes; relevant records may be retained while an investigation or claim remains open. Backup retention must follow recovery needs and applicable deletion obligations. Data without a continuing lawful purpose must be deleted or anonymised. You may ask for the retention criteria or period applicable to your records.
9. Your rights and requests
Subject to the conditions of applicable law, you may request access and a copy of your personal data, correction, erasure, restriction of processing and portability of data processed automatically under consent or a contract. You may object to processing based on legitimate interests, including the public feed, and withdraw consent for any processing that relies on it. Erasure may be limited where records are legally required or needed for legal claims.
Use the Support section linked in section 1. We may request proportionate information to verify account ownership. Where GDPR applies, requests are normally free and must receive a response without undue delay, within one month. Where permitted, complex or numerous requests may require up to two additional months; the reason and extension must be communicated within the first month. A refusal must explain the reason and available complaint routes.
You may complain to the data protection authority competent under applicable law. Where GDPR applies, this includes the authority in the EU/EEA country of your habitual residence, place of work or alleged infringement. Contacting us first is not a condition for making a complaint.
10. Automated processing
The service automatically checks balance, transaction and delivery conditions and determines case results from the available item pool and its probabilities. These operations affect your balance and inventory. If you dispute an automated outcome or restriction, you may request an explanation and human review, state your position and contest the result using section 1. This does not guarantee reversal of a correctly completed transaction or limit rights provided by applicable law, including GDPR Article 22 where applicable.
11. Security and age restrictions
Protecting data requires technical and organisational measures proportionate to the risks, including protected connections, restricted access and session protection. No online service can guarantee absolute security. Protect your Google or Steam account and never share your session credentials. If a personal data breach requires notification, the controller must inform the competent authority and affected individuals as required by law.
Paid features are intended only for users aged 18 or over, as stated in the user agreement. If you believe a child has provided personal data in connection with these features, contact the controller so the circumstances, access restriction and any required deletion can be reviewed.
12. Changes to this policy
The revision date is shown at the top of this page. Changes must reflect how the service actually processes data. Material changes must be brought to your attention before the new processing starts, and fresh consent must be requested where required. A policy update does not remove your rights or retroactively authorise a new use of your data.
User agreement