Privacy Policy
Last updated: December 9, 2024
Your privacy is important to us. This Privacy Policy explains how Kurast Trade ("we," "us," or "our") collects, uses, discloses, and protects your information when you use our platform.
GDPR Compliance: This policy is designed to comply with the General Data Protection Regulation (GDPR) and other applicable data protection laws.
Quick Overview
Minimal Data
We only collect what's necessary for the service
Secure Storage
Your data is protected with industry-standard security
Your Control
Delete your account and data at any time
1. Information We Collect
1.1 Information You Provide
When you use our platform, you may provide:
| Data Type | Details | Purpose |
|---|---|---|
| Account Information | Battle.net ID, BattleTag (via OAuth) | Account creation and identification |
| Profile Preferences | Preferred class, realm, game mode settings | Personalized experience |
| Listings | Item descriptions, prices, images | Trading marketplace functionality |
| Chat Messages | Messages exchanged with other users | Facilitate trade negotiations |
1.2 Information Collected Automatically
When you access our platform, we automatically collect:
| Data Type | Details | Purpose |
|---|---|---|
| Device Information | Browser type, operating system, device type | Optimize platform performance |
| Usage Data | Pages viewed, features used, time spent | Improve user experience |
| IP Address | Your internet protocol address | Security and rate limiting |
1.3 Information from Third Parties
We receive limited information from Blizzard when you authenticate:
- Battle.net Account ID — Unique identifier for your Blizzard account
- BattleTag — Your public Blizzard username (e.g., Player#1234)
We do not receive your email address, real name, or any game data from Blizzard.
2. How We Use Your Information
We use the information we collect for the following purposes:
2.1 Provide and Maintain Service
- Enable account creation and authentication
- Display and manage your item listings
- Facilitate chat and trade communications
- Show seller online status and activity
2.2 Improve and Personalize
- Analyze usage patterns to improve features
- Remember your preferences (class, realm, filters)
- Provide relevant build and item recommendations
2.3 Safety and Security
- Prevent fraud, scams, and abuse
- Enforce our Terms of Service
- Apply rate limiting to prevent spam
- Investigate and respond to violations
2.4 Communications
- Send important service notifications
- Respond to your support requests
We do not send marketing emails as we do not collect email addresses.
3. Legal Basis for Processing (GDPR)
Under GDPR, we process your data based on the following legal grounds:
Contractual Necessity
Processing necessary to provide the trading platform service you requested when creating an account.
Legitimate Interests
Processing for fraud prevention, security, and improving our services, balanced against your rights.
Consent
For optional analytics and non-essential cookies (where applicable), based on your explicit consent.
Legal Obligations
Processing required to comply with applicable laws and regulations.
5. Data Security
We implement industry-standard security measures to protect your information:
- Encryption — All data transmitted over HTTPS/TLS encryption
- Secure Infrastructure — Data stored on Convex's secure, managed infrastructure
- OAuth Authentication — We never store your Battle.net password
- Access Controls — Limited access to user data on a need-to-know basis
- Rate Limiting — Protection against automated attacks
While we strive to protect your data, no method of transmission over the internet is 100% secure. We encourage you to use strong passwords and protect your Battle.net account.
6. Data Retention
We retain your data for as long as necessary to provide our services:
| Data Type | Details | Purpose |
|---|---|---|
| Account Data | BattleTag, preferences | Until you delete your account |
| Listings | Active items for trade | Until sold/removed or account deleted |
| Chat Messages | Trade conversations | Until account deleted |
| Analytics Data | Aggregated usage statistics | Up to 26 months (anonymized) |
When you delete your account, we permanently delete all associated data within 30 days, except where retention is required by law.
7. Your Rights
Under GDPR and similar laws, you have the following rights:
Right to Access
Request a copy of your personal data
Right to Rectification
Correct inaccurate or incomplete data
Right to Erasure
Delete your data ('right to be forgotten')
Right to Portability
Receive your data in a portable format
Right to Restrict
Limit how we process your data
Right to Object
Object to certain processing activities
How to Exercise Your Rights
- Delete Account: Go to Profile → Danger Zone → Delete Account
- Access Data: Contact us at privacy@kurast.trade
- Other Requests: Email us with your BattleTag for verification
We will respond to all valid requests within 30 days.
8. International Data Transfers
Our service providers may process data in various locations. When transferring data outside the European Economic Area (EEA), we ensure appropriate safeguards:
- Standard Contractual Clauses (SCCs) approved by the EU Commission
- Data processing agreements with all sub-processors
- Selection of providers with adequate security certifications
9. Children's Privacy
Our platform is not intended for children under 13 years of age. We do not knowingly collect personal information from children under 13.
If you believe a child has provided us with personal information, please contact us immediately. We will promptly delete such information from our systems.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes by:
- Updating the "Last Updated" date at the top of this policy
- Displaying a prominent notice on our platform
We encourage you to review this policy periodically. Your continued use of our platform after changes constitutes acceptance of the updated policy.
11. Contact Us
If you have questions about this Privacy Policy or wish to exercise your rights, please contact us:
Kurast Trade Privacy
- Email: privacy@kurast.trade
- For GDPR requests: gdpr@kurast.trade
EU residents may also lodge a complaint with your local Data Protection Authority if you believe your rights have been violated.
