PRIVACY POLICY
Last Updated Date: 19th of June 2026
- Data Controller
- GPP CROWN LTD
- Registration number
- 17246978
- Address
- 77 Smiths Square, London, England, W6 8AF
- Phone
- +44 7886 077869
- Website
- reliqskins.com
This Privacy Policy serves as an official disclosure outlining the modalities by which your personal data is processed, managed, and shared during your interaction with the Website, the acquisition of Virtual Cosmetic Items, or any other manual transmission of information via our platform. Additionally, this policy delineates material legal disclosures regarding your fundamental privacy entitlements. If you act as a representative submitting personal data on behalf of another individual, you are legally required to notify the data subject of these processing practices and provide them with a copy of this disclosure.
1. WHAT KIND OF PERSONAL DATA IS COLLECTED
Account Registration and Administration
For the purpose of account creation, customers must supply their first name, last name, phone number, personal email address, and a unique password. These data sets are processed to facilitate account deployment, manage user profiles, and enforce security protocols. We reserve the right to employ technical surveillance methods to audit a customer's location for compliance and risk management purposes. In the event that these checks uncover data anomalies or reveal access from blocked or restricted countries, we may refuse account creation or veto the execution of orders. Legal Basis: Performance of a Contract.
Identify Validation and Regulatory Compliance
To ensure accuracy and authenticity of customer records, we may mandate the submission of validating materials, such as national ID documents, transactional receipts, authorization of representation, or secondary contact details. The Customer must furnish these documents or high-resolution copies within a strict deadline of five (5) business days. Non-compliance with this verification window empowers the Company to reject the registration request or terminate the purchase of Virtual Cosmetic Items, with any collected funds being returned to the source. Legal Basis: Legal Obligation and Legitimate Interest.
Data Analytics and Operational Usage Data
We record structural metrics regarding how our platform is accessed and navigated, classified as Usage Data. This data package may comprise your IP address, browser configuration characteristics, specific URLs accessed, timestamps of your visit, session durations, and proprietary device identification signatures. We leverage this telemetry to reliably deploy and upgrade our service portfolio, compile macro-level statistical analytics, and monitor network traffic for illicit or unapproved activities. Legal Basis: Legitimate Interest (improving our services and ensuring security).
Promotional Communications and Commercial Outreach
Upon receiving your affirmative consent, we will distribute newsletters, marketing campaigns, and promotional materials relative to our platform services. To optimize these communications, we may gather marketing-associated information, such as your designated communication channels, recorded preferences, data regarding your engagement with our advertisements, and user-item interest metrics. Legal Basis: Consent (can be revoked at any time).
2. COOKIES MANAGEMENT AND TRACKING
We can store cookies on your device automatically if they are strictly necessary for the operation of the Website. For all other types of cookies, we need your explicit permission.
You have the right to choose whether or not to accept non-essential cookies. You can change or withdraw your consent at any time in the Cookie Settings. We only use data for its intended purpose unless we notify you of a new, unrelated purpose with a valid legal basis. We may process data without your knowledge or consent if legally required or permitted.
We may use the following cookies categories and tracking methods:
Necessary
Necessary cookies help make a website usable by enabling basic functions like page navigation and access to secure areas of the website. The website cannot function properly without these cookies.
Marketing
Marketing cookies are used to track visitors across websites. The intention is to display ads that are relevant and engaging for the individual user and thereby more valuable for publishers and third party advertisers.
Preferences
Preference cookies enable a website to remember information that changes the way the website behaves or looks, like your preferred language or the region that you are in.
Statistics
Statistic cookies help website owners to understand how visitors interact with websites by collecting and reporting information anonymously.
Lifespan: Session cookies expire when the browser is closed. Persistent cookies remain stored on the device for a pre-defined period or until you manually delete them.
Third-Party Cookies
Cookies managed by verified third-party providers, which are established by network domains outside of our direct digital control. These third-party tracking mechanisms are deployed primarily to advance our analytical and advertising endeavors. Specifically, third-party analytical entities provide processing services that illustrate user engagement trends to support platform optimization, while third-party advertising cookies are leveraged to serve tailored commercial content to users on external platforms. The user acknowledges that we do not govern the mechanical deployment of these external tracking tools, and their operation is regulated entirely by the respective privacy statements of the originating third parties.
Pixel Tags and Web Beacons
Tiny graphics files with unique identifiers that enable us to recognize when someone has visited our Website or opened an email we sent them.
Local Storage
HTML5 Local Storage mechanisms to write and preserve operational data structures directly within your browser’s local caching infrastructure. This technical storage is executed solely to optimize platform efficiency, enhance system processing speeds, and retain user-defined configuration preferences across sessions.
3. DATA RETENTION PERIODS
Personal data is stored strictly for as long as necessary to fulfill the purposes outlined in this Policy and in accordance with the UK GDPR, EU GDPR and other relevant laws.
Communication data
Stored for up to two (2) years to improve service quality, assist with potential legal issues and dispute resolutions.
Analytics data
Stored for up to twelve (12) months to monitor website performance, security patterns and traffic metrics.
Other personal data
Stored for the duration of the customer’s account existence plus three (3) years.
Data may be kept longer if necessary to protect legitimate interests, handle legal disputes, or fulfill legal obligations.
4. DATA DISCLOSURE, INTERNATIONAL TRANSFERS AND ALGORITHMIC PROCESSING
Engagement of Data Processors
We are authorized to share personal information with external data processors, including cloud hosting providers, compliance and identity verification services, and professional consultants (such as auditors and legal representatives). We retain full responsibility and care for the security of your data during these processor engagements.
Independent Third-Party Processing
Where a user voluntarily provides personal data directly to a third party, that entity assumes the status of an independent data controller. We accept no legal liability or obligation for data processing conducted under the privacy frameworks of those separate entities.
Merchant and Payment Gateway Operations
All credit and payment card transactions are executed directly through PCI-DSS compliant payment processors. We do not collect or store full payment card details.
Direct Marketing Opt-In
Users who affirmatively consent via the platform will be registered to receive weekly newsletters and contextual advertisements. The option to unsubscribe is permanently available via a dedicated link located in the footer of each email transmission.
Transborder Data Flows
The Data Controller reserves the right to transfer personal data across borders to its corporate subsidiaries, affiliates, partner entities, or external third parties for the purposes defined herein. Personal data originating within the European Economic Area (“EEA”) may be exported to non-EEA nations. Such transfers are structurally safeguarded via European Commission-approved Standard Contractual Clauses, other valid legal mechanisms recognized under European Union law (such as binding corporate rules), or via the explicit consent of the data subject.
Statistical Compilation
We anonymize and aggregate collected data to identify macro-level user trends and improve operational performance. This non-personally identifiable information may be shared, distributed, or commercialized without restriction.
Automated Determinations and AI Systems
Automated Decision-Making (“ADM”), which includes automated profiling generating legal effects or significant individual impact, will not be enforced unless supported by one of the following legal bases: (a) your unambiguous consent, (b) direct statutory authorization, or (c) necessity for entering into or executing a binding contract. ADM systems are deployed on this platform to deliver service recommendations, apply operational restrictions when prohibited conduct is identified, and mitigate chargeback risks. Under your authorization, artificial intelligence chatbots may perform customer care services, and AI technologies may generate text suggestions or translations through trusted partner networks. All such data processing is confined strictly to the performance of these services, and users maintain the right to bypass automated systems and request human review by contacting customer support.
Cross-Device Synchronization
With your consent, we cooperate with third-party service providers to track and aggregate user behavior across multiple devices using statistical modeling techniques. This synchronization supports platform security, campaign performance tracking, and customized marketing delivery.
Asset Transfers and Legal Mandates
In the event of a corporate merger, acquisition, insolvency, or winding-up of the business, personal data may be transferred as part of the company's assets. Furthermore, we reserve the right to disclose personal records to satisfy legal obligations, enforce current terms of service, defend our legal interests, protect user safety, or mitigate fraud.
5. DATA PRIVACY RIGHTS
For data subjects residing within the European Union or the United Kingdom whose personal data is collected, stored, and processed, specific statutory entitlements are guaranteed under the GDPR, UK GDPR, and the Data Protection Act 2018.
Right of Access and Confirmation
You maintain the right to obtain official confirmation as to whether or not your personal information is undergoing processing operations by the Company. Where such processing is verified, you are entitled to access your personal data along with disclosures regarding: the explicit purposes of the processing; the categories of personal data concerned; the recipients or categories of recipients to whom the personal information has been or will be disclosed; and the envisaged retention period or the criteria utilized to establish said duration.
Conditions for Data Provision
The Company shall furnish a copy of your processed personal records strictly conditional upon: the successful verification and proof of your identity, and the assurance that provisioning such data will not adversely affect the rights and freedoms of third parties.
Right to Erasure
You possess the right to demand the erasure of your personal records, and the Company shall execute such deletion without undue delay where one of the following criteria is satisfied: the personal information is no longer requisite for the purposes for which it was originally collected; you formally withdraw consent upon which the processing was uniquely predicated and no alternative legal framework exists; you object to the processing activities and there are no overriding legitimate grounds to sustain them; the personal data has been unlawfully processed; or the erasure is mandated to ensure compliance with a statutory legal obligation.
Right to Data Portability
You are entitled to receive the personal data you have provisioned to us in a structured, commonly utilized, and machine-readable format, and you maintain the right to transmit said data to an alternative corporate entity without hindrance, provided that: the processing relies explicitly on your consent or contractual necessity; and the processing operations are executed via automated methodologies.
Revocation of Consent
You retain the absolute right to withdraw your consent regarding the processing of your personal data at any given time. The invocation of this withdrawal shall not invalidate or affect the lawfulness of any data processing executed based upon consent prior to its formal revocation.
Right to Submit a Complaint
You maintain the statutory right to file a formal complaint with a competent supervisory authority, particularly within the EU Member State of your habitual residence, place of work, or the jurisdiction of the alleged statutory infraction, if you determine that our data processing violates the GDPR. For residents of the United Kingdom, such appeals must be directed to the Information Commissioner’s Office (ICO).
To invoke any of the aforementioned legal rights, you must submit a formal petition to our customer support division via the corporate electronic mail address specified at the header of this document.
6. DATA SECURITY MEASURES AND RISK DISCLAIMERS
Encryption and Software Maintenance
The Platform leverages 256-bit SSL encryption mechanisms to protect Customer data transfers, supplemented by the systematic deployment of modern software patches and defensive configurations to address emerging security vulnerabilities.
Server Protection and Physical Security
Automated diagnostic scans are executed on our server environment on a daily basis to guard against unapproved access and malicious exploits. Additionally, the underlying hardware is positioned inside a physically fortified facility to deny unauthorized entry.
Security Limitation Disclaimers
Although we actively enforce appropriate administrative and technical controls to protect your personal information, the User recognizes that electronic data transmissions over the internet are never fully secure. No server can be definitively guaranteed against unauthorized penetration or data interception; therefore, while the Company takes comprehensive protective steps, it cannot offer an absolute warranty of complete data safety.
7. POLICY MODIFICATIONS AND UPDATES
The Company (acting as the Service Provider) explicitly reserves the right to amend, alter, or update this Privacy Policy at any given time. Any such modifications shall become legally binding and effective immediately upon their publication on this webpage. The "Last Updated Date" timestamp featured at the apex of this document shall serve as the official indicator of the most recent revision. In the event of material alterations that substantially impact your consumer rights, the Company will employ reasonable commercial efforts to provide notice, including but not limited to electronic mail correspondence or a prominent notification broadcasted across our Website.
Your subsequent or continued engagement with the Website or associated Services following the publication of any modifications establishes your definitive and binding acceptance of the revised Privacy Policy. Consequently, we strongly advise you to review this document periodically to maintain awareness of our current terms.