# The cost of proving yourself.

Canonical: https://phishdestroy.io/steam_dossier/aml-data
Language: en
Author: Agent Clara
Publisher: PhishDestroy
Published: 11 October 2026

MONEY, IDENTITY & CONTROL / UPDATED 11 OCTOBER 2026

How a skin-gambling service can demand identity and financial records before releasing access to the user’s balance.

CSGORoll asks for identity papers, financial histories and, in some cases, a relative’s documents. Its policy places those records in the hands of its own trained team — and ties refusal to withdrawal delays and account suspension. We follow that claim through the company records, security promises and privacy notices.

[Read their promise ↓](https://phishdestroy.io/steam_dossier/aml-data#promise)  [See the full document scope](https://phishdestroy.io/steam_dossier/aml-data#documents)

WHAT LEAVES THE USER’S CONTROL

01 / IDENTITY **Passport. Face. Home address.**  02 / FINANCIAL HISTORY

Bank accounts · Exchange records Property sales · Inheritance

03 / OTHER PEOPLE **A donor’s identity and source of funds.**

[CSGORoll AML policy · K01 ↗](https://phishdestroy.io/steam_dossier/aml-data#K01)

TRANSPARENCY DEMANDED IN ONE DIRECTION

**The user must expose their identity and finances. The operator offers assurances while retaining the power to withhold access.**  Its authority, recipients, safeguards and retention rules must withstand the same scrutiny it demands of the user. The policies examined here do not earn that trust.

[01 / VALUE **What is withdrawn?**](https://phishdestroy.io/steam_dossier/aml-data#coins-and-withdrawals)  [02 / EMPIRE **Conflicting KYC rules**](https://phishdestroy.io/steam_dossier/aml-data#empire)  [03 / PAYPAL & CODES **Follow the recipient**](https://phishdestroy.io/steam_dossier/aml-data#gift-code-route)  [04 / CUSTODY **Who controls the wallet?**](https://phishdestroy.io/steam_dossier/aml-data#wallet-custody)

THE OPERATOR’S CLAIM / THE RECORD BESIDE IT

## The “not gambling” claim and the demand for a financial dossier

The loss of control extends beyond the skin. Once value has entered an outside service, that operator can impose conditions on its release. CSGOFast distances itself from gambling and real-world monetary value; CSGORoll uses internal units with different redemption rules. Their verification policies nevertheless examine the user’s real identity, payment accounts and sources of wealth.

CSGOFAST / RESPONSIBLE PLAY POLICY §8.1

> “The Site does not present itself as a gambling platform.”

[Read the operator’s wording ↗](https://csgofast.com/responsible-play-policy)

THE RECORD BESIDE THAT CLAIM

### Paid funding, AML demands and a gambling-enforcement history

Fast’s own FAQ describes skin deposits, gift codes and cryptocurrency funding. Its AML policy requests identity and financial evidence. In April 2025, the Dutch regulator ordered Gamusoft LP to stop unlawful gambling offered through csgofast.com; its published record states that the order became final and violations continued.

[Funding instructions ↗](https://csgofast.com/faq)  [AML policy ↗](https://csgofast.com/aml-policy)  [Dutch enforcement record ↗](https://kansspelautoriteit.nl/gamusoft-lp)

The monetary-value disclaimer does not describe the whole transaction. The customer pays for a code, transfers cryptocurrency or supplies a skin; the service records a balance and controls its use. Roll’s current terms distinguish ordinary Coins from eligible Roll Chips that can be redeemed in cryptocurrency. These are restrictions on particular units and claims, rather than an absence of payment or economic value.  [Payment routes and redemption terms ↗](https://phishdestroy.io/steam_dossier/money-and-enforcement.html#payments)

Roll’s AML policy shows how far the operator’s authority over that balance can reach. It allows requests for identity documents and selfies, bank and exchange records, property-sale contracts, wills and a relative’s identity and source of funds. The same policy links missing documents to delayed withdrawals or account suspension. The user is being asked to surrender a personal file whose documented scope runs to fourteen request groups — including a deceased person’s will and a relative’s identity and source of funds — while the operator controls access to the value already inside its system.  [CSGORoll’s document demands and withdrawal conditions ↗](https://www.csgoroll.com/info/aml-policy/)

VALUE ALREADY COMMITTED **Skin, payment or redeemed code**

The operator records credit on its own ledger.

ADDITIONAL EVIDENCE DEMANDED **Identity and financial history**

The request can extend to relatives and counterparties.

RELEASE CONTROLLED **Withdrawal or account access**

The operator can delay or suspend access during verification.

### The published explanation fails the scrutiny demanded of the user

Roll assigns handling to its own trained team and promises high security standards, but its AML notice supplies no named standard or clear account of who can copy or export the original files. Its separate privacy notice allows sharing with vendors and affiliates without mapping those routes to the KYC records. That notice, revised in August 2026, still names the EU–US Privacy Shield, whose adequacy decision was invalidated in 2020. These are identifiable defects in the assurance offered to the person uploading a passport.  [Read the policies beside the legal record ↗](https://phishdestroy.io/steam_dossier/aml-data#record)

Fast’s disclosures create a different set of problems. Its AML and privacy pages display a 2024 update date while naming an Estonian company registered in September 2026. The AML wording pairs that company with UK law and includes unusual attention to the AML policy among suspicion indicators. The operator demands an explanation of the user’s finances while leaving its own identity, version history and asserted legal basis inadequately explained.  [Named companies and registry records ↗](https://phishdestroy.io/steam_dossier/aml-data#operators)   [The legal-basis discrepancy ↗](https://phishdestroy.io/steam_dossier/aml-data#finding-law)

This is the same dependence revealed by the ownership comparison, extended to another service. The consumer cannot complete the promised exchange solely by owning or sending the skin. They must satisfy a platform that controls the ledger, interprets the rules and can demand further evidence before releasing access.

[ID THE COMPLETE IDENTITY INVESTIGATION ### All fourteen document groups, the entities and the policy defects Read the source records, withdrawal conditions, data-handling claims and applicable legal tests. ↗](https://phishdestroy.io/steam_dossier/aml-data#documents)

[Coins & exits](https://phishdestroy.io/steam_dossier/aml-data#coins-and-withdrawals)  [Empire](https://phishdestroy.io/steam_dossier/aml-data#empire)  [PayPal & codes](https://phishdestroy.io/steam_dossier/aml-data#gift-code-route)  [Wallet custody](https://phishdestroy.io/steam_dossier/aml-data#wallet-custody)  [Claim & record](https://phishdestroy.io/steam_dossier/aml-data#aml-contradiction)  [01 Promise](https://phishdestroy.io/steam_dossier/aml-data#promise)  [02 Refusal](https://phishdestroy.io/steam_dossier/aml-data#leverage)  [03 Documents](https://phishdestroy.io/steam_dossier/aml-data#documents)  [04 Operators](https://phishdestroy.io/steam_dossier/aml-data#operators)  [05 Findings](https://phishdestroy.io/steam_dossier/aml-data#record)  [06 Authority](https://phishdestroy.io/steam_dossier/aml-data#authority)  [07 Questions](https://phishdestroy.io/steam_dossier/aml-data#questions)

PAYMENT FILE / THE UNIT AND THE EXIT

## They price the entry. They police the exit.

A purchased balance, a gambling stake and the asset delivered on withdrawal are different things. The question is concrete: what did the customer surrender, what did the service credit, and what can the customer actually recover?

Three operators. Three sets of published rules. Reviewed 11 October 2026.

| Operator / unit | Value entering | What leaves | Identity gate |
| --- | --- | --- | --- |
| CSGORoll Coins / eligible Roll Chips | Paid Coin top-ups; skin, card, bank, crypto and gift-card routes are documented. [K11](https://phishdestroy.io/steam_dossier/aml-data#K11) | The FAQ links Coins to CS2 skins and Chips to crypto, and rules out converting Coins into Chips. The terms restrict ordinary Coins’ cash redemption. [K10](https://phishdestroy.io/steam_dossier/aml-data#K10) [K02](https://phishdestroy.io/steam_dossier/aml-data#K02) | The FAQ describes a KYC lock after 2,000 Coins in top-ups, plus restrictions on rewards and games. This is broader than a final cash-out check. [K10](https://phishdestroy.io/steam_dossier/aml-data#K10) |
| CSGOFast Credits / Fast Coins | Skins, partner gift codes, crypto and card-mediated routes. The gift-code purchase happens on a partner’s site. [K43](https://phishdestroy.io/steam_dossier/aml-data#K43) | The reviewed withdrawal guide describes a skin delivered by another Steam user. Its policy nevertheless denies real-world monetary value to Credits and digital items. [K44](https://phishdestroy.io/steam_dossier/aml-data#K44) [K07](https://phishdestroy.io/steam_dossier/aml-data#K07) | The AML notice makes requested data mandatory and connects refusal to delays or ineligibility. It does not supply one universal numerical withdrawal threshold. [K05](https://phishdestroy.io/steam_dossier/aml-data#K05) |
| CSGOEmpire Empire Coins | Its terms cover skins, supported crypto and fiat. Its own deposit page directs gift-card buyers to Kinguin. [K36](https://phishdestroy.io/steam_dossier/aml-data#K36) [K41](https://phishdestroy.io/steam_dossier/aml-data#K41) | Published routes include skins and crypto. Its help distinguishes skin deposits, which need no wagering for crypto withdrawal, from cash/crypto deposits, where full-deposit wagering is required; skins remain an alternative. [K50](https://phishdestroy.io/steam_dossier/aml-data#K50) | Current terms and older help describe different 4,500-Coin triggers. Both allow earlier checks. [K36](https://phishdestroy.io/steam_dossier/aml-data#K36) [K37](https://phishdestroy.io/steam_dossier/aml-data#K37) [Compare the documents ↓](https://phishdestroy.io/steam_dossier/aml-data#empire) |

THE ECONOMIC QUESTION

**A “no monetary value” clause does not erase the payment that bought access.**  The accountability problem is paid entry, restricted redemption and the operator’s power to demand more evidence while value remains inside the service. The withdrawal asset and contractual promise must be named precisely.

Coins, Credits and Chips are operator-controlled balance units. The Steam WebAPI token examined in the  [trade-tracking audit](https://phishdestroy.io/steam_dossier/trade-tracking.html)  is an access credential. Empire explicitly describes gambling; the “not gambling” disclaimers examined here belong to Fast and Roll.

CSGOEMPIRE / MONEY, IDENTITY & CONTROL

## One balance. Conflicting instructions.

Empire’s rules connect a Steam inventory, an internal balance, cryptocurrency withdrawals and a third-party identity file. The public instructions leave important differences in when verification starts and what happens if the user cannot complete it.

OPERATOR

### Moonrail Limited B.V.

Curaçao · company 148182

POSSIBLE PAYMENT HANDLER

### JHOLT Ltd

Cyprus · HE393291 Named as acting on Moonrail’s behalf.  [K41](https://phishdestroy.io/steam_dossier/aml-data#K41)

NAMED VERIFICATION RECIPIENT

### Checkin.com

Named in the privacy notice dated 12 February 2025.  [K40](https://phishdestroy.io/steam_dossier/aml-data#K40)

SAME NUMBER **4,500**  EMPIRE COINS DIFFERENT ACTIVITY COUNTED

13 FEBRUARY 2025 / KYC HELP

### Cumulative crypto withdrawals

The help article describes this as the usual trigger, with possible earlier checks. It requests live identity evidence and recent address evidence and names Checkin.  [K37](https://phishdestroy.io/steam_dossier/aml-data#K37)

6 OCTOBER 2026 / TERMS §11

### Cumulative deposits and withdrawals

The terms require verification no later than this combined threshold, allow earlier checks and permit withholding or delaying the affected transaction.  [K36](https://phishdestroy.io/steam_dossier/aml-data#K36)

**The scope of the trigger has changed, but both explanations remain public.**  A customer reading the older help cannot determine the current trigger from that page. Empire should reconcile the guidance, identify the version accepted by the customer and show the transaction calculation behind a hold.

### Refuse verification: withdraw, or remain blocked?

The main FAQ says a person who fails or refuses KYC must withdraw the remaining balance and stop using the service. The newer terms permit a hold until verification is complete. These instructions conflict: the FAQ promises a user who fails or refuses KYC withdrawal of the remaining balance and an exit from the service; the newer terms authorise holding that balance until verification is complete. Empire must state which rule governs a refused user’s funds and publish the calculation behind any hold.  [K39](https://phishdestroy.io/steam_dossier/aml-data#K39)   [K36](https://phishdestroy.io/steam_dossier/aml-data#K36)

### “Automated verification” still leaves a human and a backup.

The main FAQ names Checkin or Shuftipro, says documents also enter Empire’s own backups, and describes employee review when automated reading fails. The dedicated help names Checkin; the privacy notice names Checkin.com. The record therefore reaches beyond a yes/no verification badge. Who has the original, who can retrieve the backup, and what retention rule applies to each copy?  [K39](https://phishdestroy.io/steam_dossier/aml-data#K39)   [K37](https://phishdestroy.io/steam_dossier/aml-data#K37)   [K40](https://phishdestroy.io/steam_dossier/aml-data#K40)

Empire’s 2025 privacy notice also still cites the invalidated EU–US Privacy Shield among transfer safeguards. That is the same identifiable disclosure defect examined below for Roll. An operator collecting passports must identify the safeguard actually covering the transfer.  [K40](https://phishdestroy.io/steam_dossier/aml-data#K40)   [K20](https://phishdestroy.io/steam_dossier/aml-data#K20)

[READ THE CONNECTED EVIDENCE **Empire’s coin settlement, Steam-token collection and P2P trade controls** The identity hold acts on a balance controlled by the operator. ↗](https://phishdestroy.io/steam_dossier/trade-tracking.html)   [NEW / THE COLLECTED INVENTORY **186,127 priced listings. $19,283,716.61.** Empire, Roll and Fast: the supplied minimum-price valuation, full item explorer and original CSVs.](https://phishdestroy.io/steam_dossier/money-and-enforcement.html#market-snapshot)

PAYPAL → GIFT CODE → PLATFORM BALANCE

## The payment buys a code. The operator controls what follows.

This is a documented distribution route. Empire’s redemption page directs buyers to Kinguin. Fast’s help describes payment on a partner’s website followed by code redemption on Fast.  [K41](https://phishdestroy.io/steam_dossier/aml-data#K41)   [K43](https://phishdestroy.io/steam_dossier/aml-data#K43)

[LISTING 90693 **Empire · 100 Coins** Seller shown: CSGOEmpire.com](https://phishdestroy.io/steam_dossier/aml-data#K42)   [LISTING 377753 **Roll · 1 Coin** Seller shown: CSGORoll.com](https://phishdestroy.io/steam_dossier/aml-data#K12)   [LISTING 82747 **Fast · 10 Fast Coins** Seller shown: CSGOFAST](https://phishdestroy.io/steam_dossier/aml-data#K13)

These listings identify the seller by the operator’s brand and describe official supply. Kinguin lists PayPal among its methods, with availability dependent on country, currency and cart contents. No checkout was executed here. Empire’s listing excludes activation by US residents, among other territories.  [K42](https://phishdestroy.io/steam_dossier/aml-data#K42)   [K45](https://phishdestroy.io/steam_dossier/aml-data#K45)

### The seller, payment recipient and casino operator occupy different roles in the same purchase.

Kinguin’s September 2026 terms identify Kinguin Digital Limited in Hong Kong as the marketplace operator. Payment normally goes to that entity; an alternative recipient, Anton Capitals Limited in Malta, must be disclosed before authorisation and in the payment record. Kinguin generally separates its marketplace role from the seller’s contract. The seller answers for a usable key; complaints about the external service are directed to that service, subject to mandatory consumer rights.  [K46](https://phishdestroy.io/steam_dossier/aml-data#K46)

The receipt should name the legal seller and payment recipient. Connect those identities to the marketplace order, supplied code and credited gambling balance. This is the intermediary structure the investigation asks the participating businesses and payment providers to disclose.

FOLLOW THE RESPONSIBILITY

Select where the failure occurs.

01 / THE CODE PURCHASE

### Identify who was paid and what was sold.

The record is the product description, legal seller, order, receipt and delivery evidence. PayPal eligibility must be checked separately; a functioning checkout does not itself provide Purchase Protection.

**Connect:**  order ID · legal seller · payment recipient · funding method · delivery status

02 / THE CODE REDEMPTION

### Match the delivered code to the ledger entry.

Delivery of a valid code and crediting the intended account are separate events. The receiving operator should be able to explain whether redemption occurred, which account received value, and whether the promised amount appeared.

**Connect:**  redemption timestamp · receiving account · credited unit and amount · error or rejection

03 / THE WITHDRAWAL HOLD

### The code may work while access to value remains blocked.

A later KYC hold concerns the operator’s release decision. Proof that a code was delivered does not establish that this decision was justified. Obtain the accepted policy version, trigger calculation, requested evidence, review deadline and appeal route.

**Connect:**  balance history · payout asset · KYC request · hold decision · final recipient

Analytical map of the separate events and evidence required; no individual payment or dispute outcome is reconstructed here.  [K46](https://phishdestroy.io/steam_dossier/aml-data#K46)   [K14](https://phishdestroy.io/steam_dossier/aml-data#K14)   [K38](https://phishdestroy.io/steam_dossier/aml-data#K38)

### PayPal never settles with the casino: the gift code severs direct settlement with the operator’s legal entity.

Under US Purchase Protection, both gift/prepaid value and gambling or entry-fee-and-prize activities are excluded. The code route therefore sits outside those protections; the same policy also excludes the direct gambling transaction. Card-issuer chargeback rights may be broader — but any chargeback also runs against the marketplace’s payment recipient — Kinguin Digital Limited or Anton Capitals Limited — not against the operator, so it cannot restore the severed settlement.  [K14](https://phishdestroy.io/steam_dossier/aml-data#K14)  Unauthorised transactions have a separate regime; an authorised purchase followed by a payout dispute does not automatically fall into it.  [K47](https://phishdestroy.io/steam_dossier/aml-data#K47)

PayPal’s US acceptable-use rules require prior approval for relevant stored-value services, gambling facilitation and marketplaces. A voucher does not disclose the approval, merchant classification or settlement agreement. The enforcement question is whether the actual recipient and business activity were correctly disclosed and approved. A payment logo cannot answer it.  [K48](https://phishdestroy.io/steam_dossier/aml-data#K48)

THE IDENTIFIABLE EFFECT

The customer’s payment claim and the operator’s withdrawal decision become separated. The PayPal payment settles with Kinguin Digital Limited — or its disclosed alternative — and never with the casino’s legal entity: direct settlement is severed by design. The merchant and settlement records should show who received the money, who imposed the hold and who can return it.

CRYPTO / FOLLOW CONTROL, NOT THE ICON

## A deposit address does not identify its custodian.

There are three separate control questions: who credits the gambling balance, who can sign the blockchain transfer, and who holds the customer’s eventual payout. Calling all three a “wallet” conceals the distinctions that matter.

01 / INTERNAL BALANCE

### The operator controls the release.

Empire’s manual-review help ties crypto withdrawal to verification and account restrictions. This demonstrates platform-level control over release.  [K38](https://phishdestroy.io/steam_dossier/aml-data#K38)

**PUBLISHED CONTROL**

02 / DEPOSIT ADDRESS

### Custody remains to be attributed.

Fast describes an account-linked USDT deposit address. The investigation’s working attribution — likely not an exchange — stands until Fast and its payment partners name the private-key holder; Fast must disclose who controls the address.  [K43](https://phishdestroy.io/steam_dossier/aml-data#K43)

**ATTRIBUTION TASK · LIKELY NOT AN EXCHANGE**

03 / PAYOUT DESTINATION

### The user may hold an exchange account.

Empire’s July 2023 help explicitly describes withdrawal to the user’s exchange deposit address. Current terms require destination checks. An address associated with a user is not necessarily self-custodied.  [K49](https://phishdestroy.io/steam_dossier/aml-data#K49)   [K36](https://phishdestroy.io/steam_dossier/aml-data#K36)

**PUBLISHED DESTINATION OPTION**

The custody map starts with the deposit instruction and address, network, transaction identifier and credited ledger entry. It follows the processor or custodian to the payout and final recipient. Empire, Fast and their payment partners should identify which entity holds signing authority and customer funds at each step, and release the records that connect those responsibilities.

Empire’s current terms permit a payment provider to receive, hold and manage funds. Its default crypto withdrawal rule refers to the original wallet and asset, with verified alternatives. Neither clause names the custodian of a particular deposit address.  [K36](https://phishdestroy.io/steam_dossier/aml-data#K36)

VALVE & ENFORCEMENT

**A Steam account restriction answers only part of this chain.**  It does not, by itself, identify the voucher seller, payment collector, crypto custodian or recipient of the passport. An enforcement account must explain which of those relationships it reaches and what happens to the user’s deposited value. The skin owner, the gambling ledger and the payment business must be traced separately.

[Payment routes and enforcement counts ↗](https://phishdestroy.io/steam_dossier/money-and-enforcement.html#payments)  [Who controls settlement ↗](https://phishdestroy.io/steam_dossier/gambling-system.html#control)  [Continue to all 14 document groups ↓](https://phishdestroy.io/steam_dossier/aml-data#documents)

01 / THEIR OWN WORDS

## “Our specially trained team.”

The AML notice speaks in the operator’s own voice. It gives the document-handling role to its team. It does not identify Sumsub, Onfido or another external verification company as the party performing that role.  [K01](https://phishdestroy.io/steam_dossier/aml-data#K01)

> “only handled by our specially trained team, ensuring your privacy and safety at all times”
>
> CSGORoll · User Verification and Security  [Read the policy ↗](https://www.csgoroll.com/info/aml-policy/)

THE ASSURANCE

### Highest standards. Exclusive handling. Safety at all times.

These are expansive claims about the treatment of intensely personal records. The same section supplies no named security standard, certification scope, independent audit reference or document-retention schedule.

WHAT A READER CAN VERIFY

### The promise has no measurable specification.

The AML notice does not explain who can view, copy or export the files, or identify a specific security standard. The privacy notice separately allows sharing with vendors and affiliates without mapping those routes to the KYC documents.

Together, the notices promise safe handling without giving the user a clear account of who holds the originals and who can receive copies.

### A payment processor is a different part of the chain.

The privacy notice says a payment processor stores payment data. That sentence does not identify the custodian of passports, selfies, wills or source-of-funds evidence requested under the AML policy. The two data flows need their own explanation.  [K03](https://phishdestroy.io/steam_dossier/aml-data#K03)

02 / THE CONSEQUENCE OF REFUSAL

## A friendly phrase. A restriction on access.

CSGORoll’s policy softens the consequences with the language of reassurance and a temporary pause. The stated operational consequences are withdrawal delay and possible account suspension.  [K01](https://phishdestroy.io/steam_dossier/aml-data#K01)

VALUE ALREADY COMMITTED **A platform balance or pending withdrawal**

PLATFORM REQUIREMENT **Supply the requested documents**

The operator decides whether verification is complete.

DOCUMENTS SUPPLIED

### Verification proceeds

The user has disclosed identity and financial evidence. Release remains subject to the platform’s checks.

DOCUMENTS REFUSED

### Withdrawal delayed

The policy also allows the account to be paused until the issue is resolved.

This reconstructs the published policy’s mechanism. Checks may be requested at different stages; it is not a claim that every user first encounters verification at withdrawal.

THE FINDING

**The platform controls both the evidence demand and access to the balance.**  The user’s decision takes place inside that dependency. Calling a hold a pause does not explain the legal basis, the deadline for review, or the route for challenging an excessive request.

### Consent cannot be reduced to a forced choice.

Where consent is claimed, the ability to refuse without adverse pressure matters. Where a statutory duty is claimed, identify the law and the processing it requires. The EDPB treats these as different legal bases with different conditions.  [K18](https://phishdestroy.io/steam_dossier/aml-data#K18)

03 / THE SCOPE OF THE REQUEST

## From a passport to a family’s financial history.

The following inventory covers every document category in the CSGORoll policy supplied for this investigation and checked against the live page. Requests vary by activity; the policy says the list is open-ended and documents may need renewing.  [K01](https://phishdestroy.io/steam_dossier/aml-data#K01)

01 / THE PLAYER **Identity & address**

Passport, selfie, home, payment account

02 / THE FINANCIAL HISTORY **Where value came from**

Salary, trading, crypto, property

03 / OTHER PEOPLE **Family & counterparties**

Donor identity, wills, contracts

**14**  request groups  [What this reveals ↓](https://phishdestroy.io/steam_dossier/aml-data#data-risk)

**01 **Identity** Identity and face**

Passport photo pages; driver’s licence front and back; identity card front and back; a selfie with an identity document.

EXPOSURE TO EXAMINE A legal identity and face can be connected to the platform account.

**02 **Residential address** Home and banking**

A bank statement issued within the previous three months, with a card number covered if shown; or a recent utility bill, including gas, electricity, water or council tax. Birth certificates, payslips and mobile-phone bills are not accepted for this purpose.

EXPOSURE TO EXAMINE The home address can be linked to bank and household-service records.

**03 **Payment-method ownership** Cards and accounts**

For bank transfers: a statement showing the transaction. For Visa or Mastercard: photographs of the card’s front and back. For e-wallets: the account overview with personal and account details, plus evidence of at least one transaction with the site; the website URL must be visible.

EXPOSURE TO EXAMINE The account holder, payment instrument and transaction become part of the same verification file.

**04 **Salary** Income**

A recent bank statement showing salary received, together with the original payslip.

EXPOSURE TO EXAMINE Employer, pay and potentially unrelated transactions may be visible.

**05 **Gambling winnings** Other gambling activity**

A receipt or bank record for the winnings and a certificate confirming the win.

EXPOSURE TO EXAMINE Activity with another gambling provider can be connected to the person.

**06 **Crypto trading profit** Exchanges and brokers**

Screenshots of profitable transactions, withdrawal history, or the exchange / broker account showing the user’s details.

EXPOSURE TO EXAMINE An identified exchange account and its trading or withdrawal history.

**07 **ICO and token sales** Contracts and wallets**

A contract or agreement confirming crypto payment; the ICO’s full name and project website; purchase and withdrawal histories with wallet addresses and transaction IDs; a bank statement if fiat funded the investment; and purchase-confirmation emails.

EXPOSURE TO EXAMINE The investment, payment trail, addresses and contractual counterparties.

**08 **Mining** Equipment and operations**

Equipment receipts with the buyer’s and seller’s addresses; operating expenses such as electricity bills in the user’s name; mining income or reward screenshots; or wallet transaction histories with addresses and transaction IDs. Self-compiled Excel lists are not accepted.

EXPOSURE TO EXAMINE Business equipment, operational location, expenditure and wallet activity.

**09 **Airdrops** Wallet activity**

Transaction-history screenshots identifying the relevant transfers, wallet addresses and transaction IDs.

EXPOSURE TO EXAMINE A link between the identified person and public transaction history.

**10 **Lending and liquidity pools** Collateral and DeFi**

Transaction-history screenshots with addresses and transaction IDs, plus an explanation of where assets were pledged, the amount and the origin of the collateral.

EXPOSURE TO EXAMINE Collateral positions, protocols, amounts and the provenance of the assets.

**11 **Sale of investments** Investment holdings**

A bank statement clearly showing the proceeds and a statement from the investment company.

EXPOSURE TO EXAMINE Prior holdings, an investment-provider relationship and sale proceeds.

**12 **Sale of property** Property and contracts**

A copy of the sale contract and a bank statement showing receipt of the proceeds.

EXPOSURE TO EXAMINE Property details, the transaction value and information about other parties.

**13 **Inheritance** Family and estate**

A copy of the deceased person’s will and a bank statement showing receipt of the inheritance.

EXPOSURE TO EXAMINE Estate arrangements and information about relatives or other beneficiaries.

**14 **Gift from a relative** Another person’s identity**

A donor’s letter explaining the reason, date and amount of the gift and the source of the donor’s funds; documents confirming the donor’s identity; and supporting evidence for the donor’s funding source.

EXPOSURE TO EXAMINE The request reaches beyond the player to another person’s identity and finances.

THE COMBINED EXPOSURE

### An identity record becomes a financial dossier.

Identity images, proof of address, account ownership and transaction histories can be linked to one person. A will or family-gift file extends that exposure to people who may never have used the site. Bank and exchange records can reveal counterparties and activity unrelated to the deposit being checked.

Copies of identity and financial documents create a risk of impersonation and attempted reuse elsewhere. The operator should disclose access logs, export restrictions, recipients and deletion controls. Its broad document demands put the customer’s identity at risk; its public assurances should account for the protection actually applied to those copies.

The policy explicitly asks for photographs of both sides of a payment card. It tells users to hide a card number appearing on a bank statement, but supplies no equivalent masking instruction alongside the card-photo request. That omission matters because the requested image can expose security details unnecessary to demonstrate ownership of the payment method.

### A selfie raises an additional question about processing.

A document photograph is personal data. If a face is technically processed for unique identification, the biometric-data conditions become relevant as well. The operator should disclose whether it creates a face template, runs liveness or matching, and retains the result or the original image.  [K26](https://phishdestroy.io/steam_dossier/aml-data#K26)

04 / IDENTIFY THE PARTY ASKING

## The brand is not the legal identity.

These are the entities identified by the reviewed public documents. Operator, payment handler and data controller must be mapped to the particular transaction and document request.

CSGOROLL

### Max Stacks Limited

Published registration

C 64304

Published address

Unit 207, Heritage Plaza II, Main Street, Charlestown, Nevis

Payment entity

Feral Entertainment (Cyprus) Limited · HE388908

Document role

AML page: the operator’s specially trained team. Privacy introduction: CSGORoll / Max Stacks Limited.

The terms identify the contracting company and say some payments may be handled by the Cyprus entity. The KYC file needs a corresponding, explicit responsibility map.  [K02](https://phishdestroy.io/steam_dossier/aml-data#K02)   [K03](https://phishdestroy.io/steam_dossier/aml-data#K03)

CSGOFAST

### Lumigrid OÜ PAYPLAYSOFT LIMITED

Estonian entity

Lumigrid OÜ · 17589540 Vesivärava tn 50-201, Tallinn, 10152

Cyprus entity

PAYPLAYSOFT LIMITED · HE454356 Boumpoulinas 1–3, Office 42, Nicosia, 1060

Document role

The privacy notice says either company may be the service provider and/or controller, depending on the service, payment flow, region or operation.

That conditional wording leaves the person uploading a passport without a definite controller for their particular flow. A list of possible companies does not identify who is accountable for that file.  [K05](https://phishdestroy.io/steam_dossier/aml-data#K05)   [K06](https://phishdestroy.io/steam_dossier/aml-data#K06)

ESTONIAN BUSINESS REGISTER · 10 OCTOBER 2026

### Company registration does not establish a gambling licence.

The reviewed EMTA gambling-operator list contains no match for Lumigrid, CSGOFast, PAYPLAYSOFT or Gamusoft. Separately, Lumigrid’s company registry card records incorporation on **2 September 2026**  and advertising as its principal activity. Its zero MTR entries are company-register detail, rather than the gambling-permit test.  [K08](https://phishdestroy.io/steam_dossier/aml-data#K08)   [K09](https://phishdestroy.io/steam_dossier/aml-data#K09)

The official EMTA list of legal gambling operators contains no entry for Lumigrid, CSGOFast, PAYPLAYSOFT or Gamusoft: no Estonian gambling permit is on record for the named service. A company registration is no substitute for a permit identifying the entity, domain, authorised activity and current validity.

[REGISTRY CODE **17589540** Open the official card ↗](https://ariregister.rik.ee/eng/company/17589540/Lumigrid-O%C3%9C)

05 / DOCUMENTARY FINDINGS

## Specific discrepancies. Identifiable sources.

The findings below concern published wording, dates and official records. They do not depend on accepting the operators’ security assurances.

CSGOROLL / INTERNATIONAL TRANSFERS

**2020**  Privacy Shield decision invalidated by the CJEU

**2026**  The revised privacy notice still names Privacy Shield

[Inspect the wording and sources ↓](https://phishdestroy.io/steam_dossier/aml-data#finding-shield)

CSGOFAST / POLICY VERSION

**2024**  Displayed AML and privacy revision year

**2026**  Registration of the company those pages name

[Inspect the registry comparison ↓](https://phishdestroy.io/steam_dossier/aml-data#finding-dates)

1. 01

CSGOROLL / HANDLING CLAIM

### Exclusive team handling; broader sharing elsewhere.

The AML page assigns handling to its trained team. Its privacy notice permits multiple categories of recipients, including vendors and affiliates. The reassuring AML promise leaves the reader without a clear account of which sharing routes apply to the passport and financial file.  [K01](https://phishdestroy.io/steam_dossier/aml-data#K01)   [K03](https://phishdestroy.io/steam_dossier/aml-data#K03)
2. 02

CSGOROLL / TRANSFER SAFEGUARDS

### A 2026 notice still lists Privacy Shield.

The privacy page is marked revised **1 August 2026**  and still lists the EU–US Privacy Shield as an example of an approved transfer safeguard. The CJEU invalidated that adequacy decision on **16 July 2020** . The later EU–US Data Privacy Framework is a different mechanism. Naming an invalidated framework in a 2026 notice is a concrete failure of the published assurance. The operator still owes users the valid safeguard covering their transfer.  [K03](https://phishdestroy.io/steam_dossier/aml-data#K03)   [K20](https://phishdestroy.io/steam_dossier/aml-data#K20)   [K21](https://phishdestroy.io/steam_dossier/aml-data#K21)
3. 03

CSGOROLL / ACCESS TO THE NOTICE

### The terms’ privacy link resolved to the FAQ.

On this review, the privacy URL incorporated by the terms, `/en/info/privacy-statement`, redirected to `/info/faq/`. The separate `/info/privacy-policy/` page was accessible and is the notice analysed here. The redirect and response hashes are recorded.  [K02](https://phishdestroy.io/steam_dossier/aml-data#K02)   [K04](https://phishdestroy.io/steam_dossier/aml-data#K04)
4. 04

CSGOFAST / VERSION HISTORY

### A 2024 revision date names a company formed in 2026.

The AML and privacy pages name Lumigrid OÜ while displaying **10.11.2024**  as their last-update date. The official registry dates the company’s registration to **2 September 2026** . A 2024 revision label cannot account for the introduction of a company formed in 2026. The displayed history fails to tell users when their purported controller changed.  [K05](https://phishdestroy.io/steam_dossier/aml-data#K05)   [K06](https://phishdestroy.io/steam_dossier/aml-data#K06)   [K08](https://phishdestroy.io/steam_dossier/aml-data#K08)
5. 05

CSGOFAST / LEGAL BASIS

### The Estonian company is paired with UK law.

Section 2.1 of the AML policy assigns Cyprus law to PAYPLAYSOFT and United Kingdom law to Lumigrid. The introduction identifies Lumigrid as Estonian. The policy also invokes an EU AML directive and public-interest processing. It does not explain the UK connection or identify the national provision imposing the relevant duty on this Estonian operator.  [K05](https://phishdestroy.io/steam_dossier/aml-data#K05)
6. 06

CSGOFAST / SCRUTINY OF THE POLICY

### Attention to the AML policy is itself a suspicion indicator.

Section 4 includes unusual attention to the companies’ AML policy among examples of suspicious activity. The policy turns scrutiny of its own authority into a suspicion indicator. A user challenging a passport demand is entitled to a reasoned explanation; the operator’s wording creates pressure in the opposite direction.  [K05](https://phishdestroy.io/steam_dossier/aml-data#K05)
7. 07

BOTH OPERATORS / LIFE OF THE FILE

### The notices do not explain the life of the KYC file.

Both notices give general retention criteria without clearly applying them to the identity images, financial evidence and family documents requested in these checks. The reader cannot identify which event starts retention for this file, which duty determines its duration, or when the originals and backups will be deleted.  [K03](https://phishdestroy.io/steam_dossier/aml-data#K03)   [K06](https://phishdestroy.io/steam_dossier/aml-data#K06)

CSGOFast’s notice claims encrypted transmission and storage and agreements with processors. Those statements do not name the actual custodians, access arrangements or retention implementation — CSGOFast must disclose them.  [K06](https://phishdestroy.io/steam_dossier/aml-data#K06)

06 / AUTHORITY MUST BE TRACEABLE

## Who imposes the duty? Who supervises its use?

There are three distinct issues: the company’s existence, permission to offer the relevant service, and the lawful basis for each data-processing activity. A registration number or an AML heading cannot settle all three.

THE LEGAL-BASIS TEST

### Name the law. Show the connection.

The EDPB requires a legal obligation to be imposed on the controller by applicable EU or national law, with a defined processing purpose. Public-interest processing also needs a basis in law. A private notice cannot create that authority simply by declaring the activity to be in the public interest.  [K18](https://phishdestroy.io/steam_dossier/aml-data#K18)

Estonia’s AML Act identifies categories of obliged entities, including gambling operators, and provides rules for diligence, record keeping and supervision. The missing link in CSGOFast’s notice is a precise explanation of which category, national provision and supervisor applies to each named company and service.  [K27](https://phishdestroy.io/steam_dossier/aml-data#K27)

A separate assessment is required for collection based on fraud prevention or another claimed interest: purpose, necessity, proportionality and the person’s rights. Requesting a document and retaining its full original are separate decisions that each need justification.

RESPONSIBILITY FOR THE DOCUMENTS

### The party deciding why the file is collected is accountable.

A controller determines the purposes and means; a processor acts on its instructions. For the promise under review, the immediate question concerns CSGORoll’s own team. If a third party also participates, its role and access must be explained. Outsourcing does not remove the controller’s responsibility.  [K19](https://phishdestroy.io/steam_dossier/aml-data#K19)

Readers should be able to establish the purposes and legal basis, relevant recipients, retention period or meaningful criteria, rights and transfer safeguards. These are substantive transparency requirements.  [K22](https://phishdestroy.io/steam_dossier/aml-data#K22)   [K23](https://phishdestroy.io/steam_dossier/aml-data#K23)

THE PUBLIC ENFORCEMENT RECORD

## There are named regulators. There are recorded actions.

17 MAY 2023 · AUSTRALIA

### CSGORoll / Feral Holdings Limited

ACMA announced a formal warning for prohibited interactive gambling services and said the site had withdrawn from Australia. Its reasoning expressly addressed skins and their conversion through third-party markets.  [K16](https://phishdestroy.io/steam_dossier/aml-data#K16)

APRIL–JUNE 2025 · AUSTRALIA

### CSGOFast / Gamusoft LP

ACMA’s quarterly record lists a formal warning to Gamusoft LP for providing CSGOFast as a prohibited interactive gambling service.  [K17](https://phishdestroy.io/steam_dossier/aml-data#K17)

16 APRIL 2025 · NETHERLANDS

### CSGOFast / Gamusoft LP

Ksa ordered the unlawful offer to Dutch players to stop, backed by €280,000 per week up to €840,000. Its page records that the decision became final and that follow-up checks found continued violations with penalties incurred.  [K24](https://phishdestroy.io/steam_dossier/aml-data#K24)

These gambling-enforcement records are dated, public and final where recorded. No regulator has yet adjudicated the AML document-handling examined here — the operators’ own notices are the record of it, and they are the parties who must disclose the handling, access and retention logs.

EU / EEA

### Protection follows the processing.

GDPR scope covers processing in the context of an EEA establishment and can reach non-EEA operators targeting people in the EU or monitoring their behaviour there. Relevant establishment and targeting facts matter. Where GDPR applies, disclosure to another organisation outside the EEA also engages the international-transfer rules. The applicable safeguard must be explained alongside the basis for collecting the data.  [K28](https://phishdestroy.io/steam_dossier/aml-data#K28)   [K23](https://phishdestroy.io/steam_dossier/aml-data#K23)

Data-protection oversight is distinct from gambling licensing. Estonia’s Data Protection Inspectorate and Cyprus’s Commissioner for Personal Data Protection are listed by the EDPB; individuals can identify the authority relevant to their circumstances through that directory.  [K29](https://phishdestroy.io/steam_dossier/aml-data#K29)

UNITED STATES

### Identify the applicable protection.

State, residency and business-scope rules need to be checked. For example, California’s CCPA grants rights to California residents against covered businesses, including notice and access rights. US citizenship alone does not identify one universal KYC-storage regime.  [K30](https://phishdestroy.io/steam_dossier/aml-data#K30)

The operator should specify the protections applicable to the person’s records, the responsible entity and the complaint route. An offshore address does not answer those questions.

CSGOFAST / SERVICE DESCRIPTION AND ACCESS

### The non-gambling claim beside the trading machinery.

The current Responsible Play Policy denies a gambling identity. The new review places that wording beside its funding instructions, Dutch enforcement record and SIH permission flow.

[Read the Fast findings ↗](https://phishdestroy.io/steam_dossier/trade-tracking.html#fast)

07 / THE RECORDS THAT WOULD ANSWER THIS

## Make the handling of identity inspectable.

The investigation asks for concrete records about authority and control. The user’s willingness to upload a passport cannot substitute for those records.

1. **Identify the controller for each flow.**  Which legal entity receives the identity file, payment-ownership evidence and source-of-funds material? Explain any joint responsibility.
2. **Identify the actual legal duty.**  Give the national law, relevant provision, obliged-entity category, regulated service and competent supervisor. Explain the UK-law references for Lumigrid.
3. **Justify each requested field and original.**  Explain why age confirmation, a redacted statement or a verified result is insufficient in that case. Address donor information and unrelated counterparties.
4. **Explain who handles the files.**  Name service providers and their roles; identify which staff groups can view, download, export or forward originals and how access is reviewed.
5. **Describe storage and transfers.**  Give hosting and support-access countries, encryption and key-management responsibilities, current transfer mechanisms and onward recipients.
6. **Set out retention and deletion.**  Provide periods or meaningful criteria for originals, extracted fields, biometric outputs, logs and backups; explain legal holds and deletion verification.
7. **Explain the withdrawal hold.**  State the trigger, scope, review deadline, proportionality assessment, appeal route and treatment of unused value when a document request is contested.
8. **Make the security promise testable.**  Identify the standard, certification scope and independent assurance available to users; explain incident response and protection against document reuse.
9. **Account for earlier operators and policy versions.**  Provide revision dates, notices of controller changes, transfers of historical KYC files and the duties retained by each entity.
10. **Map the payment counterparty.**  For direct payments, crypto and vouchers, identify the legal seller, recipient, processor and applicable refund or dispute route.

THE INVESTIGATION’S FINDING

**The internal currency is the operator’s label. The exposure belongs to the user.**  Real assets enter the service; real passports, bank records and family documents can be demanded. The operator can hold access while its own published account of authority and handling remains defective. That imbalance is the central finding, and a security promise does not resolve it.

IDENTITY & AML / NEW EVIDENCE FILE

### Your documents. Their discretion.

CSGORoll’s own-team handling promise, the full document inventory, CSGOFast’s entity and policy-date discrepancies, and the legal basis for withholding access while demanding records.

[Inspect the policy findings ↗](https://phishdestroy.io/steam_dossier/aml-data#record)

REVIEW SCOPE

## What was checked.

Public operator policies, company and regulator records, product listings and payment rules were reviewed on 10 October 2026. No identity documents were uploaded, no user account was verified and no payment or withdrawal was attempted. Internal storage, staff access, vendor contracts and production data transfers were not inspected.

Findings about omissions are scoped to the reviewed documents. Potential identity reuse is examined as a risk and a demand for controls, rather than an attributed incident. The linked evidence record contains source URLs, retrieval times, response hashes and the registry-name search result. Hashes identify the downloaded responses, including changing page content; they are not security certifications.

**11 October 2026 addition:**  Empire’s published rules, balance units, gift-code counterparties, PayPal US terms and wallet-custody questions were checked separately. Direct public responses were retained where accessible; Empire policies were also read through indexed primary-source pages where direct requests returned 403. The retained record covers the published arrangements, policy versions, named counterparties and available wallet-custody statements.  [Read the added source record ↗](https://phishdestroy.io/steam_dossier/case_assets/assets/evidence/aml-payment-review-2026-10-11/review-record.json)

[Download evidence record ↗](https://phishdestroy.io/steam_dossier/case_assets/assets/evidence/aml-review-2026-10-10/review-record.json)  [Payments & enforcement ↗](https://phishdestroy.io/steam_dossier/money-and-enforcement.html)  [Main investigation ↗](https://phishdestroy.io/steam_dossier/valve-and-enforcement.html#privacy)  [Session-token code audit ↗](https://phishdestroy.io/steam_dossier/extension-audit.html)

SOURCE REGISTER / IDENTITY & AML

## Read the underlying record.

Operator statements establish what the operator publishes. Registry and enforcement records establish their own dated findings. Legal guidance explains the standards used to assess the disclosure.

1. K01

[User Verification and Security / AML policy ↗](https://www.csgoroll.com/info/aml-policy/)  PRIMARY SOURCE · CSGORoll

Operator policy; document categories also supplied by the investigator.
2. K02

[Terms of Service — effective 12 August 2026 ↗](https://www.csgoroll.com/info/terms-of-service/)  PRIMARY SOURCE · CSGORoll

Published entities, balances, verification powers and incorporated policy URL.
3. K03

[Privacy policy — revised 1 August 2026 ↗](https://www.csgoroll.com/info/privacy-policy/)  PRIMARY SOURCE · CSGORoll

Recipient categories, payment-data wording, retention criteria and transfer safeguards.
4. K04

[Privacy URL incorporated by the terms ↗](https://www.csgoroll.com/en/info/privacy-statement)  PRIMARY SOURCE · CSGORoll

Resolved to the FAQ during the recorded HTTP retrieval.
5. K05

[AML-CFT policy — displayed date 10.11.2024 ↗](https://csgofast.com/aml-policy)  PRIMARY SOURCE · CSGOFast

Reviewed sections 1, 2.1, 4, 6, 7 and Annex 1.
6. K06

[Privacy policy — displayed date 10.11.2024 ↗](https://csgofast.com/privacy-policy)  PRIMARY SOURCE · CSGOFast

Conditional controller identity, claimed safeguards and retention criteria.
7. K08

[Lumigrid OÜ — registry code 17589540 ↗](https://ariregister.rik.ee/eng/company/17589540/Lumigrid-O%C3%9C)  PRIMARY SOURCE · Estonian e-Business Register

Official registration date, principal activity and MTR counts, reviewed 10 October 2026.
8. K09

[List of legal gambling operators ↗](https://www.emta.ee/en/business-client/registration-business/gambling-operators/list-legal-gambling-operators)  PRIMARY SOURCE · Estonian Tax and Customs Board

Official list and explanation of operating permits; name search recorded.
9. K16

[Action against CS:GO Roll / Feral Holdings — 17 May 2023 ↗](https://www.acma.gov.au/articles/2023-05/acma-takes-action-against-illegal-skins-gambling-site)  PRIMARY SOURCE · ACMA

Australian enforcement announcement, including the role of skins and youth-market concern.
10. K17

[Interactive gambling enforcement — April to June 2025 ↗](https://www.acma.gov.au/publications/2025-07/report/action-interactive-gambling-april-june-2025)  PRIMARY SOURCE · ACMA

Quarterly record lists CSGOFast / Gamusoft LP.
11. K18

[Process personal data lawfully ↗](https://www.edpb.europa.eu/sme/be-compliant/process-personal-data-lawfully_en)  PRIMARY SOURCE · European Data Protection Board

Official explanation of legal obligation, public interest, consent and necessity.
12. K19

[Data controller or data processor ↗](https://www.edpb.europa.eu/sme/learn-the-basics/data-controller-or-data-processor_en)  PRIMARY SOURCE · European Data Protection Board

Roles, contracts, responsibilities and continuing controller accountability.
13. K20

[Schrems II — judgment announcement, 16 July 2020 ↗](https://curia.europa.eu/jcms/upload/docs/application/pdf/2020-07/cp200091en.pdf)  PRIMARY SOURCE · Court of Justice of the European Union

Invalidation of the EU–US Privacy Shield adequacy decision.
14. K21

[EU–US data transfers ↗](https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection/eu-us-data-transfers_en)  PRIMARY SOURCE · European Commission

The later Data Privacy Framework and current transfer arrangements.
15. K22

[Respect individuals’ rights ↗](https://www.edpb.europa.eu/sme/be-compliant/respect-individuals-rights_en)  PRIMARY SOURCE · European Data Protection Board

Transparency, access, recipients and retention information.
16. K23

[International data transfers ↗](https://www.edpb.europa.eu/sme/be-compliant/international-data-transfers_en)  PRIMARY SOURCE · European Data Protection Board

Transfer mechanisms and safeguards for data leaving the EEA.
17. K24

[Gamusoft LP — order dated 16 April 2025 ↗](https://kansspelautoriteit.nl/gamusoft-lp)  PRIMARY SOURCE · Kansspelautoriteit

Official Dutch order page, finality and enforcement follow-up.
18. K26

[Biometric-data definition — paragraphs 312–313 ↗](https://www.edpb.europa.eu/system/files/2025-02/decision1594_0.pdf)  PRIMARY SOURCE · Supervisory-authority decision, hosted by EDPB

Distinction between ordinary photographs and specific technical processing for identification.
19. K27

[Money Laundering and Terrorist Financing Prevention Act ↗](https://www.riigiteataja.ee/en/akt/520072026005)  PRIMARY SOURCE · Riigi Teataja / Riigikogu

Official English text; obliged entities, preservation of data (§47) and supervision.
20. K28

[Guidelines 3/2018 on territorial scope ↗](https://www.edpb.europa.eu/sites/default/files/files/file1/edpb_guidelines_3_2018_territorial_scope_after_public_consultation_en_1.pdf)  PRIMARY SOURCE · European Data Protection Board

Establishment, targeting and location criteria under Article 3.
21. K29

[Members — national supervisory authorities ↗](https://www.edpb.europa.eu/about-edpb/about-edpb/members_en)  PRIMARY SOURCE · European Data Protection Board

Official directory including Estonia and Cyprus.
22. K30

[Frequently Asked Questions ↗](https://cppa.ca.gov/faq.html)  PRIMARY SOURCE · California Privacy Protection Agency

California residents, covered businesses and applicable privacy rights.
23. K07

[Responsible Play Policy ↗](https://csgofast.com/responsible-play-policy)  PRIMARY SOURCE · CSGOFast

Operator identity and the stated treatment of Credits and digital items.
24. K10

[FAQ — balances, KYC and P2P settlement ↗](https://www.csgoroll.com/info/faq/)  PRIMARY SOURCE · CSGORoll

Coins / Chips distinction and published platform trading rules.
25. K11

[What Payment Methods do we Accept? ↗](https://intercom.help/csgoroll/en/articles/9626919-what-payment-methods-do-we-accept)  PRIMARY SOURCE · CSGORoll Help Center

Payment-method list, dated 21 July 2026.
26. K12

[CSGORoll 1 Coin Gift Card ↗](https://www.kinguin.net/category/377753/csgoroll-1-coin-gift-card)  PRIMARY SOURCE · Kinguin

Marketplace listing and displayed seller name; no test purchase.
27. K13

[CSGOFAST 10 Fast Coins Gift Card ↗](https://www.kinguin.net/category/82747/csgofast-10-usd-gift-card)  PRIMARY SOURCE · Kinguin

Marketplace listing and displayed seller name; no test purchase.
28. K14

[Purchase Protection Program ↗](https://www.paypal.com/us/legalhub/paypal/buyer-protection)  PRIMARY SOURCE · PayPal US

Gift-card / gaming exclusions and separate card-issuer dispute provisions; US terms.
29. K36

[Terms of Service — 6 October 2026 ↗](https://csgoempire.com/tos)  PRIMARY SOURCE · CSGOEmpire

Deposits & Withdrawals §§11–12; KYC; trading; payment-provider authority. Published rules, not verification of implementation.
30. K37

[KYC checks — 13 February 2025 ↗](https://help.csgoempire.com/en/articles/5349729-kyc-checks)  PRIMARY SOURCE · CSGOEmpire Help Centre

Older crypto-withdrawal threshold, identity/address evidence and Checkin processing.
31. K38

[Account under manual review — 13 February 2025 ↗](https://help.csgoempire.com/en/articles/5911936-account-under-manual-review)  PRIMARY SOURCE · CSGOEmpire Help Centre

Withdrawal restrictions for verification and unwagered cash/crypto funding, including gift codes.
32. K39

[Main FAQ / About ↗](https://csgoempire.com/faq)  PRIMARY SOURCE · CSGOEmpire

KYC-refusal exit wording, named providers, operator backups and manual document review. Undated live page.
33. K40

[Privacy policy — 12 February 2025 ↗](https://csgoempire.com/privacy-policy)  PRIMARY SOURCE · CSGOEmpire

Checkin.com recipient, retention and transfer wording including Privacy Shield.
34. K41

[Kinguin gift-card purchase and redemption page ↗](https://csgoempire.com/deposit/kinguin)  PRIMARY SOURCE · CSGOEmpire

Operator-endorsed purchase route and footer entity disclosures. No code entered or checkout attempted.
35. K42

[CSGOEmpire 100 Coin Gift Card — listing 90693 ↗](https://www.kinguin.net/category/90693/csgoempire-100-coin-gift-card)  PRIMARY SOURCE · Kinguin

Seller label, official-publisher claim and territory restrictions; listing excludes US residents. No transaction.
36. K43

[FAQ — balance funding ↗](https://csgofast.com/faq)  PRIMARY SOURCE · CSGOFast

Partner vouchers, skin deposits, crypto/card routes and account-linked USDT deposit addresses; does not identify key custody.
37. K44

[How to make a withdrawal? ↗](https://csgofast.gg/faq/general_info/1)  PRIMARY SOURCE · CSGOFast

Operator description of user-to-user skin delivery. Its older trade-ban wording is not relied on here.
38. K45

[Which payment methods does Kinguin accept? ↗](https://support.kinguin.net/hc/en-us/articles/37698235193245-Which-payment-methods-does-Kinguin-accept)  PRIMARY SOURCE · Kinguin Support

PayPal listed; availability depends on billing country, currency and cart contents.
39. K46

[Terms and Conditions v1.3 — September 2026 ↗](https://static.kinguin.net/cms/2026_9_25_Kinguin_net_T_and_C_ver_1_3_ENG_3cf9318e46/2026_9_25_Kinguin_net_T_and_C_ver_1_3_ENG_3cf9318e46.pdf)  PRIMARY SOURCE · Kinguin

§§1.10, 2.2–2.3.3 and 5.2.1–5.2.4: operator, seller, external service and payment collection; mandatory consumer rights retained.
40. K47

[User Agreement — 14 September 2026 ↗](https://www.paypal.com/us/legalhub/paypal/useragreement-full)  PRIMARY SOURCE · PayPal US

US account terms; Liability for Unauthorized Transactions and Other Errors. Separate from Purchase Protection.
41. K48

[Acceptable Use Policy ↗](https://www.paypal.com/us/legalhub/paypal/acceptableuse-full)  PRIMARY SOURCE · PayPal US

Activities Requiring Approval: stored-value services, gambling facilitation and marketplaces. No merchant-specific approval was obtained.
42. K49

[How do I sell my crypto? — 20 July 2023 ↗](https://help.csgoempire.com/en/articles/5366952-how-do-i-sell-my-crypto)  PRIMARY SOURCE · CSGOEmpire Help Centre

Published example of payout to a customer’s exchange deposit address.
43. K50

[Do I need to wager to withdraw? (Crypto) — 27 November 2023 ↗](https://help.csgoempire.com/en/articles/5366986-do-i-need-to-wager-to-withdraw-crypto)  PRIMARY SOURCE · CSGOEmpire Help Centre

Different payout conditions for skin-funded and cash/crypto-funded balances; compared with current Trading terms.
