Payment Security
Last updated: 24 September 2026
SkinsDrop is a trading name of NOVATORA MARKETPLACE LTD. This page explains how your card details and your account are protected when you buy from SkinsDrop.
Your card details never reach us
When you pay by card you are taken to the secure, hosted payment page of our PCI DSS-compliant payment provider. You type your card number, expiry date and security code (CVV) there, not on our website. We never receive, see or store your full card number or your CVV; we only receive a confirmation that the payment succeeded, with a payment reference.
Strong customer authentication
Your bank may ask you to confirm the payment with 3-D Secure (Visa Secure or Mastercard Identity Check) โ for example in the banking app or with a one-time code. This protects you from someone else using your card.
Encryption and site protection
- Every page is served over HTTPS with TLS 1.2 or newer; older protocols are refused, and browsers are told to always use HTTPS (HSTS).
- A strict, nonce-based Content Security Policy lets only our own scripts run โ a script injected into a page is refused by your browser. We run no third-party advertising or analytics scripts.
- Our pages cannot be embedded in other websites, which prevents click-jacking.
- Passwords are stored only as salted hashes. You can also sign in with Steam, in which case we never see a password at all.
Charges and fees
Prices are in US dollars and we add no card surcharges or payment fees. There are no subscriptions or recurring charges: you pay once per order. Card payments appear on your statement as SKINSDROP.STORE.
Reporting a problem
If you see a charge you don't recognise, or think you have found a security issue on our website, email support@skinsdrop.store and we will respond within 24 hours.