topper.BETA
Skip to document

1. Guest browse vs an account

You can open Topper and look at sports pages without an account. We then store only what the browser and hosting stack need to serve the page (including a session cookie once you sign in).

An account is required to place a prediction, create a party, or join a party. We then collect the data in section 2.

2. What we collect today

  • Phone number in E.164 form, country inferred from the calling code, and a timestamp when the number is verified.
  • Date of birth (to enforce 18+). We lock this after you set it.
  • Handle, display name, and country / state / city from our picker. We do not store GPS coordinates from that picker.
  • Avatar as a third-party GIF identifier and image URLs — not a photo you upload.
  • Predictions, Match Point ledgers, party membership, and leaderboard scores.
  • Consent records: age-and-terms acceptance, and SMS-service consent for one-time codes.
  • Auth events such as OTP requested or verified. The schema can store IP address and user-agent; we use those for integrity when they are written.

We do not collect payment cards. We do not take deposits. We do not run user-facing AI prompts. Match-card art is generated by operators, not from your messages.

3. Why we use it

  • Contract — to create your account, send the SMS one-time code, run predictions, parties, and leaderboards, and keep one phone to one account.
  • Consent — the 18+ and Terms checkbox, and SMS for the login code.
  • Legitimate interests / DPDP legitimate use — stopping multi-accounting, abuse, and real-money solicitation; keeping ranks rebuildable from the ledger.

4. Who processes it

  • A hosted auth and database service — accounts, wallets, and predictions.
  • An SMS provider — delivery of one-time sign-in codes.
  • A cache and ranking store — short-lived one-time-code state, session cache, and leaderboard indexes.
  • Cloud hosting — the servers that run topper.app.
  • A GIF library — avatar search. Your query goes through our server; that library’s own terms apply to the images.

Sports odds and scoreboard data come from third-party feeds. Those feeds are not given your phone number or handle. They describe matches, not you.

5. Cookies

Signed-in sessions use HttpOnly cookies from our auth provider. We do not run an analytics SDK, ad pixel, or marketing cookie today. Theme preference lives in localStorage on your device. If we add analytics or push later, we will update this section before we turn them on for you.

6. Your rights (DPDP and GDPR)

Subject to law, you may ask to access, correct, or delete your personal data, withdraw consent where we rely on it, and complain to a supervisory authority. For GDPR you may also object to or restrict some processing, and ask for portability of data you gave us.

Write to ops@topper.app. That address is also the grievance contact until a separate officer is named.

7. Deletion and retention

When we delete an account we tombstone the user row, hard-delete phone and other identifiers, and release the handle immediately so someone else can take it. Predictions and ledger rows stay, reattributed to “Deleted user”, so leaderboards do not rewrite history. Party memberships are removed. Chat messages, when they exist, are reattributed the same way.

We keep a live account for as long as you use Topper. OTP codes expire in minutes. Auth logs are kept only as long as we need them for security and dispute review.

8. International transfers

Hosting and processors may store data outside India and outside the EEA. We use them to run a worldwide product. If you want detail on a specific transfer, ask ops@topper.app.

9. Children

Topper is 18+ only. We do not knowingly collect data from children. If you believe we have, email us and we will delete the account.

10. Not collected yet

These are designed or discussed in the product, but they are not live collection today: Google sign-in, push notifications, Sentry crash reporting, Perspective API chat moderation, and device-fingerprint hashes. If we switch any of them on for players, we will name them here first.

11. No extra liability

This policy describes how we handle personal data. It does not create a warranty, a duty of care beyond what DPDP or GDPR already require, or a right to damages for feed errors, SMS delays, hosting outages, or another user’s conduct. To the fullest extent those statutes allow, the release, indemnity, and liability cap in the Terms of Service apply to privacy-related claims as well.

You remain responsible for any civil or criminal consequence of how you use your account. Statutory access, correction, and deletion rights are not waived.

12. Changes

We will update the effective date when this policy changes. Effective 27 August 2026.