This Privacy Policy explains how Topper (topper.app) handles personal data. The controller is the Topper brand operator. There is no separate registered company name in this policy. Contact: ops@topper.app. This policy sits with the Terms of Service. Topper is available worldwide, so India’s Digital Personal Data Protection Act, 2023 (DPDP) and the EU/UK GDPR can both apply from the first user.
1. Guest browse vs an account
You can open Topper and look at sports pages without an account. We then store only what the browser and hosting stack need to serve the page (including a session cookie once you sign in).
An account is required to place a prediction, create a party, or join a party. We then collect the data in section 2.
2. What we collect today
- Phone number in E.164 form, country inferred from the calling code, and a timestamp when the number is verified.
- Date of birth (to enforce 18+). We lock this after you set it.
- Handle, display name, and country / state / city from our picker. We do not store GPS coordinates from that picker.
- Avatar as a third-party GIF identifier and image URLs — not a photo you upload.
- Predictions, Match Point ledgers, party membership, and leaderboard scores.
- Consent records: age-and-terms acceptance, and SMS-service consent for one-time codes.
- Auth events such as OTP requested or verified. The schema can store IP address and user-agent; we use those for integrity when they are written.
We do not collect payment cards. We do not take deposits. We do not run user-facing AI prompts. Match-card art is generated by operators, not from your messages.
3. Why we use it
- Contract — to create your account, send the SMS one-time code, run predictions, parties, and leaderboards, and keep one phone to one account.
- Consent — the 18+ and Terms checkbox, and SMS for the login code.
- Legitimate interests / DPDP legitimate use — stopping multi-accounting, abuse, and real-money solicitation; keeping ranks rebuildable from the ledger.
4. Who processes it
- A hosted auth and database service — accounts, wallets, and predictions.
- An SMS provider — delivery of one-time sign-in codes.
- A cache and ranking store — short-lived one-time-code state, session cache, and leaderboard indexes.
- Cloud hosting — the servers that run topper.app.
- A GIF library — avatar search. Your query goes through our server; that library’s own terms apply to the images.
Sports odds and scoreboard data come from third-party feeds. Those feeds are not given your phone number or handle. They describe matches, not you.
6. Your rights (DPDP and GDPR)
Subject to law, you may ask to access, correct, or delete your personal data, withdraw consent where we rely on it, and complain to a supervisory authority. For GDPR you may also object to or restrict some processing, and ask for portability of data you gave us.
Write to ops@topper.app. That address is also the grievance contact until a separate officer is named.
7. Deletion and retention
When we delete an account we tombstone the user row, hard-delete phone and other identifiers, and release the handle immediately so someone else can take it. Predictions and ledger rows stay, reattributed to “Deleted user”, so leaderboards do not rewrite history. Party memberships are removed. Chat messages, when they exist, are reattributed the same way.
We keep a live account for as long as you use Topper. OTP codes expire in minutes. Auth logs are kept only as long as we need them for security and dispute review.
8. International transfers
Hosting and processors may store data outside India and outside the EEA. We use them to run a worldwide product. If you want detail on a specific transfer, ask ops@topper.app.
9. Children
Topper is 18+ only. We do not knowingly collect data from children. If you believe we have, email us and we will delete the account.
10. Not collected yet
These are designed or discussed in the product, but they are not live collection today: Google sign-in, push notifications, Sentry crash reporting, Perspective API chat moderation, and device-fingerprint hashes. If we switch any of them on for players, we will name them here first.
11. No extra liability
This policy describes how we handle personal data. It does not create a warranty, a duty of care beyond what DPDP or GDPR already require, or a right to damages for feed errors, SMS delays, hosting outages, or another user’s conduct. To the fullest extent those statutes allow, the release, indemnity, and liability cap in the Terms of Service apply to privacy-related claims as well.
You remain responsible for any civil or criminal consequence of how you use your account. Statutory access, correction, and deletion rights are not waived.
12. Changes
We will update the effective date when this policy changes. Effective 27 August 2026.