This Privacy Policy explains what personal information TopSlash collects, how we use it, who we share it with, and the choices you have. TopSlash is operated by Envol, Inc., a California corporation ("we", "us"). It applies to https://topslash.app and to the emails we send.
We use information to operate TopSlash, provide support and process the services you choose. We do not sell personal information or use advertising trackers or analytics cookies. For connected purchases, the vendor receives the information needed to fulfill the subscription through Stripe. Native offer links lead to the vendor or store, which processes your information under its own terms.
What applies to the current website. Pages marked as previews are interactive demonstrations. They do not create real accounts, process purchases, connect payment providers or send newsletter subscriptions. Some choices and sample drafts are saved in your browser's local or session storage, including text or images you choose to enter. These preview drafts are not uploaded to a TopSlash account. Cloudflare processes requests to deliver and protect the website. If you email support, we receive and handle that message as described below. Sections about accounts, transactions and verification apply when you use those enabled services; viewing a demonstration does not cause those activities.
1. Information we collect
When you browse the website or an enabled application (no account required):
- A visitor hash, where live application counters are enabled. The application derives a daily identifier from request information such as IP address, browser user agent and language using a rotating secret. This reduces direct identification and cross-day matching; hashing does not make information anonymous in every circumstance. We use the identifier for unique visitor and outbound-click counts and abuse limits. Static preview figures are sample data, not measurements of your visit.
- Security logs. Our hosting and security providers process technical request information, including IP addresses, browser details and request identifiers, to deliver pages, detect abuse and investigate failures. Where application security logging is enabled, we minimize identifying fields and redact credentials and payment-card data. Providers may keep their own security logs under their policies.
- Our providers Cloudflare and Hetzner see the IP addresses of requests as part of delivering and protecting the site (Section 5).
If you create an account:
- Your email address and verified sign-in identifiers. If you choose an available Google, Apple or X sign-in or linking option, that provider supplies the identity and profile fields covered by its authorization screen, which may include a name, profile image or email address. Apple may supply a private relay address; some providers may not supply an email. Linking a provider requires its verification. We do not receive your provider password.
- Your optional display name, profile image and X handle if you add them. First and last names are not required for an ordinary profile. A public product contact or handle is shown only as identified in that product's setup; linked sign-in identifiers are not automatically public. Billing providers may separately collect required identity information.
- Your marketing and notification preferences. Marketing requires opt-in where offered, and each marketing email provides an unsubscribe option. Essential account, billing and service notices are separate. A preview newsletter field does not enroll you in a mailing list.
- Account activity: sign-in times, listings, campaigns, checkout reservations, native link claims, purchases, appeals, reports and any feedback you submit, linked to your account.
If you are a founder or vendor:
- The website URL you submit, everything our verification extracts from your public site (title, description, logo, screenshot, pricing link, social links, a text sample), the verification results, and your edits.
- Your advertising orders and payments: amount, time, Stripe references, plan, billing period, cancellation status, consent record, publication credit grants and uses, and rank contributions. Ranking contribution history is public by listing name; your billing account and unused credit balance are not public.
- Your deal: plan name, features, normal annual price, renewal price, refund policy, support and cancellation links, the public pricing URL attached to your listing, and available listing-verification evidence, which may include public-page text and a screenshot.
- Your Stripe connected account id and its status (whether charges and payouts are enabled, what Stripe still requires), and the business name and country Stripe reports for the account. The business name and country are shown to buyers as "Sold by".
- Sales events used for TopSlash connected deals: purchases, refunds, disputes and subscription changes. Connected-account webhooks can deliver events beyond one campaign; we use attribution to associate relevant events with TopSlash records. This policy does not promise that a provider sends only TopSlash events.
- Native offer configuration: store type, vendor-supplied redemption link, annual prices, eligibility, expiry, claim cap, test attestation and campaign history.
- Setup-test records: sandbox checkout references and payment/webhook results. A sandbox result is not an actual buyer purchase or proof of product access.
If you are a buyer:
- Your claims (which deal, which tier, when) and your purchases: product, plan, amount paid, savings, renewal date, renewal price, and the Stripe session, subscription, invoice, and customer ids on the vendor's account. We never receive or store your card number. Card details go directly to Stripe on Stripe's own pages.
- Refunds, disputes, and cancellations that Stripe reports to us.
- For a native link claim, your TopSlash account id, offer id and claim time. A claim does not provide us with your Apple or Google account identity, card details, store receipt or proof of access. A public offers-claimed total does not identify claimants.
- Any buyer feedback you choose to submit where that feature is available. The form identifies which feedback and display name will be public before submission; it is separate from private claim and billing records.
If you contact us:
- Your sender email address, any name or other information you include, the message, attachments and correspondence history. Public support is support@topslash.app. Cloudflare Email Routing forwards incoming mail to our business Gmail inbox; Google stores and processes that correspondence, and Resend sends support replies from our support address. If an enabled report or appeal form is used, we also keep its relevant account or abuse-prevention reference. Do not send passwords, API keys or full payment-card details.
Emails we send:
- Email providers process recipient addresses and message content to deliver emails. Application transactional logs may include the template, a hashed recipient reference, delivery status and provider message id. Support correspondence also remains in our business inbox; a hashed application log does not mean the email provider cannot see the delivery address.
We do not knowingly collect sensitive information (such as government ids, health, or precise location), and you should not send it to us.
2. How we use information
- To run the Service: accounts, sign-in, listings, verification, the leaderboard, deals, claims, purchases, the public bid history, and public counters.
- To process payments through Stripe and to keep the financial ledger the law requires.
- To send transactional emails: sign-in codes, listing status, payment confirmations, connected purchase confirmations, TopSlash plan and campaign-expiry notices, hold expirations, removal notices, appeal decisions, and account deletion confirmations.
- To keep the Service safe: fraud prevention, abuse prevention, rate limiting, bot detection, security investigations, and moderation.
- To answer your messages and to handle reports and appeals.
- To measure the Service with our own counters and error monitoring.
- To meet legal obligations, including tax, accounting, and automatic-renewal-law record keeping.
The new campaign service does not routinely monitor buyer access through RevenueCat or send buyer annual-renewal reminders. Earlier purchases retain any expressly promised notices. Vendor campaign-expiry notices and notices about a vendor's own TopSlash billing plan are separate.
We do not use your information for behavioral advertising, and we do not build advertising profiles.
3. Legal bases for processing
Where data-protection law requires a legal basis, we rely on:
- Contract. We process account, listing, claim, purchase, and service communications as needed to provide the Service and carry out our contracts with you.
- Legitimate interests. We process limited technical, security, verification, moderation, fraud-prevention, measurement, and support information to operate and protect TopSlash, its users, and the integrity of its public records. We balance those interests against your rights.
- Legal obligations. We keep and disclose records when needed for tax, accounting, automatic-renewal, sanctions, court, regulatory, and other legal duties.
- Consent. We rely on consent for optional marketing and any other processing for which we specifically ask. You may withdraw consent at any time without affecting processing that already occurred.
4. What is public
The following is public on TopSlash and is meant to be:
- Listing content (name, tagline, description, category, logo, screenshot, website link, and X handle if you added one).
- Every placement payment and reversal, by listing name, amount, time, and resulting position, forever, on the Complete Bid History page. The founder's personal name is not shown.
- Deal content, including prices, the vendor's refund policy, and the vendor's business name and country from Stripe.
- Counters: unique visitors, approved listings, confirmed placement revenue, unique outbound clicks, claims, verified purchases, and verified savings. These are totals. Private billing and claim identities are not published with these totals. Voluntary public feedback is identified separately before submission.
5. Who we share information with
We share information only with the providers that run the Service, with vendors when you buy from them, and when the law requires. We do not sell personal information, and we do not share it for cross-context behavioral advertising.
Vendors on connected Stripe purchases. The vendor is the seller and receives your email address and the billing and transaction information that Stripe makes available on its connected account; neither the vendor nor TopSlash receives your full card number from Stripe Checkout. We deliver the configured purchase notification with your email address, plan, tier and amount through the supported setup so the vendor can fulfill your order. From then on, the vendor's privacy policy governs what the vendor does with that information.
Native stores and vendor destinations. When you follow a native offer link, Apple, Google or the vendor receives the request and processes any subsequent account and payment information under its own privacy terms. A TopSlash claim does not automatically share your TopSlash email with Apple or Google or give a vendor a list of identified store purchasers. No RevenueCat connection is used for native link claims.
Service providers. The current website and support use Cloudflare, Google and Resend. Enabled application features may also use the providers below. A provider receives information only for the relevant feature; some act as independent controllers under their own policies:
- Stripe (payments, connected accounts, receipts). Stripe collects your card details directly on its own pages and is an independent controller for the information it collects. See Stripe's privacy policy at https://stripe.com/privacy.
- Supabase (database and authentication hosting).
- Hetzner (servers that run the application).
- Cloudflare (website delivery and security, incoming email forwarding, and, where enabled, Turnstile and public-site screenshots for product verification).
- Resend (sending transactional emails and support replies, including recipient addresses and message content).
- Google Web Risk (checks whether a submitted public website URL is known to be malicious; we send only the public URL).
- OpenAI (classifies the public text of a submitted website to check that it describes an eligible SaaS or app and not a prohibited category; we send only public website content, never your account information).
- Sentry (error monitoring; receives technical details about failures, a request id, and a hashed user id when you are signed in).
- Google (our business Gmail support inbox, and Google sign-in if you choose it).
- Apple and X (if you choose their available sign-in or account-linking options). Their policies govern their accounts and authorization services.
Sharing and external links. Using an available social-sharing or Ask AI link opens the named third-party service and may pass the public product URL or prepared public text shown for that action. Its privacy policy applies. Downloading a share card saves an image on your device. Your private billing information is not part of a public rank or deal card.
Legal and safety. We may disclose information if required by law, subpoena, or court order; to protect the rights, property, or safety of users, Envol, Inc., or the public; to investigate fraud or abuse; or in connection with a merger, sale, or reorganization of our business, in which case the new owner is bound by this policy.
6. Cookies and similar technologies
- TopSlash sets no analytics or advertising cookies on public pages. Where enabled, live counters use the identifier described in Section 1. Cloudflare may set necessary security cookies.
- Preview preferences and drafts may use local storage (for settings such as display preferences) or session storage (for changes within the browser tab). Clear the site's browser storage to remove them; session data usually ends when its tab session ends. Clearing a preview does not delete a real account or cancel a subscription.
- When you sign in, we set the session cookies needed to keep you signed in. They are essential and are not used for tracking.
- During listing submission, if you start before signing in, we keep the URL you entered in an encrypted cookie for 15 minutes so that it survives the sign-in step.
- Cloudflare may set short-lived, strictly necessary security cookies (for example
__cf_bmorcf_clearance) to distinguish legitimate requests from automated abuse. These cookies are used for security, not advertising or profiling, and expire according to Cloudflare's configuration. - Stripe sets its own cookies on its checkout pages under its own policy.
We use no advertising cookies, no analytics cookies, and no third-party trackers on our pages. We do not embed third-party behavioral-advertising trackers. Following an external link or signing in through another provider is subject to that service's own privacy practices.
7. Do Not Track and Global Privacy Control
We do not track you across other websites or over time for advertising, so there is nothing for a "Do Not Track" signal to turn off. We treat every visitor as if the signal were on. We do not sell or share personal information, so a Global Privacy Control signal changes nothing either; you are already opted out.
8. How to review, change, or delete your information
- Review and change. Sign in and open your account settings to see and edit your display name, X handle, and marketing preference. Your listings, deals, claims, and purchases are on your dashboard and account pages. For anything else, email us.
- Delete your account. Sign in, open account settings, and choose delete. An enabled account-deletion flow removes or pseudonymizes the account's personal profile and unpublishes its listings unless transferred, subject to the records we must retain. If the control is unavailable, email support with your request. A sample deletion in a preview only changes the demonstration. We will email a confirmation to the address you had.
- What deletion does not remove. Financial ledgers are kept as the law requires: Paid Rank payments, reversals, campaign orders, credit grants and uses, subscription consent records, historical listing-fee records, purchases, refunds, disputes, and the Stripe events behind them. The public bid history keeps your listing name and amounts. Security logs and moderation records are kept for as long as they are needed for security. We delete or anonymize personal information when its purpose ends unless we need it for a legal, security, fraud-prevention, dispute, backup, or public-ledger reason described here. A deleted account cannot be restored, and deleting your TopSlash account does not cancel any subscription you have with a vendor; cancel that with the vendor.
- Email requests. You can also email support@topslash.app from the address on your account to ask for a copy of your information, a correction, or deletion. We answer within 30 days. We may ask you to confirm the request from your account email.
9. How long we keep information
- Raw visitor hashes: 35 days, then only the daily totals are kept. The in-memory counting keys expire within 40 days.
- Outbound click records: retained to maintain public counters and investigate abuse. They contain a daily-rotating visitor hash and listing id; the daily identifier is designed to limit matching across days.
- Financial ledgers (Paid Rank payments, reversals, campaign orders, credit grants and uses, subscription consent records, historical listing-fee records, purchases, refunds, disputes, Stripe events): retained for accounting, tax, fraud prevention, audits and disputes for as long as needed or required by law. Public contribution history may remain permanently; this does not require keeping all personal identifiers forever. Records of automatic-renewal consent are kept for at least 3 years or 1 year after the subscription ends, whichever is longer.
- Public bid history: permanent.
- Account information: for as long as your account exists, then pseudonymized as described in Section 8.
- Listings, campaigns and native claims: retained while needed to provide saved claims, enforce allocation limits, preserve relevant terms and resolve support or abuse reports. Ending a promotional period does not erase its history; personal data is deleted or anonymized when no longer needed, subject to the purposes and exceptions above.
- Verification results and pricing evidence: for as long as the listing exists and afterwards when needed to investigate a complaint, appeal, or pricing dispute.
- Support, report, and appeal messages: while the matter is active and afterwards when reasonably needed for support records, safety, or disputes.
- Security events and email logs: while reasonably needed to prevent or investigate fraud, abuse, delivery problems, or a legal dispute.
- Server and proxy logs: rotated automatically and kept only as long as reasonably needed for operations and security. Application logging is configured to minimize personal data; hosting and security providers have their own operational retention practices.
- Error reports (Sentry): for up to 90 days under our current Sentry plan.
10. Children
TopSlash is not for people under 18. We do not knowingly collect personal information from anyone under 18. If you believe a person under 18 has given us information, email us and we will delete it.
11. California residents
California law may provide additional rights when it applies. We offer the request routes below regardless of whether a statutory business threshold applies:
- Right to know. Ask us what personal information we hold about you and how we use it. Sections 1 and 5 describe it; email us for your specific records.
- Right to delete. Delete your account yourself (Section 8) or ask us by email.
- Right to correct. Edit your profile, or ask us by email.
- No sale or sharing. We do not sell personal information and do not share it for cross-context behavioral advertising, and we have not done so in the past 12 months. We therefore offer no "Do Not Sell or Share" link; there is nothing to opt out of.
- No discrimination. We will not treat you differently for exercising these rights.
- Shine the Light (Civil Code section 1798.83). We do not disclose personal information to third parties for their own direct-marketing purposes.
We will re-evaluate CCPA applicability as the business and applicable legal thresholds change and will update this policy when required. Sections 6 and 7 explain our cookie practices, response to Do Not Track and Global Privacy Control signals, and whether third parties collect information across websites.
12. EEA, United Kingdom, and other users outside the United States
TopSlash is operated from the United States, and your information is processed in the United States and wherever our providers operate. Where transfer law applies, we and our providers use an available lawful transfer mechanism, such as approved standard contractual clauses or another recognized safeguard. Contact us if you want information about the mechanism relevant to your information.
If the General Data Protection Regulation, United Kingdom GDPR, or a similar law applies to you, you may have the right to access and correct your information; request deletion; restrict or object to processing; receive portable information you supplied; withdraw consent; and complain to the data-protection authority where you live or work. These rights can have legal exceptions. Email support@topslash.app to exercise them. We will verify your identity and respond within the period required by applicable law.
Envol, Inc. is the controller for TopSlash's processing described in this policy. Vendors are independent controllers for buyer information they receive. We do not currently maintain an EEA or United Kingdom representative. We do not intentionally direct paid TopSlash services to those regions until any legally required representative and related launch controls are in place; mere website availability there is not an offer of paid services.
13. Security
For enabled checkout, payment-card details are entered with the payment provider. We use encrypted transport, access controls, data minimization and relevant security records to protect information. Do not put card details or credentials in support emails or preview fields. No system is perfectly secure. If we learn of a breach that affects your personal information, we will notify you as the law requires.
14. Changes to this policy
We may update this policy. When we do, we post the new version at https://topslash.app/privacy with a new effective date. If the change is material, we also email account holders before it takes effect.
15. Contact
Envol, Inc., operating TopSlash. Email: support@topslash.app. Postal address: Envol, Inc., 2108 N St Ste N, Sacramento, CA 95816, United States. You can also use the contact page.