The Top Board — home

Privacy Policy

Version 1.2 · Effective 2026-08-22 · Last updated 2026-08-22

This policy explains what personal data The Top Board collects, why, how long it is kept, and what rights you have. We designed the Service to collect as little personal data as it can while still operating a paid public leaderboard safely.

Who Is Responsible (Controller)

The controller of personal data processed through the Service is ZINI advertising, an Israeli registered business (Registration No. 026580431), David Ben Gaon 36, Nahariya, Israel. Privacy contact: privacy@thetopboard.com.

What We Collect

Listing data

The URL you submit, plus metadata we fetch from the destination site to display the listing (title, description, images). Listings are public by design.

Purchaser data

Your email address, the billing country as reported by the payment provider, transaction identifiers, and payment status. We never receive full card numbers or CVV codes — the payment itself happens on the payment provider's hosted page.

Legal acceptance records

Which policy versions you accepted at checkout, and when.

Abuse reports and support communications

The content of reports you file and messages you send us, so we can act on them.

Technical and security data

For rate limiting, fraud filtering, and deduplication (for example the "online now" count and click filtering), we derive short-lived rotating pseudonymous identifiers from your network address and browser information using keyed hashing. This data is pseudonymous, not anonymous. The hashing key rotates on a schedule (by default every 24 hours), so these identifiers cannot be linked across rotation periods. Raw IP addresses are not stored in our application database.

Aggregate statistics

Per-day, per-country counters of page views, visits, and clicks. These counters contain no identifiers; the country is derived from country headers provided by our infrastructure, not from stored IP addresses.

Infrastructure Logs

Our hosting and CDN providers may briefly process IP addresses in their own security and operational logs, under their own retention rules. For logs we control, we target a baseline retention of about 7 days for security-relevant raw data.

Why We Process Data (Purposes)

  • Providing the Service: displaying listings, computing rankings.
  • Processing and verifying payments and issuing refunds.
  • Fraud prevention, rate limiting, click filtering, and security.
  • Live and aggregate statistics that contain no identifiers.
  • Moderation and handling of abuse reports.
  • Legal and accounting compliance.
  • Responding to support requests.

Where the GDPR or a similar law applies, our legal bases are: performance of a contract (providing placements you paid for), legitimate interests (security, fraud prevention, operating public statistics), and legal obligation (accounting and tax records).

Who Receives Data (Recipients and Processors)

  • The external payment provider, which processes your payment on its hosted page. The active processor for this deployment is a test payment provider (development only).
  • Hosting and database hosting providers that run the Service.
  • An email delivery provider, if configured, for transactional emails.
  • Google (Google Tag Manager and Google Analytics 4), used only for the categories you consent to. See “Analytics, Cookies, and Consent” below.
  • Meta (Meta Pixel and the Meta Conversions API), used for advertising measurement: the browser Pixel only with your Advertising consent, and a server-side conversion report for completed purchases. See “Analytics, Cookies, and Consent” below.

Some providers may process data outside your country. Where required, transfers are covered by appropriate safeguards. [Configuration-dependent — details depend on the providers the operator selects.]

How Long We Keep Data (Retention Summary)

  • Raw IP addresses in our application database: not intentionally persisted.
  • Anti-abuse pseudonymous identifiers: about 24 hours (the key rotation period).
  • Security logs we control: about 7 days baseline.
  • Aggregate country/traffic statistics: retained (aggregated, no identifiers).
  • Financial records and legal acceptance records: as long as legally required (accounting and tax law).
  • Abuse reports and support communications: kept for a limited period, then deleted.

Your Rights

Where applicable law grants them, you have the right to access, correct, or delete your personal data, to object to or restrict processing, and to complain to a supervisory authority. To exercise a right, email privacy@thetopboard.com; we may need to verify that a request relates to your own data.

We do not sell personal information. We do not share browsing data for cross-context behavioral advertising except to the extent you switch on the “Advertising” category in our consent controls; if you do not, no advertising signals are collected from your browser. Separately, when you complete a purchase we report that conversion server-side to our advertising platform (Meta Conversions API) using hashed identifiers (a one-way hash of the payer email and billing country, the order value, and — when you arrived via an ad — the ad-click id), so we can measure whether our advertising works. This concerns completed purchases only, never your browsing. We send no marketing emails without a separate opt-in — only transactional emails related to your purchases and listings.

Analytics, Cookies, and Consent

Strictly necessary storage (always on). We use a small amount of first-party storage that is essential to run the Service and is not used for tracking: an HttpOnly authentication cookie for administrators; a locally stored record of your consent choice; and a locally stored record of how you arrived (for example UTM campaign tags or a referrer) so we can attribute a purchase to the campaign that led to it. These are first-party and are never sold.

First-party analytics (necessary). Independently of any third party, we keep privacy-preserving counters — an approximate “online now” count, a cumulative “visitors since launch” count, and per-listing click counts — using the short-lived rotating pseudonymous identifiers described above. These contain no raw IP address and are not third-party tracking.

Google Tag Manager and Google Analytics 4 (consent-based). With your consent we load Google Tag Manager, which runs Google Analytics 4 to help us understand aggregate usage. We implement Google Consent Mode v2: before you choose, analytics and advertising storage are set to “denied”, so Google sets no analytics or advertising cookies. Google acts as our processor for analytics; usage data may be processed by Google outside your country under its own safeguards.

Advertising signals (consent-based). Advertising storage and ad personalization signals remain denied unless you enable the “Advertising” category.

Meta Pixel and Conversions API (consent-based / purchase measurement). If you enable the “Advertising” category, we load the Meta Pixel, which may set the _fbp and _fbc cookies and reports page views, checkout starts, and purchases to Meta to measure our advertising. Without that consent, no Meta code loads and no Meta request is made from your browser; withdrawing consent stops further Pixel tracking. Independently of browser consent, when a purchase is completed we report that single conversion to Meta server-side using hashed identifiers, as described under “Your Rights” above. Meta processes this data under its own terms; data may be processed outside your country.

Your control. When you first visit, a consent banner lets you Accept all, Reject non-essential, or manage each category (Necessary is always on; Analytics and Advertising are optional). You can change your choice at any time using the “Privacy preferences” link in the footer, without clearing your browser storage. Rejecting non-essential categories does not affect any core functionality — ranking, checkout, the public counters, click counts and live activity all keep working.

Children

The Service is not intended for anyone under 18, and we do not knowingly collect data from children. If you believe a child has provided us data, contact the privacy email above and we will delete it.

Changes to This Policy

We may update this policy; the version and dates above identify the edition in force. Material changes will be reflected in a new version number before they take effect.

Contact

Privacy requests: privacy@thetopboard.com. Other channels are listed on the Contact page.