Privacy Policy
Effective date: August 30, 2026
This Privacy Policy explains what personal information TopSlash collects, how we use it, who we share it with, and the choices you have. TopSlash is operated by Envol, Inc., a California corporation ("we", "us"). It applies to https://topslash.lol and to the emails we send.
Short version: we collect the minimum needed to run a leaderboard and a marketplace. We do not sell personal information. We do not use advertising trackers. Public pages set no cookies. Visitors are counted with a daily-rotating hash, not with a cookie or an identifier. When you buy a deal, the vendor becomes the seller and receives your email and purchase details through Stripe.
1. Information we collect
From everyone who visits (no account):
- A visitor hash. For each page view we compute a one-way hash of your IP address, browser user-agent string, and language setting, combined with a secret salt that changes every day. We store the hash, not the inputs. The hash cannot be turned back into your IP address, and because the salt changes daily, hashes from different days cannot be linked. We use it to count unique visitors, to count one outbound click per visitor per listing per day, and to accept one abuse report per visitor per listing.
- Security logs. When a request is blocked or rate-limited, or a security check fails, we record a hashed IP address, the Cloudflare request id, and technical details of the event. We never log raw IP addresses, emails, tokens, or card data in application logs.
- Our providers Cloudflare and Hetzner see the IP addresses of requests as part of delivering and protecting the site (Section 4).
If you create an account:
- Your email address (from the one-time code you request, or from your Google account if you sign in with Google). If you use Google sign-in, Google gives us your email address and basic profile information (name and profile picture); we store only what we need, which is the email address and, if you keep it, the display name.
- Your display name and, if you add one, your X handle. The X handle appears on your listing if you are a founder.
- Your marketing preference (opt-in only; there is no marketing email at launch).
- Account activity: sign-in times, listings, deals, claims, purchases, appeals, and reports linked to your account.
If you are a founder or vendor:
- The website URL you submit, everything our verification extracts from your public site (title, description, logo, screenshot, pricing link, social links, a text sample), the verification results, and your edits.
- Your placement payments: amount, time, Stripe payment and session ids, and the receipt Stripe sends. This history is public by listing name.
- Your listing fee payment, if any.
- Your deal: plan name, features, normal annual price, renewal price, refund policy, support and cancellation links, and a stored copy and screenshot of your public pricing page.
- Your Stripe connected account id and its status (whether charges and payouts are enabled, what Stripe still requires), and the business name and country Stripe reports for the account. The business name and country are shown to buyers as "Sold by".
- Sales events on your Stripe account that relate to TopSlash deals: purchases, refunds, disputes, and subscription cancellations.
If you are a buyer:
- Your claims (which deal, which tier, when) and your purchases: product, plan, amount paid, savings, renewal date, renewal price, and the Stripe session, subscription, invoice, and customer ids on the vendor's account. We never receive or store your card number. Card details go directly to Stripe on Stripe's own pages.
- Refunds, disputes, and cancellations that Stripe reports to us.
If you contact us:
- The name, email address, and message you send through the contact form, report form, or appeal form, or by email. Report forms may be sent without an account; in that case we store a visitor hash with the report.
Emails we send:
- A log of each transactional email: the template, a hash of the address, the delivery status, and the provider's message id.
We do not knowingly collect sensitive information (such as government ids, health, or precise location), and you should not send it to us.
2. How we use information
- To run the Service: accounts, sign-in, listings, verification, the leaderboard, deals, claims, purchases, the public bid history, and public counters.
- To process payments through Stripe and to keep the financial ledger the law requires.
- To send transactional emails: sign-in codes, listing status, payment confirmations, purchase confirmations, renewal reminders, hold expirations, removal notices, appeal decisions, and account deletion confirmations.
- To keep the Service safe: fraud prevention, abuse prevention, rate limiting, bot detection, security investigations, and moderation.
- To answer your messages and to handle reports and appeals.
- To measure the Service with our own counters and error monitoring.
- To meet legal obligations, including tax, accounting, and automatic-renewal-law record keeping.
We do not use your information for behavioral advertising, and we do not build advertising profiles.
3. What is public
The following is public on TopSlash and is meant to be:
- Listing content (name, tagline, description, category, logo, screenshot, website link, and X handle if you added one).
- Every placement payment and reversal, by listing name, amount, time, and resulting position, forever, on the Complete Bid History page. The founder's personal name is not shown.
- Deal content, including prices, the vendor's refund policy, and the vendor's business name and country from Stripe.
- Counters: unique visitors, approved listings, confirmed placement revenue, unique outbound clicks, claims, verified purchases, and verified savings. These are totals. Buyer identities are never public.
4. Who we share information with
We share information only with the providers that run the Service, with vendors when you buy from them, and when the law requires. We do not sell personal information, and we do not share it for cross-context behavioral advertising.
Vendors. When you buy a deal, the vendor is the seller. The vendor receives your email address and payment details on its Stripe account, and we email the vendor your email address, plan, tier, and amount so it can fulfill your order. From then on, the vendor's privacy policy governs what the vendor does with that information.
Service providers (processors). Each one processes information only to provide its service to us:
- Stripe (payments, connected accounts, receipts). Stripe collects your card details directly on its own pages and is an independent controller for the information it collects. See Stripe's privacy policy at https://stripe.com/privacy.
- Supabase (database and authentication hosting).
- Hetzner (servers that run the application).
- Cloudflare (network delivery, DDoS protection, firewall, bot protection, the Turnstile human-check widget, and Browser Rendering, which takes screenshots of public websites submitted for listing).
- Resend (sending our emails).
- Google Web Risk (checks whether a submitted public website URL is known to be malicious; we send only the public URL).
- OpenAI (classifies the public text of a submitted website to check that it is a software product and not a prohibited category; we send only public website content, never your account information).
- Sentry (error monitoring; receives technical details about failures, a request id, and a hashed user id when you are signed in).
- Google (if you choose Google sign-in; Google's privacy policy governs your Google account).
Legal and safety. We may disclose information if required by law, subpoena, or court order; to protect the rights, property, or safety of users, Envol, Inc., or the public; to investigate fraud or abuse; or in connection with a merger, sale, or reorganization of our business, in which case the new owner is bound by this policy.
[OPERATOR: confirm the hosting regions for Hetzner and Supabase so that Section 11 can name them.]
5. Cookies and similar technologies
- Public pages set no cookies. Browsing the leaderboard, listings, deals, and history is cookie-free. Visitor counting uses the daily-rotating hash described in Section 1.
- When you sign in, we set the session cookies needed to keep you signed in. They are essential and are not used for tracking.
- During listing submission, if you start before signing in, we keep the URL you entered in an encrypted cookie for 15 minutes so that it survives the sign-in step.
- Cloudflare may set a short-lived security cookie (for example
__cf_bmorcf_clearance) to tell people from bots. It carries no profile and expires quickly. [OPERATOR: confirm which Cloudflare security cookies are active on the production zone.] - Stripe sets its own cookies on its checkout pages under its own policy.
We use no advertising cookies, no analytics cookies, and no third-party trackers on our pages. We do not allow third parties to collect information about your activity across sites through our Service.
6. Do Not Track and Global Privacy Control
We do not track you across other websites or over time for advertising, so there is nothing for a "Do Not Track" signal to turn off. We treat every visitor as if the signal were on. We do not sell or share personal information, so a Global Privacy Control signal changes nothing either; you are already opted out.
7. How to review, change, or delete your information
- Review and change. Sign in and open your account settings to see and edit your display name, X handle, and marketing preference. Your listings, deals, claims, and purchases are on your dashboard and account pages. For anything else, email us.
- Delete your account. Sign in, open account settings, and choose delete. Your profile is pseudonymized: your display name becomes "Deleted user", your email address is removed from the authentication system, and your listings are unpublished unless you transferred them. We will email a confirmation to the address you had.
- What deletion does not remove. Financial ledgers are kept as the law requires: placement payments, reversals, listing fees, purchases, refunds, disputes, and the Stripe events behind them. The public bid history keeps your listing name and amounts. Security logs and moderation records are kept for as long as they are needed for security. A deleted account cannot be restored, and deleting your TopSlash account does not cancel any subscription you have with a vendor; cancel that with the vendor.
- Email requests. You can also email [email protected] from the address on your account to ask for a copy of your information, a correction, or deletion. We answer within 30 days. We may ask you to confirm the request from your account email.
8. How long we keep information
- Raw visitor hashes: 35 days, then only the daily totals are kept. The in-memory counting keys expire within 40 days.
- Outbound click records: kept indefinitely; they contain a visitor hash and a listing id, no personal information.
- Financial ledgers (placement payments, reversals, listing fees, purchases, refunds, disputes, Stripe events): kept indefinitely, as required for accounting, tax, and dispute purposes. Records of automatic-renewal consent are kept for at least 3 years.
- Public bid history: permanent.
- Account information: for as long as your account exists, then pseudonymized as described in Section 7.
- Listings and deals: for as long as they are live; removed listings keep their history.
- Verification results and stored pricing pages: for as long as the listing exists. [OPERATOR: confirm the retention period for verification runs and pricing-page snapshots.]
- Support, report, and appeal messages: [OPERATOR: confirm; suggested 2 years after the matter is closed.]
- Security events and email logs: [OPERATOR: confirm; suggested 1 year.]
- Server logs: 14 days, and they contain no raw IP addresses.
- Error reports (Sentry): per Sentry's retention for our plan, currently 90 days. [OPERATOR: confirm.]
9. Children
TopSlash is not for people under 18. We do not knowingly collect personal information from anyone under 18. If you believe a person under 18 has given us information, email us and we will delete it.
10. California residents
Envol, Inc. is a small company. At this time we do not meet the thresholds that make the California Consumer Privacy Act (CCPA, as amended by the CPRA) apply to a business. We honor its core rights anyway:
- Right to know. Ask us what personal information we hold about you and how we use it. Section 1 and Section 4 describe it; email us for your specific records.
- Right to delete. Delete your account yourself (Section 7) or ask us by email.
- Right to correct. Edit your profile, or ask us by email.
- No sale or sharing. We do not sell personal information and do not share it for cross-context behavioral advertising, and we have not done so in the past 12 months. We therefore offer no "Do Not Sell or Share" link; there is nothing to opt out of.
- No discrimination. We will not treat you differently for exercising these rights.
- Shine the Light (Civil Code section 1798.83). We do not disclose personal information to third parties for their own direct marketing. [COUNSEL: confirm the fewer-than-20-employees exemption applies to Envol, Inc. and that this sentence is sufficient.]
We will re-evaluate CCPA applicability if we reach its thresholds and update this policy. [COUNSEL: confirm the CCPA threshold statement and this section's wording for CalOPPA compliance (B&P §22575), including the "how we respond to Do Not Track" and "third-party cross-site collection" disclosures in Sections 5 and 6.]
11. Users outside the United States
TopSlash is operated from the United States, and your information is processed in the United States and wherever our providers operate. By using the Service you understand that your information is transferred to and processed in the United States, where privacy laws may differ from those of your country.
12. Security
We use Stripe so that card data never touches our systems, hash visitor and IP data, encrypt data in transit, limit who can access production systems, log security events, and keep append-only financial ledgers. No system is perfectly secure. If we learn of a breach that affects your personal information, we will notify you as the law requires.
13. Changes to this policy
We may update this policy. When we do, we post the new version at https://topslash.lol/privacy with a new effective date. If the change is material, we also email account holders before it takes effect.
14. Contact
Envol, Inc., operating TopSlash. Email: [email protected]. Postal address: Envol, Inc., 2108 N St Ste N, Sacramento, CA 95816, United States. You can also use the contact form.