Privacy Policy
Version 1.0 · Effective 2026-08-22 · Last updated 2026-08-22
This policy explains what personal data The Top Board collects, why, how long it is kept, and what rights you have. We designed the Service to collect as little personal data as it can while still operating a paid public leaderboard safely.
Who Is Responsible (Controller)
The controller of personal data processed through the Service is ZINI advertising, an Israeli registered business (Registration No. 026580431), David Ben Gaon 36, Nahariya, Israel. Privacy contact: privacy@thetopboard.com.
What We Collect
Listing data
The URL you submit, plus metadata we fetch from the destination site to display the listing (title, description, images). Listings are public by design.
Purchaser data
Your email address, the billing country as reported by the payment provider, transaction identifiers, and payment status. We never receive full card numbers or CVV codes — the payment itself happens on the payment provider's hosted page.
Legal acceptance records
Which policy versions you accepted at checkout, and when.
Abuse reports and support communications
The content of reports you file and messages you send us, so we can act on them.
Technical and security data
For rate limiting, fraud filtering, and deduplication (for example the "online now" count and click filtering), we derive short-lived rotating pseudonymous identifiers from your network address and browser information using keyed hashing. This data is pseudonymous, not anonymous. The hashing key rotates on a schedule (by default every 24 hours), so these identifiers cannot be linked across rotation periods. Raw IP addresses are not stored in our application database.
Aggregate statistics
Per-day, per-country counters of page views, visits, and clicks. These counters contain no identifiers; the country is derived from country headers provided by our infrastructure, not from stored IP addresses.
Infrastructure Logs
Our hosting and CDN providers may briefly process IP addresses in their own security and operational logs, under their own retention rules. For logs we control, we target a baseline retention of about 7 days for security-relevant raw data.
Why We Process Data (Purposes)
- Providing the Service: displaying listings, computing rankings.
- Processing and verifying payments and issuing refunds.
- Fraud prevention, rate limiting, click filtering, and security.
- Live and aggregate statistics that contain no identifiers.
- Moderation and handling of abuse reports.
- Legal and accounting compliance.
- Responding to support requests.
Where the GDPR or a similar law applies, our legal bases are: performance of a contract (providing placements you paid for), legitimate interests (security, fraud prevention, operating public statistics), and legal obligation (accounting and tax records).
Who Receives Data (Recipients and Processors)
- The external payment provider, which processes your payment on its hosted page. The active processor for this deployment is a test payment provider (development only).
- Hosting and database hosting providers that run the Service.
- An email delivery provider, if configured, for transactional emails.
Some providers may process data outside your country. Where required, transfers are covered by appropriate safeguards. [Configuration-dependent — details depend on the providers the operator selects.]
How Long We Keep Data (Retention Summary)
- Raw IP addresses in our application database: not intentionally persisted.
- Anti-abuse pseudonymous identifiers: about 24 hours (the key rotation period).
- Security logs we control: about 7 days baseline.
- Aggregate country/traffic statistics: retained (aggregated, no identifiers).
- Financial records and legal acceptance records: as long as legally required (accounting and tax law).
- Abuse reports and support communications: kept for a limited period, then deleted.
Your Rights
Where applicable law grants them, you have the right to access, correct, or delete your personal data, to object to or restrict processing, and to complain to a supervisory authority. To exercise a right, email privacy@thetopboard.com; we may need to verify that a request relates to your own data.
We do not sell personal information and do not share it for cross-context behavioral advertising. We send no marketing emails without a separate opt-in — only transactional emails related to your purchases and listings.
Cookies and Local Storage
We use only strictly necessary storage: an HttpOnly authentication cookie used by administrators to access the admin area. There are no analytics or marketing cookies and no third-party trackers, so there is nothing non-essential to consent to and no consent banner is shown. If that ever changes, a consent mechanism will be added before any non-essential storage is used.
Children
The Service is not intended for anyone under 18, and we do not knowingly collect data from children. If you believe a child has provided us data, contact the privacy email above and we will delete it.
Changes to This Policy
We may update this policy; the version and dates above identify the edition in force. Material changes will be reflected in a new version number before they take effect.
Contact
Privacy requests: privacy@thetopboard.com. Other channels are listed on the Contact page.

