This version is retained for earlier accepted orders. Its historical service descriptions are not the current campaign offer. View current policies and version information.
Clarified: September 5, 2026 — SaaS and app eligibility and vendor-provided access.
This Privacy Policy explains what personal information TopSlash collects, how we use it, who we share it with, and the choices you have. TopSlash is operated by Envol, Inc., a California corporation ("we", "us"). It applies to https://topslash.app and to the emails we send.
Short version: we collect the minimum needed to run a leaderboard and marketplace for SaaS and apps. We do not sell personal information. We do not use advertising trackers or analytics cookies. Cloudflare may set strictly necessary, short-lived security cookies. Visitors are counted with a daily-rotating hash, not with an advertising identifier. When you buy a deal, the vendor becomes the seller and receives your email and transaction information through Stripe.
1. Information we collect
From everyone who visits (no account):
- A visitor hash. For each page view we compute a one-way hash of your IP address, browser user-agent string, and language setting, combined with a secret salt that changes every day. We store the hash, not the inputs. The hash cannot be turned back into your IP address, and because the salt changes daily, hashes from different days cannot be linked. We use it to count unique visitors, to count one outbound click per visitor per listing per day, and to accept one abuse report per visitor per listing.
- Security logs. When a request is blocked or rate-limited, or a security check fails, we record a hashed IP address, the Cloudflare request id, and technical details of the event. We never log raw IP addresses, emails, tokens, or card data in application logs.
- Our providers Cloudflare and Hetzner see the IP addresses of requests as part of delivering and protecting the site (Section 5).
If you create an account:
- Your email address (from the one-time code you request, or from your Google account if you sign in with Google). If you use Google sign-in, Google gives us your email address and basic profile information (name and profile picture); we store only what we need, which is the email address and, if you keep it, the display name.
- Your display name and, if you add one, your X handle. The X handle appears on your listing if you are a founder.
- Your marketing preference (opt-in only; there is no marketing email at launch).
- Account activity: sign-in times, listings, deals, claims, purchases, appeals, and reports linked to your account.
If you are a founder or vendor:
- The website URL you submit, everything our verification extracts from your public site (title, description, logo, screenshot, pricing link, social links, a text sample), the verification results, and your edits.
- Your Paid Rank payments: amount, time, Stripe payment and session ids, the receipt Stripe sends, and whether the payment published a listing or unlocked deal creation. The payment history is public by listing name.
- Your deal: plan name, features, normal annual price, renewal price, refund policy, support and cancellation links, the public pricing URL attached to your listing, and available listing-verification evidence, which may include public-page text and a screenshot.
- Your Stripe connected account id and its status (whether charges and payouts are enabled, what Stripe still requires), and the business name and country Stripe reports for the account. The business name and country are shown to buyers as "Sold by".
- Sales events on your Stripe account that relate to TopSlash deals: purchases, refunds, disputes, and subscription cancellations.
If you are a buyer:
- Your claims (which deal, which tier, when) and your purchases: product, plan, amount paid, savings, renewal date, renewal price, and the Stripe session, subscription, invoice, and customer ids on the vendor's account. We never receive or store your card number. Card details go directly to Stripe on Stripe's own pages.
- Refunds, disputes, and cancellations that Stripe reports to us.
If you contact us:
- The name, email address, and message you send through the contact form, report form, or appeal form, or by email. Report forms may be sent without an account; in that case we store a visitor hash with the report.
Emails we send:
- A log of each transactional email: the template, a hash of the address, the delivery status, and the provider's message id.
We do not knowingly collect sensitive information (such as government ids, health, or precise location), and you should not send it to us.
2. How we use information
- To run the Service: accounts, sign-in, listings, verification, the leaderboard, deals, claims, purchases, the public bid history, and public counters.
- To process payments through Stripe and to keep the financial ledger the law requires.
- To send transactional emails: sign-in codes, listing status, payment confirmations, purchase confirmations, renewal reminders, hold expirations, removal notices, appeal decisions, and account deletion confirmations.
- To keep the Service safe: fraud prevention, abuse prevention, rate limiting, bot detection, security investigations, and moderation.
- To answer your messages and to handle reports and appeals.
- To measure the Service with our own counters and error monitoring.
- To meet legal obligations, including tax, accounting, and automatic-renewal-law record keeping.
We do not use your information for behavioral advertising, and we do not build advertising profiles.
3. Legal bases for processing
Where data-protection law requires a legal basis, we rely on:
- Contract. We process account, listing, claim, purchase, and service communications as needed to provide the Service and carry out our contracts with you.
- Legitimate interests. We process limited technical, security, verification, moderation, fraud-prevention, measurement, and support information to operate and protect TopSlash, its users, and the integrity of its public records. We balance those interests against your rights.
- Legal obligations. We keep and disclose records when needed for tax, accounting, automatic-renewal, sanctions, court, regulatory, and other legal duties.
- Consent. We rely on consent for optional marketing and any other processing for which we specifically ask. You may withdraw consent at any time without affecting processing that already occurred.
4. What is public
The following is public on TopSlash and is meant to be:
- Listing content (name, tagline, description, category, logo, screenshot, website link, and X handle if you added one).
- Every placement payment and reversal, by listing name, amount, time, and resulting position, forever, on the Complete Bid History page. The founder's personal name is not shown.
- Deal content, including prices, the vendor's refund policy, and the vendor's business name and country from Stripe.
- Counters: unique visitors, approved listings, confirmed placement revenue, unique outbound clicks, claims, verified purchases, and verified savings. These are totals. Buyer identities are never public.
5. Who we share information with
We share information only with the providers that run the Service, with vendors when you buy from them, and when the law requires. We do not sell personal information, and we do not share it for cross-context behavioral advertising.
Vendors. When you buy a deal, the vendor is the seller. The vendor receives your email address and the billing and transaction information that Stripe makes available on its connected account; neither the vendor nor TopSlash receives your full card number from Stripe Checkout. We email the vendor your email address, plan, tier, and amount so it can fulfill your order. From then on, the vendor's privacy policy governs what the vendor does with that information.
Service providers (processors). Each one processes information only to provide its service to us:
- Stripe (payments, connected accounts, receipts). Stripe collects your card details directly on its own pages and is an independent controller for the information it collects. See Stripe's privacy policy at https://stripe.com/privacy.
- Supabase (database and authentication hosting).
- Hetzner (servers that run the application).
- Cloudflare (network delivery, DDoS protection, firewall, bot protection, the Turnstile human-check widget, and Browser Rendering, which takes screenshots of public websites submitted for listing).
- Resend (sending our emails).
- Google Web Risk (checks whether a submitted public website URL is known to be malicious; we send only the public URL).
- OpenAI (classifies the public text of a submitted website to check that it describes an eligible SaaS or app and not a prohibited category; we send only public website content, never your account information).
- Sentry (error monitoring; receives technical details about failures, a request id, and a hashed user id when you are signed in).
- Google (if you choose Google sign-in; Google's privacy policy governs your Google account).
Legal and safety. We may disclose information if required by law, subpoena, or court order; to protect the rights, property, or safety of users, Envol, Inc., or the public; to investigate fraud or abuse; or in connection with a merger, sale, or reorganization of our business, in which case the new owner is bound by this policy.
6. Cookies and similar technologies
- TopSlash sets no analytics or advertising cookies on public pages. Visitor counting uses the daily-rotating hash described in Section 1. Cloudflare may set the strictly necessary security cookies described below.
- When you sign in, we set the session cookies needed to keep you signed in. They are essential and are not used for tracking.
- During listing submission, if you start before signing in, we keep the URL you entered in an encrypted cookie for 15 minutes so that it survives the sign-in step.
- Cloudflare may set short-lived, strictly necessary security cookies (for example
__cf_bmorcf_clearance) to distinguish legitimate requests from automated abuse. These cookies are used for security, not advertising or profiling, and expire according to Cloudflare's configuration. - Stripe sets its own cookies on its checkout pages under its own policy.
We use no advertising cookies, no analytics cookies, and no third-party trackers on our pages. We do not allow third parties to collect information about your activity across sites through our Service.
7. Do Not Track and Global Privacy Control
We do not track you across other websites or over time for advertising, so there is nothing for a "Do Not Track" signal to turn off. We treat every visitor as if the signal were on. We do not sell or share personal information, so a Global Privacy Control signal changes nothing either; you are already opted out.
8. How to review, change, or delete your information
- Review and change. Sign in and open your account settings to see and edit your display name, X handle, and marketing preference. Your listings, deals, claims, and purchases are on your dashboard and account pages. For anything else, email us.
- Delete your account. Sign in, open account settings, and choose delete. Your profile is pseudonymized: your display name becomes "Deleted user", your email address is removed from the authentication system, and your listings are unpublished unless you transferred them. We will email a confirmation to the address you had.
- What deletion does not remove. Financial ledgers are kept as the law requires: Paid Rank payments, reversals, historical listing-fee records, purchases, refunds, disputes, and the Stripe events behind them. The public bid history keeps your listing name and amounts. Security logs and moderation records are kept for as long as they are needed for security. We delete or anonymize personal information when its purpose ends unless we need it for a legal, security, fraud-prevention, dispute, backup, or public-ledger reason described here. A deleted account cannot be restored, and deleting your TopSlash account does not cancel any subscription you have with a vendor; cancel that with the vendor.
- Email requests. You can also email support@topslash.app from the address on your account to ask for a copy of your information, a correction, or deletion. We answer within 30 days. We may ask you to confirm the request from your account email.
9. How long we keep information
- Raw visitor hashes: 35 days, then only the daily totals are kept. The in-memory counting keys expire within 40 days.
- Outbound click records: retained to maintain public counters and investigate abuse. They contain a daily-rotating visitor hash and listing id; the hash cannot be used to recognize the same visitor on another day.
- Financial ledgers (Paid Rank payments, reversals, historical listing-fee records, purchases, refunds, disputes, Stripe events): retained as permanent audit records for accounting, tax, fraud prevention, audits, and disputes. Records of automatic-renewal consent are kept for at least 3 years or 1 year after the subscription ends, whichever is longer.
- Public bid history: permanent.
- Account information: for as long as your account exists, then pseudonymized as described in Section 8.
- Listings and deals: for as long as they are live; removed listings keep their history.
- Verification results and pricing evidence: for as long as the listing exists and afterwards when needed to investigate a complaint, appeal, or pricing dispute.
- Support, report, and appeal messages: while the matter is active and afterwards when reasonably needed for support records, safety, or disputes.
- Security events and email logs: while reasonably needed to prevent or investigate fraud, abuse, delivery problems, or a legal dispute.
- Server and proxy logs: rotated automatically and kept only as long as reasonably needed for operations and security. They are configured not to retain raw client IP addresses or request headers.
- Error reports (Sentry): for up to 90 days under our current Sentry plan.
10. Children
TopSlash is not for people under 18. We do not knowingly collect personal information from anyone under 18. If you believe a person under 18 has given us information, email us and we will delete it.
11. California residents
Envol, Inc. is a small company. At this time we do not meet the thresholds that make the California Consumer Privacy Act (CCPA, as amended by the CPRA) apply to a business. We honor its core rights anyway:
- Right to know. Ask us what personal information we hold about you and how we use it. Sections 1 and 5 describe it; email us for your specific records.
- Right to delete. Delete your account yourself (Section 8) or ask us by email.
- Right to correct. Edit your profile, or ask us by email.
- No sale or sharing. We do not sell personal information and do not share it for cross-context behavioral advertising, and we have not done so in the past 12 months. We therefore offer no "Do Not Sell or Share" link; there is nothing to opt out of.
- No discrimination. We will not treat you differently for exercising these rights.
- Shine the Light (Civil Code section 1798.83). We do not disclose personal information to third parties for their own direct-marketing purposes.
We will re-evaluate CCPA applicability as the business and applicable legal thresholds change and will update this policy when required. Sections 6 and 7 explain our cookie practices, response to Do Not Track and Global Privacy Control signals, and whether third parties collect information across websites.
12. EEA, United Kingdom, and other users outside the United States
TopSlash is operated from the United States, and your information is processed in the United States and wherever our providers operate. Where transfer law applies, we and our providers use an available lawful transfer mechanism, such as approved standard contractual clauses or another recognized safeguard. Contact us if you want information about the mechanism relevant to your information.
If the General Data Protection Regulation, United Kingdom GDPR, or a similar law applies to you, you may have the right to access and correct your information; request deletion; restrict or object to processing; receive portable information you supplied; withdraw consent; and complain to the data-protection authority where you live or work. These rights can have legal exceptions. Email support@topslash.app to exercise them. We will verify your identity and respond within the period required by applicable law.
Envol, Inc. is the controller for TopSlash's processing described in this policy. Vendors are independent controllers for buyer information they receive. We do not currently maintain an EEA or United Kingdom representative. We do not intentionally direct paid TopSlash services to those regions until any legally required representative and related launch controls are in place; mere website availability there is not an offer of paid services.
13. Security
We use Stripe so that card data never touches our systems, hash visitor and IP data, encrypt data in transit, limit who can access production systems, log security events, and keep append-only financial ledgers. No system is perfectly secure. If we learn of a breach that affects your personal information, we will notify you as the law requires.
14. Changes to this policy
We may update this policy. When we do, we post the new version at https://topslash.app/privacy with a new effective date. If the change is material, we also email account holders before it takes effect.
15. Contact
Envol, Inc., operating TopSlash. Email: support@topslash.app. Postal address: Envol, Inc., 2108 N St Ste N, Sacramento, CA 95816, United States. You can also use the contact form.