← TopPair
Draft — pending legal review. This privacy policy applies to both our website and our mobile app. It is provided in good faith but has not yet been reviewed by a lawyer and will be finalised with legal counsel before the commercial launch. TopPair uses play money only — there is no real-money gambling, no deposits and no cash-outs.

Privacy policy

Information pursuant to Art. 13 GDPR — applies to the TopPair website and mobile app

1. Controller

The controller responsible for processing personal data in connection with the TopPair website and mobile app is:

Jaron Schleer
Am Lehenbühl 16, 79423 Heitersheim, Germany
E-mail: jaron.schleer@gmail.com

2. Purposes and legal bases of processing

2.1 Providing the platform (account data)

When you register — on the website or in the app — we process your e-mail address, display name and password hash. If you sign in with Google OAuth we also process your profile picture and Google ID.

  • Legal basis: Art. 6(1)(b) GDPR (performance of a contract)
  • Retention: until you request deletion, and at most 30 days after account closure

2.2 Game and training progress

We store your training results, hand histories, achievements and ELO ratings so your learning progress is preserved across the website and the app.

  • Legal basis: Art. 6(1)(b) GDPR
  • Retention: for as long as your account is active

2.3 Payment processing (Pro subscription via the app stores)

Currently inactive: Paid Pro subscriptions are disabled during the beta. The information below describes what will happen once payments go live; no payment data is being processed right now.

Pro subscriptions are sold and billed exclusively through the app stores — the Apple App Store (on iOS) and Google Play (on Android). Apple and Google act as seller / merchant of record: they process the payment, collect any applicable tax and issue the receipt. We never receive or store your payment details (card number, billing address, etc.) — these are handled entirely by Apple or Google. We only receive a purchase confirmation in order to unlock your Pro access.

  • Legal basis: Art. 6(1)(b) GDPR (performance of a contract)
  • Recipients:
    • Apple Inc., One Apple Park Way, Cupertino, CA 95014, USA (App Store)
    • Google Ireland Ltd, Gordon House, Barrow Street, Dublin 4, Ireland (Google Play)
  • Their privacy policies: apple.com/legal/privacy · policies.google.com/privacy
  • Retention: we only store whether your account is Pro plus the plan and expiry date; billing records are kept by the stores under their own policies.

2.4 Server logs

Each time you access our website or use our app, our server automatically stores technical data (IP address, timestamp, requested resource, user agent) for at most 14 days to defend against attacks and keep the service stable.

  • Legal basis: Art. 6(1)(f) GDPR (legitimate interest in IT security)

2.5 Hosting

The platform is hosted on the infrastructure of Railway Corp. (548 Market St PMB 75827, San Francisco, CA 94104, USA). Railway acts as a data processor within the meaning of Art. 28 GDPR and processes the data listed above on our behalf only.

  • Legal basis: Art. 6(1)(f) GDPR (legitimate interest in providing a reliable platform)
  • Transfers to third countries: Railway is a US company; transfers are safeguarded through Standard Contractual Clauses (Art. 46(2)(c) GDPR) and, where applicable, the EU–US Data Privacy Framework. The actual server region used for this platform is within the European Union whenever possible. Details: railway.com/legal/dpa

2.6 Error monitoring (Sentry)

We use Functional Software, Inc. d/b/a Sentry (45 Fremont Street, 8th Floor, San Francisco, CA 94105, USA) to capture and analyse application errors and crashes on the website and in the app. Sentry receives technical data such as IP address, user agent, the URL or screen on which an error occurred, a stack trace and — when you are logged in — your user id. We use the EU data residency option; events are stored in EU data centers.

  • Purpose: detecting and fixing software defects, improving reliability
  • Legal basis: Art. 6(1)(f) GDPR (legitimate interest in a stable service)
  • Retention: 30 days by default
  • Transfers to third countries: Sentry is a US company; transfers are safeguarded through Standard Contractual Clauses (Art. 46(2)(c) GDPR) and, where applicable, the EU–US Data Privacy Framework. Details: sentry.io/legal/privacy

2.7 Analytics (Plausible)

We use Plausible Insights OÜ (Västriku tn 2, 50403 Tartu, Estonia) for cookieless, privacy-friendly analytics. Plausible processes the page URL, referrer, anonymized IP address and user-agent string. No cookies are set, no cross-site tracking, no personal profiles are built. Data is processed and stored in the European Union.

  • Purpose: aggregated, anonymous usage statistics (page views, referrers)
  • Legal basis: Art. 6(1)(f) GDPR (legitimate interest in measuring reach without identifying visitors)
  • Retention: aggregated statistics indefinitely; no raw personal data is stored
  • Transfers to third countries: none — Plausible hosts entirely within the EU. Details: plausible.io/privacy

2.8 Mobile app and app stores

Our mobile app is distributed through the Apple App Store and Google Play. When you download or update the app, Apple or Google process installation and device data under their own privacy policies; we do not receive your store-account credentials.

While you use the app, technical data such as device type, operating-system version and app version may be processed to deliver and secure the service (this is the same processing described in sections 2.1–2.7, applied to the app). The app does not use advertising identifiers, does not display ads, and does not share data with third-party advertising or tracking networks.

  • Legal basis: Art. 6(1)(b) GDPR (performance of a contract) and Art. 6(1)(f) GDPR (legitimate interest in a secure, reliable app)

3. Cookies and local storage

On the website we use strictly necessary cookies and similar technologies (e.g. localStorage); in the app we use the device's local storage for the same purposes — keeping you logged in and remembering UI preferences. These do not require consent (§ 25(2) no. 2 TTDSG, Art. 6(1)(b) GDPR).

We do not use analytics cookies, advertising identifiers or cross-site tracking. If we add optional cookies later we will introduce a consent banner and only set them after you give your explicit consent.

4. Age requirement

Our service is intended for adults and is not directed at children. You may only use TopPair if you are at least 18 years old (see our Terms and Conditions). We do not knowingly process personal data from anyone under that age.

5. Your rights

You can exercise the following rights against us at any time:

  • Access to the personal data we store about you (Art. 15)
  • Rectification of inaccurate data (Art. 16)
  • Erasure (“right to be forgotten”, Art. 17)
  • Restriction of processing (Art. 18)
  • Data portability (Art. 20)
  • Objection to processing (Art. 21)
  • Withdrawal of consent with effect for the future (Art. 7(3))

An informal message to jaron.schleer@gmail.com is enough to exercise any of these rights. You can also delete your account and all associated data yourself at any time under Profile → Delete account.

6. Right to lodge a complaint

You have the right to lodge a complaint with a data protection supervisory authority about our processing of your personal data (Art. 77 GDPR). The competent authority is the one in your place of residence or in our place of business.

7. Data security

All data is transmitted over encrypted connections (HTTPS/TLS). Passwords are stored only as salted hashes, never in plain text. We apply technical and organisational measures appropriate to the risk (Art. 32 GDPR) to protect your data against loss, misuse and unauthorised access.

8. Changes to this policy

We update this privacy policy when our data processing changes. We will inform you of any material changes by e-mail or through a notice in the app or on the website.

Last updated: 21 June 2026

This document is a good-faith draft and has not yet been reviewed by a lawyer. A qualified lawyer should review it before the commercial launch.