Privacy Policy

Effective: September 2026 | Contact: contact@top5fella.com

1. Overview

This Privacy Policy describes how top5fella.com ("we", "us", "our", or "top5fella") collects, uses, discloses, and protects your information. We are committed to being transparent about how we process your data and respect your privacy rights.

2. Information We Collect

Email Address

When you sign up, we collect your email address. This is required for account creation, login, email verification, and account recovery (password reset).

Password & Authentication

Passwords are hashed using bcryptjs before storage; we never store or see your plain password. If you use Google OAuth, your Google account is linked securely via the NextAuth platform.

IP Address (Hashed)

Your IP address is collected and stored as a cryptographic hash (SHA-256) for fraud prevention, abuse detection, and security. We do not store or use raw IP addresses. The hash is used to identify suspicious patterns (velocity, cross-account overlap, datacenter access) but cannot be reversed to recover your original IP.

Device Fingerprint

We collect a device fingerprint—a hashed identifier based on browser attributes (user agent, fonts, canvas hash, WebGL data)—to detect abuse and prevent multi-account fraud. The fingerprint is hashed and cannot identify you personally.

Network & Geolocation Signals

We infer your autonomous system number (ASN), approximate geolocation (country/region, not precise street-level), and VPN/proxy usage from IP address data. These signals are used for fraud prevention only and are not sold to third parties.

Cookies & Browser Storage

We use secure, httpOnly, sameSite cookies for session management and authentication. localStorage may store user consent preferences (e.g., cookie banner acceptance). These are essential for security and functionality; they are not used for tracking or advertising.

Payment Information

All payments are processed by Stripe, Inc. You enter your card details on a page served by Stripe, not by us. Your full card number never touches our servers. We store only what we need to run your subscription: your Stripe customer and subscription identifiers, your plan and its status, and, so you can recognise the card on file in your account page, the card brand and last four digits that Stripe supplies to us. We never see or store your full card number, expiry date or security code. See Stripe's Privacy Policy for details on their processing.

Usage Data

We log when you use simulations (session timestamps, simulation ID, run success/failure for debugging). This data helps us detect abuse and improve the service. Usage logs are not shared with third parties.

3. How We Use Your Information

  • Account management: registration, login, email verification, password reset.
  • Service delivery: processing subscriptions, computing simulation runs, managing quotas.
  • Fraud & abuse prevention: detecting multi-account schemes, velocity attacks, datacenter abuse.
  • Security: detecting unauthorized access, protecting against credential compromise.
  • Billing & payments: processing subscriptions, handling disputes (via Stripe webhooks).
  • Legal compliance: responding to lawful requests from authorities.
  • Service improvement: analyzing error logs, usage patterns (anonymized).

What we do not do

  • We do not sell, rent or trade your personal information to anyone.
  • We do not use your personal information, your account activity or your simulation runs to train artificial-intelligence or machine-learning models, and we do not provide them to anyone else for that purpose.
  • We do not show advertising, and we do not share your information with advertisers or data brokers.
  • We do not build profiles of you for marketing. The only automated decisions we make are the fraud and abuse checks described above, which can limit sign-ups or simulation runs. If one of those checks affects you, contact us and a person will review it.
  • We collect the minimum needed to run the service. If we do not need it to give you the simulations you signed up for, keep your account secure or meet a legal obligation, we do not collect it.

4. Data Sharing & Third Parties

We do not sell, rent, or trade your personal data to third parties. We share data only as necessary for service delivery:

  • Stripe: payment processor (PCI-DSS compliant). See their Privacy Policy.
  • Resend: transactional email service (for verification & reset emails). See their Privacy Policy.
  • Upstash Redis: rate limiting & session storage (EU). See their Privacy Policy.
  • Neon (PostgreSQL): database hosting (EU). See their Privacy Policy.
  • Vercel: hosting & analytics (privacy-friendly). See their Privacy Policy.
  • Cloudflare Turnstile: CAPTCHA (privacy-focused, no third-party tracking). See their Privacy Policy.
  • Sentry: error monitoring. Receives technical error reports, which may include a hashed IP address and the page that failed, so we can fix bugs. See their Privacy Policy.
  • Google: only if you choose to sign in with Google. Google tells us your email address and that it is verified; we do not receive your contacts, calendar or anything else. See their Privacy Policy.

These providers process data on our behalf under their own privacy and security terms, and we do not give any of them your data for advertising or for training their models. Stripe is the one exception to “on our behalf”: as a payment processor it also handles payment data in its own right, for example to detect fraud, under its own policy linked above.

5. Data Retention

We retain personal data only as long as necessary:

  • Active accounts: email, password hash, device fingerprint, hashed IP — retained while your account is active.
  • Usage logs: session records retained for 90 days for debugging & abuse investigation.
  • Fraud signals: risk scores retained for 180 days to detect patterns; older records anonymized.
  • Billing records: Stripe subscription data retained per legal/tax requirements (typically 7 years).
  • Soft deletion: when you delete your account, we mark it deletedAt (soft-delete) and stop processing data, but retain it encrypted for 7 years for legal/fraud defense.

6. Your Privacy Rights

top5fella is operated from Victoria, Australia, and we handle personal information in line with the Australian Privacy Principles in the Privacy Act 1988 (Cth). If you are in the European Union or the United Kingdom, the GDPR gives you equivalent rights, and we honour them for everyone regardless of where you live. You have the right to:

  • Access: request a copy of your personal data. Use Export my data on your account page for an immediate download, or email us.
  • Correction: update or correct inaccurate data via your account settings.
  • Deletion (Right to be Forgotten): request erasure of your data. Available in account settings; we will delete active data within 30 days (legal/tax records retained per obligation).
  • Data portability: receive your data in a portable, machine-readable format. Export my data on your account page provides this as JSON.
  • Restriction of processing: limit how we use your data.
  • Object: object to processing for certain purposes (e.g., profiling for fraud).

To exercise these rights, contact us at contact@top5fella.com. We aim to respond within 30 days. If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au, or to the data-protection authority in your own country.

7. Security

We implement industry-standard security measures:

  • TLS (HTTPS) for all communications.
  • Passwords hashed with bcryptjs (no plaintext storage).
  • Database encryption in transit and at rest (Neon).
  • Secrets stored only in environment variables, never in code.
  • Rate limiting to prevent brute-force attacks.
  • CSRF protection on all state-changing endpoints.
  • Regular dependency scanning (npm audit).

No security is perfect. If you suspect unauthorized access to your account, contact us immediately at contact@top5fella.com.

8. Cookies & Consent

We use cookies for:

  • Authentication: session tokens (NextAuth).
  • Security: CSRF tokens, fraud prevention flags.
  • Preferences: consent banner dismissal (localStorage).

These are essential for functionality and security, not tracking or advertising. You can manage cookies in your browser settings, but disabling them may break login and session management.

9. International Transfers

Our infrastructure (Vercel, Neon, Upstash) is hosted in the EU. If you access the site from outside the EU, your data may be transferred across borders. By using top5fella.com, you consent to such transfers. We ensure appropriate safeguards (e.g., Standard Contractual Clauses) are in place.

10. Policy Updates

We may update this Privacy Policy as needed. Material changes will be posted here with an updated "Effective"date. Continued use of the site after changes constitutes acceptance.

11. Contact Us

Questions or concerns about this Privacy Policy? Contact us at: contact@top5fella.com