Privacy Policy
Last updated: April 28, 2026
1. Who We Are
Faisal Mohammed Al Sooj ("we", "us"), trading as "Top Ten List" / "ALSOOJ", operates the Top Ten List game and website at toptenlist.app (the "Service"). We act as the data controller for the personal data described in this Privacy Policy.
2. Data We Collect
We collect the following categories of personal data:
- Account data: email address, display name, and (optionally) profile information from sign-in providers (Google, Apple).
- Device and session data: a generated device identifier, IP address, browser/OS information, and timestamps used to enforce single-device sessions and prevent account sharing.
- Game progress: categories played, scores, history, unlocked content, and preferences.
- Support communications: messages you send us via email or in-app feedback.
- Cookies and similar storage: used for session management, preferences, and basic analytics.
Payment card details are collected and processed by our payment provider, Paddle, and are never stored by us.
3. How We Use Your Data
- To create and operate your account and provide the Service;
- To enforce single-device sessions and prevent abuse, fraud, and account sharing;
- To process and fulfill purchases and subscriptions (via Paddle);
- To respond to support requests;
- To improve the Service, fix bugs, and develop new features;
- To comply with legal obligations.
4. Legal Basis
We process personal data on the following bases:
- Contract: to provide the Service you requested;
- Legitimate interests: security, fraud prevention, product improvement;
- Consent: where required (e.g. optional analytics or marketing);
- Legal obligation: tax, accounting, and compliance.
5. Sharing With Third Parties
We share personal data only with the following categories of recipients:
- Paddle.com — our Merchant of Record for the sale of digital products. Paddle handles payments, subscription management, tax compliance, invoicing, and refunds. See Paddle's Privacy Notice.
- Supabase — backend hosting, authentication, and database services that store account and game data on our behalf.
- Sign-in providers (Google, Apple) — only when you choose to sign in with them.
- Professional advisers (legal, accounting) when needed.
- Authorities where required by law.
We do not sell your personal data.
6. International Transfers
Our service providers may process data outside Qatar (including in the EU and the United States). Where required, we rely on appropriate safeguards such as standard contractual clauses.
7. Data Retention
We keep personal data for as long as your account is active and for a reasonable period afterwards to comply with legal, tax, accounting, and dispute-resolution obligations. When data is no longer needed, we delete or anonymise it.
8. Your Rights
Subject to applicable law, you may have the right to access, correct, delete, restrict, or port your personal data, to object to certain processing, and to withdraw consent. To exercise any of these rights, contact us at privacy@toptenlist.app. You also have the right to lodge a complaint with the data protection authority in your country.
9. Security
We use appropriate technical and organisational measures, including encryption in transit, access controls, and row-level database security, to protect personal data. No system is 100% secure, but we work hard to keep your data safe.
10. Cookies
We use essential cookies and local storage for sign-in sessions, device session enforcement, and saving your preferences (e.g. dark mode, sound). We may also use minimal analytics. You can control cookies through your browser settings.
11. Children
The Service is not intended for children under 13 (or the minimum age in your jurisdiction). We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us so we can remove it.
12. Changes
We may update this Privacy Policy from time to time. Material changes will be communicated through the Service.
13. Contact
For privacy questions, contact privacy@toptenlist.app.