International Version | Greater China Version

Privacy Policy

Last Updated: 24 June 2024

At TopHatch, we take your privacy seriously. Please read the following to learn how we treat Personal Data that we collect about you when you use or access TopHatch Services.

Remember that your use of TopHatch Services is at all times subject to the TopHatch Terms of Service. Any capitalized terms we use in this Privacy Policy without defining them have the definitions given to them in the TopHatch Terms of Service.

What this Privacy Policy Covers

This Privacy Policy covers how we collect, retain, use, disclose and otherwise treat Personal Data that we gather through:

Collectively, we refer to the App, Websites, Social Media Pages, emails, and offline business interactions as the “Services”.

"Personal Data" means any information that identifies or relates to a directly or indirectly identifiable individual and also includes information referred to as “personally identifiable information” or “personal information” under applicable data privacy laws, rules, or regulations.

This Privacy Policy does not cover the practices of companies we don’t own or control or people we don’t manage. This Privacy Policy also does not cover Personal Data that we handle on behalf of our enterprise customers as a processor; we handle such data in accordance with our applicable customer agreements.

We use third party payment services to process payments made through the Services. If you choose to make a payment through the Services, your payment-related data will be collected directly by the third party payment service rather than by us and will be subject to the third party’s privacy policy, rather than this Privacy Policy.

Sources of Personal Data

We collect Personal Data about you from:

We need to collect Personal Data to provide the requested Services to you. If you do not provide the data requested, we may not be able to provide the Services. If you disclose any Personal Data relating to other people to us or to our service providers in connection with the Services, you represent that you have the authority to do so and to permit us to use the data in accordance with this Privacy Policy.

Categories of Personal Data We Collect

The following chart details the categories of Personal Data that we collect and have collected over the twelve (12) months preceding the date this Privacy Policy was last updated and the categories of sources the Personal Data is collected from. Throughout this Privacy Policy, we will refer back to the categories of Personal Data listed in this chart (for example, “Category A. Personal identifiers”).

Category of Personal DataPersonal Data We CollectSource
A.Personal identifiers
Examples: Real name, alias, postal address, unique personal identifier, online identifier, Internet Protocol address, email address, account name, Social Security number, driver's license number, passport number or other similar identifiers.
Email address (optional)
Name (optional)
Unique personal identifier
Telephone number (optional)
IP address (we may also derive your approximate location from your IP address)
You
B.Customer records identified by state law (including the California Customer Records statute (Cal. Civ. Code § 1798.80(e)))
Examples: Name, signature, Social Security number, physical characteristics or description, address, telephone number, passport number, driver's license or state identification card number, insurance policy number, education, employment, employment history, bank account number, credit card number, debit card number or any other financial information, medical information or health insurance information.
Name (optional)
Telephone number (optional)
You
C.Protected classification characteristics under state or federal law
Examples: Age (40 years or older), race, color, ancestry, national origin, citizenship, religion or creed, marital status, medical condition, physical or mental disability, sex (including gender, gender identity, gender expression, pregnancy or childbirth and related medical conditions), sexual orientation, veteran or military status or genetic information (including familial genetic information).
We do not collect this category of Personal Data.N/A
D.Commercial information
Examples: Records of personal property, products or services purchased, obtained, or considered, or other purchasing or consuming histories or tendencies.
Purchase information is sent to us via billing partners (for example, Apple, Google) when you make a purchase of a feature of one of our applications via their store.Affiliates and business partners
E.Biometric information
Examples: Genetic, physiological, behavioral, and biological characteristics or identifying activity patterns, such as fingerprints, faceprints, and voiceprints, iris or retina scans, keystroke, gait, or other physical patterns, and sleep, health or exercise data.
We do not collect this category of Personal Data.N/A
F.Internet or other similar network activity information
Examples: Browsing history, search history, or information on a consumer's interaction with a website, application or advertisement.
Interaction with our applications to monitor application performance and stability. Optionally, you may provide details to us about the categories of your use for our applications when creating an account with us. For example, Architecture, Product Design etc.You
G.Geolocation data
Examples: Physical location or movements.
We do not collect this category of Personal Data.N/A
H.Sensory data
Examples: Audio, electronic, visual, thermal, olfactory or similar information.
We do not collect this category of Personal Data.N/A
I.Professional or employment related information
Examples: Current or past job history or performance evaluations.
We do not collect this category of Personal Data.N/A
J.Non-public education information (per the Family Educational Rights and Privacy Act (20 U.S.C. Section 1232g, 34 C.F.R. Part 99))
Education records directly related to a student maintained by an educational institution or party acting on its behalf, such as grades, transcripts, class lists, student schedules, student identification codes, student financial information or student disciplinary records.
We do not collect this category of Personal Data.N/A
K.Inferences drawn from other personal information
Examples: Profile reflecting a person's preferences, characteristics, psychological trends, predispositions, behavior, attitudes, intelligence, abilities and aptitudes.
We do not collect this category of Personal Data.N/A
L.Sensitive personal information
Personal information revealing a consumer’s (i) Social Security, driver’s license, state identification card or passport number, (ii) account log-in, financial account, debit card, or credit card number in combination with any required security or access code, password, or credentials allowing access to an account, (iii) geolocation information accurate within a radius of 1850 feet or less, (iv) racial or ethnic origin, religious or philosophical beliefs, citizenship, immigration status, or union membership, (v) contents of mail, email, and text messages unless TopHatch is the intended recipient of the communication, or (vi) genetic data; personal information collected and analyzed concerning an individual’s health; information on medical history, mental or physical health conditions, or medical treatment or diagnosis by a health care professional; biometric information used for the purpose of uniquely identifying a consumer; personal information collected and analyzed concerning an consumer’s sex life or sexual orientation; personal information collected from a known child under 13 years of age.
We do not collect this category of Personal Data.N/A
M.Age or date of birth
We do not collect this category of Personal Data.N/A
N.Special categories of data under the EU General Data Protection Regulation
Personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership; genetic data or biometric data processed for the purpose of uniquely identifying a natural person; data concerning health; or data concerning a natural person’s sex life or sexual orientation.
We do not collect this category of Personal Data.N/A
O.Personal Data about children under the age of 16
This includes any type of Personal Data that relates to someone under the age of 16.
We do not knowingly collect this category of Personal Data; however, some users of the education version of our services may be children under the age of 16. With respect to users of the education version, we collect all of the foregoing categories of Personal Data, but only as authorized by the applicable educational institution. See the below section, Personal Data of Children, for more information about how we collect and treat children’s Personal Data.You

Information Collected Automatically

The Services collect information automatically through cookies and similar technologies, such as pixel tags, web beacons, clear GIFs, and JavaScript including through:

Your browser or device. Certain information is collected by most browsers or automatically through your device, such as your Media Access Control (MAC) address, computer type (Windows or Mac), screen resolution, operating system name and version, device manufacturer and model, language, Internet browser type and version and the name and version of the Services you are using. We use this information to ensure that the Services function properly.

Your use of the App. When you download and use the App, we and our service providers may track and collect App usage data, such as the date and time the App on your device accesses our servers and what information and files have been downloaded to the App based on your device number.

Cookies. Cookies are small pieces of data– usually text files – placed on your computer, tablet, phone, or similar device when you use that device to visit our Services. Cookies allow us to collect such information as browser type, time spent on the Services, pages visited, language preferences, and traffic data. We use the information for security purposes, to facilitate navigation, to display information more effectively, and to personalize your experience. We also gather statistical information about use of the Services in order to continually improve their design and functionality, understand how they are used, and assist us with resolving questions regarding them.

We use the following types of Cookies:

You can decide whether or not to accept cookies through your internet browser’s settings. Most browsers have an option for turning off the cookie feature, which will prevent your browser from accepting new cookies, as well as (depending on the sophistication of your browser software) allow you to decide on acceptance of each new cookie in a variety of ways. You can also delete all cookies that are already on your computer. If you do this, however, you may have to manually adjust some preferences every time you visit a site and some Services and functionalities may not work. Some browsers have incorporated Do Not Track (“DNT”) preferences. We make efforts to respond to DNT signals, although as there is not yet a uniform industry standard for handling DNT signals from website browsers, we cannot guarantee our response to DNT signals.

To explore what cookie setting are available to you, look in the “preferences” or “options” section of your browser’s menu. To find out more information about cookies, including information about how to manage and delete cookies, please visit https://ico.org.uk/for-the-public/online/cookies/ or https://www.allaboutcookies.org/. If, however, you do not accept cookies, you may experience some inconvenience in your use of the Services.

Pixel tags and other similar technologies. Pixel tags (also known as web beacons and clear GIFs) may be used to, among other things, track the actions of users of the Services (including email recipients), measure the success of our marketing campaigns, and compile statistics about usage of the Services and response rates.

Analytics. We use analytics services to collect and analyze information about use of the Services and report on activities and trends.

How We Use Your Personal Data

We process Personal Data to operate, improve, understand and personalize our Services, including for the following business or commercial purposes:

How We Share Your Personal Data

Disclosures of Personal Data for a Business Purpose

As further described in the chart below, we disclose your Personal Data to service providers and other parties. In addition, by using the Services, you may also elect to disclose Personal Data:

The following chart details the categories of Personal Data that we collect as per the chart above and that we disclose.

Category of Personal DataDisclosed to Which Categories of Third Parties
A.Personal identifiers
Service providers
Service performance and security monitoring, marketing communications, user support services, payment processing, hosting (including App and Website hosting) and other technology and communications providers and contract personnel.
Our affiliates
For the purposes described in this Privacy Policy. You can consult the list and location of our affiliates here.
Other parties at your direction
Other users (where you post data publicly or as otherwise necessary to effect a transaction initiated or authorized by you through the Services), social media services (if you intentionally interact with them through your use of the Services), third-party business partners who you access through the Services, and other parties authorized by you.
B.Customer records identified by state law (including the California Customer Records statute (Cal. Civ. Code § 1798.80(e)))
Service providers
Service performance and security monitoring, marketing communications, user support services, payment processing, hosting (including App and Website hosting) and other technology and communications providers and contract personnel.
Our affiliates
For the purposes described in this Privacy Policy. You can consult the list and location of our affiliates here.
Other parties at your direction
Other users (where you post data publicly or as otherwise necessary to effect a transaction initiated or authorized by you through the Services), social media services (if you intentionally interact with them through your use of the Services), third-party business partners who you access through the Services, and other parties authorized by you.
C.Commercial information
Service providers
Service performance and security monitoring, marketing communications, user support services, payment processing, hosting and other technology and communications providers and contract personnel.
Our affiliates
For the purposes described in this Privacy Policy. You can consult the list and location of our affiliates here.
D.Internet or other similar network activity information
Service providers
Service performance and security monitoring, marketing communications, user support services, payment processing, hosting (including App and Website hosting) and other technology and communications providers and contract personnel.
Our affiliates
For the purposes described in this Privacy Policy. You can consult the list and location of our affiliates here.

In addition, we may disclose Personal Data to a third party in connection with a sale or business transaction. We have a legitimate interest in disclosing or transferring your Personal Data to a third party in the event of any reorganization, merger, sale, joint venture, assignment, transfer, or other disposition of all or any portion of our business, assets, or stock (including in connection with any bankruptcy or similar proceedings).

Sensitive Personal Data

Unless we request it, we ask that you not send us, and you not disclose, any sensitive Personal Data (e.g., social security numbers, information related to racial or ethnic origin, political opinions, religion or other beliefs, health, biometrics or genetic characteristics, criminal background, or trade union membership) on or through the Services or otherwise to us.

Data Security and Retention

We seek to protect your Personal Data from unauthorized access, use and disclosure using appropriate physical, technical, organizational and administrative security measures based on the type of Personal Data and how we are processing that data. The Services use industry standard Secure Sockets Layer (SSL) technology to allow for the encryption of sensitive Personal Data you provide to us. You should also help protect your data by appropriately selecting and protecting your password and/or other sign-on mechanism; limiting access to your computer or device and browser; and signing off after you have finished accessing your account.

We retain Personal Data about you for as long as needed in light of the purpose(s) for which it was collected. The criteria used to determine our retention periods include:

Your Privacy Rights and Choices

If you do not want to receive marketing-related emails from us at any time, you can follow the unsubscribe link that is present in each of these emails or indicate your preference by emailing us at privacy@concepts.app. Please note that if you opt out of receiving marketing related emails from us, we may still send you important administrative messages, from which you cannot opt out.

If you would like to request to access, correct, update, suppress, restrict, or delete Personal Data, object to or opt out of the processing of Personal Data, or if you would like to request to receive a copy of your Personal Data for purposes of transmitting it to another company (to the extent these rights are provided to you by applicable law), please contact us at privacy@concepts.app. We will respond to your request consistent with applicable law.

In your request, please make clear what Personal Data you would like to have changed or whether you would like to have your Personal Data suppressed from our database. For your protection, we may only implement requests with respect to the Personal Data associated with the particular email address that you use to send us your request, and we may need to verify your identity before implementing your request. Please note that we may need to retain certain data for recordkeeping purposes and/or to complete any transactions that you began prior to requesting a change or erasure (e.g., when you make a payment, you may not be able to change or erase the Personal Data provided until after the completion of such payment).

Personal Data of Children

As noted in the TopHatch Terms of Service, we do not knowingly collect or solicit Personal Data from children under 16 except if a child is using the education version of our services as authorized by an applicable educational institution; if you are a child under 16, please do not attempt to register for or otherwise use the Services or send us any Personal Data. If we learn we have collected Personal Data from a child under 16, we will delete that data as quickly as possible. If you believe that a child under 16 may have provided us Personal Data, please contact us at privacy@concepts.app.

The Children’s Online Privacy Protection Act (“COPPA”) requires that online service providers obtain parental consent before they knowingly collect personal information online from children who are under 13. We do not knowingly collect or solicit personally identifiable information from children under 13, as defined in 16 C.F.R. 312.2. If we learn we have collected personal information from a child under 13, we will delete that information as quickly as possible. If you believe that a child under 13 may have provided us personal information, please contact us at privacy@concepts.app.

TopHatch is not an educational agency or institution as defined in 34 C.F.R. 99.3 and, therefore, is not subject to the Family Educational Rights and Privacy Act (“FERPA”).

Third-Party Services

This Privacy Policy does not address, and we are not responsible for, the privacy, data, or other practices of any third parties, including any third party operating any website or service to which the Services link. The inclusion of a link on the Services does not imply endorsement of the linked site or service by us or by our affiliates.

In addition, we are not responsible for the data collection, use, disclosure, or security policies or practices of other organizations, such as Meta, Apple, Google, Microsoft, or any other social media platform provider, app developer, app provider, operating system provider, wireless service provider, or device manufacturer, including with respect to any Personal Data you disclose to other organizations through or in connection with our App or Social Media Pages.

Nevada Residents

If you are a resident of Nevada, you have the right to opt-out of the sale of certain Personal Data to third parties who intend to license or sell that Personal Data. Please note that we do not currently sell your Personal Data as sales are defined in Nevada Revised Statutes Chapter 603A.

Additional Information Regarding the EEA/UK

If you are located in the European Economic Area (“EEA”) or the United Kingdom (“UK”), you may have additional rights under applicable privacy law, such as the EU General Data Protection Regulation or the EU General Data Protection Regulation as transposed into the national law of the United Kingdom by the UK European Union (Withdrawal) Act 2018 and amended by the UK Data Protection, Privacy and Electronic Communications (Amendments etc) (EU Exit) Regulations 2019 (collectively the “GDPR”) with respect to your Personal Data, as outlined below.

For this section, we use the terms “Personal Data” and “processing” as they are defined in the GDPR, but “Personal Data” generally means data that can be used to individually identify a person, and “processing” generally covers actions that can be performed in connection with data such as collection, use, storage and disclosure. TopHatch generally will be the controller of your Personal Data processed in connection with your use of the Services, unless we are handling your Personal Data as a processor on behalf of your organization.

If there are any conflicts between this section and any other provision of this Privacy Policy, the policy or portion that is more protective of Personal Data shall control to the extent of such conflict.

Personal Data We Collect

The “Categories of Personal Data We Collect” section above details the Personal Data that we collect from you.

Personal Data Use and Processing Grounds

The “How We Use Your Personal Data” section above explains how we use your Personal Data.

We will only process your Personal Data if we have a lawful basis for doing so. Lawful bases for processing include consent, contractual necessity and our “legitimate interests” or the legitimate interest of others, as further described below.

Sharing Personal Data

The “How We Share Your Personal Data” section above details how we share your Personal Data with third parties.

Lodging a Complaint

You may lodge a complaint with a data protection authority for your country or region where you have your habitual residence or place of work or where an alleged infringement of applicable data protection law occurs. A list of EEA data protection authorities is available at https://ec.europa.eu/newsroom/article29/items/612080, and the UK Information Commissioner’s Office’s contact details can be found at https://ico.org.uk/global/contact-us/. The Swiss authority is the FDIC, at https://www.edoeb.admin.ch.

Transfers of Personal Data

Your Personal Data may be stored and processed in any country where we have facilities or in which we engage service providers, and by using the Services you understand that your information will be transferred to countries outside of your country of residence, including the United States, which may have data protection rules that are different from those of your country. In certain circumstances, courts, law enforcement agencies, regulatory agencies, or security authorities in those other countries may be entitled to access your Personal Data.

Some countries outside of the EEA and the UK are recognized by the European Commission and/or the UK government as providing an adequate level of data protection according to EEA or UK standards: the list of the EEA’s adequate jurisdictions is available here and the list of the UK’s adequate jurisdictions is available here. For transfers from the EEA and the UK to countries not considered adequate by the European Commission or the UK government (as applicable), we have put in place adequate measures, such as standard contractual clauses adopted by the relevant authority to protect your Personal Data. You may obtain a copy of these measures by contacting us in accordance with the “Contact Information” section below.

Changes to this Privacy Policy

We’re constantly trying to improve our Services, so we may need to change this Privacy Policy from time to time. The "Last Updated" legend at the top of this Privacy Policy indicates when this Privacy Policy was last revised. Any changes will become effective when we post the revised Privacy Policy on the Services.

Contact Information

TopHatch, Inc., located at 303 Twin Dolphin Drive, Suite 600, Redwood City, CA 94065. USA, is the company responsible for collection, use, and disclosure of your Personal Data under this Privacy Policy.