International Version | Greater China Version

Privacy Policy

Last Updated: 24 January 2023

At TopHatch, we take your privacy seriously. Please read the following to learn how we treat personal information that we collect about you when you use or access TopHatch Services.

Remember that your use of TopHatch Services is at all times subject to the TopHatch Terms of Service. Any capitalized terms we use in this Policy without defining them have the definitions given to them in the TopHatch Terms of Service.

What this Privacy Policy Covers

This Privacy Policy covers how we collect, retrain, use, disclose and otherwise treat Personal Data that we gather when you access or use our Services. “Personal Data” means any information that identifies or relates to a directly or indirectly identifiable individual and also includes information referred to as “personally identifiable information” or “personal information” under applicable data privacy laws, rules, or regulations. This Privacy Policy does not cover the practices of companies we don’t own or control or people we don’t manage. This Privacy Policy also does not cover Personal Data that we handle on behalf of our enterprise customers as a processor; we handle such data in accordance with our applicable customer agreements.

Sources of Personal Data

We collect Personal Data about you from:

Categories of Personal Data We Collect

The following chart details the categories of Personal Data that we collect and have collected over the twelve (12) months preceding the date this Privacy Policy was last updated and the categories of sources the Personal Data is collected from. Throughout this Privacy Policy, we will refer back to the categories of Personal Data listed in this chart (for example, “Category A. Personal identifiers”).

Category of Personal DataPersonal Data CollectedSource
A.Personal identifiers
Examples: Real name, alias, postal address, unique personal identifier, online identifier, Internet Protocol address, email address, account name, Social Security number, driver's license number, passport number or other similar identifiers.
Email address (optional)
Name (optional)
Unique personal identifier
Telephone number (optional)
You
B.Customer records identified by state law (including the California Customer Records statute (Cal. Civ. Code § 1798.80(e)))
Examples: Name, signature, Social Security number, physical characteristics or description, address, telephone number, passport number, driver's license or state identification card number, insurance policy number, education, employment, employment history, bank account number, credit card number, debit card number or any other financial information, medical information or health insurance information.
Name (optional)
Telephone number (optional)
You
C.Protected classification characteristics under state or federal law
Examples: Age (40 years or older), race, color, ancestry, national origin, citizenship, religion or creed, marital status, medical condition, physical or mental disability, sex (including gender, gender identity, gender expression, pregnancy or childbirth and related medical conditions), sexual orientation, veteran or military status or genetic information (including familial genetic information).
We do not collect this category of Personal Data.N/A
D.Commercial information
Examples: Records of personal property, products or services purchased, obtained, or considered, or other purchasing or consuming histories or tendencies.
Purchase information is sent to us via billing partners (for example, Apple, Google) when you make a purchase of a feature of one of our applications via their store.Affiliates and business partners
E.Biometric information
Examples: Genetic, physiological, behavioral, and biological characteristics or identifying activity patterns, such as fingerprints, faceprints, and voiceprints, iris or retina scans, keystroke, gait, or other physical patterns, and sleep, health or exercise data.
We do not collect this category of Personal Data.N/A
F.Internet or other similar network activity information
Examples: Browsing history, search history, or information on a consumer's interaction with a website, application or advertisement.
Interaction with our applications to monitor application performance and stability. Optionally, you may provide details to us about the categories of your use for our applications when creating an account with us. For example, Architecture, Product Design etc.You
G.Geolocation data
Examples: Physical location or movements.
We do not collect this category of Personal Data.N/A
H.Sensory data
Examples: Audio, electronic, visual, thermal, olfactory or similar information.
We do not collect this category of Personal Data.N/A
I.Professional or employment related information
Examples: Current or past job history or performance evaluations.
We do not collect this category of Personal Data.N/A
J.Non-public education information (per the Family Educational Rights and Privacy Act (20 U.S.C. Section 1232g, 34 C.F.R. Part 99))
Education records directly related to a student maintained by an educational institution or party acting on its behalf, such as grades, transcripts, class lists, student schedules, student identification codes, student financial information or student disciplinary records.
We do not collect this category of Personal Data.N/A
K.Inferences drawn from other personal information
Examples: Profile reflecting a person's preferences, characteristics, psychological trends, predispositions, behavior, attitudes, intelligence, abilities and aptitudes.
We do not collect this category of Personal Data.N/A
L.Sensitive personal information
Personal information revealing a consumer’s (i) Social Security, driver’s license, state identification card or passport number, (ii) account log-in, financial account, debit card, or credit card number in combination with any required security or access code, password, or credentials allowing access to an account, (iii) geolocation information accurate within a radius of 1850 feet or less, (iv) racial or ethnic origin, religious or philosophical beliefs, citizenship, immigration status, or union membership, (v) contents of mail, email, and text messages unless TopHatch is the intended recipient of the communication, or (vi) genetic data; personal information collected and analyzed concerning an individual’s health; information on medical history, mental or physical health conditions, or medical treatment or diagnosis by a health care professional; biometric information used for the purpose of uniquely identifying a consumer; personal information collected and analyzed concerning an consumer’s sex life or sexual orientation; personal information collected from a known child under 13 years of age.
We do not collect this category of Personal Data.N/A
M.Age or date of birth
We do not collect this category of Personal Data.N/A
N.Special categories of data under the EU General Data Protection Regulation
Personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership; genetic data or biometric data processed for the purpose of uniquely identifying a natural person; data concerning health; or data concerning a natural person’s sex life or sexual orientation.
We do not collect this category of Personal Data.N/A
O.Personal Data about children under the age of 16
This includes any type of Personal Data that relates to someone under the age of 16.
We do not knowingly collect this category of Personal Data; however, some users of the education version of our services may be children under the age of 16. With respect to users of the education version, we collect all of the foregoing categories information, but only as authorized by the applicable educational institution. See below section Personal Data of Children for more information about how we collect and treat children’s Personal Data.You

The following sections provide additional information about how we collect your Personal Data.

Information Collected Automatically

The Services use cookies and similar technologies such as pixel tags, web beacons, clear GIFs, and JavaScript (collectively, “Cookies”) to enable our servers to recognize your web browser and tell us how and when you visit and use our Services, to analyze trends, learn about our user base and operate and improve our Services. Cookies are small pieces of data– usually text files – placed on your computer, tablet, phone, or similar device when you use that device to visit our Services.

We use the following types of Cookies:

You can decide whether or not to accept Cookies through your internet browser’s settings. Most browsers have an option for turning off the Cookie feature, which will prevent your browser from accepting new Cookies, as well as (depending on the sophistication of your browser software) allow you to decide on acceptance of each new Cookie in a variety of ways. You can also delete all Cookies that are already on your computer. If you do this, however, you may have to manually adjust some preferences every time you visit a site and some Services and functionalities may not work. Some browsers have incorporated Do Not Track (“DNT”) preferences. We make efforts to respond to DNT signals, although as there is not yet a uniform industry standard for handling DNT signals from website browsers, we cannot guarantee our response to DNT signals.

To explore what Cookie setting are available to you, look in the “preferences” or “options” section of your browser’s menu. To find out more information about Cookies, including information about how to manage and delete Cookies, please visit https://ico.org.uk/for-the-public/online/cookies/ or https://www.allaboutcookies.org/.

How We Use Your Personal Data

We process Personal Data to operate, improve, understand and personalize our Services. We use Personal Data for the following business or commercial purposes:

We will not collect additional categories of Personal Data or use the Personal Data we collected for materially different, unrelated, or incompatible purposes without providing you notice or, where necessary, obtaining your consent.

As noted in the list above, we may communicate with you if you’ve provided us the means to do so. For example, if you’ve given us your email address, we may send you promotional email offers or email you about your use of the Services. Also, we may receive a confirmation when you open an email from us, which helps us improve our services. Where necessary under applicable law, we will obtain your consent before using your Personal Data for these purposes. If you do not want to receive marketing-related emails from us at any time, you can follow the unsubscribe link that is present in each of these emails or indicate your preference by emailing us at privacy@concepts.app. Please note that if you opt out of receiving marketing related emails from us, we may still send you important administrative messages, from which you cannot opt out.

How We Share Your Personal Data

Disclosures of Personal Data for a Business Purpose

As further described in the chart below, we disclose your Personal Data to service providers and other parties for the following business purposes:

The following chart details the categories of Personal Data that we collect as per the chart above and that we disclose and have disclosed over the twelve (12) months preceding the date this Privacy Policy was last updated.

Category of Personal DataDisclosed to Which Categories of Third Parties
A.Personal identifiers
Examples: Real name, alias, postal address, unique personal identifier, online identifier, Internet Protocol address, email address, account name, Social Security number, driver's license number, passport number or other similar identifiers.
Service providers
Service performance and security monitoring, marketing communications, user support services, payment processing, hosting and other technology and communications providers and contract personnel.
Other parties at your direction
Other users (where you post information publicly or as otherwise necessary to effect a transaction initiated or authorized by you through the Services), social media services (if you intentionally interact with them through your use of the Services), third-party business partners who you access through the Services, and other parties authorized by you.
B.Customer records identified by state law (including the California Customer Records statute (Cal. Civ. Code § 1798.80(e)))
Examples: Name, signature, Social Security number, physical characteristics or description, address, telephone number, passport number, driver's license or state identification card number, insurance policy number, education, employment, employment history, bank account number, credit card number, debit card number or any other financial information, medical information or health insurance information.
Service providers
Service performance and security monitoring, marketing communications, user support services, payment processing, hosting and other technology and communications providers and contract personnel.
Other parties at your direction
Other users (where you post information publicly or as otherwise necessary to effect a transaction initiated or authorized by you through the Services), social media services (if you intentionally interact with them through your use of the Services), third-party business partners who you access through the Services, and other parties authorized by you.
C.Internet or other similar network activity information
Examples: Browsing history, search history, or information on a consumer's interaction with a website, application or advertisement.
Service providers
Service performance and security monitoring, marketing communications, user support services, payment processing, hosting and other technology and communications providers and contract personnel.

In addition, we may disclose Personal Data to a third party if we undergo a merger, acquisition, bankruptcy, reorganization, or other disposition of all or any portion of our business, assets, or stock.

Sales and Sharing of Personal Data, Targeted Advertising

We do not sell Personal Data and we do not share or otherwise process Personal Data for the purposes of cross-context behavioral or targeted advertising, as defined under applicable law. We have not engaged in such activities in the twelve (12) months preceding the date this Privacy Policy was last updated. Without limiting the foregoing, we do not sell or share or otherwise process for the purposes of cross-text behavioral or targeted advertising, as defined under applicable law, the Personal Data of consumers under age 16 years of page.

Data Security and Retention

We seek to protect your Personal Data from unauthorized access, use and disclosure using appropriate physical, technical, organizational and administrative security measures based on the type of Personal Data and how we are processing that data. The Services use industry standard Secure Sockets Layer (SSL) technology to allow for the encryption of sensitive Personal Data you provide to us. You should also help protect your data by appropriately selecting and protecting your password and/or other sign-on mechanism; limiting access to your computer or device and browser; and signing off after you have finished accessing your account.

We retain Personal Data about you for as long as needed in light of the purpose(s) for which it was collected. The criteria used to determine our retention periods include:

Afterwards, we may retain some information in a depersonalized or aggregated form but not in a way that would constitute Personal Data or otherwise identify you personally.

Personal Data of Children

As noted in the TopHatch Terms of Service, we do not knowingly collect or solicit Personal Data from children under 16 except if a child is using the education version of our services as authorized by an applicable educational institution; if you are a child under 16, please do not attempt to register for or otherwise use the Services or send us any Personal Data. If we learn we have collected Personal Data from a child under 16, we will delete that information as quickly as possible. If you believe that a child under 16 may have provided us Personal Data, please contact us at privacy@concepts.app.

The Children’s Online Privacy Protection Act (“COPPA”) requires that online service providers obtain parental consent before they knowingly collect personal information online from children who are under 13. We do not knowingly collect or solicit personally identifiable information from children under 13, as defined in 16 C.F.R. 312.2. If we learn we have collected personal information from a child under 13, we will delete that information as quickly as possible. If you believe that a child under 13 may have provided us personal information, please contact us at privacy@concepts.app.

TopHatch is not an educational agency or institution as defined in 34 C.F.R. 99.3 and, therefore, is not subject to the Family Educational Rights and Privacy Act (“FERPA”).

California and Virginia Resident Rights

If you are a California or Virginia resident, you have the rights outlined in this section. Please see the “Exercising Your Rights” section below for instructions regarding how to exercise these rights. If there are any conflicts between this section and any other provision of this Privacy Policy and you are a California or Virginia resident, the portion that is more protective of Personal Data shall control to the extent of such conflict. If you have any questions about this section or whether any of the following applies to you, please contact us by email at privacy@concepts.app.

Access

You may request to know whether we process your Personal Data, and to access such Personal Data. If you are a California resident, you may request that we disclose to you the following information about the processing of your Personal Data collected or maintained on or after January 1, 2022, covering the 12 months preceding your request or, unless this would prove impossible or involve disproportionate effort, beyond the 12-month period:

Correction

You may request that we correct inaccuracies in Personal Data we maintain about you, taking into account the nature of the Personal Data and the purposes of the processing of the Personal Data.

Deletion

Subject to certain exceptions defined by applicable law, you have the right to request that we delete your Personal Data. If you are a California resident, this right applies to Personal Data that we have collected from you.

Portability

Subject to certain exceptions defined by applicable law, you may request to receive a copy of your Personal Data in an easily understandable and, where technically feasible, portable and readily usable format. If you are a Virginia resident, this right applies to Personal Data you previously provided to us, where the processing is carried out by automated means.

Exercising Your Rights

To exercise the rights described above, you must send us a request that (1) provides sufficient information to allow us to verify that you are the person about whom we have collected Personal Data, such as an email sent from the email address associated with your account and (2) describes your request in sufficient detail to allow us to understand, evaluate, and respond to it. We will verify and respond to your request consistent with applicable law, taking into account the type and sensitivity of the Personal Data subject to the request. In some instances, we may decline to honor your request where the law or right you are invoking does not apply or where an exception applies. We may need to request additional Personal Data from you in order to verify your identity and protect against fraudulent requests. If you make a request to delete, we may ask you to confirm your request before we delete your Personal Data.

You may submit a Valid Request using the following methods:

We Will Not Discriminate Against You for Exercising Your Rights

You have the right to be free from unlawful discrimination for exercising your rights regarding the processing of your Personal Data, and we will not engage in such discrimination. We will not deny you our goods or services, charge you different prices or rates, or provide you a lower quality of goods and services if you exercise rights.

Authorized Agents

If an agent would like to make a request on your behalf as permitted under applicable law, the agent may use the submission methods noted above. Not all kinds of requests can be made by authorized agents in all states. As part of our verification process, we may request that you verify your identity as described above or confirm that you provided the agent permission to submit the request.

If you are a California resident and an agent makes a request on your behalf, this may include:

Nevada Resident Rights

If you are a resident of Nevada, you have the right to opt-out of the sale of certain Personal Data to third parties who intend to license or sell that Personal Data. Please note that we do not currently sell your Personal Data as sales are defined in Nevada Revised Statutes Chapter 603A.

European Union Data Subject Rights

EU Residents

If you are a resident of the European Union (“EU”), United Kingdom, Lichtenstein, Norway, or Iceland, you may have additional rights under the EU General Data Protection Regulation or the EU General Data Protection Regulation as transposed into the national law of the United Kingdom by the UK European Union (Withdrawal) Act 2018 and amended by the UK Data Protection, Privacy and Electronic Communications (Amendments etc) (EU Exit) Regulations 2019 (collectively the “GDPR”) with respect to your Personal Data, as outlined below.

For this section, we use the terms “Personal Data” and “processing” as they are defined in the GDPR, but “Personal Data” generally means information that can be used to individually identify a person, and “processing” generally covers actions that can be performed in connection with data such as collection, use, storage and disclosure. TopHatch generally will be the controller of your Personal Data processed in connection with your use of the Services, unless we are handling your Personal Data as a processor on behalf of your organization.

If there are any conflicts between this section and any other provision of this Privacy Policy, the policy or portion that is more protective of Personal Data shall control to the extent of such conflict. If you have any questions about this section or whether any of the following applies to you, please contact us at privacy@concepts.app.

Personal Data We Collect

The “Categories of Personal Data We Collect” section above details the Personal Data that we collect from you.

Personal Data Use and Processing Grounds

The “How We Use Your Personal Data” section above explains how we use your Personal Data.

We will only process your Personal Data if we have a lawful basis for doing so. Lawful bases for processing include consent, contractual necessity and our “legitimate interests” or the legitimate interest of others, as further described below.

Sharing Personal Data

The “How We Share Your Personal Data” section above details how we share your Personal Data with third parties.

EU Data Subject Rights

If you are an EU Data Subject, you have certain rights with respect to your Personal Data, including those set forth below. For more information about these rights, or to submit a request, please email privacy@concepts.app. Please note that in some circumstances, we may not be able to fully comply with your request, such as if it is frivolous or extremely impractical, if it jeopardizes the rights of others, or if it is not required by law, but in those circumstances, we will still respond to notify you of such a decision. In some cases, we may also need to you to provide us with additional information, which may include Personal Data, if necessary to verify your identity and the nature of your request.

Transfers of Personal Data

The Services are hosted and operated in the United States (“U.S.”) through Company and its service providers, and if you do not reside in the U.S., laws in the U.S. may differ from the laws where you reside. By using the Services, you acknowledge that any Personal Data about you, regardless of whether provided by you or obtained from a third party, is being provided to Company in the U.S. and will be hosted on U.S. servers, and you authorize Company to transfer, store and process your information to and in the U.S., and possibly other countries.

Changes to this Privacy Policy

We’re constantly trying to improve our Services, so we may need to change this Privacy Policy from time to time as well, but we will alert you to changes by placing a notice on the https://concepts.app website, by sending you an email, and/or by some other means. Please note that if you’ve opted not to receive legal notice emails from us (or you haven’t provided us with your email address), those legal notices will still govern your use of the Services, and you are still responsible for reading and understanding them. If you use the Services after any changes to the Privacy Policy have been posted, that means you agree to all of the changes. Use of information we collect is subject to the Privacy Policy in effect at the time such information is collected.

Contact Information:

If you have any questions or comments about this Privacy Policy, the ways in which we collect and use your Personal Data, your choices and rights regarding such use, please do not hesitate to contact us at: