Privacy Policy

Last updated: November 19, 2025

Privacy Policy

Last updated: November 2025

1. Introduction

TopupFI ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our mobile application and web platform.

2. Information We Collect

2.1 Personal Information (Firestore user_profiles collection)

  • Full name and unique username
  • Email address (from Firebase Authentication and Google Sign-In)
  • Profile picture/avatar (when using Google Sign-In or uploading custom images)
  • Account creation and last login timestamps
  • Account status and activity information
  • Email verification status

2.2 Technical and Device Information

  • Device model, manufacturer, and operating system version
  • App version and build number
  • IP address (for security and fraud prevention)
  • Firebase authentication tokens
  • FCM device token for push notifications (when granted)
  • Google Advertising ID (for ad personalization and analytics)
  • Last active timestamps and session information
  • App performance and crash data
  • Device identifiers for fraud prevention and security
  • Network connection type and quality metrics

2.3 Usage Analytics (Firebase Analytics)

  • App usage patterns and screen views
  • Feature usage statistics
  • Error reports and app stability data
  • User interaction patterns (wallet actions, shop actions, order actions)
  • In-app messaging engagement data
  • Achievement and milestone tracking
  • Performance monitoring data

2.4 Advertising and Monetization Data (Google AdMob)

  • Ad viewing history and interaction data
  • Ad impressions, clicks, and conversion tracking
  • Rewarded ad completion status (for coin rewards)
  • Ad personalization preferences
  • Advertising ID for targeted advertising
  • Third-party ad network data sharing
  • Ad performance metrics and analytics

2.5 Referral and Deep Link Data

  • Referral codes and referrer relationships
  • Deep link sources and campaign parameters
  • Referral earnings and redemption history
  • App installation source tracking

2.6 User-Generated Content

  • Task completion screenshots (uploaded to ImgBB)
  • Custom avatar images (uploaded to ImgBB)
  • Review and feedback submissions

3. How We Use Your Information

3.1 Service Delivery

  • Process mobile top-ups, recharges, and digital purchases
  • Provide customer support for top-up and recharge services

3.2 Security and Compliance

  • Prevent fraud and unauthorized access
  • Monitor for suspicious activities and security threats
  • Track device information for account security

3.3 App Improvement and Analytics

  • Analyze app usage to improve features and user experience
  • Monitor app performance and fix bugs
  • Develop new services and products
  • Conduct market research and user behavior analysis
  • Personalize your experience within the app

3.4 Communication and Notifications

  • Send push notifications about account activity and transactions
  • Provide customer support responses
  • Deliver important service announcements
  • Send security alerts and account notifications

3.5 Advertising and Monetization

  • Display personalized and non-personalized advertisements
  • Deliver rewarded video ads for earning in-app coins
  • Track ad performance and optimize ad delivery
  • Measure advertising campaign effectiveness
  • Provide ad-free experiences based on user preferences

3.6 Referral Program Management

  • Track referral relationships and earnings
  • Process deep link attribution for app installations
  • Calculate and distribute referral rewards
  • Prevent referral fraud and abuse

4. Information Sharing and Disclosure

4.1 We DO NOT sell your personal information to third parties.

We share your information only with authorized partners:

  • Firebase/Google Cloud: For data storage, analytics, authentication, and cloud messaging
  • Google AdMob: For ad serving, personalization, and monetization (shares Advertising ID, device info, app usage)
  • Google Sign-In: For authentication services (receives name, email, profile picture)
  • ImgBB: For image hosting services (user-uploaded avatars and task screenshots)
  • Payment Processors: For processing deposits (bKash, Nagad, Rocket)
  • Mobile Service Providers: For fulfilling top-up orders (minimal transaction data only)
  • Legal Authorities: When required by law or to protect our rights

All third-party partners are bound by strict confidentiality agreements and must comply with applicable data protection laws.

5. Data Security Measures

We implement industry-standard security measures:

  • Secure data encryption in transit and at rest
  • Secure HTTPS connections for all communications
  • Firebase Authentication for secure user management
  • Security monitoring and protection measures
  • Secure cloud storage with access controls
  • Security monitoring and fraud prevention measures

However, no system is 100% secure. We cannot guarantee absolute security but continuously work to protect your data.

6. Data Retention

  • Account information: Retained while your account is active and for 1 year after closure
  • Inactive accounts: Accounts with no activity for 90 consecutive days may be flagged for review, but data is retained unless you request deletion
  • Transaction records: 7 years (regulatory requirement for financial services)
  • Analytics data: 26 months (Firebase Analytics default retention)
  • Advertising data: Per Google AdMob policy (typically 18-24 months)
  • Support communications: 3 years after last interaction
  • User-generated content: Until account deletion or manual removal

You can request deletion of your personal data at any time, subject to legal and regulatory requirements. Note that some data may be retained for fraud prevention and legal compliance.

7. Your Privacy Rights

You have the right to:

  • Access your personal information stored in our systems
  • Correct inaccurate data through app settings or support
  • Delete your account and associated data (subject to legal requirements)
  • Export your data in a portable format
  • Turn off push notifications
  • Opt-out of personalized advertising (reset Advertising ID in device settings)
  • Request limitation of data processing
  • Object to automated decision-making
  • File complaints with data protection authorities

Advertising Opt-Out Options:

  • Android: Settings > Google > Ads > Reset advertising ID or Opt out of Ads Personalization
  • iOS: Settings > Privacy > Tracking > Disable "Allow Apps to Request to Track"
  • In-App: Notification preferences to control ad-related communications

To exercise these rights, contact us through the app or email support.

8. Children's Privacy and Age Requirements

8.1 Age Requirements

  • TopupFI is designed for users of all ages
  • Users under 18 should use the app with parental or guardian supervision
  • We recommend parental controls for users under 13

8.2 COPPA Compliance (Children Under 13)

We take special care to protect children's privacy:

  • We do NOT knowingly collect personal information from children under 13 without verifiable parental consent
  • Parents can review, delete, or refuse further collection of their child's information
  • We do NOT condition a child's participation on disclosure of more information than reasonably necessary
  • Advertising shown to children is age-appropriate and complies with COPPA regulations

8.3 Parental Controls

Parents and guardians can:

  • Monitor their child's account activity
  • Control notification settings and permissions
  • Request deletion of child's data at any time
  • Disable ad personalization for minors
  • Contact us to exercise parental rights

8.4 Data Minimization for Minors

For users who identify as under 18, we:

  • Limit data collection to essential service delivery only
  • Apply stricter privacy controls by default
  • Restrict certain features that may not be age-appropriate
  • Ensure ads shown are family-friendly and non-targeted

9. Analytics and Tracking Technologies

9.1 Firebase Analytics

We use Firebase Analytics to understand app usage patterns, including:

  • Screen views and user navigation
  • Feature usage and engagement metrics
  • App performance and crash analytics
  • User acquisition and retention data

9.2 Crashlytics

Firebase Crashlytics helps us identify and fix app crashes by collecting:

  • Device information and app state during crashes
  • Stack traces and error details
  • User actions leading to crashes (anonymized)

9.3 Performance Monitoring

We monitor app performance including:

  • App startup times and network request performance
  • Screen rendering performance
  • Resource usage metrics

9.4 Opt-Out Options

You can opt-out of analytics collection through:

  • Device settings (Advertising ID reset/opt-out)
  • App notification preferences

10. Advertising and Monetization (Google AdMob)

10.1 Types of Ads Displayed

We use Google AdMob to display various types of advertisements:

  • Banner Ads: Displayed on home screen and transaction history
  • Interstitial Ads: Full-screen ads shown between app transitions (order completion, daily login)
  • Native Ads: Integrated ads on product details and referral dashboard
  • Rewarded Video Ads: Optional ads users can watch to earn in-app coins

10.2 How Advertising Works

  • Ads may be personalized based on your interests, app usage, and Google account activity
  • We share Advertising ID with AdMob for ad targeting and measurement
  • Third-party ad networks may collect data through AdMob mediation
  • Ad performance is tracked to improve relevance and user experience

10.3 Rewarded Advertising

  • Users can voluntarily watch video ads to earn virtual coins
  • Default reward: 50 coins per ad (configurable by system settings)
  • Daily limit: Maximum 5 rewarded ads per day (configurable)
  • Coins can be used within the app for purchases and services
  • No personal information is required to participate

10.4 Third-Party Ad Networks

AdMob may work with third-party ad networks including but not limited to:

  • Google Ads and Display Network
  • AdMob mediation partners (varies by region)
  • Measurement and analytics partners

Each network has its own privacy policy governing data collection and use.

10.5 Children and Advertising

  • Ads shown to users under 13 are family-friendly and COPPA-compliant
  • Personalized ads are disabled for known child accounts
  • We comply with Google's Ad Content Policy for children
  • Rewarded ads for children do not require personal information

10.6 Advertising Data Collection

Through AdMob, the following data may be collected:

  • Device Advertising ID (IDFA/AAID)
  • Device type, model, and OS version
  • IP address and approximate location
  • App usage and ad interaction data
  • Ad impressions, clicks, and conversions
  • Time spent viewing ads

11. Push Notifications and Messaging

11.1 FCM Token Collection

We collect your FCM (Firebase Cloud Messaging) device token to send:

  • Transaction confirmations and receipts
  • Security alerts and account notifications
  • Promotional offers (with permission)
  • Service announcements and updates

11.2 Notification Controls

You can control notifications through:

  • App notification settings
  • Device notification preferences
  • Complete opt-out options

12. App Store Compliance and Financial Services Disclaimer

12.1 App Store Compliance

  • Primary target audience: Users 18 and older (recommended)
  • Secondary audience: Users under 18 with parental supervision
  • Content rating: Suitable for all ages with appropriate safeguards
  • Complies with Google Play Family Policy and Apple App Store guidelines
  • Contains advertisements (Google AdMob) with age-appropriate controls
  • We do NOT provide banking, lending, or general financial services
  • We do NOT facilitate peer-to-peer money transfers or cash withdrawals
  • Our privacy practices comply with platform policies and industry standards

12.2 Google Play Data Safety Disclosure

Our app discloses the following in Google Play Data Safety:

  • Personal info: Name, email address, user IDs
  • Financial info: Purchase history, wallet balance (for service prepayment only)
  • Photos: Optional avatar uploads
  • App activity: In-app actions, ad interactions
  • Device identifiers: Advertising ID, device ID
  • Data is encrypted in transit and at rest
  • Users can request data deletion

12.3 Financial Services Limitation

  • TopupFI is NOT a financial institution or money service business
  • We provide ONLY top-up, recharge, and digital content services
  • Digital wallet is for prepayment of our services, not general banking
  • We do not provide investment, trading, or currency exchange services

12.4 Regulatory Compliance

  • We maintain appropriate licenses for digital recharge services in Bangladesh
  • Data handling complies with Bangladesh telecommunications and financial regulations
  • Security monitoring ensures continued compliance with applicable laws

13. Changes to This Policy

We may update this Privacy Policy to reflect:

  • Changes in our services or data practices
  • Legal or regulatory requirements
  • Industry best practices and security improvements
  • User feedback and operational needs

When we make significant changes, we will:

  • Notify you through the app or email
  • Update the "Last updated" date
  • Provide clear explanation of changes
  • Give you options to review and accept updated terms

14. Location and International Transfers

TopupFI operates primarily in Bangladesh. Your data is processed in:

  • Bangladesh (primary operations and compliance)
  • Singapore (Firebase/Google Cloud servers in asia-southeast1 region)
  • United States (some Google services and analytics)

We ensure appropriate safeguards are in place for international data transfers, including standard contractual clauses and Google's adequate security measures.

15. Contact Information

Questions about this Privacy Policy?

Contact Methods:

  • In-App Support: Use the customer support feature in the TopupFI app
  • Email: support@topupfi.com
  • Privacy-specific inquiries: privacy@topupfi.com
  • Response Time: Within 24 hours for privacy-related inquiries

Mailing Address:

TopupFI Privacy Team
Dhaka, Bangladesh

Parental Consent and Child Privacy:

  • Parents/guardians can contact us to review, modify, or delete child data
  • Email: parents@topupfi.com

Advertising and Opt-Out:

  • For advertising-related questions: ads@topupfi.com
  • To opt-out of personalized ads: Use device settings or contact support

For data protection complaints in Bangladesh, you may also contact the relevant regulatory authorities.