> For the complete documentation index, see [llms.txt](https://docs.top.market/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.top.market/user-agreements/privacy-policy.md).

# Privacy Policy

**Draft dated September 28, 2026**

**Publication Status:** Draft for legal and product review

This Privacy Policy explains how HYPER COLLECTIBLES LIMITED (“Topmarket,” “we,” “us,” or “our”) collects, uses, discloses, retains, and protects personal information in connection with the Topmarket Platform and related Services.

**Websites** means the websites operated by Topmarket, including top.market, whether accessed through a desktop browser, mobile browser, or embedded web view. **App** means the Topmarket native mobile applications for iOS and Android. **Platform** means the Websites and the App collectively. **Services** means the services actually provided through or in connection with the Platform, including related customer support and activities that expressly link to this Policy.

This is one Policy for the Websites and the App. It covers guest browsing, account access, card packs, marketplace activity, auctions, wallet and payment activity, rewards, custody records, physical delivery, and any other feature described below that you actually use. Collection depends on your access channel, device, feature, and choices. A web-only integration is not automatically an App integration, and an App permission is not automatically requested on the Websites.

A third-party website, wallet, app, blockchain, payment service, or shipping service has its own privacy notice for its independent processing. Opening a Topmarket web page from the App does not take that page outside this Policy.

This Policy provides information about our processing; it does not itself obtain consent for every activity it describes. Where consent is required for a particular use, we request it through the relevant feature, cookie control, or permission flow. Optional processing is subject to your applicable choices.

## 1 Platform Scope and Geographic Availability

The Services are not available in every jurisdiction and are not offered to users located in Mainland China. Availability may differ by feature and access channel because of legal, payment, blockchain, custody, insurance, or shipping requirements. This Policy explains data practices; it does not itself authorize access to a Service or establish that a country is supported.

This Policy should be read together with our Terms of Service, including their refund and delivery provisions, and any applicable feature-specific notice. A supplemental notice may explain additional processing for a particular feature but does not remove rights under this Policy or applicable law. The description of a feature does not mean that it is currently available through every channel.

## 2 Personal Information We Collect

The information we collect depends on whether you browse as a guest, sign in, connect a wallet, complete a transaction, use rewards, contact support, or request a physical-card service.

### 2.1 Account and Authentication Information

We may collect:

* Your email address and records relating to one-time verification codes.
* Identifiers and limited profile information received from Google Sign-In or Sign in with Apple, depending on the option you choose and information the provider makes available.
* Wallet addresses, wallet-connection status, public signatures used for authentication, and related login records.
* Your account identifier, display name, profile image, language, and communication preferences.
* Session, login, account-security, and account-recovery records.

Authentication methods may differ between the Websites, the iOS App, and the Android App. We process information associated with the method you actually use. We do not need your wallet seed phrase or private key and will not ask you to provide either.

Where you use the same account across channels, we may associate the relevant account, wallet, transaction, preference, and support records to provide the Services. This does not mean that separate accounts are automatically merged or that cookie and device permissions automatically carry across devices.

We use Privy's embedded-wallet infrastructure to provide and operate user wallets. Depending on the authentication and wallet action involved, we and Privy may process account and wallet identifiers, authentication and session information, and information needed to request, authorize, and record wallet actions. Topmarket does not receive or store your complete wallet private key. Privy's key-management and signing infrastructure is distinct from the account and transaction information maintained by Topmarket.

Topmarket's backend does not currently have a Privy session signer or delegated signer configured. In the browser-session-based embedded-wallet flow, you confirm an action in Topmarket's transaction confirmation dialog, after which the authenticated front end requests the corresponding wallet signature through Privy without displaying a second Privy wallet confirmation dialog. We and Privy may process the associated account and session identifiers, confirmation and authorization information, signing requests, and transaction results to carry out the requested action, maintain security, reconcile transactions, and respond to support requests. This information is distinct from your complete wallet private key and does not constitute a backend delegated-signing authorization.

### 2.2 Wallet Blockchain and Balance Information

We may collect or associate with your account:

* Public wallet addresses, including your Privy embedded-wallet address and any connected external-wallet addresses.
* Transaction hashes, blockchain network, digital-asset transfers, and smart-contract interactions.
* Supported asset balances and USDC deposits, withdrawals, pending amounts, and transaction history.
* Connected-wallet status, authentication signatures, transaction execution results, contract events, block numbers, and transaction-confirmation or failure information.
* Fraud, sanctions, wallet-risk, and transaction-monitoring results.

Public blockchain data is available to anyone. We may obtain it directly from blockchains or from blockchain infrastructure, explorer, analytics, wallet, and compliance providers.

The Services primarily use Base Mainnet (chain ID 8453) and native USDC. We read relevant on-chain balances, transactions, and contract events and associate them with account and order records to display balances, confirm transactions, reconcile errors, and provide support. Our database records do not replace the USDC held on-chain in your wallet. Wallet addresses and transaction records may be linked to your identity through information you provide or through other available information; a public wallet address is not necessarily anonymous.

### 2.3 Card Packs Marketplace and Auction Information

We may collect:

* Packs viewed or purchased, disclosed odds, purchase amount, coupons, fees, opening status, and outcome.
* Decisions to keep a card or accept an available buyback or recycle quote.
* Marketplace searches, series and cards viewed, listings, asking prices, purchases, sales, offers, withdrawals, acceptances, and expirations.
* Auction creation details, bids, reserve prices, status, settlement, and related timestamps.
* Collectible ownership, account activity, transaction status, and dispute records.

### 2.4 Physical Collectible Custody and Delivery Information

If you view or use custody or physical delivery features, we may collect:

* Card name, set, year, card number, images, grading company, grade, certification number, declared value, and other card identifiers.
* Custody intake, verification, storage, rejection, return, insurance, and tracking records.
* Sender or recipient name, telephone number, street address, postal code, country or region, delivery instructions, and customs information.
* Shipping method, shipping fee, tracking number, carrier events, delivery status, and related transaction information.
* Records of changes to the account entry associated with a Collectible, including restrictions on trading, cancellation, and processing of a physical-delivery request.

New custody submissions are not currently open through the App. Existing custody records and delivery requests are separate features. Where a channel provides a form or support process for an eligible physical-card service, the information involved depends on the fields you provide and the processing described for that flow. Viewing an existing record does not itself submit a new custody request.

### 2.5 Rewards and Membership Information

We may collect GP and CP balances, earning and deduction records, membership level, progress, displayed multipliers, benefit eligibility, inactivity or decay status, and records used to detect duplicate or abusive activity.

A membership benefit marked “coming soon” or inactive is not an active service merely because it is displayed.

### 2.6 Identity and Compliance Information

Where required for withdrawals, high-value transactions, physical delivery, fraud prevention, sanctions screening, or legal compliance, we or a verification provider may collect:

* Legal name, date of birth, nationality, address, and proof of address.
* Government-issued identification and verification images.
* Source-of-funds or transaction-purpose information.
* Screening results, risk indicators, and verification status.

We will request this information only when needed for the relevant purpose. A verification provider may collect information directly under its own privacy notice.

### 2.7 Communications and Support Information

We collect information you provide when you contact us, including emails, support requests, screenshots, attachments, survey responses, feedback, complaints, disputes, and records of our response.

{% hint style="warning" %}
Do not send us a private key or seed phrase.
{% endhint %}

Use the support function available in the Platform or <info@top.market> for account, privacy, payment, wallet, identity-verification, or transaction issues. Do not post personal or sensitive information in the official Topmarket Discord community or another public community channel.

### 2.8 Device Browser and App Usage Information

When you use the Platform, we and our service providers may automatically collect:

* Device type, operating system and version, browser type and version, App version and build where applicable, language, time zone, screen or interface characteristics, and network information.
* IP address and approximate location derived from IP address.
* Web pages or App screens viewed, searches, clicks or taps, navigation paths, session duration, referring URLs or deep links, and feature interactions.
* Crash reports, performance data, error logs, network diagnostics, and loading or retry events.
* Security information, including login attempts, device or session identifiers, rate-limit events, integrity signals, suspicious activity, and bot or abuse indicators.

The Websites and App may store account state, language, preferences, and other limited data on your device. Clearing browser cookies, local storage, or App data does not necessarily delete information stored in our systems.

### 2.9 Device Permissions

A Website or the App may request a browser or operating-system permission when a feature needs access to a protected device capability. The relevant notice or permission prompt explains the purpose. You may deny or later revoke the permission through the applicable browser or device settings, although the related feature may not work.

Permissions and technologies differ by browser, operating system, access channel, and App build. Browser permissions, native App permissions, website cookie choices, and App tracking permissions are separate controls. Our store disclosures concern the actual App release and are not a list of every technology used on the Websites.

### 2.10 Information From Third Parties

We may receive information from:

* Google and Apple authentication services.
* Privy, compatible wallet apps, and other wallet infrastructure providers.
* Public blockchains, RPC providers, blockchain explorers, and on-chain analytics or compliance services.
* Payment, crypto transfer, fraud prevention, sanctions screening, and identity verification providers.
* Grading companies, custody or vault partners, insurers, logistics providers, carriers, and customs agents.
* Analytics, crash-reporting, security, communications, and customer-support providers.
* Public databases, authorities, and other sources permitted by law.

We may combine this information with information collected through the Platform.

### 2.11 Website Payments and Optional Programs

If you use a payment or fiat-to-crypto provider offered through a channel, information may include payment method and billing details, transaction amounts, payment references, verification results, refund status, and fraud or chargeback records. A provider such as Coinflow, where offered, may collect payment details directly under its own notice. A payment method mentioned here is not necessarily available in the App.

If you participate in a referral, free-card campaign, giveaway, raffle, or other promotion actually offered to you, we may process invite codes, attribution and referral relationships, entry or claim records, eligibility checks, reward records, and any applicable holding restrictions. If an Earn, lending, or borrowing feature is actually offered, we may process the transaction, position, collateral, reward or interest, repayment, and settlement information needed for that feature, as described in its supplemental notice.

If a feature allows public content or community participation, we may process the profile content, images, submissions, messages, or feedback you choose to provide. The existence of this section does not activate a program or imply that a feature is available in all channels.

## 3 How We Use Personal Information

We use personal information for the purposes below.

### 3.1 Provide and Operate the Services

We use information to:

* Create, authenticate, maintain, and secure accounts.
* Connect wallets and display wallet or platform account information.
* Provide guest browsing, search, Pack purchases and openings, marketplace transactions, offers, listings, auctions, and account records.
* Process and reconcile USDC deposits, withdrawals, payments, refunds, pending amounts, and transaction restrictions within our control, as well as any payment-provider steps you use.
* Administer GP and CP points, membership levels, active benefits, and any optional program you actually join under its applicable rules.
* Display collectible, custody, and physical delivery records.
* Process eligible physical delivery requests and provide shipping updates.
* Remember language, settings, and session state.

### 3.2 Security Fraud Prevention and Compliance

We use information to:

* Prevent unauthorized access, bots, multiple-account abuse, account takeover, fraud, wash trading, market manipulation, counterfeit-card submissions, and exploitation of errors.
* Verify identity and eligibility and conduct sanctions, anti-money laundering, and risk checks where required.
* Protect users, assets, the Platform, our partners, and the public.
* Investigate disputes, chargebacks, suspicious transactions, security incidents, and policy violations.
* Enforce our Terms and comply with law, court orders, and government requests.

### 3.3 Platform Performance Analytics and Improvement

We use information to:

* Diagnose crashes, loading failures, transaction interruptions, and compatibility problems.
* Understand how users navigate and use Platform features.
* Measure product reliability, feature performance, campaign attribution, and conversion.
* Improve interface design, search, recommendations, support, security, and fraud controls.
* Create aggregated or de-identified statistics that do not reasonably identify an individual.

### 3.4 Communications

We use contact information to send:

* One-time verification codes and account-security messages.
* Transaction, balance, custody, and physical delivery updates.
* Support responses and administrative notices.
* Changes to terms, privacy notices, or material service conditions.
* Marketing communications where permitted by law and consistent with your choices.

You can opt out of marketing emails using the unsubscribe link or by contacting us. You will still receive necessary service and security communications.

### 3.5 Legal and Business Purposes

We use information for accounting, tax, insurance, audits, recordkeeping, legal claims, corporate governance, and a merger, financing, reorganization, acquisition, bankruptcy, or sale of assets.

## 4 Legal Bases for Processing

Where the law requires a legal basis, we rely on one or more of the following:

* **Contract:** To create and maintain your account, process transactions, provide requested features, and respond to support requests.
* **Legitimate interests:** To secure and improve the Platform, prevent fraud, understand use, protect legal rights, and operate our business, where those interests are not overridden by your rights.
* **Consent:** For optional device permissions, certain analytics or marketing technologies, marketing messages, or another purpose explained when consent is requested.
* **Legal obligation:** To comply with tax, accounting, sanctions, anti-money laundering, consumer-protection, regulatory, and legal-process requirements.
* **Vital or public interests:** Where applicable and permitted by law to protect safety or comply with a task carried out in the public interest.

## 5 How We Disclose Personal Information

We may disclose personal information to the categories below for the stated purposes. We do not authorize service providers to use personal information for unrelated purposes.

### 5.1 Affiliates

We may disclose information to our corporate affiliates for purposes consistent with this Policy.

### 5.2 Authentication and Wallet Providers

We may exchange account, session, and authentication information with Google, Apple, Privy, compatible wallet apps, and other wallet infrastructure providers to complete the sign-in or wallet action you request, including an embedded-wallet transaction confirmed through Topmarket's transaction confirmation dialog.

Privy provides embedded-wallet infrastructure used by the Services. Information processed for that integration may include account and authentication identifiers, wallet addresses, session and authorization information, wallet-action details, and device or network information necessary to operate and secure the service. The information involved depends on the sign-in method and wallet functionality you use. See [Privy's Privacy Policy](https://www.privy.io/privacy-policy) for its description of personal-information handling. This does not replace Topmarket's responsibilities for its own processing or its use of service providers.

### 5.3 Payment Blockchain and Compliance Providers

We may disclose wallet addresses, transaction information, account information, and risk information to blockchain infrastructure providers, payment or crypto transfer providers, identity verification vendors, transaction-monitoring services, fraud prevention vendors, and sanctions screening providers.

Blockchain transactions are public by design. Wallet addresses, transaction hashes, asset transfers, and smart-contract interactions may be copied, indexed, analyzed, or retained by anyone.

### 5.4 Custody Grading Insurance and Delivery Providers

We may disclose card details, identity and contact information, address, declared value, verification status, tracking information, and delivery instructions to grading companies, custody or vault providers, insurers, carriers, logistics providers, customs agents, and other parties needed to provide physical-card services.

### 5.5 Technical and Business Service Providers

We may disclose information to providers of hosting, cloud infrastructure, Platform analytics, crash reporting, communications, email delivery, customer support, cybersecurity, audit, and professional services.

Providers and technologies may differ by channel and change over time. We are responsible for keeping this Policy, channel-specific notices and consent flows, and the App's store disclosures accurate for the processing actually performed.

### 5.6 Other Users and Public Features

Marketplace and blockchain activity may make certain information visible to other users or the public, including wallet address, display name, collectible, listing, offer, bid, sale, price, and transaction history. The Platform may also share a public web link when you use a share feature.

Do not include private or sensitive information in a public field. Information made public may be copied or retained by others after you remove it from the Platform.

### 5.7 Authorities Advisors and Rights Protection

We may disclose information to courts, law enforcement, regulators, tax authorities, government agencies, lawyers, auditors, insurers, banks, and other parties where we reasonably believe disclosure is necessary to comply with law, protect rights or safety, investigate misconduct, or establish or defend legal claims.

### 5.8 Business Transfers

We may disclose or transfer information in connection with a merger, acquisition, financing, reorganization, bankruptcy, sale of assets, or similar transaction, subject to applicable law.

### 5.9 At Your Direction

We disclose information when you direct us to do so, such as when you connect a wallet, open an external service, share a public link, or provide consent.

## 6 Website Cookies App Technologies and Linked Content

### 6.1 Websites and Mobile Browsers

The Websites may use cookies, local storage, pixels, and similar technologies to maintain sessions, remember preferences, secure the service, measure usage, and support marketing where permitted. Website integrations may include Google Analytics 4 and PostHog for analytics, and Meta Pixel for advertising measurement or marketing, where those tools are deployed and subject to the applicable configuration and choices.

You can use available website cookie controls and browser settings to manage the relevant technologies. Where consent is required, optional technologies must not operate before that consent is obtained. Browser settings can block or remove cookies, but disabling necessary storage may affect sign-in or other requested functionality. Cookie choices may be browser- or device-specific; deleting cookies may also remove the saved choice.

### 6.2 Native Mobile Apps

The App may use local storage, identifiers, analytics SDKs, crash-reporting tools, and similar technologies to operate the App, maintain security, remember preferences, and understand performance and use. The technologies actually included in the App may differ from those deployed on the Websites. Naming a website analytics or advertising provider in this Policy does not mean that its native SDK is included in the App.

Where App activity constitutes tracking that requires Apple's App Tracking Transparency permission, we request that permission before the tracking occurs. A website cookie choice does not replace a required App tracking permission. You can manage applicable permissions through the App or operating-system settings.

### 6.3 Embedded Pages and Third Party Content

Topmarket web pages opened inside or from the App remain covered by this Policy and the applicable website notices. A third-party page or integration may have its own notice for its independent processing. We remain responsible for processing attributable to our own integrations; opening web content does not remove applicable consent or disclosure obligations.

## 7 Advertising and Sale or Sharing of Personal Information

We do not sell personal information for money.

Certain analytics, attribution, or marketing activities may be treated as a “sale,” “sharing,” or “targeted advertising” under some U.S. state privacy laws, even when no money is exchanged. Where a channel engages in such activity, including through website advertising tools where applicable, we provide the notices and opt-out mechanism required by applicable law. App store disclosures must reflect the App's actual practices, including applicable embedded integrations.

The application of these rules depends on actual data flows and provider use, not merely a tool's name. We do not treat the presence of a web analytics tool as proof that the App conducts the same processing. Contact us for assistance with the choices applicable to the channel you use.

## 8 Your Choices

You may:

* Browse certain public content without signing in.
* Choose among available sign-in methods.
* Disconnect a compatible wallet, subject to any open transaction or security restrictions.
* Change language and other settings in the Platform.
* Deny or revoke device permissions in system settings.
* Opt out of marketing emails.
* Use available website cookie controls, browser settings, and privacy or tracking controls made available by your device, app store, or the Platform.

These choices may limit the associated feature but will not affect processing required for security, completed transactions, legal obligations, or operation of a feature you continue to use.

## 9 Your Privacy Rights

Depending on where you live, you may have the right to:

* Request access to personal information we hold about you.
* Request correction of inaccurate information.
* Request deletion of personal information.
* Restrict or object to certain processing.
* Receive a portable copy of certain information.
* Withdraw consent for future processing based on consent.
* Opt out of certain marketing, targeted advertising, sale, or sharing activities.
* Appeal a refusal of a request or complain to a data protection authority.

To exercise a privacy right other than account deletion, submit a privacy or support request through the Platform where available, or contact <info@top.market>. Tell us the right you wish to exercise and provide enough information for us to locate your account. We may verify your identity and authority before acting. You may use an authorized agent where applicable law permits. Account deletion is addressed in Section 10.

We will not discriminate against you for exercising a privacy right. A right may be limited by applicable exceptions, including transaction integrity, fraud prevention, legal claims, regulatory records, and information we cannot control on a public blockchain.

## 10 Account and Data Deletion

Signing out, uninstalling the App, disconnecting a wallet, or clearing browser cookies, local storage, or App data does not delete your account or information held in our systems.

App users may initiate permanent account deletion through the verified account-deletion process available in the App without being required to send an email. Website users may use any account-deletion control actually offered on the Websites or contact <info@top.market>. A Website control is not implied by the existence of an App control. Where you use the same account across channels, deletion concerns that account across the Platform rather than only the access channel or device. Signing out or receiving a sign-out confirmation is not account deletion.

Account-deletion requests are reviewed manually. We normally complete a verified request within seven business days. If applicable law, a verified security concern, or an unresolved account matter permits or requires additional time, we will explain the reason and provide an updated expected completion date. We will confirm through an authorized channel when deletion has been completed.

Before completing deletion, we may require identity verification and the lawful handling of open balances, Collectibles, listings, bids, offers, transactions, custody records, physical delivery requests, disputes, or legal holds. We will provide instructions describing the balance-handling options then available under applicable law, supported payment methods, and technical capabilities. Submitting a deletion request does not, by itself, waive or transfer your ownership of a balance or Collectible.

After deletion, we may retain limited information where necessary for legal compliance, accounting, fraud prevention, sanctions controls, security, dispute resolution, or enforcement of agreements. We will not retain unrelated personal information solely because an account previously had an unresolved matter. Where the deleted account used Sign in with Apple, we will revoke the associated Sign in with Apple tokens as part of the deletion process where applicable.

Public blockchain records are immutable and may remain publicly available indefinitely. We cannot delete, reverse, or anonymize data controlled by an independent blockchain.

## 11 Additional Notice for Certain United States Residents

Subject to applicable law, categories of personal information we may collect include:

* Identifiers, such as email, account ID, wallet address, IP address, device or session identifiers, and authentication identifiers.
* Customer records, such as contact, delivery, verification, and account information.
* Commercial information, such as Packs, purchases, sales, listings, offers, bids, refunds, rewards, custody, and delivery history.
* Internet or electronic activity, such as Platform use, searches, navigation, interactions, and diagnostic logs.
* Approximate geolocation derived from IP address.
* Financial information, such as supported asset balances, payment status, transaction details, and refund records.
* Inferences, such as fraud risk, product interests, and feature or campaign attribution.
* Sensitive personal information, such as government identification, account credentials, precise transaction or financial information, or other verification data, when collected.

We use and disclose these categories for the purposes described in Sections 3 and 5. We do not knowingly sell or share the personal information of users under 18.

Where applicable, you may have the rights described in Section 9, including rights to know, correct, delete, opt out, limit certain uses of sensitive personal information, and appeal. We will provide any required opt-out mechanism if the Platform engages in regulated sale, sharing, or targeted advertising.

## 12 Additional Notice for the EEA United Kingdom and Similar Jurisdictions

The controller of personal information covered by this Policy is HYPER COLLECTIBLES LIMITED, unless a feature-specific notice identifies another controller.

Our legal bases are described in Section 4. You may have the rights described in Section 9 and the right to lodge a complaint with your local supervisory authority. We encourage you to contact us first so that we can try to resolve the issue.

Where required, we use approved contractual terms, adequacy decisions, or another lawful mechanism for international transfers.

## 13 Retention

We retain personal information only for as long as reasonably necessary for the purposes described in this Policy, including to provide the Services, maintain security, comply with law, resolve disputes, prevent fraud, preserve transaction integrity, and enforce agreements.

Retention varies by data type. For example:

* Account and preference information may be kept while the account is active and for a reasonable period afterward.
* Authentication and security logs may be retained for fraud prevention and incident investigation.
* Payment, blockchain, transaction, tax, accounting, sanctions, and dispute records may be kept for legally required or risk-appropriate periods.
* Custody, grading, insurance, customs, and delivery records may be kept for fulfillment, audit, claims, and legal compliance.
* Public blockchain data may remain available indefinitely and cannot be deleted by us.

We may retain de-identified information where it cannot reasonably be used to identify you.

## 14 Security

We use technical, organizational, and administrative safeguards designed to protect personal information. These may include access controls, authentication, encryption in transit, monitoring, logging, vendor review, and incident response.

No system is completely secure. You are responsible for protecting your device, email, authentication methods, connected wallets, private keys, seed phrases, and recovery information. Contact us promptly if you suspect unauthorized access.

## 15 Server Location and International Transfers

The servers used to host the Topmarket Services are located in Singapore. Personal information processed through those servers is processed in Singapore.

This server location does not mean that Privy's infrastructure, other third-party services, or blockchain nodes are all located in Singapore.

We and our service providers may process information outside the country where you live. Those locations may have different privacy laws. Where required, we use lawful transfer safeguards.

Blockchain, wallet, authentication, payment, custody, and delivery services may operate across multiple jurisdictions, and public blockchain data is globally accessible.

## 16 Children

The Services are not directed to anyone under 18 or under the age of majority in their jurisdiction, whichever is higher. We do not knowingly collect personal information from children.

If you believe a child has provided personal information, contact <info@top.market>. We will take appropriate action as required by law.

## 17 Third Party Services

The Platform may link to or integrate with authentication providers, wallet apps, blockchain explorers, payment and transfer services, grading companies, custody providers, carriers, app stores, and other third parties.

We do not control their independent privacy practices. Review their privacy notices before providing information or using their services. A third party may be an independent controller of information it receives directly from you.

## 18 App Store and Google Play Disclosures

Apple App Privacy and Google Play Data Safety disclosures summarize the practices of the relevant native App release, including applicable SDKs and embedded integrations. They do not replace this unified Policy or necessarily describe technologies used only on the Websites. We will use reasonable processes to keep those disclosures, App consent screens, website notices, and this Policy consistent with the processing actually performed in each channel.

If you identify an inconsistency, contact us so we can investigate and correct the disclosure or underlying processing. An inaccurate store label or website notice does not excuse non-compliance with this Policy or applicable law.

## 19 Changes to This Policy

We may update this Policy from time to time. We will identify the effective date of a published update and provide notice of material changes through the Platform, email, or another method required by law. Where consent is required, we will request it. The Websites and App will use the same published Policy version; channel-specific notices explain the relevant differences.

## 20 Contact Us

For privacy questions, rights requests, or account-deletion requests, contact:

HYPER COLLECTIBLES LIMITED\
Room D07, 8/F, Phase 2, Kaiser Estate\
99 King Fuk Street, San Po Kong\
Hong Kong\
Email: <info@top.market>


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.top.market/user-agreements/privacy-policy.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
