Privacy Policy
Effective date: 17 July 2026 · Last updated: 17 July 2026
Flippd is operated by Zanatech Ltd (“Flippd”, “we”, “us”), a company registered in England and Wales (Company No. 17327817), registered office: 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom. We are the “data controller” of the personal data described in this policy.
Contact: privacy@flippdkids.com
Flippd is a geography learning game for children aged 6–12. Because children use Flippd, we hold ourselves to the strictest applicable standards: the UK GDPR and the ICO’s Age Appropriate Design Code, the EU GDPR, and the US Children’s Online Privacy Protection Act (COPPA), including the amended COPPA Rule in effect from April 2026.
The short version
- Accounts are created and owned by parents or guardians (18+). Children never create accounts.
- We collect the minimum data needed to run the game: a parent email, and for each child a first name or nickname, an age band, and game progress.
- We do not collect children’s email addresses, phone numbers, precise location, photos, videos, voice recordings, or biometric data.
- There are no ads, no third-party tracking, no chat, and no social features. We never sell personal data, and we never will.
- Children appear on leaderboards only under auto-generated nicknames — never real names.
- Parents can view, correct, download, or delete their child’s data at any time from the parent dashboard or by emailing us.
1. Who this policy covers
- Parents/guardians who create and manage a Flippd account.
- Children who play under a player profile inside a parent’s account.
- Visitors to flippdkids.com.
2. What we collect
From parents
| Data | Why | Legal basis (UK/EU GDPR) |
|---|---|---|
| Email address | Account creation, sign-in (magic link), service emails | Contract (Art. 6(1)(b)) |
| Google account name, email and avatar (if you sign in with Google) | Sign-in | Contract |
| Subscription plan, billing history | Providing your subscription | Contract |
| Payment card details | Collected and stored by Stripe, our payment processor — never by us | Contract |
| Support correspondence | Answering your questions | Legitimate interests (Art. 6(1)(f)) |
About children (entered by the parent)
| Data | Why | Legal basis |
|---|---|---|
| First name or nickname | Personalising the child’s profile inside your account | Contract + parental consent |
| Age band | Age-appropriate content settings | Contract + parental consent |
| Avatar selection (from our preset gallery) | Personalisation | Contract + parental consent |
| Game progress, scores, streaks, medals | Core gameplay and the parent progress dashboard | Contract + parental consent |
| Auto-generated leaderboard nickname (e.g. “BraveLion42”) | Weekly leaderboard without revealing identity | Contract + parental consent |
Automatically
| Data | Why | Legal basis |
|---|---|---|
| IP address, browser type, device type | Security, fraud prevention, making the site work | Legitimate interests |
| Strictly necessary cookies (session/auth) | Keeping you signed in | Legitimate interests — see our Cookie Policy |
We do not use analytics or advertising cookies. If that ever changes, we will update this policy and our Cookie Policy first, ask for consent where required, and will never apply behavioural tracking to child profiles.
3. Children’s privacy (COPPA notice — please read)
This section is our notice under the US Children’s Online Privacy Protection Act and reflects our approach globally.
Verifiable parental consent. Only an adult can create a Flippd account. Before a child profile can be used, we obtain verifiable parental consent: on paid plans, through the parent’s payment transaction; on the free plan, through a consent confirmation completed by the account-holding parent at profile creation. We do not collect personal information from a child before consent is given.
What we collect from children. Only what the parent enters (name/nickname, age band, avatar) and gameplay data (scores, progress). Persistent identifiers (session cookies, IP address) are used solely to support internal operations — authentication, security, and serving the game — as permitted by COPPA, and for no other purpose.
What we never collect from children. Email addresses, phone numbers, home addresses, precise geolocation, photos, video, audio recordings, or biometric identifiers.
No behavioural advertising or profiling. We show no advertising of any kind and build no profiles of children beyond their in-game progress.
Disclosure to third parties. We do not disclose children’s personal information to third parties, other than the service providers listed in Section 5 who process it on our instructions under contract. We do not — and will not — share, sell, or license children’s data for marketing, advertising, or any independent use. Under the amended COPPA Rule, any future disclosure beyond service providers would require your separate, opt-in consent; we have no plans to ever ask.
Parents’ rights. At any time you may: review the personal information we hold about your child; correct it; download it; refuse to permit further collection; or have it deleted (delete the child profile in your dashboard, or email privacy@flippdkids.com and we will act within 30 days, usually much faster). We will never require a child to provide more information than is reasonably necessary to play.
Data retention. We keep children’s data only as long as the profile is active. See Section 7.
4. UK & EU specifics
Age Appropriate Design Code. Flippd is designed to conform with the ICO’s Children’s Code: settings are high-privacy by default, we practise data minimisation, we do not profile children, we do not use nudge techniques to extend play or extract data, and geolocation is never collected.
Consent. Where consent is the legal basis for processing a child’s data, that consent is given by the parent/guardian who owns the account — children cannot consent within Flippd, regardless of the varying digital consent ages (13–16) across the UK and EU member states.
International transfers. Our database and authentication are hosted with Supabase in Ireland (EU). Where a service provider processes data outside the UK/EEA (e.g. Stripe, Vercel), transfers are protected by UK International Data Transfer Agreements / EU Standard Contractual Clauses and, where applicable, the EU–US Data Privacy Framework.
5. Who we share data with (sub-processors)
We share personal data only with service providers who process it on our behalf, under contract, and only as needed:
| Provider | Purpose | Location |
|---|---|---|
| Supabase | Database, authentication, file storage | Ireland (EU) |
| Stripe | Payment processing and billing | US/EU (DPF + SCCs) |
| Vercel | Website hosting and delivery | US/EU (DPF + SCCs) |
| Sign-in with Google (only if you choose it) | US/EU (DPF + SCCs) |
We also disclose data if required by law, or to protect the rights, safety, or property of our users. We never sell personal data — adult’s or child’s — and do not “share” it for cross-context behavioural advertising.
6. Your rights
Everyone (UK/EU GDPR): access, rectification, erasure, restriction, portability, objection, and withdrawal of consent at any time. Write to privacy@flippdkids.com. We respond within one month. You may complain to the ICO (ico.org.uk) or your local EU data protection authority — though we’d appreciate the chance to resolve it first.
California residents (CCPA/CPRA): rights to know, delete, correct, and portability; the right to non-discrimination for exercising them. We do not sell or share personal information as defined by the CCPA, including data of consumers under 16. Authorised agents may submit requests to privacy@flippdkids.com.
All US parents: the COPPA rights in Section 3.
7. How long we keep data
| Data | Retention |
|---|---|
| Parent account | Life of account + 30 days after deletion request |
| Child profile & gameplay data | Life of profile; deleted within 30 days of profile deletion or account closure |
| Inactive free accounts | Deleted after 24 months of inactivity, with email warning first |
| Billing records | 6 years (UK tax law requirement) — held as parent data, never child data |
| Support emails | 24 months |
| Server logs (IP addresses) | 30 days |
This is our written retention schedule as required by the amended COPPA Rule. Data is deleted or irreversibly anonymised at the end of the period.
8. Security
Data is encrypted in transit (TLS) and at rest. Access is restricted to authorised personnel on a need-to-know basis. Payment data is handled entirely by Stripe (PCI-DSS Level 1). We maintain a written information security programme and review it regularly. No system is perfectly secure; if a breach affects your data we will notify you and the relevant regulator as required by law (within 72 hours to the ICO where applicable).
9. Just for kids 🌍
Flippd is a game that helps you learn about the world. Here’s our promise to you: we only know the name and age your parent gave us, and how well you’re doing in the games. We never show you adverts. Other players only ever see your fun nickname, like “BraveLion42” — never your real name. Your parent is in charge of your account and can see or delete everything. If anything ever feels wrong, tell a grown-up you trust.
10. Changes to this policy
If we make material changes — especially anything affecting children’s data — we will email account holders before the changes take effect and, where the law requires, ask for fresh consent. The “last updated” date at the top always tells you the current version.
11. Contact
Zanatech Ltd, 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom
privacy@flippdkids.com · support@flippdkids.com