FLIPPDPlay

Privacy Policy

Effective date: 17 July 2026 · Last updated: 17 July 2026

Flippd is operated by Zanatech Ltd (“Flippd”, “we”, “us”), a company registered in England and Wales (Company No. 17327817), registered office: 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom. We are the “data controller” of the personal data described in this policy.

Contact: privacy@flippdkids.com

Flippd is a geography learning game for children aged 6–12. Because children use Flippd, we hold ourselves to the strictest applicable standards: the UK GDPR and the ICO’s Age Appropriate Design Code, the EU GDPR, and the US Children’s Online Privacy Protection Act (COPPA), including the amended COPPA Rule in effect from April 2026.

The short version

  • Accounts are created and owned by parents or guardians (18+). Children never create accounts.
  • We collect the minimum data needed to run the game: a parent email, and for each child a first name or nickname, an age band, and game progress.
  • We do not collect children’s email addresses, phone numbers, precise location, photos, videos, voice recordings, or biometric data.
  • There are no ads, no third-party tracking, no chat, and no social features. We never sell personal data, and we never will.
  • Children appear on leaderboards only under auto-generated nicknames — never real names.
  • Parents can view, correct, download, or delete their child’s data at any time from the parent dashboard or by emailing us.

1. Who this policy covers

  • Parents/guardians who create and manage a Flippd account.
  • Children who play under a player profile inside a parent’s account.
  • Visitors to flippdkids.com.

2. What we collect

From parents

DataWhyLegal basis (UK/EU GDPR)
Email addressAccount creation, sign-in (magic link), service emailsContract (Art. 6(1)(b))
Google account name, email and avatar (if you sign in with Google)Sign-inContract
Subscription plan, billing historyProviding your subscriptionContract
Payment card detailsCollected and stored by Stripe, our payment processor — never by usContract
Support correspondenceAnswering your questionsLegitimate interests (Art. 6(1)(f))

About children (entered by the parent)

DataWhyLegal basis
First name or nicknamePersonalising the child’s profile inside your accountContract + parental consent
Age bandAge-appropriate content settingsContract + parental consent
Avatar selection (from our preset gallery)PersonalisationContract + parental consent
Game progress, scores, streaks, medalsCore gameplay and the parent progress dashboardContract + parental consent
Auto-generated leaderboard nickname (e.g. “BraveLion42”)Weekly leaderboard without revealing identityContract + parental consent

Automatically

DataWhyLegal basis
IP address, browser type, device typeSecurity, fraud prevention, making the site workLegitimate interests
Strictly necessary cookies (session/auth)Keeping you signed inLegitimate interests — see our Cookie Policy

We do not use analytics or advertising cookies. If that ever changes, we will update this policy and our Cookie Policy first, ask for consent where required, and will never apply behavioural tracking to child profiles.

3. Children’s privacy (COPPA notice — please read)

This section is our notice under the US Children’s Online Privacy Protection Act and reflects our approach globally.

Verifiable parental consent. Only an adult can create a Flippd account. Before a child profile can be used, we obtain verifiable parental consent: on paid plans, through the parent’s payment transaction; on the free plan, through a consent confirmation completed by the account-holding parent at profile creation. We do not collect personal information from a child before consent is given.

What we collect from children. Only what the parent enters (name/nickname, age band, avatar) and gameplay data (scores, progress). Persistent identifiers (session cookies, IP address) are used solely to support internal operations — authentication, security, and serving the game — as permitted by COPPA, and for no other purpose.

What we never collect from children. Email addresses, phone numbers, home addresses, precise geolocation, photos, video, audio recordings, or biometric identifiers.

No behavioural advertising or profiling. We show no advertising of any kind and build no profiles of children beyond their in-game progress.

Disclosure to third parties. We do not disclose children’s personal information to third parties, other than the service providers listed in Section 5 who process it on our instructions under contract. We do not — and will not — share, sell, or license children’s data for marketing, advertising, or any independent use. Under the amended COPPA Rule, any future disclosure beyond service providers would require your separate, opt-in consent; we have no plans to ever ask.

Parents’ rights. At any time you may: review the personal information we hold about your child; correct it; download it; refuse to permit further collection; or have it deleted (delete the child profile in your dashboard, or email privacy@flippdkids.com and we will act within 30 days, usually much faster). We will never require a child to provide more information than is reasonably necessary to play.

Data retention. We keep children’s data only as long as the profile is active. See Section 7.

4. UK & EU specifics

Age Appropriate Design Code. Flippd is designed to conform with the ICO’s Children’s Code: settings are high-privacy by default, we practise data minimisation, we do not profile children, we do not use nudge techniques to extend play or extract data, and geolocation is never collected.

Consent. Where consent is the legal basis for processing a child’s data, that consent is given by the parent/guardian who owns the account — children cannot consent within Flippd, regardless of the varying digital consent ages (13–16) across the UK and EU member states.

International transfers. Our database and authentication are hosted with Supabase in Ireland (EU). Where a service provider processes data outside the UK/EEA (e.g. Stripe, Vercel), transfers are protected by UK International Data Transfer Agreements / EU Standard Contractual Clauses and, where applicable, the EU–US Data Privacy Framework.

5. Who we share data with (sub-processors)

We share personal data only with service providers who process it on our behalf, under contract, and only as needed:

ProviderPurposeLocation
SupabaseDatabase, authentication, file storageIreland (EU)
StripePayment processing and billingUS/EU (DPF + SCCs)
VercelWebsite hosting and deliveryUS/EU (DPF + SCCs)
GoogleSign-in with Google (only if you choose it)US/EU (DPF + SCCs)

We also disclose data if required by law, or to protect the rights, safety, or property of our users. We never sell personal data — adult’s or child’s — and do not “share” it for cross-context behavioural advertising.

6. Your rights

Everyone (UK/EU GDPR): access, rectification, erasure, restriction, portability, objection, and withdrawal of consent at any time. Write to privacy@flippdkids.com. We respond within one month. You may complain to the ICO (ico.org.uk) or your local EU data protection authority — though we’d appreciate the chance to resolve it first.

California residents (CCPA/CPRA): rights to know, delete, correct, and portability; the right to non-discrimination for exercising them. We do not sell or share personal information as defined by the CCPA, including data of consumers under 16. Authorised agents may submit requests to privacy@flippdkids.com.

All US parents: the COPPA rights in Section 3.

7. How long we keep data

DataRetention
Parent accountLife of account + 30 days after deletion request
Child profile & gameplay dataLife of profile; deleted within 30 days of profile deletion or account closure
Inactive free accountsDeleted after 24 months of inactivity, with email warning first
Billing records6 years (UK tax law requirement) — held as parent data, never child data
Support emails24 months
Server logs (IP addresses)30 days

This is our written retention schedule as required by the amended COPPA Rule. Data is deleted or irreversibly anonymised at the end of the period.

8. Security

Data is encrypted in transit (TLS) and at rest. Access is restricted to authorised personnel on a need-to-know basis. Payment data is handled entirely by Stripe (PCI-DSS Level 1). We maintain a written information security programme and review it regularly. No system is perfectly secure; if a breach affects your data we will notify you and the relevant regulator as required by law (within 72 hours to the ICO where applicable).

9. Just for kids 🌍

Flippd is a game that helps you learn about the world. Here’s our promise to you: we only know the name and age your parent gave us, and how well you’re doing in the games. We never show you adverts. Other players only ever see your fun nickname, like “BraveLion42” — never your real name. Your parent is in charge of your account and can see or delete everything. If anything ever feels wrong, tell a grown-up you trust.

10. Changes to this policy

If we make material changes — especially anything affecting children’s data — we will email account holders before the changes take effect and, where the law requires, ask for fresh consent. The “last updated” date at the top always tells you the current version.

11. Contact

Zanatech Ltd, 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom
privacy@flippdkids.com · support@flippdkids.com

PrivacyTermsCookiesSupport
🇬🇧 UK🇺🇸 US🇪🇺 EU

© 2026 Flippd · Zanatech Ltd · Registered in England & Wales · Company No. 17327817
71-75 Shelton Street, Covent Garden, London WC2H 9JQ, United Kingdom