Privacy Policy
Effective date: 15 July 2026. This English version is for convenience only — the Czech version (/cs/privacy) is the legally binding text per CZ law.
0. Stripe Connect (from 14 May 2026)
Stripe Connect onboarding (Tipsters). During onboarding, the Tipster provides their data (name, contact details, business ID (IČO) where applicable, identity documents) directly to Stripe Payments Europe Ltd. (registered in Ireland) for KYC/AML purposes. The Operator shares a limited set of data with Stripe — name, e-mail, business ID (IČO, where relevant) and the Tipster's internal ID — to the extent necessary to link the account (legal basis: Article 6(1)(b) GDPR, performance of a contract).
DAC7 (Directive (EU) 2021/514). The Operator does not file DAC7 reports — see Section 2.6 below for the detailed reasoning.
Retention. The accounting trail of marketplace transactions (Stripe payment intents, tax documents and correction documents, refunds) is retained for 10 years pursuant to Section 35(2) of the VAT Act (tax documents) and Section 31(2)(a) of Act No. 563/1991 Coll. (financial statements). Identification via Stripe Connect is retained for 10 years — a period voluntarily aligned with the AML retention standard (the Operator is not an obliged entity under Act No. 253/2008 Coll.; the legal basis for the retention period is Section 35(2) of the VAT Act (tax documents) and Section 31(2)(a) of Act No. 563/1991 Coll. (financial statements)).
1. Controller of personal data
The controller of personal data within the meaning of Article 4(7) of Regulation (EU) 2016/679 of the European Parliament and of the Council (hereinafter the "GDPR") and the operator of the FlipKing Pro platform (hereinafter the "Controller" or the "Operator") is:
- Maxim Ponomarenko
- Business ID (IČO): 73988146
- VAT ID (DIČ): CZ8507074378
- Place of business: náměstí Naděje 771, 566 01 Vysoké Mýto, Czech Republic
- Self-employed natural person (sole trader)
Contact e-mail for exercising data subject rights: [email protected]. General support: [email protected].
The Operator has not appointed a Data Protection Officer (DPO) within the meaning of Article 37(1) GDPR — none of the mandatory triggers apply (we are not a public authority, our core activity is neither large-scale regular and systematic monitoring nor large-scale processing of special categories of data under Article 9). This analysis is reviewed annually, most recently on 2026-04-24. The contact person for all GDPR enquiries is Maxim Ponomarenko, the operator — [email protected].
1.5 Territorial scope
We process personal data primarily within the European Economic Area (Hetzner servers, data centres in Falkenstein, DE / Helsinki, FI). Cross-border transfers outside the EEA take place only to the extent necessary for payment processing (Stripe Payments Europe Ltd., IE; Stripe Inc., US — under the EU-US Data Privacy Framework) and the delivery of transactional e-mails (Resend, Inc., US — under the DPF / SCCs). These transfers are governed by the Standard Contractual Clauses under Commission Implementing Decision (EU) 2021/914 and are described in detail in Section 4a.
The Platform is available only to residents of the Czech Republic — we do not carry out targeted processing or profiling of persons outside the Czech Republic. A data subject residing outside the Czech Republic whose data nevertheless ends up on the Platform has all rights under the GDPR (Articles 15–22) to the extent set out below.
2. What data we process
2.1 Registration data
- E-mail address
- First name and surname (optionally a nickname)
- Password hash (bcrypt, cannot be reversed)
2.2 Identification data (identity verification via Stripe Connect)
As part of registration and identity verification via Stripe Connect (the payment service provider performs KYC when payouts are connected), we process the following identification data:
- name — first name and surname identifying the subject.
- date of birth — to verify that the user is a fully legally capable person over 18 (age gate; legal basis Art. 6(1)(b) GDPR — performance of a contract whose conclusion requires full legal capacity under Sec. 30 and 15 of the Czech Civil Code).
Identity verification is provided by Stripe Connect (the payment service provider), which is the legally binding identification (KYC) for AML purposes and for payouts to Tipsters (Stripe Connect onboarding).
2.3 Payment data
All payments (top-ups of Purchased FK, Marketplace, bounties, Subscription, payouts to Tipsters) are processed by Stripe Payments Europe, Limited (Ireland); within the Stripe group, Stripe, Inc. (USA) may also be involved as a sub-processor. The Controller does not store payment card numbers — it holds only a token and transaction metadata (amount, currency, status, last four digits of the card, Stripe payment intent ID, Stripe Connect transfer ID). The Tipster, as the recipient of funds, provides the data required for KYC directly to Stripe during Stripe Connect onboarding.
2.4 Operational data
- IP address, user agent, browser language, screen resolution.
- Logs of access and actions on the Platform (audit trail) — user identifier, time, action, outcome.
- Content of published tips and interactions with the Platform.
- Purchased FK wallet balance and the transaction history of purchases and spending. Legal basis: Article 6(1)(b) GDPR (performance of the user account contract) in combination with Article 6(1)(c) (legal obligation under Section 35(2) of the VAT Act — tax documents — and Section 31(2)(a) of Act No. 563/1991 Coll. — financial statements; 10-year retention).
2.5 Product analytics and session recording (optional)
Only with consent given in the cookie banner (Article 6(1)(a) GDPR) do we record:
- Click and scroll data — for product analytics, conversion measurement and UX testing.
- Session recording (session replay via rrweb) — sequences of DOM interactions; the values of sensitive fields (passwords, card numbers, identification data) are technically masked at capture. The recording is linked to the logged-in user's ID and a session identifier.
The purpose of the processing is product improvement, error diagnostics and protection against fraudulent conduct. Data are stored in the EU. The user may withdraw consent at any time in the page footer ("Cookie settings") — recording stops from the moment of withdrawal.
2.6 DAC7 (the Operator does not file reports)
The Operator does not file reports under DAC7 (Council Directive (EU) 2021/514, implemented in Act No. 164/2013 Coll.) and does not transfer Tipster data to the General Financial Directorate. The platform operator reporting obligation under DAC7 applies only to entities (legal persons and units without legal personality), not to natural persons — the Platform is operated by a self-employed natural person. Moreover, the sale of tips (a static data unit) is not a reportable activity under Annex V (rental of immovable property, transport, personal service, sale of goods).
For DAC7 purposes, the Operator therefore neither processes nor transfers any personal data of Tipsters to the General Financial Directorate. The Tipster has their own tax obligations regarding their income under the Income Tax Act; for the purposes of their tax return, the Operator provides an overview of payouts for the calendar year in the Tipster Dashboard.
3. Legal basis of processing
- Performance of a contract (Article 6(1)(b) GDPR) — registration, account operation, transaction processing.
- Legitimate interest (Article 6(1)(f) GDPR) — Platform security, fraud prevention (including automated anomaly detection), audit logs and the technical logging necessary for incident resolution. Legitimate interest does not extend to product analytics and session recording — those rely exclusively on consent.
- Consent (Article 6(1)(a) GDPR) — product analytics and session recording (session replay), optional cookies beyond those strictly necessary, marketing e-mails, optional supplementary profile data. Consent may be withdrawn at any time as easily as it was given (Article 7(3) GDPR).
- Legal obligation (Article 6(1)(c) GDPR) — accounting and tax regulations (Acts No. 563/1991 Coll., 235/2004 Coll., 586/1992 Coll.), obligations arising from cooperation with law enforcement authorities and supervisory authorities.
4. Processors, independent controllers and recipients
We share personal data with the following parties. For each, we state in what capacity within the meaning of the GDPR it acts towards users:
- Stripe Payments Europe, Limited (Ireland) — payment services and Stripe Connect. Stripe acts simultaneously as a processor under Article 28 GDPR (for the data we transfer to it under our payment instruction) and as an independent controller under Article 4(7) GDPR for the purposes of fulfilling its own legal obligations (AML, fraud prevention, regulatory reporting, KYC Connect onboarding). Stripe's processing as an independent controller is governed by the Stripe Global Privacy Policy. Within the Stripe group, transfers to the USA may occur, protected by the European Commission's Standard Contractual Clauses and Stripe's participation in the EU-U.S. Data Privacy Framework.
- Hetzner Online GmbH (Germany, EU) — hosting of server infrastructure (processor under Article 28 GDPR).
- Cloudflare, Inc. (USA) — CDN, attack protection and edge security; processor under Article 28 GDPR. Transfers to the USA are protected by the European Commission's Standard Contractual Clauses (Article 46 GDPR) and Cloudflare's participation in the EU-U.S. Data Privacy Framework.
- Resend, Inc. (USA) — sending transactional and notification e-mails (registration confirmation, password reset, platform notifications). Processor under Article 28 GDPR; the transfer is protected by EU Standard Contractual Clauses and by participation in the EU-U.S. Data Privacy Framework programme.
- Seyfor, a.s. (Company ID (IČO) 01572377, Brno, Czech Republic — EU) — the iDoklad invoicing service: issuance and records of tax documents. Data transferred: name / business name, e-mail, company ID (IČO), VAT ID (DIČ), billing address, document line items and amounts. Processing takes place in the EU.
- Askela (Czech Republic) — CRM, error telemetry and product analytics signals (processor under Article 28 GDPR).
- Google Ireland Ltd., resp. Google LLC (USA) — Google Analytics 4 (traffic and conversion measurement on landing pages; with consent to marketing cookies also GA4 advertising signals). Active only with consent to analytics, resp. marketing cookies; processor under Article 28 GDPR. Transfers to the USA protected by Standard Contractual Clauses and participation in the EU-U.S. Data Privacy Framework.
- Mapy.cz / Seznam.cz, a.s. (Czech Republic) — rendering of interactive maps for properties; independent controller of the technical data (IP, User-Agent, geocoordinates for requested map tiles) associated with requesting map tiles.
- ČÚZK, ARES, ISIR (Czech public authorities) — public registers from which we obtain data on property ownership, legal entities and insolvencies for verification and fraud prevention purposes; independent controllers, with whom we share data only to the extent necessary for the query.
- Public authorities — independent controllers; we disclose data to them only to the extent required by law (Czech Police, Office for Personal Data Protection, Tax Administration, courts, or, where applicable, the Financial Analytical Office).
4a. Transfers outside the EEA
In the course of payments, certain data are transferred to the USA (Stripe, Inc., Delaware). With consent to analytics, resp. marketing cookies, certain data are also transferred to the USA via the Google (Google Analytics 4) tool. All such transfers are protected by the European Commission's Standard Contractual Clauses (Article 46(2)(c) GDPR) and the participation of the relevant entities in the EU-U.S. Data Privacy Framework (Article 45 GDPR). The Controller does not normally carry out any other transfers outside Europe. If a selected sub-processor processes data outside the EEA, it will always be listed here with a reference to the safeguard used.
4b. Automated decision-making and profiling
The Platform uses the following automated evaluation:
- Tipster rank (NEWCOMER / VERIFIED / EXPERT / ELITE) — recalculated automatically based on the number of completed sales (only ratings on transactions in the RELEASED state, after disputes and refunds have been resolved) and the average rating from Buyers. The rank determines the commission rate and is earned through performance (it cannot be purchased). The maximum number of active tips and the length of the pre-payout protection period are determined by the paid subscription (§ 6.3.1), not the rank; an active subscription also applies a 20% cap to the commission. Neither rank nor subscription has any direct effect on the ability to use the account.
- Anomaly detection — rules identify suspicious patterns (e.g. multiple accounts, unusual transaction sequences, attempts to circumvent rate limits). When a rule is triggered, the corresponding action is rejected or the account is automatically suspended.
If the system detects a risk signal, the corresponding action is automatically rejected or the account is automatically suspended (account freeze). Such a measure may have significant effects on the user (in particular the inability to make Marketplace purchases and use paid services; for Tipsters, suspension of payouts via Stripe Connect), and in accordance with Article 22(3) GDPR the user has the right to human review of this decision.
In accordance with Article 22(3) GDPR, the user has the right to:
- obtain human intervention — the Operator will ensure manual review of the decision by a responsible person without undue delay after receiving a reasoned request;
- express their point of view and provide evidence of circumstances the system could not take into account;
- contest the decision before the Office for Personal Data Protection or through the courts.
A review request may be submitted directly in the application or by e-mail to [email protected] with the account identification and a brief description of the situation. The automated measure remains in effect until the request has been assessed. The review is carried out manually by a responsible person of the Operator, and the Operator applies the following fixed SLAs:
- Notification to the user about automatic suspension — sent by e-mail within 24 hours of the auto-freeze trigger (with reasoning to the extent that does not conflict with the anti-tipping-off obligation in AML cases).
- Deadline for human review upon the user's request under Article 22(3) GDPR — the Operator will decide no later than 7 calendar days from the submission of a reasoned request.
- Maximum duration of automatic suspension without a completed review — 60 days; after this period the Operator will either unblock the account or formally escalate the matter to the competent authority (FAÚ, ÚOOÚ) and inform the user of the escalation.
- Escalation to the ÚOOÚ — if a dispute about an automated decision is not resolved between the user and the Operator within 30 days of the Operator's response, the user is entitled to contact the Office for Personal Data Protection (uoou.gov.cz).
These SLAs correspond to the Operator's compliance procedure and serve as guidance for user expectations. In exceptional cases (e.g. a parallel investigation by law enforcement authorities), the deadline for human review may be extended, but always with active notification to the user stating the reason for the extension.
4c. Third-party data from public registers (Art. 14 GDPR)
When verifying properties and preventing fraud, the Operator processes — at the user's request — personal data of third parties who are not users of the Platform and which the Operator did not obtain directly from them, but from public registers. In accordance with Art. 14 GDPR, it provides the following information:
- Categories of data and source (Art. 14(1)(d) and (2)(f)): from the real-estate cadastre (ČÚZK), the name, surname and address of property owners listed on requested title-deed extracts; from the insolvency register (ISIR), the name, surname and birth number of debtors (processing of the birth number is governed by Section 13c of Act No. 133/2000 Coll. on the register of inhabitants). The data come exclusively from publicly accessible official registers (ČÚZK, ISIR, ARES).
- Purpose and legal basis (Art. 14(1)(c)): verification of ownership and the legal status of a property and fraud prevention on the basis of the legitimate interest of the Operator and the user (Art. 6(1)(f) GDPR); an objection to this processing may be raised under Art. 21 GDPR.
- Storage period: downloaded official ČÚZK extracts are retained for the period necessary to evidence the check performed (max. 10 years under accounting and evidentiary periods); an ISIR check serves only for verification and is not stored beyond the audit trail of the query.
- Recipients: the data are made available only to the querying user (or their Company) to the extent necessary for the given query and are not passed on further or indexed for search.
- Rights: the data subject has the rights under Art. 15–21 GDPR (access, rectification, erasure, restriction, objection); requests are handled by the Operator at [email protected]. As the data originate from public registers and are processed on an ad-hoc basis at the user's request, the Operator relies on the exemption from direct notification under Art. 14(5)(b) GDPR (disproportionate effort) and fulfils its information obligation by this publication.
5. Retention periods
Automatic periods (technically enforced by scheduled jobs):
- Session recording (rrweb) and product analytics — no more than 30 days from capture; deleted automatically thereafter.
- Detailed information on purchased tips (sensitive data on a specific property) — no more than 90 days from purchase; removed automatically thereafter.
Managed periods (retained for as long as necessary; erasure occurs upon request or as part of a regular review):
- Account and profile data — for the duration of the account's existence. After a deletion request is submitted, a 30-day grace period runs, after which the profile is automatically anonymised.
- KYC and identification data (Stripe Connect data; the Operator does not store copies of identity documents — these are held exclusively by Stripe as an independent controller) — 10 years after the end of the business relationship. The Operator is not an obliged entity under Section 2 of Act No. 253/2008 Coll. (the obliged entity is Stripe as the payment service provider — see Section 1A.2 of the Terms and Section 4.2 of this policy); the 10-year retention arises from Section 35(2) of Act No. 235/2004 Coll., on VAT (tax documents) and from Section 31(2)(a) of Act No. 563/1991 Coll. (financial statements). The 10-year period is also voluntarily aligned with the retention of AML obliged entities for the purposes of possible voluntary cooperation with the Financial Analytical Office.
- Audit log (security forensics + voluntary AML support) — 10 years from the creation of the record. The legal basis is Section 35(2) of the VAT Act (tax documents) and Section 31(2)(a) of Act No. 563/1991 Coll. (financial statements) to the extent that the audit log documents accounting-relevant operations (credit spending, payouts, refunds), and legitimate interest in security (Article 6(1)(f) GDPR) for security forensics. Section 31(2)(b) and (c) of the Accounting Act provides for a 5-year period for accounting documents; the Operator opts for a uniform 10-year retention for traceability and to enable cooperation with supervisory authorities (ÚOOÚ, FAÚ, ČNB, GFŘ). The AML Act No. 253/2008 Coll. does not directly impose this retention on the Operator — the Operator is not an obliged entity. For non-accounting audit records (e.g. records of logins or completed onboarding), the data subject may submit an erasure request under Article 17 GDPR after 5 years; the Operator will handle it based on an individual assessment.
- Login history — the IP address and browser identification are anonymised after 30 days; complete login records are deleted after 180 days.
- Marketing consent (newsletter) — 1 year after withdrawal of consent, for the purpose of evidencing the existence and scope of consent before the supervisory authority (Section 7(2) of Act No. 480/2004 Coll.).
- Cookie and analytics consent — 5 years from granting/withdrawal (evidence for an ÚOOÚ inspection, per ÚOOÚ guidance).
- Data after account cancellation (profile data, transaction metadata other than KYC) — retained for as long as necessary to settle open claims, complaints and tax audits; erasure or anonymisation is carried out by the Operator at the data subject's request, but no later than upon expiry of the general limitation period (Section 629 of the Civil Code).
- Identification and transaction data of verified Tipsters (KYC data and transaction metadata from Stripe Connect) — no more than 10 years from the end of the relationship. The legal basis is legitimate interest (Article 6(1)(f) GDPR) in the ability to settle potential claims and to evidence the course of transactions; to the extent a specific item is required by special regulations (accounting, VAT, or AML should the Operator become an obliged entity), the legal basis is a legal obligation (Article 6(1)(c) GDPR).
Statutory periods:
- Accounting records — 10 years (the Operator is a VAT payer, VAT ID CZ8507074378) pursuant to Section 35(2) of Act No. 235/2004 Coll., on VAT (tax documents), and Section 31(2)(a) of Act No. 563/1991 Coll. (financial statements).
The periods stated above are maximums. The data subject may at any time request erasure under Article 17 GDPR by e-mail to [email protected]. The Operator will handle the request within 30 days (Article 12(3) GDPR) and will inform which data have been erased and which must be retained due to legal obligations or legitimate interests.
Note: Account deletion is available as self-service in Account Settings → "Delete account". The request goes through a 30-day grace period, after which the Operator automatically anonymises the personal data; selected transaction metadata and accounting records are kept in anonymised form for the period necessary under the retention periods stated above.
6. Data subject rights
As a data subject, you have the following rights under the GDPR, which you may exercise by e-mail to [email protected]:
- Right of access to the data we process about you (Article 15).
- Right to rectification of inaccurate data (Article 16).
- Right to erasure ("right to be forgotten", Article 17) — except for data we are required to retain by law.
- Right to restriction of processing (Article 18).
- Right to data portability to another service in a machine-readable format (Article 20).
- Right to object to processing based on legitimate interest (Article 21).
- Right to withdraw consent (with effect for the future, Article 7).
- Right to lodge a complaint with the supervisory authority — the Office for Personal Data Protection (uoou.gov.cz).
Consequences of not providing data (Article 13(2)(e) GDPR): The provision of KYC data (identification via Stripe Connect, business ID (IČO), VAT ID for VAT payers, address) is a contractual requirement — without these data it is not possible to complete the connection of payouts via Stripe Connect (Stripe, as the payment service provider, is an obliged entity under Act No. 253/2008 Coll. and requires the verification), nor to fulfil the Operator's tax obligations (Section 28 of the VAT Act — issuance of tax documents). Without these data, it is not possible to activate tipster features, issue tax documents or process payouts. The consequence of not providing them is the inability to use the paid features of the platform.
7. Cookies, analytics and session recording
The Platform uses technical cookies and local storage necessary for its operation (login, CSRF protection, language preference, record of granted consent). These processing operations are based on legitimate interest (Article 6(1)(f) GDPR) and Section 89 of Act No. 127/2005 Coll. — consent is not required.
Analytics and product tools, including session recording (session replay via rrweb), are activated only after consent is given in the cookie banner (Article 6(1)(a) GDPR). Consent may be withdrawn at any time using the "Cookie settings" button in the page footer — withdrawal takes immediate effect and any ongoing recording is terminated. A detailed description of the categories and technologies is provided in the Cookie Policy.
8. Security
The Controller has adopted appropriate technical and organisational measures to protect personal data — encryption in transit (TLS 1.2+), password hashing, backups, least-privilege access control and regular security audits.
9. Changes to this policy
This policy may be updated. We will inform users of material changes by e-mail or by an in-app notice at least 14 days before the change takes effect.
Current version dated 15 July 2026.