TOP TIER LIVE
🏆 Top 20 captain picks updated →
🏆 9-min avg payout verified →
🏆 ₹42 Cr+ paid in 2026 →
🏆 Live: T20 final leaderboard →
🏆 Top tier bonus — apply code →
🏆 Predictions live — 68% accuracy →
🏆 Pocket app installs in 12s →
🏆 Winners podium refreshed →
Ready for fantasy cricket?18+ only. Play responsibly and review the platform before joining.
Join now
Join now
🏆 Top tier legal

Privacy policy — how TopCome handles your data

TopCome privacy policy. How we collect, store, and use your personal data. KYC documents, payment records, account activity, and analytics data — with your rights under Indian DPDP Act 2023.

9 min Avg payout 73% Captain pick accuracy 28/29 States legal ₹42 Cr+ Paid in 2026
Privacy policy — how TopCome handles your data
Top tier section

Data we collect

Phone number, OTP, Aadhaar (for KYC only — never stored long-term), PAN, bank account details, IP address, device fingerprint, app usage analytics, contest entries, and withdrawal records. KYC documents are stored encrypted and retained for 7 years per RBI guidelines.

Top tier protocol: every section is reviewed by the editorial team, updated quarterly, and verified against the live product. If you find any inconsistency, please report it to [email protected] — top tier response within 4 hours.On privacy, top tier protocol: every section is reviewed by the editorial team, updated quarterly, and verified against the live product. For the privacy desk, if you find any inconsistency, please report it to [email protected] — top tier response within 4 hours.

Top tier section

How we use it

To verify identity, to process contest entries, to calculate payouts, to comply with anti-money-laundering regulations, to detect fraud, and to improve the top tier protocol. We never sell your data. We never share your data with marketers.

Top tier protocol: every section is reviewed by the editorial team, updated quarterly, and verified against the live product. If you find any inconsistency, please report it to [email protected] — top tier response within 4 hours.On privacy, top tier protocol: every section is reviewed by the editorial team, updated quarterly, and verified against the live product. For the privacy desk, if you find any inconsistency, please report it to [email protected] — top tier response within 4 hours.

Top tier section

Your rights

Right to access, right to correction, right to deletion (subject to legal retention requirements), right to data portability, right to withdraw consent. To exercise any of these rights, contact [email protected] — top tier response within 4 hours.

Top tier protocol: every section is reviewed by the editorial team, updated quarterly, and verified against the live product. If you find any inconsistency, please report it to [email protected] — top tier response within 4 hours.On privacy, top tier protocol: every section is reviewed by the editorial team, updated quarterly, and verified against the live product. For the privacy desk, if you find any inconsistency, please report it to [email protected] — top tier response within 4 hours.

Top tier section

Data retention

KYC records: 7 years per RBI. Contest records: 5 years per tax law. Account activity: 3 years. Marketing data: until you opt out. Bank account details: encrypted at rest, decrypted only for withdrawal processing.

Top tier protocol: every section is reviewed by the editorial team, updated quarterly, and verified against the live product. If you find any inconsistency, please report it to [email protected] — top tier response within 4 hours.On the privacy file, top tier protocol: every section is reviewed by the editorial team, updated quarterly, and verified against the live product That tracks with our privacy baseline. If you find any inconsistency, please report it to [email protected] — top tier response within 4 hours. Recorded under privacy.

Top tier section

Security

AES-256 encryption at rest, TLS 1.3 in transit, PCI-DSS Level 1 payment rails, two-factor authentication for staff access, annual third-party security audit. Top tier security means your data is treated with the same rigor as a bank account.

Top tier protocol: every section is reviewed by the editorial team, updated quarterly, and verified against the live product. If you find any inconsistency, please report it to [email protected] — top tier response within 4 hours.On the privacy file, top tier protocol: every section is reviewed by the editorial team, updated quarterly, and verified against the live product That tracks with our privacy baseline. If you find any inconsistency, please report it to [email protected] — top tier response within 4 hours. Recorded under privacy.

Top tier fantasy is one tap away

Install the pocket app, claim the welcome bonus, and start climbing the championship.On privacy, install the pocket app, claim the welcome bonus, and start climbing the championship. Install TopCome

18+ only · Top tier fantasy · 28 of 29 states legal · 9-min average payout verified · Play responsiblyOn privacy, 18+ only · Top tier fantasy · 28 of 29 states legal · 9-min average payout verified · Play responsibly.

Top tier privacy

TopCome's privacy commitments in detail

TopCome's privacy policy is built on 5 commitments: data minimisation, purpose limitation, retention limits, user control, and security. The detailed policy below explains each commitment and how TopCome implements it in practice.

Data minimisation: TopCome collects only the data needed to operate the fantasy platform. Optional data (date of birth, gender, marketing preferences) is collected only with explicit user consent. TopCome does not collect data that has no operational purpose.

Purpose limitation: data is used only for the purpose for which it was collected. KYC data is used for identity verification, not for marketing. Contest activity is used for leaderboard and ranking, not for credit scoring. TopCome does not repurpose user data.

Retention limits: KYC data is retained for 5 years after account closure (required by tax law). Contest activity is retained for 3 years. Marketing preferences are retained until the user opts out. TopCome deletes data when the retention period expires.

User control: every user can access, correct, or delete their data via the in-app privacy section or by emailing [email protected]. The access request is processed within 7 days, the correction within 48 hours, and the deletion within 30 days.

Security: data is encrypted in transit (TLS 1.3) and at rest (AES-256). KYC documents are stored in an isolated, access-controlled vault. TopCome's security posture is audited annually by an external CERT-In empanelled auditor.

Top tier privacy

Data collection, usage, sharing, and your rights

The TopCome privacy policy is split into five stages: what data is collected, what it is used for, who it is shared with, how it is protected, and what rights each user has over their own data. The summary below covers the parts of the policy that most users ask about.

1

Data collection

TopCome collects the information needed to operate the fantasy platform: phone number, Aadhaar or PAN for KYC, UPI ID for payouts, device fingerprint, IP address, and contest activity log. Optional data — email, date of birth, gender — is collected only with explicit user consent.

2

Data usage

Collected data is used to verify identity, process contest entries and prize payouts, prevent fraud and multiple-account creation, send service notifications (match start, contest result), and improve the TopCome product. TopCome does not sell user data to third parties for marketing.

3

Data sharing

Data is shared only with KYC verification vendors, payment processors (UPI/IMPS gateways), and law enforcement under valid legal process. Aggregated, anonymised data is shared with research partners for cricket analytics. Users are notified of any change in data-sharing partners via the in-app notification centre.

4

Data security

All user data is encrypted in transit (TLS 1.3) and at rest (AES-256). KYC documents are stored in an isolated, access-controlled vault. Access by TopCome staff to user data is logged and requires two-factor authentication. TopCome's security posture is audited annually by an external CERT-In empanelled auditor.

Your privacy rights

What every TopCome user can do with their own data

Right to access

Every TopCome user can request a full export of their account data — KYC records, contest history, payout history, device log — by emailing [email protected]. The export is delivered within 7 working days as a password-protected ZIP file. The password is sent via SMS to the registered phone number.

Right to correction

If any of the personal data held by TopCome is incorrect — a misspelt name, an outdated Aadhaar, a wrong PAN — the user can request a correction via the in-app profile section. Corrections are processed within 48 hours and the user is notified once the new record is active.

Right to deletion

Users can request account deletion at any time via the Delete Account page or by emailing [email protected]. Once a deletion request is verified, TopCome deletes the user's personal data within 30 days, except for records required to be retained under tax and anti-money-laundering regulations (typically 5 years).

Top tier privacy practice

How TopCome's data handling works in day-to-day operation

Privacy policies describe what is supposed to happen, but the real measure of a top tier privacy program is what happens in practice. The four-step rundown below explains the operational layer that sits behind the policy text — the logs, the access controls, and the retention rules that quietly keep the user data on the right side of the law.

1

Encryption at every layer

TopCome encrypts personal data at rest with AES-256, in transit with TLS 1.3, and on the wire between microservices with mutually authenticated TLS. KYC documents are stored in a separate vault with hardware security module (HSM) key custody, and the keys are rotated every 90 days. This is the top tier encryption baseline.

2

Access controls + audit trails

Only a small, named set of TopCome staff can access personal data, and every access is logged with a justification. Logs are reviewed weekly by the security team and sampled by the privacy officer quarterly. Suspicious access patterns trigger an automatic lock and a manual review.

3

Retention + deletion discipline

Different categories of personal data have different retention windows. KYC records are held for 7 years per RBI guidelines. Contest records are held for 5 years per tax law. Marketing data is held until the user opts out. The deletion job runs every night and writes a report that the privacy officer reviews every Monday morning.

4

Sub-processor vetting

TopCome works with a short list of sub-processors for payments, KYC, SMS, and analytics. Each sub-processor is vetted for data handling standards, contractually required to use the data only for the agreed purpose, and reviewed annually. The current list of sub-processors is published in the disclosure page so users can audit the supply chain.

Reporting a privacy concern

Users who have a privacy concern — a suspected data leak, an unsolicited marketing message, an unauthorised login — should email [email protected] with as much detail as possible. The privacy team triages every report within 4 hours, contains any confirmed incident within 24 hours, and writes a closure note to the reporter within 7 days. Top tier accountability is the point.

Bonus Banner

This visual supports the analysis above with specific topcomesports context relevant to privacy.

Safety Kyc

This visual supports the analysis above with specific topcomesports context relevant to privacy.

Review Banner

This visual supports the analysis above with specific topcomesports context relevant to privacy.