Pops Today Privacy Policy
Last updated: 2026-05-04
This Privacy Policy explains what information Pops Today ("we", "us", "the app") collects when you use the Pops Today website and mobile application, how that information is used, who it is shared with, and the choices you have. It is written to satisfy Apple App Store Guideline 5.1.1 and the App Store Connect privacy questionnaire requirements.
If you have questions, contact: [email protected]
1. Who we are
Pops Today is an independent collector community for Funko POP! collectibles, operated by the Pops Today team. We are not affiliated with, endorsed by, or sponsored by Funko, LLC.
The mobile app is published under the bundle identifier com.popstoday.app.
2. What we collect
2.1 Information you provide
- Account details: email address, first and last name, password (stored as a salted bcrypt hash, never in plaintext).
- Sign in with Apple / Google: the email address and (where available) the display name returned by the provider. We do not receive your Apple ID or Google password.
- Profile content: username, bio, profile picture, and your top-4 favourite products.
- Collection data: products you have marked as collected, wished, liked, rated, or added to a checklist; any public or private notes you attach to a collected item; your "my date" (the date you acquired the item).
- User-generated content: reviews, comments, replies, and lists you post.
- Reports: if you report another user's content, the reported item, your user ID, optional reason, and free-text detail you provide.
- Currency and display preferences.
2.2 Information collected automatically
- Device & session data: IP address (used for rate-limiting and audit logs), platform (iOS/Android/web), and login timestamps.
- Push notification token: if you enable push notifications, the Expo / APNs / FCM token for your device, stored against your account so we can deliver notifications.
- Affiliate click events: when you tap an "Amazon", "eBay", or "Entertainment Earth" button, we record that the click occurred along with your user ID and the product ID. This is used to attribute referrals so retailers can pay us the commissions we are owed; we do not receive your purchase details.
- Barcode scans: UPC codes you scan in the app and the matched product ID, used to improve scan accuracy.
2.3 Information we do not collect
- We do not use third-party analytics SDKs (no Firebase, Segment, Mixpanel, Amplitude, AdMob, or similar).
- We do not track you across other companies' apps or websites and we do not share data with advertising networks. We therefore do not present an App Tracking Transparency (ATT) prompt.
- We do not collect precise location, contacts, photos, microphone, or health data.
3. How we use your information
- To provide the core features of the app: signing you in, saving your collection, displaying your profile, sending notifications you have opted into.
- To enforce our community rules: profanity filtering, evaluating reports, applying account suspensions when warranted.
- To attribute affiliate referrals so retailers can pay commissions that fund the operation of the app.
- To investigate abuse, fraud, or security issues, and to comply with legal obligations.
We do not sell your personal information.
4. Affiliate links and external retailers
When you tap an affiliate link in the app (e.g., "Check Amazon", "Pre-Order Now"), you are sent to the retailer's website in your device's system browser. We earn a commission on qualifying purchases as part of the Amazon Associates Program, the eBay Partner Network, and the Entertainment Earth affiliate program. Once you reach the retailer, your interaction with that site is governed by the retailer's own privacy policy. We do not see what you buy or the price you pay.
5. Who we share information with
- Retailers / affiliate networks (Amazon, eBay, Entertainment Earth, and similar partners): when you tap an affiliate link, the retailer's URL contains an identifier that lets the retailer credit Pops Today with the referral. We do not transmit your name, email, or password.
- Authentication providers (Apple, Google): we receive your email/name from them when you choose Sign in with Apple or Sign in with Google.
- Push notification providers (Expo, APNs, FCM): we forward push tokens to these services to deliver notifications you have enabled.
- Hosting and infrastructure providers acting as our processors (Cloudflare for CDN/WAF, our database host).
- Law enforcement or regulators where we are legally required to do so.
We do not sell or rent personal information to third parties.
6. Public content
The following information is public by default and visible to anyone using Pops Today, including non-members:
- Username, bio, profile picture, and top-4 favourites.
- Reviews, comments, replies, lists, and ratings you post.
- Aggregate counts on your profile (collection size, follower count).
You can change visibility of your collection, wishlist, lists, and shop in My Profile → Settings.
7. User-generated content moderation
We rely on community reporting and a profanity filter to keep the app respectful. Tap the kebab (···) icon next to any review or reply to:
- Report content you believe violates our community rules.
- Block a user — you will no longer see their reviews, replies, or activity, and any follow relationships between you will be removed.
Reports are reviewed by Pops Today moderators. Repeated abuse leads to account suspension or termination.
8. Data retention and deletion
You can delete your account at any time from My Profile → Account → Delete Account. When you do:
- Your collection, wishlist, ratings, comments, replies, lists, follows, favourites, scan history, push tokens, and affiliate-click history are permanently removed.
- The login record is anonymized (your email, name, profile picture, and third-party login emails are cleared) so that the user ID cannot be linked back to you while we retain audit logs required for fraud prevention.
Audit logs (IP address, login timestamps, the fact of an account-deletion event) are retained for up to 12 months for security purposes.
You can also exercise the following rights, where applicable under GDPR / CCPA or comparable laws, by emailing [email protected]:
- Access a copy of your data.
- Correct inaccurate information.
- Object to processing or restrict it.
9. Children
Pops Today is not directed at children under 13 (or under the equivalent minimum age in your jurisdiction). We do not knowingly collect data from children. If you believe a child has created an account, contact us and we will remove it.
10. Security
- Passwords are hashed with bcrypt (12 rounds) before storage.
- All traffic is served over HTTPS.
- Database connections use private networking; access is limited to authorized application servers.
No system is perfectly secure. If you become aware of a security issue, please email [email protected].
11. International transfers
Pops Today is operated from servers that may be located outside your country of residence. By using the app you consent to your information being transferred to and processed in those locations.
12. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be announced in-app and the "Last updated" date at the top will be revised. Your continued use of the app after changes take effect constitutes acceptance of the revised policy.
13. Contact
For privacy questions or to exercise your rights: [email protected]