Privacy policy
Last updated August 27, 2026
This privacy policy describes how Sello ("we", "us") handles personal information across everything we run: the Sello mobile and web app (the "App"), the website sello-app.com (the "Site"), and the services behind them. One policy covers it all.
Who we are
Sello provides digital loyalty programs for local businesses. For questions about this policy or your data, contact us at support@sello-app.com.
Your account
Sign-in is handled by Firebase Authentication, a Google service. You can sign in with Google, Apple, Facebook, X, or an email address and password. Passwords are managed by Firebase — we never see or store them. Email-verification and password-reset emails are sent by Firebase directly.
When you create an account we receive and store:
- Email address — your account identity, also used for the emails described below.
- Name and photo. Your display name comes from your sign-in provider (or, failing that, from the start of your email address). If your provider has a profile photo, we copy it to your Sello profile. You can change your name, or replace the photo with one from your library, at any time.
- Language and country. The App's language (English or Spanish) starts from your device's language and can be changed in Settings. When you create a customer profile we assign a country ("market") from your device's country setting or, failing that, an approximate location derived from your IP address — it decides which regional content you see.
Your loyalty activity
We store what makes your loyalty cards work: the programs you join, the stamps and points you collect, the rewards you redeem, and when and at which premise each of those happened. We also store the businesses you choose to follow.
When you show your QR code to be stamped, the business's staff see your first name and an initial — never your email address. Businesses see their own programs' activity (stamps, redemptions, new followers) with customers identified the same way.
Business accounts and teams
If you use Sello as a business, we additionally store your team's name and logo, its premises, and each member's role. Team members with management rights can see the names and email addresses of the members they manage. When you invite a colleague, we store the email address you enter until the invitation is accepted or declined, and use it only to deliver and track the invitation.
Premise details — name, address, coordinates, phone number, opening hours, ratings, photos — come from Google Maps Platform's business listings and are stored with the premise.
Camera, location and photos
- Camera (business side) is used only to scan customers' QR codes. Frames are processed on the device — no photo or video is ever stored or uploaded.
- Location is used to find what's nearby. On the customer side, distances to premises are computed on your device; your coordinates are not sent to us. When a business sets up a premise, the device's coordinates and any typed search text are sent through our servers to Google Maps Platform to find the business's listing — we store the premise's location, never your movements.
- Photos. Only images you pick are uploaded: a profile picture, a team logo or a premise cover image.
Emails we send
Transactional only — we do not send marketing email. Team invitations (carrying the inviter's name, the team name and the offered role) and an account-deletion confirmation. They are delivered by Resend, our email provider.
Analytics and session replay in the App
We use PostHog to understand how the App is used and to fix problems:
- Usage events — screens viewed and product actions (signing up, creating a program, stamping, redeeming…), together with your app version, platform, language and country.
- Approximate location. Our servers see your IP address and pass it to PostHog, which derives an approximate, city-level location from it. We never collect a precise location for analytics.
- Your analytics profile. Analytics are tied to your account and include your email, display name, language, market and — for business users — team name and role.
- Session replay. On the mobile App, PostHog records replays of sessions: the screens you visit and how you interact with them, including the content shown on screen. The camera view is never recorded. We watch replays only to find and fix problems.
PostHog is operated by PostHog Inc. and processes this data on its US cloud; transfers out of the EEA/UK are protected by EU-approved safeguards (Standard Contractual Clauses). See PostHog's privacy policy for details.
What we collect on the Site
- Traffic measurement. We use Cloudflare Web Analytics, a privacy-first analytics service that does not use cookies, does not store identifiers on your device, and does not track you across sites. It gives us aggregate information such as page views, referrers, country-level location and browser type.
- Product analytics. We use PostHog to understand how the Site is used: pages visited, clicks, referrers, approximate location derived from your IP address, and device and browser type. PostHog stores a random identifier in a first-party cookie and in your browser's local storage for up to one year, so repeat visits to this Site can be recognised. It is used on this Site only and does not follow you across other websites.
- Session replay. PostHog may also record a reconstruction of your visit — the pages you view, mouse movement, scrolling and clicks — to help us find and fix usability problems. Anything you type into a form on the Site is masked on your device before it is sent, so we never see it.
- Language preference. If you choose a language/region in the footer, we store that choice in a cookie (
sello_locale) so the Site remembers it. This cookie contains only the locale code (for examplees-mx) and is kept for up to one year. It is strictly functional. - Email. If you email us, we receive your address and message and use them only to respond.
You can block or delete the PostHog cookie in your browser at any time — the Site stays fully functional.
QR posters and install links
Sello QR posters redirect through our servers. Scanning one records an anonymous event — device type and an approximate location derived from the IP address — so we can count scans; it is not linked to you. On Android, if you install the App through such a link, we read Google Play's install referrer once so the App can open that business's page right away.
Where your data lives
Our servers and database run on Amazon Web Services in the United States (us-east-1); uploaded images are stored in a private bucket. Besides AWS, the providers that process personal data for us are:
- Firebase Authentication (Google) — sign-in, as described above.
- Google Maps Platform — business search and listings.
- PostHog Inc. — analytics and session replay, on the Site and in the App.
- Resend — transactional email delivery.
- Cloudflare — hosts the Site and provides its cookieless traffic analytics.
- Stripe — payment processing if you buy a paid plan; card details go directly to Stripe and never touch our servers.
- Sentry — server error monitoring, configured not to receive personal data.
Where the GDPR applies, we process personal data to provide the service you signed up for (performance of a contract) and, for analytics and security, based on our legitimate interest in understanding and improving Sello. Transfers out of the EEA/UK are protected by EU-approved safeguards (Standard Contractual Clauses).
What we don't do
- We do not sell personal data, and we do not share it for advertising.
- We do not use advertising trackers — not in the App, not on the Site — and we do not track you across other apps or websites.
- Beyond the providers named above, we do not transfer your data to anyone.
Retention and deletion
We keep your data while your account exists. You can delete your account yourself in the App (Profile → Settings → Account → Delete my account) — deletion is immediate and permanent, and covers your profile, cards, stamps, team memberships, your Firebase sign-in record and the analytics profile linked to your account. See how account deletion works, including how to delete without the app installed. Invitations are kept until they are accepted or declined. Operational logs and backups rotate on a short schedule.
Your rights
If you are in the European Economic Area or the UK, you have rights under the GDPR, including access, rectification and erasure of personal data we hold about you — covering analytics and session-replay data as well as correspondence. Wherever you are, we honour the same requests: email support@sello-app.com and we will handle it.
Children
Sello is not directed at children. You must be at least 13 years old to use it — 16 in the European Economic Area, unless your country's law sets a lower age.
Changes
We will update this policy as Sello evolves. The date above reflects the latest revision. If a change materially affects you, we will give you notice in the App or by email before it takes effect.