1. Introduction
Sellrow (“we,” “us,” “our”) operates a payment and commerce platform that lets organizations collect dues, sell tickets and merchandise, receive donations, and run paid votes and nomination forms. This Privacy Policy explains what data we collect, why we collect it, how long we keep it, and what rights you have over it.
For the purposes of the EU and UK General Data Protection Regulation, Sellrow is the data controller for the personal data described here, except where we act as a processor on behalf of an organization you transact with — see section 4. Our legal entity and registered address are [TO CONFIRM].
2. Who this policy covers
Sellrow has two kinds of user, and we handle their data differently:
- Organizations and their administrators, who hold accounts, complete identity verification, and receive payouts.
- Buyers, who pay an organization without creating an account. We collect a buyer’s name, email address, and phone number in order to process the payment and deliver a receipt, ticket, or digital file.
3. Information we collect
Information you give us. Account details (name, email address, password); organization details (name, type, description, address); buyer checkout details (name, email address, phone number); and the contents of messages you send us.
Identity verification data. Before an organization can receive a payout, we collect the legal name, contact details, and address of the organization, together with an identity document type and number, date of birth, and — where required — an uploaded copy of an identity document. We submit these to an identity-verification provider and retain the result of that check, including the response we receive. We also collect settlement bank account details in order to pay out funds.
Payment data. Card and bank details are collected and processed directly by our payment provider under their own privacy terms. We never receive or store full card numbers. We do store the amount, currency, status, reference, and date of each transaction.
Information collected automatically. Server logs including IP address, browser type, and pages requested, kept for security and fraud prevention. We use a single cookie to keep you signed in. We do not use advertising cookies, third-party analytics, or tracking pixels, and we do not track you across other websites.
4. Organizations as independent controllers
When you buy from an organization on Sellrow, that organization receives your name, email address, phone number, and order details so it can fulfil your order and keep its own records. It is an independent controller of that data and its own privacy practices govern what it does with it. If you want your data corrected or erased from an organization’s own records, contact that organization directly; we can pass a request on but we cannot control their systems.
5. Why we process your data, and our legal basis
Where the EU or UK GDPR applies, we rely on the following legal bases:
| Purpose | Legal basis |
|---|---|
| Processing a payment and delivering the receipt, ticket, or file you paid for | Performance of a contract |
| Creating and running an organization account | Performance of a contract |
| Identity verification and anti-money-laundering checks before payout | Legal obligation |
| Retaining transaction and verification records after an account closes | Legal obligation |
| Fraud prevention, platform security, and abuse investigation | Legitimate interests — keeping the platform and its users safe |
| Service emails: receipts, payment confirmations, account notices | Performance of a contract |
| Reminder emails about a checkout you did not complete | Legitimate interests — completing a transaction you started. You can opt out at any time. |
| Marketing emails, where we send them | Consent, which you may withdraw at any time |
6. How long we keep it
Account data is kept while the account is open. After it closes, we keep what we are legally required to keep and remove the rest.
Identity-verification and transaction records are retained for at least five years after the end of the business relationship, because anti-money-laundering law requires it and requires those records to remain sufficient to reconstruct individual transactions. This obligation overrides a request for erasure: where you ask us to delete data we are required to retain, we will tell you so and explain the basis, and we will still delete anything not covered by the requirement. [TO CONFIRM: five years is the baseline; the longest period applicable across the jurisdictions we operate in governs.]
Server logs are kept for a short period for security purposes. Records relating to a suspected-fraud report are kept until the matter is resolved.
7. Who we share it with
We share personal data with: the organization you transacted with (section 4); our payment provider, in order to take payment and pay organizations out; our identity-verification provider, for the checks described in section 3; our email provider, to send receipts and notices; and our hosting and file-storage providers, which run the platform and store uploaded documents. Each acts under contract and may use the data only to provide its service to us.
We also disclose data where the law requires it — including to financial-intelligence and law-enforcement authorities — and where necessary to investigate fraud or protect the rights and safety of users.
We do not sell your personal information, and we do not share it for cross-context behavioural advertising, as those terms are defined under California law.
8. Your rights in the EU and UK
If you are in the EU or UK, you have the right to:
- Access — obtain a copy of the personal data we hold about you.
- Rectification — have inaccurate data corrected.
- Erasure — have your data deleted, subject to the retention rules in section 6.
- Restriction — ask us to limit how we use your data while a dispute is resolved.
- Portability — receive data you gave us in a machine-readable format.
- Objection — object to processing we base on legitimate interests, including abandoned-checkout reminders.
- Withdraw consent — where we rely on consent, withdraw it at any time without affecting earlier processing.
- Complain — lodge a complaint with your national data protection authority, or with the Information Commissioner’s Office in the UK.
Write to privacy@sellrow.co and we will respond within one month. We may ask you to verify your identity first, so that we do not disclose your data to somebody else.
9. Your rights in the United States
If you are a California resident, you may request the categories and specific pieces of personal information we have collected about you, the categories of source and of recipient, and the purpose of collection; request correction or deletion; and, because we do not sell or share personal information, you have nothing to opt out of in that respect. Residents of other US states with comparable laws have similar rights, and we apply the same process to all of them.
We will not discriminate against you for exercising any of these rights. You will not be denied service, charged a different price, or given a lower quality of service. Contact privacy@sellrow.co and we will respond within 45 days, extendable once where the law allows.
10. International transfers
Sellrow operates internationally and our staff and infrastructure are located in more than one country, including outside the European Economic Area and the United Kingdom. Where we transfer personal data out of the EEA or UK to a country without an adequacy decision, we rely on the European Commission’s Standard Contractual Clauses, together with the UK International Data Transfer Addendum where the UK GDPR applies, and we assess whether additional safeguards are needed for the destination country. [TO CONFIRM: this section must describe the transfer mechanism actually executed, including any transfer to Nigeria, which has no EU adequacy decision.]
You can request a copy of the safeguards we rely on by writing to privacy@sellrow.co.
11. Children
Sellrow is not directed to children. The platform is intended for adults, and organizations may not use it to collect personal data from children. We do not knowingly collect personal information from anyone under 13, and where the GDPR applies we do not knowingly collect it from anyone under 16 without the consent of a parent or guardian.
If you believe a child has given us personal data, write to privacy@sellrow.co and we will delete it promptly.
12. Security
Data is encrypted in transit. Passwords are stored hashed, never in plain text. Uploaded identity documents are held in private storage and are reachable only by authorized staff through an access-controlled route, never by a public link. Access to production data is restricted to staff who need it. No system is perfectly secure, and we cannot guarantee absolute security, but if a breach affects your rights we will notify you and the relevant regulator as the law requires.
13. Contact us
For any privacy question or to exercise a right, contact privacy@sellrow.co.
[TO CONFIRM: our EU representative under Article 27 GDPR and our UK representative under the UK GDPR, with their addresses, and our Data Protection Officer if one is appointed.]
14. Changes to this policy
We may update this policy. We will post the new version here and update the date above, and we will tell you by email or through the platform if the change materially affects your rights.
