Login
Legal

Privacy Policy

Effective July 27, 2026Updated July 27, 2026

This Privacy Policy explains how Sellora collects, uses, shares, and protects personal data. It should be read together with our Terms of Service and, where applicable, our Data Processing Addendum (DPA).

Sellora Inc. · 254 Chapman Rd, Ste 208 #28297, Newark, Delaware 19702, United States

1. Introduction and scope

1.1 Sellora Inc. ("Sellora," "we," "us," or "our") provides an AI-native sales and marketing platform (the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard personal data, and the rights and choices available to individuals.

1.2 This Policy applies to personal data we process through the Service, our websites, and related communications. It does not apply to third-party services you connect to or visit — those are governed by their own privacy policies.

1.3 This Policy should be read together with our Terms of Service and, where applicable, a Data Processing Addendum ("DPA").

2. Our roles: controller and processor

2.1 Sellora as a controller. For personal data about our customers, prospective customers, website visitors, and the individual users who administer or use the Service — for example, account registration details, billing contacts, and usage data — Sellora acts as a "controller" (or "business" under U.S. state laws) and decides how and why that data is processed.

2.2 Sellora as a processor. When a customer uses the Service to upload, generate, or process data about its own contacts, leads, companies, and communication recipients ("Customer Data" and "End Recipients"), the customer is the controller of that personal data and Sellora acts as a "processor" (or "service provider"), processing it on the customer's documented instructions and on the customer's behalf.

If you are an End Recipient and have questions about how a Sellora customer is processing your data, please contact that customer directly — see Section 13.

3. Personal data we collect

We collect the following categories, depending on how you interact with the Service.

3.1 Account and profile data. Name, business email address, password and authentication identifiers, organisation or workspace name, job title, role and permissions, and preferences.

3.2 Billing and transaction data. Subscription plan, credit balances and usage, billing contact details, and payment-related information. Card and bank details are collected and processed by our payment processor, Stripe. Sellora generally receives only limited billing metadata — such as the last four digits, card brand, and transaction status — and does not store full payment card numbers.

3.3 Usage, device, and log data. IP address, browser and device information, pages and features used, actions taken, timestamps, referring URLs, diagnostic and performance data, audit logs, and cookies or similar identifiers.

3.4 Cookies and similar technologies. We use strictly necessary cookies — including a secure, HttpOnly session cookie — to authenticate users, maintain sessions, and protect the Service. Where required, and if enabled, we may use limited analytics or preference cookies subject to your consent. See Section 8.

3.5 Customer Data (processed on behalf of customers). Data that customers submit, generate, connect, or transmit through the Service, which may include personal data about End Recipients and about the customer's own personnel, such as:

  • Contact and lead records — names, business email addresses, phone numbers, job titles, employer or company, LinkedIn and social handles, location.
  • Company and account records — industry, size, domain, addresses.
  • CRM content — opportunities, deals, campaigns, notes, tasks, and custom fields.
  • Email content sent and received through connected mailboxes and the Service's sending infrastructure, including subject lines, bodies, headers, and metadata.
  • Messaging content over connected channels such as WhatsApp, Telegram, and Slack, where enabled.
  • Telephony data such as phone numbers and call metadata, and — where you enable it — call recordings and transcriptions.
  • Documents and files uploaded to the Service.
  • Organisation, brand, and product information.

3.6 Integration data. When you connect a Third-Party Service — for example HubSpot, Salesforce, Microsoft 365, Google, Twilio, or a messaging platform — we receive and exchange data with that service as needed to provide the requested functionality, using credentials or tokens you authorize.

3.7 AI inputs and outputs. Prompts, instructions, and content you submit to AI features, and the outputs generated for you.

3.8 Communications with Sellora. Support requests, correspondence, survey responses, and feedback.

We collect this data directly from you and your Authorized Users, automatically through your use of the Service, and from the Third-Party Services you connect. Some Customer Data may originate from the customer's own sources, or from third parties from which the customer has obtained it.

4. How we use personal data

As a controller, we use personal data to:

  • provide, operate, maintain, and secure the Service, and authenticate users;
  • process transactions, manage subscriptions and credits, and prevent fraud;
  • provide customer support and respond to inquiries;
  • monitor, analyze, and improve the Service, develop new features, and ensure reliability and security — including audit logging and abuse prevention;
  • communicate with you about the Service, including service and security notices and, where permitted, marketing (subject to opt-out);
  • comply with legal obligations and enforce our Terms; and
  • create and use aggregated or de-identified data that does not identify any individual.

As a processor, we process Customer Data only to provide and support the Service on the customer's behalf, and in accordance with the customer's instructions, the Terms, and any DPA.

5. AI and machine learning processing

5.1 Third-party AI providers. AI features are powered in part by third-party AI and model providers — currently Anthropic (Claude) and OpenAI — and by Sellora's own processing. When you use an AI feature, your inputs and relevant Customer Data may be transmitted to and processed by these providers as Subprocessors, solely to generate outputs for you.

5.2 No training of general models. Sellora does not sell personal data and does not use your inputs or outputs to train third-party foundation models. We engage AI providers under terms intended to ensure that they do not use your inputs or outputs to train their general models, and that such data is retained by them only as needed to provide the service and for limited abuse monitoring as their terms permit.

5.3 Sellora model improvement. We may use aggregated or de-identified data to operate, evaluate, and improve the Service. We do not use identifiable Customer Data to train models made available to other customers, except with the relevant controller's authorization.

5.4 Human oversight. AI outputs may be inaccurate and are provided for the user's review. The Service is not designed to make legal or similarly significant automated decisions about individuals without human involvement. Customers are responsible for appropriate oversight and for any required disclosures.

7. How we disclose personal data; subprocessors

7.1 We do not sell personal data, and we do not "share" personal data for cross-context behavioral advertising as those terms are defined under U.S. state privacy laws.

7.2 Subprocessors. We use trusted service providers ("Subprocessors") to help provide the Service. They are bound by contractual obligations to protect personal data and to process it only for the purposes we specify. Our current core Subprocessors are:

ProviderPurposeLocation
Amazon Web Services (AWS)Cloud hosting and compute, storage, identity and authentication, transactional and outbound email delivery, configuration, and key managementUnited States
Anthropic, PBCAI and large-language-model processing (Claude) for AI featuresUnited States
OpenAIAI and large-language-model processing for AI featuresUnited States
Stripe, Inc.Payment processing and billingUnited States
Twilio Inc.Telephony — phone numbers, voice, and SMSUnited States

We maintain an up-to-date list of Subprocessors and will provide it on request at privacy@selloraai.com.

7.3 Customer-directed integrations. When you connect a Third-Party Service — such as HubSpot, Salesforce, Microsoft 365, Google, Slack, Telegram, or WhatsApp — personal data is exchanged with that service at your direction and under its privacy policy. Those services are not Sellora's Subprocessors; they act under your instruction.

7.4 Within your organisation. Customer Data is accessible to the Authorized Users and administrators of the customer's workspace, according to the roles and permissions the customer configures.

7.5 Legal and safety. We may disclose personal data if required by law, subpoena, or legal process, or where we believe in good faith that disclosure is necessary to protect our rights, our users, or the public, or to detect, prevent, or address fraud, security, or technical issues.

7.6 Business transfers. If Sellora is involved in a merger, acquisition, financing, reorganization, or sale of assets, personal data may be transferred as part of that transaction, subject to this Policy or a policy with equivalent protections.

7.7 Professional advisors and affiliates. We may disclose data to our Affiliates and to professional advisors — such as lawyers, auditors, and insurers — under confidentiality obligations, as needed to operate our business.

8. Cookies and similar technologies

8.1 Essential cookies. The Service uses strictly necessary cookies, including a secure, HttpOnly session cookie, to authenticate users, maintain sessions, provide security (including CSRF protection), and remember essential settings. These cannot be disabled without breaking the Service.

8.2 Analytics and preference technologies. We do not use advertising cookies. Where enabled and permitted, we may use limited analytics or preference technologies to understand usage and improve the Service. Where consent is required by law, we will request it and provide controls, such as a cookie banner or settings panel.

8.3 Managing cookies. Most browsers let you refuse or delete cookies; doing so may affect functionality. Because there is no common industry standard for interpreting "Do Not Track" signals, we do not currently respond to them. Where required, we honor recognized opt-out preference signals such as Global Privacy Control (GPC).

9. International data transfers

Sellora is based in the United States and uses Subprocessors located in the United States. If you access the Service from outside the United States, your personal data may be transferred to, stored, and processed in the United States and other countries whose data-protection laws may differ from those of your own.

Where we transfer personal data from the EEA, the UK, or Switzerland to a country not deemed adequate, we rely on appropriate safeguards — such as the European Commission's Standard Contractual Clauses, together with the UK Addendum or Swiss addendum as applicable — and implement supplementary measures where required. You may request a copy of the relevant safeguards using the contact details in Section 19.

10. Data retention

10.1 We retain personal data for as long as needed to provide the Service, maintain your account, comply with legal obligations, resolve disputes, and enforce our agreements.

10.2 As a processor, we retain Customer Data for the duration of the customer's subscription, and delete or return it after termination as described in the Terms or an order form — subject to legal retention requirements and routine backup cycles, from which data is purged on a rolling basis.

10.3 Aggregated or de-identified data may be retained indefinitely.

11. Security

We implement administrative, technical, and organizational measures designed to protect personal data, including:

  • encryption in transit and at rest, with managed key storage;
  • secure credential handling — HttpOnly session cookies, with no tokens stored in browser storage;
  • role-based access controls and least-privilege practices;
  • network protections and audit logging.

No method of transmission or storage is completely secure, and we cannot guarantee absolute security. You are responsible for safeguarding your credentials and configuring access appropriately.

If we become aware of a personal-data breach affecting your data, we will notify affected parties as required by applicable law and — where Sellora is a processor — notify the relevant customer without undue delay.

12. Your privacy rights

12.1 Your rights. Depending on your jurisdiction, you may have the right to access your personal data; correct inaccurate data; delete data; obtain a portable copy; restrict or object to certain processing; withdraw consent; and not be subject to unlawful automated decision-making. You may also opt out of marketing at any time.

12.2 How to exercise them. To exercise rights with respect to data for which Sellora is the controller, contact us at privacy@selloraai.com. We will verify your identity and respond within the timeframes required by applicable law. You may authorize an agent to act on your behalf where permitted.

12.3 Customer Data. Where Sellora processes personal data as a processor on a customer's behalf, requests should be directed to the relevant customer, who is the controller. We assist our customers in responding to such requests as required by the DPA and applicable law.

12.4 No discrimination. We will not discriminate against you for exercising your rights.

12.5 Complaints. You may lodge a complaint with your local data-protection or privacy authority. In the EEA or UK, you may contact your supervisory authority. We ask that you contact us first so we can try to resolve your concern.

13. If you are a lead, contact, or end recipient

If you received a communication sent using Sellora, or your information appears in a Sellora customer's account, that customer — not Sellora — is the controller of your data and determines why and how it is processed. Please direct access, deletion, opt-out, and similar requests to that customer.

If you are unsure who contacted you, or cannot reach them, contact us at privacy@selloraai.com and we will make reasonable efforts to route your request to the relevant customer. To stop receiving communications, you may also use the unsubscribe or opt-out mechanism included in the communication.

14. Children's privacy

The Service is intended for business use by individuals who are at least 18 years old. We do not knowingly collect personal data from children. If you believe a child has provided us personal data, contact us and we will delete it.

16. Marketing communications

We may send you service-related communications, which you cannot opt out of while you have an account, and — where permitted — marketing communications about our products. You may opt out of marketing at any time via the unsubscribe link or by contacting us.

Any marketing you send to your own contacts using the Service is governed by the Terms and by your own obligations as the sender.

17. Region-specific disclosures

17.1 European Economic Area, United Kingdom, and Switzerland. Sellora is the controller for the data described in Section 2.1. Our legal bases are described in Section 6. You have the rights described in Section 12 and may contact your supervisory authority. To reach us about this Policy, email privacy@selloraai.com.

17.2 California (CCPA/CPRA). In the preceding 12 months, we have collected the categories of personal information described in Section 3 — identifiers; commercial information; internet and network activity; professional and employment information; and, where you provide it, other information — for the business purposes in Section 4, and disclosed it to the categories of recipients in Section 7.

We do not "sell" or "share" personal information as those terms are defined by the CPRA, and do not knowingly do so for minors. California residents may exercise rights to know, delete, correct, and limit as described in Section 12, and may use an authorized agent. We do not offer financial incentives.

17.3 Other U.S. states. Residents of states with comprehensive privacy laws — including Virginia, Colorado, Connecticut, Utah, Texas, and others as they take effect — have rights to access, correct, delete, and obtain a copy of personal data, and to opt out of certain processing including targeted advertising, sale, and certain profiling. You may also appeal a denied request. We honor recognized opt-out preference signals where required. To exercise these rights, contact us as described in Section 12.

17.4 Processor note. Many of the above rights, when they concern Customer Data, are fulfilled by the customer as controller. Sellora assists as described in Section 13 and any DPA.

18. Changes to this policy

We may update this Privacy Policy from time to time. If we make material changes, we will update the "Last updated" date and provide notice by email or in-product notice before the changes take effect, where required. Your continued use of the Service after the effective date constitutes acceptance of the updated Policy.

19. How to contact us

Sellora Inc.
254 Chapman Rd, Ste 208 #28297
Newark, Delaware 19702, United States

Privacy and data protectionprivacy@selloraai.com
General and supportsupport@selloraai.com
Websiteselloraai.com

If you have questions about this Policy or our data practices, or wish to exercise your rights, please contact us using the details above.