Sellora
Use Cases Pricing Team Blog User Manual
Login Try Free

Privacy Policy

Effective date: July 27, 2026 · Last updated: July 27, 2026

Sellora Inc. · 254 Chapman Rd, Ste 208 #28297, Newark, Delaware 19702, United States

This Privacy Policy explains how Sellora collects, uses, shares, and protects personal data. It should be read together with our Terms of Service and, where applicable, our Data Processing Addendum (DPA).


The short version

This summary is provided for convenience only. The full sections below are what govern our practices.

  • We sell nothing. We do not sell personal data, and we do not share it for cross-context behavioral advertising.
  • Two different roles. For your account, billing, and website data we are the controller. For the contacts, leads, and messages you put into Sellora, you are the controller and we act as your processor.
  • AI is powered by vetted providers. AI features use Anthropic and OpenAI under contracts intended to prevent your inputs and outputs from training their general models.
  • You have rights. Access, correction, deletion, portability, objection, and opt-out — see Your privacy rights.
  • Not a Sellora customer? If you received a message sent through Sellora, the sender controls your data. See If you are a lead, contact, or end recipient.
  • Questions? Email privacy@selloraai.com.

Contents

  1. Introduction and scope
  2. Our roles: controller and processor
  3. Personal data we collect
  4. How we use personal data
  5. AI and machine learning processing
  6. Legal bases (EEA/UK and similar laws)
  7. How we disclose personal data; subprocessors
  8. Cookies and similar technologies
  9. International data transfers
  10. Data retention
  11. Security
  12. Your privacy rights
  13. If you are a lead, contact, or end recipient
  14. Children's privacy
  15. Third-party links and services
  16. Marketing communications
  17. Region-specific disclosures
  18. Changes to this policy
  19. How to contact us

1. Introduction and scope

1.1 Sellora Inc. ("Sellora," "we," "us," or "our") provides an AI-native sales and marketing platform (the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard personal data, and the rights and choices available to individuals.

1.2 This Policy applies to personal data we process through the Service, our websites, and related communications. It does not apply to third-party services you connect to or visit — those are governed by their own privacy policies.

1.3 This Policy should be read together with our Terms of Service and, where applicable, a Data Processing Addendum ("DPA").

2. Our roles: controller and processor

2.1 Sellora as a controller. For personal data about our customers, prospective customers, website visitors, and the individual users who administer or use the Service — for example, account registration details, billing contacts, and usage data — Sellora acts as a "controller" (or "business" under U.S. state laws) and decides how and why that data is processed.

2.2 Sellora as a processor. When a customer uses the Service to upload, generate, or process data about its own contacts, leads, companies, and communication recipients ("Customer Data" and "End Recipients"), the customer is the controller of that personal data and Sellora acts as a "processor" (or "service provider"), processing it on the customer's documented instructions and on the customer's behalf.

If you are an End Recipient and have questions about how a Sellora customer is processing your data, please contact that customer directly — see Section 13.

3. Personal data we collect

We collect the following categories, depending on how you interact with the Service.

3.1 Account and profile data. Name, business email address, password and authentication identifiers, organisation or workspace name, job title, role and permissions, and preferences.

3.2 Billing and transaction data. Subscription plan, credit balances and usage, billing contact details, and payment-related information. Card and bank details are collected and processed by our payment processor, Stripe. Sellora generally receives only limited billing metadata — such as the last four digits, card brand, and transaction status — and does not store full payment card numbers.

3.3 Usage, device, and log data. IP address, browser and device information, pages and features used, actions taken, timestamps, referring URLs, diagnostic and performance data, audit logs, and cookies or similar identifiers.

3.4 Cookies and similar technologies. We use strictly necessary cookies — including a secure, HttpOnly session cookie — to authenticate users, maintain sessions, and protect the Service. Where required, and if enabled, we may use limited analytics or preference cookies subject to your consent. See Section 8.

3.5 Customer Data (processed on behalf of customers). Data that customers submit, generate, connect, or transmit through the Service, which may include personal data about End Recipients and about the customer's own personnel, such as:

  • Contact and lead records — names, business email addresses, phone numbers, job titles, employer or company, LinkedIn and social handles, location.
  • Company and account records — industry, size, domain, addresses.
  • CRM content — opportunities, deals, campaigns, notes, tasks, and custom fields.
  • Email content sent and received through connected mailboxes and the Service's sending infrastructure, including subject lines, bodies, headers, and metadata.
  • Messaging content over connected channels such as WhatsApp, Telegram, and Slack, where enabled.
  • Telephony data such as phone numbers and call metadata, and — where you enable it — call recordings and transcriptions.
  • Documents and files uploaded to the Service.
  • Organisation, brand, and product information.

3.6 Integration data. When you connect a Third-Party Service — for example HubSpot, Salesforce, Microsoft 365, Google, Twilio, or a messaging platform — we receive and exchange data with that service as needed to provide the requested functionality, using credentials or tokens you authorize.

3.7 AI inputs and outputs. Prompts, instructions, and content you submit to AI features, and the outputs generated for you.

3.8 Communications with Sellora. Support requests, correspondence, survey responses, and feedback.

We collect this data directly from you and your Authorized Users, automatically through your use of the Service, and from the Third-Party Services you connect. Some Customer Data may originate from the customer's own sources, or from third parties from which the customer has obtained it.

4. How we use personal data

As a controller, we use personal data to:

  • provide, operate, maintain, and secure the Service, and authenticate users;
  • process transactions, manage subscriptions and credits, and prevent fraud;
  • provide customer support and respond to inquiries;
  • monitor, analyze, and improve the Service, develop new features, and ensure reliability and security — including audit logging and abuse prevention;
  • communicate with you about the Service, including service and security notices and, where permitted, marketing (subject to opt-out);
  • comply with legal obligations and enforce our Terms; and
  • create and use aggregated or de-identified data that does not identify any individual.

As a processor, we process Customer Data only to provide and support the Service on the customer's behalf, and in accordance with the customer's instructions, the Terms, and any DPA.

5. AI and machine learning processing

5.1 Third-party AI providers. AI features are powered in part by third-party AI and model providers — currently Anthropic (Claude) and OpenAI — and by Sellora's own processing. When you use an AI feature, your inputs and relevant Customer Data may be transmitted to and processed by these providers as Subprocessors, solely to generate outputs for you.

5.2 No training of general models. Sellora does not sell personal data and does not use your inputs or outputs to train third-party foundation models. We engage AI providers under terms intended to ensure that they do not use your inputs or outputs to train their general models, and that such data is retained by them only as needed to provide the service and for limited abuse monitoring as their terms permit.

5.3 Sellora model improvement. We may use aggregated or de-identified data to operate, evaluate, and improve the Service. We do not use identifiable Customer Data to train models made available to other customers, except with the relevant controller's authorization.

5.4 Human oversight. AI outputs may be inaccurate and are provided for the user's review. The Service is not designed to make legal or similarly significant automated decisions about individuals without human involvement. Customers are responsible for appropriate oversight and for any required disclosures.

6. Legal bases (EEA/UK and similar laws)

Where the GDPR or UK GDPR applies and Sellora acts as a controller, we rely on the following legal bases:

Legal basisWhat we rely on it for
ContractProviding the Service and performing our agreement with you.
Legitimate interestsSecuring, analyzing, and improving the Service, preventing abuse and fraud, and conducting limited B2B marketing — balanced against your rights.
ConsentWhere required, for example certain cookies or marketing. You may withdraw consent at any time.
Legal obligationComplying with applicable law.

Where Sellora acts as a processor, the customer (as controller) is responsible for establishing a legal basis for the processing it instructs.

7. How we disclose personal data; subprocessors

7.1 We do not sell personal data, and we do not "share" personal data for cross-context behavioral advertising as those terms are defined under U.S. state privacy laws.

7.2 Subprocessors. We use trusted service providers ("Subprocessors") to help provide the Service. They are bound by contractual obligations to protect personal data and to process it only for the purposes we specify. Our current core Subprocessors are:

ProviderPurposeLocation
Amazon Web Services (AWS)Cloud hosting and compute, storage, identity and authentication, transactional and outbound email delivery, configuration, and key managementUnited States
Anthropic, PBCAI and large-language-model processing (Claude) for AI featuresUnited States
OpenAIAI and large-language-model processing for AI featuresUnited States
Stripe, Inc.Payment processing and billingUnited States
Twilio Inc.Telephony — phone numbers, voice, and SMSUnited States

We maintain an up-to-date list of Subprocessors and will provide it on request at privacy@selloraai.com.

7.3 Customer-directed integrations. When you connect a Third-Party Service — such as HubSpot, Salesforce, Microsoft 365, Google, Slack, Telegram, or WhatsApp — personal data is exchanged with that service at your direction and under its privacy policy. Those services are not Sellora's Subprocessors; they act under your instruction.

7.4 Within your organisation. Customer Data is accessible to the Authorized Users and administrators of the customer's workspace, according to the roles and permissions the customer configures.

7.5 Legal and safety. We may disclose personal data if required by law, subpoena, or legal process, or where we believe in good faith that disclosure is necessary to protect our rights, our users, or the public, or to detect, prevent, or address fraud, security, or technical issues.

7.6 Business transfers. If Sellora is involved in a merger, acquisition, financing, reorganization, or sale of assets, personal data may be transferred as part of that transaction, subject to this Policy or a policy with equivalent protections.

7.7 Professional advisors and affiliates. We may disclose data to our Affiliates and to professional advisors — such as lawyers, auditors, and insurers — under confidentiality obligations, as needed to operate our business.

8. Cookies and similar technologies

8.1 Essential cookies. The Service uses strictly necessary cookies, including a secure, HttpOnly session cookie, to authenticate users, maintain sessions, provide security (including CSRF protection), and remember essential settings. These cannot be disabled without breaking the Service.

8.2 Analytics and preference technologies. We do not use advertising cookies. Where enabled and permitted, we may use limited analytics or preference technologies to understand usage and improve the Service. Where consent is required by law, we will request it and provide controls, such as a cookie banner or settings panel.

8.3 Managing cookies. Most browsers let you refuse or delete cookies; doing so may affect functionality. Because there is no common industry standard for interpreting "Do Not Track" signals, we do not currently respond to them. Where required, we honor recognized opt-out preference signals such as Global Privacy Control (GPC).

9. International data transfers

Sellora is based in the United States and uses Subprocessors located in the United States. If you access the Service from outside the United States, your personal data may be transferred to, stored, and processed in the United States and other countries whose data-protection laws may differ from those of your own.

Where we transfer personal data from the EEA, the UK, or Switzerland to a country not deemed adequate, we rely on appropriate safeguards — such as the European Commission's Standard Contractual Clauses, together with the UK Addendum or Swiss addendum as applicable — and implement supplementary measures where required. You may request a copy of the relevant safeguards using the contact details in Section 19.

10. Data retention

10.1 We retain personal data for as long as needed to provide the Service, maintain your account, comply with legal obligations, resolve disputes, and enforce our agreements.

10.2 As a processor, we retain Customer Data for the duration of the customer's subscription, and delete or return it after termination as described in the Terms or an order form — subject to legal retention requirements and routine backup cycles, from which data is purged on a rolling basis.

10.3 Aggregated or de-identified data may be retained indefinitely.

11. Security

We implement administrative, technical, and organizational measures designed to protect personal data, including:

  • encryption in transit and at rest, with managed key storage;
  • secure credential handling — HttpOnly session cookies, with no tokens stored in browser storage;
  • role-based access controls and least-privilege practices;
  • network protections and audit logging.

No method of transmission or storage is completely secure, and we cannot guarantee absolute security. You are responsible for safeguarding your credentials and configuring access appropriately.

If we become aware of a personal-data breach affecting your data, we will notify affected parties as required by applicable law and — where Sellora is a processor — notify the relevant customer without undue delay.

12. Your privacy rights

12.1 Your rights. Depending on your jurisdiction, you may have the right to access your personal data; correct inaccurate data; delete data; obtain a portable copy; restrict or object to certain processing; withdraw consent; and not be subject to unlawful automated decision-making. You may also opt out of marketing at any time.

12.2 How to exercise them. To exercise rights with respect to data for which Sellora is the controller, contact us at privacy@selloraai.com. We will verify your identity and respond within the timeframes required by applicable law. You may authorize an agent to act on your behalf where permitted.

12.3 Customer Data. Where Sellora processes personal data as a processor on a customer's behalf, requests should be directed to the relevant customer, who is the controller. We assist our customers in responding to such requests as required by the DPA and applicable law.

12.4 No discrimination. We will not discriminate against you for exercising your rights.

12.5 Complaints. You may lodge a complaint with your local data-protection or privacy authority. In the EEA or UK, you may contact your supervisory authority. We ask that you contact us first so we can try to resolve your concern.

13. If you are a lead, contact, or end recipient

If you received a communication sent using Sellora, or your information appears in a Sellora customer's account, that customer — not Sellora — is the controller of your data and determines why and how it is processed. Please direct access, deletion, opt-out, and similar requests to that customer.

If you are unsure who contacted you, or cannot reach them, contact us at privacy@selloraai.com and we will make reasonable efforts to route your request to the relevant customer. To stop receiving communications, you may also use the unsubscribe or opt-out mechanism included in the communication.

14. Children's privacy

The Service is intended for business use by individuals who are at least 18 years old. We do not knowingly collect personal data from children. If you believe a child has provided us personal data, contact us and we will delete it.

15. Third-party links and services

The Service may contain links to, or integrations with, third-party websites and services. We are not responsible for their content or privacy practices, and we encourage you to review their privacy policies.

16. Marketing communications

We may send you service-related communications, which you cannot opt out of while you have an account, and — where permitted — marketing communications about our products. You may opt out of marketing at any time via the unsubscribe link or by contacting us.

Any marketing you send to your own contacts using the Service is governed by the Terms and by your own obligations as the sender.

17. Region-specific disclosures

17.1 European Economic Area, United Kingdom, and Switzerland. Sellora is the controller for the data described in Section 2.1. Our legal bases are described in Section 6. You have the rights described in Section 12 and may contact your supervisory authority. To reach us about this Policy, email privacy@selloraai.com.

17.2 California (CCPA/CPRA). In the preceding 12 months, we have collected the categories of personal information described in Section 3 — identifiers; commercial information; internet and network activity; professional and employment information; and, where you provide it, other information — for the business purposes in Section 4, and disclosed it to the categories of recipients in Section 7.

We do not "sell" or "share" personal information as those terms are defined by the CPRA, and do not knowingly do so for minors. California residents may exercise rights to know, delete, correct, and limit as described in Section 12, and may use an authorized agent. We do not offer financial incentives.

17.3 Other U.S. states. Residents of states with comprehensive privacy laws — including Virginia, Colorado, Connecticut, Utah, Texas, and others as they take effect — have rights to access, correct, delete, and obtain a copy of personal data, and to opt out of certain processing including targeted advertising, sale, and certain profiling. You may also appeal a denied request. We honor recognized opt-out preference signals where required. To exercise these rights, contact us as described in Section 12.

17.4 Processor note. Many of the above rights, when they concern Customer Data, are fulfilled by the customer as controller. Sellora assists as described in Section 13 and any DPA.

18. Changes to this policy

We may update this Privacy Policy from time to time. If we make material changes, we will update the "Last updated" date and provide notice by email or in-product notice before the changes take effect, where required. Your continued use of the Service after the effective date constitutes acceptance of the updated Policy.

19. How to contact us

Sellora Inc. 254 Chapman Rd, Ste 208 #28297 Newark, Delaware 19702, United States

Privacy and data protectionprivacy@selloraai.com
General and supportsupport@selloraai.com
Websiteselloraai.com

If you have questions about this Policy or our data practices, or wish to exercise your rights, please contact us using the details above.

Product
How it worksPlatformIntegrationsHear a callPricing
Use cases
Enter a new marketWake a stale CRMCold outboundEvent follow-up
Company
TeamSecurityBlogUser manualContact
Find us
Sellora Inc. 254 Chapman Rd, Ste 208 #28297
Newark, Delaware 19702, US
All systems operational

© 2026 Sellora Inc. All rights reserved.

PrivacyTerms