This Privacy Policy explains how [LEGAL ENTITY NAME] Ltd (company no. [COMPANIES HOUSE NUMBER]), registered at [REGISTERED OFFICE ADDRESS, UK], collects, uses and protects your personal data as the data controller for Logosell. We are registered with the Information Commissioner's Office (ICO), registration [ICO REGISTRATION NUMBER]. You can contact our privacy team at privacy@logosell.app. This policy should be read together with our Terms. Effective [EFFECTIVE DATE] (v2.6).
Account & profile: name, email, city/approximate area, handle, bio, photo, membership tier, date of birth (for age verification) and role. Verification: a guided selfie and its result, and peer vouches (see section 5). Content: your Listings, photos/video, messages, offers, reviews, Q&A, saved searches and circles. Location: approximate location for "near me" (coarsened), and, if you choose, precise live location shared during a meetup. Usage & device: app interactions and analytics events, device model, operating system, app version, language, IP address, identifiers, and crash/diagnostic data. Notifications: your device push token. Purchases: confirmation and status of any paid extra (not card details). Support: messages and information you send us. Advertising: ad identifiers and interaction data via our ad partner. Consent records: the legal version you accepted and when. We do not collect payment card or bank details.
Directly from you (when you register, verify, list, message, buy an extra or contact us); automatically as you use the app (device, usage/analytics, approximate location, ad identifiers, diagnostics); and from others (a Member who invites, vouches for, or reports you).
If you ask to join via our waitlist, we collect the email address (and any optional city or referral detail) you provide, solely to manage the waitlist and send you an invitation. If you are not invited or ask us to, we will delete this information. Providing waitlist details does not create an account.
Our verification may use a selfie to help confirm you are a real, unique person. Depending on how it is processed, this can involve biometric information, which is "special category" data under UK GDPR. We only carry out this processing with your explicit consent, which you give when you choose to verify, relying on Article 9(2)(a) (explicit consent). You can withdraw consent and ask us to delete your verification data at any time by emailing privacy@logosell.app; withdrawing may limit access to features that need verification. We do not use verification data for advertising. Authorised staff may view your verification selfie only where necessary for trust and safety — for example, to confirm you are a real and unique person, to investigate fraud or abuse, and to prevent members we have banned from returning under a new account (ban evasion). We never use it for any other purpose, and access is limited and recorded.
To provide the Service — create your account, show and match Listings, enable messaging, offers and deals, and remember your preferences (lawful basis: performance of our contract with you). To keep the marketplace safe and trusted — verification, moderation, fraud/abuse prevention, enforcing our Terms, and handling reports and appeals (legitimate interests, and legal obligation where applicable). To verify identity using biometrics (explicit consent). For product analytics to understand and improve the app, and for advertising (consent where required under PECR, otherwise legitimate interests). To meet legal duties — for example HMRC/DAC7 reporting, Online Safety Act duties, and responding to lawful requests (legal obligation). To communicate service messages, and, with your consent, any marketing. Where we rely on legitimate interests, we have balanced them against your rights; you can object at any time. You can withdraw consent at any time without affecting earlier processing.
We use a coarsened (approximate) location to show items near you and to auto-fill your area. Precise, live location is used only if you actively turn on live-location sharing during a meetup, and only for as long as you share it. You can control or revoke location permission at any time in your device settings.
Some features send your Content (for example, a Listing photo or text, or a report) to our AI provider (Anthropic), acting as our processor, to generate suggestions, moderate content or triage reports. This is done to operate and protect the Service. We instruct our AI provider not to use your data to train their models. AI-assisted moderation always has human oversight for significant decisions (see section 16).
If you enable notifications, we store a device push token to send you alerts about messages, offers, invites, safety and Service updates. Notifications are delivered via Google's Firebase Cloud Messaging as our processor. You can turn notifications off at any time in your device or app settings.
We may show ads via third-party networks (for example, Google AdMob) that use device/ad identifiers to select and measure ads. Where required by law (PECR/UK GDPR), we ask for your consent through a consent prompt and you can change your choices in the app or device settings; you can also reset or limit ad personalisation on your device. Members with active Logosell Pro or an ad-free pass see no ads. Separately, we use first-party, privacy-friendly product analytics (events such as screen views and key actions), stored in our own systems, to understand usage and improve the app; we do not sell this data.
We do not process payments between Members and never see or store your card or bank details. If you buy a paid extra (Promote, Boost or Logosell Pro), it is handled by the Google Play Store under its own terms and privacy policy; we receive only confirmation of your purchase or pass status so we can apply the benefit.
Processors acting on our behalf under contract: hosting, database and authentication (Supabase); AI processing (Anthropic); push notifications (Google Firebase Cloud Messaging); crash and error diagnostics (Sentry); advertising (Google AdMob); app distribution and billing (Google Play); and maps (Google). Other Members: only what is needed to use the Service (for example, your profile, Listings, messages, and any location you choose to share). Authorities and third parties: where required by law, to comply with HMRC/DAC7 or the Online Safety Act, to respond to a valid legal request (such as a court order or police request), or to prevent, detect or prosecute crime and protect rights, safety, property and the Service. Where strictly necessary and lawful, this may include special category data (such as verification information), relying on the relevant conditions in the law (for example, legal obligation, the establishment or defence of legal claims, or reasons of substantial public interest). Business transfers: to a prospective or actual buyer if we sell, merge or reorganise the business, under confidentiality. We do not sell your personal data.
Some processors (for example, Anthropic and Google) may process data outside the UK, including in the United States. Where they do, we rely on appropriate safeguards, such as UK adequacy regulations, the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses, together with supplementary measures where needed. Our crash and error diagnostics are hosted within the European Union (a region covered by UK adequacy). You can ask us for details of the safeguards in place for any transfer.
We keep personal data only as long as needed for the purposes above and to meet our legal obligations, then delete or anonymise it. Our retention schedule is, in general: account and profile data — while your account is active, then deleted or anonymised within [90 days] of closure (a short window lets us reverse an accidental deletion and complete any safety checks); verification and biometric data — deleted promptly when you withdraw consent or when your verified status is no longer needed, and in any event within [30 days] of account closure; messages, Listings, offers and reviews — for the life of your account, and afterwards only where still needed for safety or legal reasons; waitlist data — until you are invited or ask us to delete it; usage analytics and crash/diagnostic data — kept for a limited period ([up to 90 days]) then held only in a reduced or aggregated form; tax and DAC7 records — [6 years] as required by HM Revenue & Customs; and moderation, fraud, safety and legal records — for as long as necessary to detect repeat abuse and to establish, exercise or defend legal claims (typically [up to 6 years]). Where a longer period is required by law or an ongoing investigation, we keep the data for that period only.
We use automated tools for trust signals (for example, reputation and connection distance) and to help detect prohibited content, scams and abuse and to triage reports, including an AI assistant that prioritises and summarises the moderation queue. We build in safeguards proportionate to the impact of each action. Automated triage and prioritisation have no direct effect on you by themselves. A reversible action (for example, temporarily hiding a Listing) is only taken automatically where two independent signals agree — a deterministic rule match and the AI's assessment — and it can be undone. Significant or hard-to-reverse actions (for example, suspending or permanently banning an account, or a decision about your verification) are never taken solely by automated means: the system may only propose them, and a human decides. You can request human review, express your view and appeal any decision that affects you (see our Terms). We do not use your data for automated decisions that produce legal or similarly significant effects on you without this human involvement.
Under UK GDPR you have the right to: be informed; access your data; correct inaccurate data; erase data ("right to be forgotten"); restrict or object to processing (including profiling and direct marketing); data portability; and withdraw consent (including for biometric verification) at any time. Rights are not absolute and some may not apply in a given case. You can exercise many of these in the app (for example, data export and account deletion) or by emailing privacy@logosell.app.
To make a request, contact privacy@logosell.app or use the in-app tools. We may need to verify your identity before acting, to protect your data. We will respond within one month (extendable by two months for complex requests, and we will tell you if so). Making a request is free unless it is manifestly unfounded or excessive. If you are unhappy with how we handle your data, you can complain to the ICO at ico.org.uk or on 0303 123 1113 — but we would welcome the chance to resolve it first.
We send service and safety communications that are necessary to operate your account and cannot generally be opted out of while you hold an account. We will only send marketing where you have consented, and you can withdraw consent at any time via the message or your settings. We do not sell your data to third parties for their own marketing.
We protect your data with measures including encryption in transit, row-level security on our database, least-privilege access controls, rate limiting, optional two-factor authentication for your account, secure storage of session credentials, and restricting access to those who need it. No system is perfectly secure, and you are responsible for keeping your login and device secure.
We have procedures to detect, investigate and respond to personal data breaches. Where a breach is likely to result in a risk to your rights and freedoms, we will notify the ICO, and you, where the law requires and without undue delay.
Logosell is strictly for those aged 16 and over. We do not knowingly collect data from anyone under 16; if we learn that we have, we will delete it. If you believe a child is using the Service, contact privacy@logosell.app.
The app uses on-device storage and third-party SDKs (for example, for ads, maps, push notifications, crash reporting and secure session storage) that may set or read identifiers. We use only what is necessary to run the app, plus, where required, what you consent to (for example, advertising identifiers). You can manage advertising identifiers and app permissions in your device settings.
We may create aggregated or anonymised data (which cannot reasonably identify you) from your data — for example, usage statistics and trends — and use and share it for any lawful purpose, including improving and promoting the Service.
We are accountable for how we handle your data. We keep a record of our processing activities, apply data protection by design and by default, restrict and log access to sensitive data, and limit who can handle it. Before we begin processing that is likely to be high risk — in particular our biometric verification — we carry out a Data Protection Impact Assessment (DPIA) to identify and reduce the risks, and we maintain an Appropriate Policy Document for our processing of special category data as UK law requires. We keep these assessments under review. You can ask us about our safeguards, and if we ever appoint a Data Protection Officer or UK representative we will publish their contact details here.
We may update this policy from time to time and will notify you of material changes in the app. For any privacy question or to exercise your rights, contact privacy@logosell.app. [LEGAL ENTITY NAME] Ltd, [REGISTERED OFFICE ADDRESS, UK]. ICO registration [ICO REGISTRATION NUMBER].