Join the waitlist
Legal

Privacy Notice

What we collect, why we're allowed to, who we share it with, how long we keep it, and what you can tell us to do about it.

Version 1.0 · Last updated 29 August 2026 · Applies to wello.social and the Wello apps

This notice explains how Wello handles personal data. It covers the website at wello.social, the Wello web app, and the Wello iOS and Android apps. We've written it to be read, not to be survived, but it's also the formal notice required by Articles 13 and 14 of the UK GDPR.

1. Who we are

The data controller for the personal data described in this notice is Wello Technologies Ltd, a company registered in England and Wales under number 17428209, with its registered office at 167-169 Great Portland Street, Fifth Floor, London, W1W 5PF. We trade as Wello.

For anything to do with your data: questions, requests, or complaints: contact privacy@wello.social. You can also reach us in the app through Help & resolution.

We are registered with the Information Commissioner's Office under registration number ZC235076. We have not appointed a Data Protection Officer, because we are not required to. Our director is accountable for data protection at Wello.

One important distinction. For your Wello account, we are the controller. But when you attend or host an experience, the Host is running their own event: anything a Host does with your information outside Wello (adding you to their own mailing list, for example) is their responsibility, not ours, and they are a separate controller for it.

2. What we collect

Nearly all of this comes directly from you. Where it doesn't, we've said so.

If you join the waitlist

  • Your name and email address.
  • Whether you signed up as a prospective host or guest.
  • A referral code, if you arrived through someone else's invite link, so we know who referred you.
  • Whether you ticked the optional box asking us to send you hosting ideas, guides and news — along with the date you ticked it and the exact wording you agreed to, so we have a record.

Joining the waitlist asks us to tell you when invites open in your city, so we'll send you that either way. Anything beyond it — guides, ideas, our newsletter — only goes out if you ticked the optional box, and every one of those emails carries a one-click unsubscribe. You can change your mind at any time by using that link or emailing us.

If you create an account

  • Account details: name, email address, date of birth, and an authentication credential (a password, or a sign-in token from Apple or Google if you use those).
  • Profile: display name, photos, bio, prompts, city, and any optional details you choose to add. Some fields are optional and clearly marked: including gender, which we ask for so hosts can see the balance of a group, and which is never shown on your public profile.
  • Taste and interests: the choices you make during onboarding, used to decide what to show you.

If you host or attend

  • Experiences: listings you create, including the exact address, which is hidden from guests until you accept them.
  • Requests and bookings: who requested what, the status, capacity, and any answers you gave to a host's questions.
  • Messages: event chat, direct messages, host broadcasts and enquiries. We can access message content where we need to investigate a report, a dispute or a safety concern.
  • Attendance: check-in records, including QR check-in.
  • Ratings and reviews you give and receive. Only people who actually attended can leave one.
  • Payment records: amounts, status, and identifiers issued by Stripe. See section 6: we never hold your card details.

Automatically, when you use Wello

  • Device and technical data: device type, operating system, app version, IP address, and push notification tokens if you turn notifications on.
  • Usage data: which screens you visit and what you tap, so we can tell what works. See section 12.
  • Error data: crash and error reports, so we can fix things.
  • Location: covered separately in section 4, because it deserves it.

From other people and services

  • Stripe tells us the outcome of identity verification and the status of a host's payout account. See sections 5 and 6.
  • Other users may name you in a report, a dispute or a rating.
  • Apple or Google pass us your name and email if you use their sign-in.

3. Why we use it, and our lawful basis

Under UK GDPR we need a lawful basis for every use. Here is each one, in plain terms.

What we doLawful basis
Create and run your account; show you experiences; let you request, host, message and check inContract: we can't provide Wello without it
Take payment, pay hosts, process refundsContract
Send service messages: request accepted, event tomorrow, payment takenContract
Verify identity for paid experiences and verified-guest eventsContract, and legitimate interests in keeping the community safe
Investigate reports, disputes, fraud and safety concerns; suspend or ban accountsLegitimate interests: protecting users and the service. We've weighed this against your privacy and consider it proportionate given people meet in person.
Understand how the product is used, and improve itLegitimate interests, or consent where analytics cookies require it
Record who referred whomLegitimate interests in understanding where our community comes from
Keep your precise location while you're on the way to an eventConsent: you turn it on, and it stops on its own
Send push notificationsConsent
Send marketing emails about WelloConsent, or the soft opt-in for existing users. Unsubscribe any time.
Ask for optional profile details like genderConsent: leave it blank and nothing breaks
Keep tax, accounting and transaction recordsLegal obligation
Respond to lawful requests from police, courts or regulatorsLegal obligation
Report seller information to HMRC, if and when the digital platform reporting rules apply to usLegal obligation

Where we rely on legitimate interests, you can object. See section 10. Where we rely on consent, you can withdraw it at any time, and that won't affect anything we did before you withdrew it.

Do you have to give us this? The account details in section 2 are required to have an account at all. That's a contractual requirement, and without them we can't provide the service. Everything marked optional is genuinely optional.

4. Location data

Location is the most sensitive thing Wello handles day to day, so here is exactly how it works.

  • Discovery. To show you what's nearby we use an approximate location: either from your device, with your permission, or from the city on your profile. You can decline and browse by city instead.
  • An experience's address. Hosts give us the exact address. Guests never see it, and it is not in the public map data, until the host accepts their request. Before that the map shows an approximate area only.
  • Live location on the way. If you choose to share that you're on your way, the host can see your approximate position for a limited window around the event. It is opt-in, it is not on by default, you can stop it at any time, and it expires by itself. We delete the position trail after the event window closes.

We do not sell location data, we do not use it for advertising, and we do not track you in the background when you aren't using Wello.

5. Identity verification

Verification is carried out by Stripe Identity, a regulated third party. Your identity document and selfie are submitted directly to Stripe. They do not pass through Wello's servers and we cannot see them.

What Stripe returns to us, and what we store, is: whether you were verified, your first name, your date of birth, and a reference to the Stripe verification session. We use the name so your account matches your ID, and the date of birth to confirm you're 18. We do not store your surname on your public profile, your document images or your selfie.

If there is a genuine safety, fraud or legal need. A serious report, or a lawful request from the police, an authorised member of the Wello team can retrieve verified identity details from Stripe. This is restricted to senior staff, requires a recorded reason, and every access is logged. It is not routine and it is not available to most of our team.

Stripe processes this as an independent controller under its own privacy policy: stripe.com/gb/privacy.

6. Payments

Wello never sees or stores your card details. Card data goes directly to Stripe, which is PCI-DSS certified.

For paid experiences, your card is authorised when you request a place and only charged if the host accepts you. If the host declines, or the request expires, the authorisation is released and you are not charged.

Money for a paid experience is paid into the host's own Stripe account, not ours: the host is the merchant of record for their event. Wello takes a service fee from the transaction. Stripe then pays the host out on that account's own payout schedule.

We store the amount, the status, and Stripe's identifiers, so we can show you your bookings, handle refunds and keep proper accounts. Hosts additionally have a Stripe Connect account, and Stripe collects identity and, for companies, business verification information directly for that purpose.

7. Who we share your data with

We do not sell personal data. We share it in four situations.

With other users, because that's the product

  • Your public profile: name, photos, bio, ratings, verification badge — is visible to other signed-in users.
  • When you request a place, the host sees your profile and anything you wrote to them. When a host accepts you, you see the exact address.
  • Other guests at an experience you're confirmed for can see your profile and anything you post in the event chat.
  • Ratings you leave and receive are visible as described in the app.
  • Gender, exact date of birth and email address are not shown on your public profile.

With service providers who process data for us

ProviderWhat for
SupabaseDatabase, authentication and file storage
VercelHosting the web app and API
StripePayments, payouts and identity verification
Apple / Google / web push servicesDelivering push notifications
ResendSending service and account emails
PostHogProduct analytics
SentryError and crash reporting
Mapping providerRendering maps and turning addresses into coordinates

Each is bound by a contract that requires them to act only on our instructions and to keep the data secure.

Where the law requires it

We will disclose data to the police, a court, a regulator or another authority where we are legally required to, or where we believe in good faith that it is necessary to prevent serious harm. We will tell you when we're allowed to.

If the business changes hands

If Wello is sold, merged or reorganised, data may transfer to the new owner. They'd be bound by this notice until they gave you a new one.

8. International transfers

Some of our providers are based outside the UK, principally in the United States and the European Economic Area. Where data leaves the UK, we rely on one of the following safeguards:

  • Adequacy regulations: for the EEA, and for US organisations certified under the UK Extension to the EU–US Data Privacy Framework.
  • The International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses, together with a transfer risk assessment.

You can ask us for a copy of the safeguards that apply to a particular transfer.

9. How long we keep things

DataKept for
Account and profileWhile your account is open. Deleted within 30 days of you deleting your account.
MessagesWhile your account is open, then deleted with it, except where retained for an open report or dispute.
Transaction and payment records6 years from the end of the relevant tax year, required for tax and accounting.
Reports, disputes and moderation decisionsUp to 6 years, so we can act on repeat behaviour and defend legal claims. Kept even if the account is deleted, in reduced form.
Suspension and ban recordsUp to 6 years, so a banned user cannot simply return.
Identity verification outcomeWhile your account is open. The documents themselves are held by Stripe under its own retention rules.
Live location while on the wayDeleted once the event window closes.
Analytics and error dataUp to 12 months.
Waitlist signupsUntil you're invited and create an account, until you ask us to remove you, or 24 months after signup — whichever comes first.

Where we anonymise data so it can no longer identify you, we may keep it indefinitely for statistics.

10. Your rights

Under UK data protection law you have the right to:

  • Be informed: which is what this notice is for.
  • Access a copy of the personal data we hold about you.
  • Rectification: have inaccurate data corrected. Most of it you can edit yourself in Settings.
  • Erasure: ask us to delete your data. You can delete your account and its data yourself in Settings at any time. Note that we may keep a limited record where we have a legal obligation or an ongoing safety concern, and we'll tell you if that applies.
  • Restrict processing: ask us to pause using your data while a dispute about it is resolved.
  • Data portability: receive the data you gave us in a machine-readable format, or have it sent to someone else.
  • Object: to processing based on legitimate interests, including profiling. We'll stop unless we have compelling grounds that override yours.
  • Object to direct marketing: at any time, absolutely, no reason needed.
  • Withdraw consent: for anything we do on the basis of consent, at any time.

To exercise any of these, email privacy@wello.social or use Help & resolution in the app. We'll respond within one month. It's free, unless a request is manifestly unfounded or excessive. We may need to confirm who you are first.

11. How we protect it

  • Everything is encrypted in transit (TLS) and at rest.
  • Card details and identity documents never reach our servers, they go to Stripe.
  • Access to production data is limited to people who need it, with individual named accounts and multi-factor authentication. Access to sensitive records is logged.
  • Exact addresses are withheld until a host accepts a guest, at the database level, not just in the interface.
  • We keep an audit trail of administrative actions: refunds, suspensions, and any access to verified identity.

No system is perfectly secure. If there is a breach that is likely to risk your rights and freedoms, we will tell the ICO within 72 hours and tell you without undue delay where the risk is high.

12. Cookies and analytics

Essential cookies keep you signed in and keep the service secure. These don't need consent because the service can't work without them.

Analytics. We use PostHog to understand how the product is used, and Sentry to catch errors. Where these require consent under the Privacy and Electronic Communications Regulations, we ask for it before setting them, and you can change your mind at any time.

We do not use advertising cookies and we do not share data with advertising networks.

The waitlist site at wello.social does not ask for your location and does not set advertising cookies.

13. Age of users

Wello is for adults. You must be 18 or over to create an account. The service brings people together in person, and we are not set up to safeguard children, so we don't accept them.

We check age at signup and against the date of birth confirmed during identity verification. If we find out someone under 18 has an account, we will close it and delete their data. If you believe a child has an account, tell us at privacy@wello.social.

14. Automated decision-making

We do not make decisions that produce legal or similarly significant effects about you by automated means alone.

Two things are automated but come with a human route: identity verification, which Stripe decides automatically and which you can ask us to review; and automated fraud and safety checks, which may hold a booking or flag an account for a person to look at. A human makes the final call on any suspension or ban.

We rank and recommend experiences based on your stated interests and location. This affects what you see first, not what you're allowed to do.

15. Changes to this notice

We'll update this notice when what we do changes. The version number and date at the top always tell you which one you're reading. If a change materially affects your rights, we'll tell you directly, by email or in the app, before it takes effect.

16. How to complain

Come to us first at privacy@wello.social. We'd rather fix it.

You also have the right to complain to the UK's data protection regulator at any time:

  • Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
  • Helpline: 0303 123 1113
  • ico.org.uk/make-a-complaint