This notice explains how Wello handles personal data. It covers the website at wello.social, the Wello web app, and the Wello iOS and Android apps. We've written it to be read, not to be survived, but it's also the formal notice required by Articles 13 and 14 of the UK GDPR.
Contents
1. Who we are
The data controller for the personal data described in this notice is Wello Technologies Ltd, a company registered in England and Wales under number 17428209, with its registered office at 167-169 Great Portland Street, Fifth Floor, London, W1W 5PF. We trade as Wello.
For anything to do with your data: questions, requests, or complaints: contact privacy@wello.social. You can also reach us in the app through Help & resolution.
We are registered with the Information Commissioner's Office under registration number ZC235076. We have not appointed a Data Protection Officer, because we are not required to. Our director is accountable for data protection at Wello.
One important distinction. For your Wello account, we are the controller. But when you attend or host an experience, the Host is running their own event: anything a Host does with your information outside Wello (adding you to their own mailing list, for example) is their responsibility, not ours, and they are a separate controller for it.
2. What we collect
Nearly all of this comes directly from you. Where it doesn't, we've said so.
If you join the waitlist
- Your name and email address.
- Whether you signed up as a prospective host or guest.
- A referral code, if you arrived through someone else's invite link, so we know who referred you.
- Whether you ticked the optional box asking us to send you hosting ideas, guides and news — along with the date you ticked it and the exact wording you agreed to, so we have a record.
Joining the waitlist asks us to tell you when invites open in your city, so we'll send you that either way. Anything beyond it — guides, ideas, our newsletter — only goes out if you ticked the optional box, and every one of those emails carries a one-click unsubscribe. You can change your mind at any time by using that link or emailing us.
If you create an account
- Account details: name, email address, date of birth, and an authentication credential (a password, or a sign-in token from Apple or Google if you use those).
- Profile: display name, photos, bio, prompts, city, and any optional details you choose to add. Some fields are optional and clearly marked: including gender, which we ask for so hosts can see the balance of a group, and which is never shown on your public profile.
- Taste and interests: the choices you make during onboarding, used to decide what to show you.
If you host or attend
- Experiences: listings you create, including the exact address, which is hidden from guests until you accept them.
- Requests and bookings: who requested what, the status, capacity, and any answers you gave to a host's questions.
- Messages: event chat, direct messages, host broadcasts and enquiries. We can access message content where we need to investigate a report, a dispute or a safety concern.
- Attendance: check-in records, including QR check-in.
- Ratings and reviews you give and receive. Only people who actually attended can leave one.
- Payment records: amounts, status, and identifiers issued by Stripe. See section 6: we never hold your card details.
Automatically, when you use Wello
- Device and technical data: device type, operating system, app version, IP address, and push notification tokens if you turn notifications on.
- Usage data: which screens you visit and what you tap, so we can tell what works. See section 12.
- Error data: crash and error reports, so we can fix things.
- Location: covered separately in section 4, because it deserves it.
From other people and services
3. Why we use it, and our lawful basis
Under UK GDPR we need a lawful basis for every use. Here is each one, in plain terms.
| What we do | Lawful basis |
|---|---|
| Create and run your account; show you experiences; let you request, host, message and check in | Contract: we can't provide Wello without it |
| Take payment, pay hosts, process refunds | Contract |
| Send service messages: request accepted, event tomorrow, payment taken | Contract |
| Verify identity for paid experiences and verified-guest events | Contract, and legitimate interests in keeping the community safe |
| Investigate reports, disputes, fraud and safety concerns; suspend or ban accounts | Legitimate interests: protecting users and the service. We've weighed this against your privacy and consider it proportionate given people meet in person. |
| Understand how the product is used, and improve it | Legitimate interests, or consent where analytics cookies require it |
| Record who referred whom | Legitimate interests in understanding where our community comes from |
| Keep your precise location while you're on the way to an event | Consent: you turn it on, and it stops on its own |
| Send push notifications | Consent |
| Send marketing emails about Wello | Consent, or the soft opt-in for existing users. Unsubscribe any time. |
| Ask for optional profile details like gender | Consent: leave it blank and nothing breaks |
| Keep tax, accounting and transaction records | Legal obligation |
| Respond to lawful requests from police, courts or regulators | Legal obligation |
| Report seller information to HMRC, if and when the digital platform reporting rules apply to us | Legal obligation |
Where we rely on legitimate interests, you can object. See section 10. Where we rely on consent, you can withdraw it at any time, and that won't affect anything we did before you withdrew it.
Do you have to give us this? The account details in section 2 are required to have an account at all. That's a contractual requirement, and without them we can't provide the service. Everything marked optional is genuinely optional.
4. Location data
Location is the most sensitive thing Wello handles day to day, so here is exactly how it works.
- Discovery. To show you what's nearby we use an approximate location: either from your device, with your permission, or from the city on your profile. You can decline and browse by city instead.
- An experience's address. Hosts give us the exact address. Guests never see it, and it is not in the public map data, until the host accepts their request. Before that the map shows an approximate area only.
- Live location on the way. If you choose to share that you're on your way, the host can see your approximate position for a limited window around the event. It is opt-in, it is not on by default, you can stop it at any time, and it expires by itself. We delete the position trail after the event window closes.
We do not sell location data, we do not use it for advertising, and we do not track you in the background when you aren't using Wello.
5. Identity verification
Verification is carried out by Stripe Identity, a regulated third party. Your identity document and selfie are submitted directly to Stripe. They do not pass through Wello's servers and we cannot see them.
What Stripe returns to us, and what we store, is: whether you were verified, your first name, your date of birth, and a reference to the Stripe verification session. We use the name so your account matches your ID, and the date of birth to confirm you're 18. We do not store your surname on your public profile, your document images or your selfie.
If there is a genuine safety, fraud or legal need. A serious report, or a lawful request from the police, an authorised member of the Wello team can retrieve verified identity details from Stripe. This is restricted to senior staff, requires a recorded reason, and every access is logged. It is not routine and it is not available to most of our team.
Stripe processes this as an independent controller under its own privacy policy: stripe.com/gb/privacy.
6. Payments
Wello never sees or stores your card details. Card data goes directly to Stripe, which is PCI-DSS certified.
For paid experiences, your card is authorised when you request a place and only charged if the host accepts you. If the host declines, or the request expires, the authorisation is released and you are not charged.
Money for a paid experience is paid into the host's own Stripe account, not ours: the host is the merchant of record for their event. Wello takes a service fee from the transaction. Stripe then pays the host out on that account's own payout schedule.
We store the amount, the status, and Stripe's identifiers, so we can show you your bookings, handle refunds and keep proper accounts. Hosts additionally have a Stripe Connect account, and Stripe collects identity and, for companies, business verification information directly for that purpose.
8. International transfers
Some of our providers are based outside the UK, principally in the United States and the European Economic Area. Where data leaves the UK, we rely on one of the following safeguards:
- Adequacy regulations: for the EEA, and for US organisations certified under the UK Extension to the EU–US Data Privacy Framework.
- The International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses, together with a transfer risk assessment.
You can ask us for a copy of the safeguards that apply to a particular transfer.
9. How long we keep things
| Data | Kept for |
|---|---|
| Account and profile | While your account is open. Deleted within 30 days of you deleting your account. |
| Messages | While your account is open, then deleted with it, except where retained for an open report or dispute. |
| Transaction and payment records | 6 years from the end of the relevant tax year, required for tax and accounting. |
| Reports, disputes and moderation decisions | Up to 6 years, so we can act on repeat behaviour and defend legal claims. Kept even if the account is deleted, in reduced form. |
| Suspension and ban records | Up to 6 years, so a banned user cannot simply return. |
| Identity verification outcome | While your account is open. The documents themselves are held by Stripe under its own retention rules. |
| Live location while on the way | Deleted once the event window closes. |
| Analytics and error data | Up to 12 months. |
| Waitlist signups | Until you're invited and create an account, until you ask us to remove you, or 24 months after signup — whichever comes first. |
Where we anonymise data so it can no longer identify you, we may keep it indefinitely for statistics.
10. Your rights
Under UK data protection law you have the right to:
- Be informed: which is what this notice is for.
- Access a copy of the personal data we hold about you.
- Rectification: have inaccurate data corrected. Most of it you can edit yourself in Settings.
- Erasure: ask us to delete your data. You can delete your account and its data yourself in Settings at any time. Note that we may keep a limited record where we have a legal obligation or an ongoing safety concern, and we'll tell you if that applies.
- Restrict processing: ask us to pause using your data while a dispute about it is resolved.
- Data portability: receive the data you gave us in a machine-readable format, or have it sent to someone else.
- Object: to processing based on legitimate interests, including profiling. We'll stop unless we have compelling grounds that override yours.
- Object to direct marketing: at any time, absolutely, no reason needed.
- Withdraw consent: for anything we do on the basis of consent, at any time.
To exercise any of these, email privacy@wello.social or use Help & resolution in the app. We'll respond within one month. It's free, unless a request is manifestly unfounded or excessive. We may need to confirm who you are first.
11. How we protect it
- Everything is encrypted in transit (TLS) and at rest.
- Card details and identity documents never reach our servers, they go to Stripe.
- Access to production data is limited to people who need it, with individual named accounts and multi-factor authentication. Access to sensitive records is logged.
- Exact addresses are withheld until a host accepts a guest, at the database level, not just in the interface.
- We keep an audit trail of administrative actions: refunds, suspensions, and any access to verified identity.
No system is perfectly secure. If there is a breach that is likely to risk your rights and freedoms, we will tell the ICO within 72 hours and tell you without undue delay where the risk is high.
13. Age of users
Wello is for adults. You must be 18 or over to create an account. The service brings people together in person, and we are not set up to safeguard children, so we don't accept them.
We check age at signup and against the date of birth confirmed during identity verification. If we find out someone under 18 has an account, we will close it and delete their data. If you believe a child has an account, tell us at privacy@wello.social.
14. Automated decision-making
We do not make decisions that produce legal or similarly significant effects about you by automated means alone.
Two things are automated but come with a human route: identity verification, which Stripe decides automatically and which you can ask us to review; and automated fraud and safety checks, which may hold a booking or flag an account for a person to look at. A human makes the final call on any suspension or ban.
We rank and recommend experiences based on your stated interests and location. This affects what you see first, not what you're allowed to do.
15. Changes to this notice
We'll update this notice when what we do changes. The version number and date at the top always tell you which one you're reading. If a change materially affects your rights, we'll tell you directly, by email or in the app, before it takes effect.
16. How to complain
Come to us first at privacy@wello.social. We'd rather fix it.
You also have the right to complain to the UK's data protection regulator at any time:
- Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
- Helpline: 0303 123 1113
- ico.org.uk/make-a-complaint