Privacy Policy
Selluvo is a point of sale app published by zzStudio. This policy explains what data the Selluvo app, its online services and this website handle, and the choices you have. If anything is unclear, write to support@zzstudio.io.vn.
- Without an account, your shop's records stay on your device. We do not receive them.
- Selluvo has no advertising and no analytics or tracking tools.
- If you sign in and turn on cloud sync, that shop's records are stored on our servers so you can open the shop on another device.
- Backups to Google Drive or iCloud go straight from your device to your own storage. They do not pass through our servers.
- You can delete your account in the app. Your online shops are removed 30 days later.
Data that stays on your device
Everything you enter in Selluvo is saved in a database on your device: shop settings, products and their photos, stock, orders, payments, refunds, expenses, and any customer details you choose to record (a name and, if you add them, a phone number, an email address and notes). If you never sign in, none of this is sent to us.
- Camera. Used to scan barcodes and take product photos. Scanning happens on your device and camera images are not sent to us.
- Photos. Used when you pick a product photo or a receipt logo. The pictures you pick are stored with your shop.
Data we receive when you use online features
Signing in
You can sign in with Google or Apple. Sign-in is handled by Firebase Authentication, a Google service, which receives your sign-in identifier and the email address and name that your Google or Apple account shares. The app shows your name, email address and profile picture on the Account screen. Our own servers store a random account ID and the sign-in identifier. They do not store your email address or name.
Cloud sync
Cloud sync is part of Selluvo Pro. If you turn it on for a shop, the app uploads that shop's records to our servers: the shop name, currency and time zone, settings, categories, products, barcodes, product photos, the receipt logo, stock movements, orders, payments, refunds, handover records, expenses, customer records, and the change history of those records. We also store a random ID for each device that opens the shop and the time it was last seen.
Barcode lookup
When you look up a product by barcode, the app sends the barcode number to our lookup service. The request does not include your account, your shop or a device identifier. If we have not seen the barcode before, our service asks Open Food Facts for the product details. We store product details by barcode, with no link to who asked.
Purchases
Selluvo Pro is bought through the App Store or Google Play, which process the payment. We never receive your card details. RevenueCat manages subscription status for us. It receives a random app user ID (your Selluvo account ID once you sign in) and your Selluvo purchase history. Our servers store whether Pro is active and until when.
Network data
Our servers run on Cloudflare and, like any online service, receive your IP address with each request. We use it only to limit abuse: it is turned into a keyed code that changes every day and is deleted within hours. We do not store raw IP addresses in our databases. Cloudflare keeps short-lived technical logs to run and protect the service.
Backups
You can save a backup file to your device, to Google Drive or to iCloud. The app writes it directly to the app's private folder in your own Google Drive or iCloud account. No backup passes through our servers and we cannot read your backups.
- A backup contains the whole shop, including customer records.
- Set a recovery password to encrypt a backup. Without one the file is not encrypted, and anyone who has the file can read it.
- A lost recovery password cannot be reset.
- In Google Drive and iCloud the app keeps the newest backup from each of the last 7 days and each of the last 4 weeks, and deletes older ones.
How we use data
We use the data above to provide the features you turn on, to keep the service secure, and to answer you when you contact support. We do not sell personal data, show advertising or build profiles of you. We access synced shop records only to run the service, to help with a problem you ask us about, or when the law requires it.
Your customers' data
Customer records belong to your business. You decide what to record, and you are responsible for telling your customers and for following the privacy laws that apply to you. When cloud sync is on, we store those records for you and handle them only to provide the service.
Companies that help us run Selluvo
| Company | What for | Data involved |
|---|---|---|
| Sign-in (Firebase Authentication), Google Drive backups, Google Play purchases | Sign-in identifier, email address, name, your backup files, purchases | |
| Apple | Sign in with Apple, iCloud backups, App Store purchases | Sign-in identifier, your backup files, purchases |
| Cloudflare | Hosting for our servers and this website | Synced shop records, request data such as IP address |
| RevenueCat | Subscription status | App user ID, Selluvo purchase history |
| Open Food Facts | Product details for barcode lookup | The barcode number only |
Some of these companies process data in countries other than your own.
How long we keep data
- On your device: until you delete the shop or remove the app.
- Synced shops: for as long as your account exists. If Pro ends, syncing stops, the online shop stays readable for 30 days, and you can still download an export for 180 days.
- Server recovery snapshots: a daily snapshot of each synced shop is kept for 7 days.
- Barcode lookups: product details are cached for up to 37 days, with no link to you.
- Abuse-prevention codes: deleted within hours.
Deleting your account and data
In the app, open Shop, then Account, and choose Delete account. Access to your account ends at once. After 30 days we delete your online shops with all their records and files, your registered devices and your Pro status. We keep a minimal record (the account ID, the cancelled sign-in identifier, the deletion request and records that a billing event happened) so the account is not recreated by mistake.
Deleting your account does not:
- remove records saved on your device. Delete the shop or remove the app to do that;
- remove backups in your Google Drive or iCloud. Delete them under Backup & sync, or in your storage account;
- cancel a store subscription. Cancel it in your App Store or Google Play settings.
Your sign-in record at Firebase Authentication (identifier, email address and name) is removed on request. If you cannot use the app, or want that record removed, email support@zzstudio.io.vn from the address on your account.
Your rights
Depending on where you live, you may have the right to see, correct, export or delete your personal data, or to object to how it is used. Most of this is available in the app through CSV export, backup and account deletion. For anything else, email us and we will respond.
Children
Selluvo is a tool for running a business. It is not directed at children, and we do not knowingly collect data from them.
This website
This website uses no cookies, no analytics and no third-party scripts. Cloudflare delivers the pages and processes your IP address to do so.
Changes to this policy
When we change this policy we will update this page and the date at the top.
Contact
zzStudio, support@zzstudio.io.vn, zzstudio.io.vn