This policy explains how aello.pro (“we” or “us”) handles personal data when you visit the website, purchase a licence, contact support, or use our software. We act as the controller of this data. The sections below explain what we collect, how we use it, and the choices and rights available to you.
1. What we collect
- Contact and order details. Names, email addresses, optional messaging or Telegram handles, and corrections you provide through checkout, trial, or enquiry forms.
- Transaction records. Order references, selected payment assets and networks, generated payment addresses, amounts due and received, transaction identifiers, confirmation counts, and timestamps.
- Licence and activation records. Licence identifiers, purchased plans and terms, device labels and identifiers, and activation or validation timestamps.
- Support and enquiry content. Messages and trial requests you send us. If the support team is marked away or has not replied within 40 seconds of your first website message, we request a full name and an email address or Telegram handle for a later reply.
- Email verification records. The address being verified, the value used to derive its confirmation code, and send and attempt counts. We do not store the code itself. The verification record is deleted when it expires.
- Delivery records. Licence email addresses, queued, sent, or failed delivery status, and expiry reminders already sent.
- Website usage. Pages viewed and actions taken, with device, browser, approximate location, and network information, collected directly or through the measurement services described below.
- Security and operational logs. Administrative and system activity, and network identifiers used temporarily for rate limiting and abuse prevention.
2. What we do not collect
- The software does not send your exchange API credentials to us. They remain encrypted on your computer or private server. Please do not include credentials in support messages.
- We do not request or knowingly collect special category data, biometric data, or government identifiers.
- We do not use automated decision-making that produces legal or similarly significant effects concerning you.
3. Why we process it, and our legal bases
Where the UK or EU GDPR applies, we rely on the following legal bases:
- Performance of a contract (Article 6(1)(b)): processing orders, issuing and delivering licences, validating activations, and providing support.
- Legal obligation (Article 6(1)(c)): retaining accounting, tax, and other legally required records.
- Legitimate interests (Article 6(1)(f)): protecting the Service, preventing fraud and misuse, maintaining an audit trail, and understanding aggregate website usage. We balance these purposes against your rights and use pseudonymous, minimised data.
- Consent (Article 6(1)(a)): processing for which we request your permission. You may withdraw consent at any time without affecting the lawfulness of earlier processing.
4. Cookies, analytics, and browser storage
Cookies and browser storage support site functions, including operator-console sessions, recent order references, and your chosen light or dark theme. These functional preferences and features are separate from analytics consent.
Google Analytics is optional and disabled until you choose “Accept analytics”. If accepted, Google may set analytics cookies and receive the page or product viewed, checkout progress, completed trial or contact requests, and completed purchases, together with device, browser, approximate location, and network information. We disable advertising signals and do not send names, email or messaging addresses, wallet addresses, licence keys, coupon codes, or raw order identifiers to Google.
Use “Cookie preferences” in the footer to reject optional analytics or withdraw consent. Withdrawal deletes Google Analytics cookies accessible to this site and stops further Google Analytics events. Browser settings provide additional cookie and storage controls.
Your licence key is never written to browser storage. Support return-contact fields remain in page memory only while the chat is open and are not written to browser storage.
5. Who we share it with
We do not sell personal data for money. We share it only with:
- providers working under our instructions and a written contract, including hosting, email, backup, payment and exchange-rate, support, analytics, advertising, and similar measurement services;
- professional advisers, where needed and under confidentiality obligations;
- authorities where disclosure is legally required, or parties involved in establishing, exercising, or defending legal claims; and
- an acquirer in a merger, acquisition, or asset sale, subject to this policy.
Support return-contact details are not copied into provider messages, provider contacts, analytics, or operational logs. If support conversations are mirrored to a configured support tool, that tool receives the message text and role label, not the return-contact fields.
6. Public payment records
Supported cryptocurrency networks publish payment addresses, amounts, and transaction identifiers. Those records may be viewed and analysed by third parties. Aello does not control the public ledger. A data-deletion request can address records we hold, subject to legal retention requirements, but does not erase transaction records from a public blockchain.
7. International transfers
We and our providers may process data outside your country, including outside the European Economic Area or United Kingdom. For transfers from those areas, we use an applicable adequacy decision or Standard Contractual Clauses with any additional safeguards required. You may contact us for details of the safeguards used.
8. How long we keep it
- First-party website analytics: automatically deleted after 180 days by default.
- Google Analytics: retained for the period configured in our Google Analytics property.
- Security and audit logs: retained for up to 730 days by default.
- Order, payment, licence, and delivery records: kept during the licence term and afterwards as needed for support, dispute resolution, accounting, and tax obligations.
- Support correspondence: closed conversations are deleted after 90 days by default. Visitor credentials and return-contact details expire with the support visitor record. After the documented expiry grace period, deletion also removes remaining local conversations associated with that record.
Records are deleted when their retention period ends. Anonymous aggregate statistics may be retained.
9. Security
Our safeguards include encryption in transit, encryption of sensitive stored values, access controls, an append-only audit trail, and regularly tested backups. These measures reduce risk but cannot guarantee absolute security. Please keep licence keys and other credentials private and contact us if you suspect unauthorised access.
10. Your rights
Depending on applicable law and its exemptions, you may request access to your data, correction, deletion, restriction of processing, or a portable machine-readable copy. You may also object to processing based on legitimate interests. We stop direct marketing on request. Where we rely on consent, you may withdraw it at any time.
We respond within one month, with an extension of up to two further months for complex requests. We may request information to verify your identity. There is no fee unless a request is manifestly unfounded or excessive. You may also raise a complaint directly with your local data protection supervisory authority.
11. California privacy rights
Where the California Consumer Privacy Act, as amended by the CPRA, applies, California residents have additional rights. During the preceding twelve months, the information described in section 1 falls within the categories of identifiers, commercial information, internet or network activity, and information voluntarily included in messages.
We obtain this information from you and your use of the website and software, for the purposes in section 3. Recipients are described in section 5.
- We do not sell personal information for money or knowingly sell or share information about consumers under 16. Some measurement technologies may fall within the statutory definitions of “sale” or “sharing”. Where they do, you may opt out through the controls in section 4 or by contacting us.
- You may request information about collection, use, and disclosure; request deletion or correction; opt out of sale or sharing; and limit applicable uses of sensitive personal information.
- Exercising these rights does not result in discriminatory treatment. We do not offer financial incentives for personal information.
- An authorised agent may act for you with proof of authorisation. We may verify identity before processing the request.
The site does not respond to Do Not Track signals. Where applicable law requires recognition of Global Privacy Control or a similar opt-out signal, we treat it as a request to opt out of sale or sharing.
12. Children
The Service is intended for adults aged 18 and over. We do not knowingly collect children’s personal data. If you believe a child has provided data, contact us so we can delete it.
13. Changes to this policy
Updated versions take effect when posted on this page, with a revised “last updated” date. We take reasonable steps to notify you of material changes.
14. Contact
To exercise a privacy right or ask a question, contact our support contact or use Contact us. Please describe the request without including licence keys or other credentials.