This policy explains what personal data Reelle collects, why we collect it, who we share it with and what control you have over it. It covers the Reelle mobile app, the website at reelle.io and the admin console at admin.reelle.io.

1. Who we are

Reelle is a luxury-asset registry and verified-identity network. For the purposes of data protection law, the data controller is [COMPANY LEGAL NAME], [REGISTERED ADDRESS], [COMPANY NUMBER]. You can reach us at privacy@reelle.io.

2. What we collect

Account data

Email address, password (stored only as a hash by our authentication provider), display name and phone number. If you sign in with Google, we receive your Google account email, name and profile picture.

Profile data

Anything you choose to add to your profile: date of birth, gender, country and city, relationship status, education, occupation, languages, biography, declared net worth, profile photograph and avatar.

Location data

If you grant location permission, we collect your device's latitude and longitude so your avatar can appear on the live map and so we can show you members nearby. Location is updated while the app is open and you are set to Online. You can switch to Offline at any time, or deny the permission entirely — the rest of the app continues to work.

Asset and document data

Details of items you register: title, brand, category, serial number, estimated value, description, photographs, video, and any warranty certificate, purchase receipt or other document you upload. For identity verification you may also upload a passport or similar identity document.

Messages

Messages you send to other members, including the content, timestamps and read status. Messages are not end-to-end encrypted; we can technically access them and will do so only where necessary to investigate a report of abuse or where we are legally required to.

Device, technical and consent data

A randomly generated installation identifier, your platform and operating system version, app version, push notification token, and — when you accept this policy and our Terms — a consent record containing that installation identifier and the date and time of acceptance. We record consent so we can demonstrate that it was given, and so we can tell you when a policy you previously accepted has changed.

The installation identifier is generated by the app, is specific to that installation, and is not a hardware serial number. Deleting and reinstalling the app generates a new one.

3. How we use it

4. Legal bases

Where the UK or EU GDPR applies, we rely on:

5. What others can see

Reelle starts private. An asset is visible to other members only if you mark it public; your net worth, age and wallet are hidden unless you switch them on; and you are absent from the map whenever you are Offline. Your name, city, avatar and verification status are visible to signed-in members.

Making an asset public shows its photographs, title, brand, category, estimated value and verification level to other members, together with your name and city.

6. Blockchain and permanence

When an asset reaches a verified state we may mint it as an ERC-721 token on the MODEM blockchain. The token stores the asset's title, brand, category, serial number, description, declared value, media URLs and verification level, together with a reference to the owning account and every subsequent transfer.

7. Who we share data with

We do not sell your personal data, and we do not use it for advertising.

8. How long we keep it

9. Your rights

Depending on where you live, you may have the right to access, correct, delete, restrict or object to our use of your data, to withdraw consent, and to receive a copy in a portable format. The app provides several of these directly: Export My Data, Delete All Assets, Delete All Data and Delete Account under Privacy & Security.

For anything else, contact privacy@reelle.io. We aim to respond within 30 days. If you are unhappy with our response you can complain to your local data protection authority.

Our ability to honour an erasure request is limited to systems we control — see section 6.

10. Security

Data is transmitted over TLS and stored on Google Cloud infrastructure with access controlled by server-side security rules. Passwords are hashed by our authentication provider and are never visible to us. No system is perfectly secure; if a breach affects your rights and freedoms we will notify you and the relevant regulator as required by law.

11. Children

Reelle is not intended for anyone under 18 and we do not knowingly collect data from children. If you believe a child has registered, contact us and we will delete the account.

12. International transfers

Our infrastructure is operated by Google Cloud and by our own servers, and data may be processed outside your country. Where required, transfers are covered by the European Commission's standard contractual clauses. Blockchain data is replicated globally by design and is not subject to any transfer mechanism.

13. Changes

If we change this policy materially we will raise the version number and ask you to accept the new version in the app. The version you accepted, and when, is recorded against your account.

14. Contact

privacy@reelle.io
[COMPANY LEGAL NAME], [REGISTERED ADDRESS]