Compradores: protegidos por depósito en garantía — tu pago se retiene hasta que confirmes la entregaSolicitudes abiertas — vende tu obra en Bello

Privacy Policy

Última actualización 8/4/2026
Esta página está disponible en inglés. Las versiones traducidas llegarán pronto.

Privacy Policy

Last updated: 3 August 2026

Bello Art ("Bello," "we," "us," or "our") respects your privacy and is committed to handling your personal data responsibly. This Privacy Policy explains what information we collect when you interact with our marketplace platform (the "Platform"), why we collect it, how we use and share it, how long we keep it, and the choices and rights available to you. This Policy is written to be read alongside our Terms of Service, which describe the marketplace mechanics referenced throughout this document.

1. Scope and Who This Applies To

This Policy applies to everyone who interacts with the Platform in any capacity: Buyers who browse, purchase, or submit Commission requests; Artists who apply to sell, list Artworks, fulfill Orders, and manage a Wallet; site Visitors who access public pages without ever creating an Account, including anyone who interacts with our support chat widget; and anyone who contacts our support team, whether or not they hold an Account. Where a section applies only to one of these groups, that is stated explicitly; otherwise, it applies to all of them.

This Policy covers data we collect directly through the Platform (our website, its APIs, and the chat widget embedded across our public pages), as well as data we receive from service providers acting on our behalf, such as payment processors and shipping carriers, to the extent that data becomes part of the records we hold about you. It does not cover the privacy practices of third-party websites you may reach by following a link from our Platform, or of payment or logistics providers acting under their own independent privacy policies, which we encourage you to review separately.

We act as the data controller (or the equivalent concept under your local law) for personal data processed in connection with operating the Platform, except where we act as a processor on behalf of a service provider, which we will indicate where relevant.

This Policy is organized to walk through, in order: the categories of data we collect (Section 2); why we use it and on what legal basis (Sections 3 and 4); the cookies and tracking technologies involved (Section 5); who we share data with and why (Section 6); how long we keep it (Section 7); how it moves across borders (Section 8); the rights you have over it and how to exercise them (Section 9); special provisions for children (Section 10), security (Section 11), and breach notification (Section 12); the AI-assisted support feature (Section 13); region-specific provisions for California and the EEA/UK (Sections 14 and 15); how we handle changes to this Policy (Section 16); third-party links, how this Policy relates to our Terms of Service, and a role-by-role summary (Sections 17 through 19); and how to reach us (Section 20). If you are looking for one specific topic, the section headings below are designed to let you jump straight to it.

We try to write this Policy in plain language wherever the underlying legal requirement allows, but because this is a marketplace handling real payments, escrowed funds, and identity verification, some sections necessarily describe technical and financial-compliance processes in specific detail — we would rather be precise about what we actually do than vague in the name of readability.

2. What Data We Collect

We collect several categories of data, depending on how you use the Platform.

Account data. When you register, we collect your email address, a hashed version of your password (we never store passwords in plain text), your legal name, and your selected role. If you apply to sell, we additionally collect your portfolio URL, primary medium, country, years of practice, and artist statement. If approved, your public artist profile additionally includes your slug, city, biography, portrait image, the year you joined, and typical shipping timeline — fields you provide and control, understanding that they are displayed publicly to Buyers browsing the Platform.

Transaction data. When you place an Order, we collect the Artworks purchased, prices, any selected options (insurance, paper stock, carrier, delegate-to-seller shipping preference), your delivery address for physical Orders, and the resulting Order and Escrow status history. When you sell, we collect your listing details and the resulting sale records, including commission and insurance amounts computed for each line item. We retain a complete Order history because it is the operative record for Escrow release, dispute resolution, tax reporting, and your own order-history view.

Wallet, deposit, and payout data. For Artists, we maintain a Wallet ledger recording every credit and debit — sale-proceeds credits, Withdrawal debits, fee deductions, adjustments, and reversals — each timestamped and, where applicable, linked to an Order. When you register a Payout Method, we collect the destination account details you provide (for example, bank account or payment-service account identifiers) together with a type and a JSON details blob, and we route that submission through our internal review process, which carries a status of pending, approved, or rejected. Where required for KYC (know-your-customer) or anti-money-laundering compliance, we may collect government-issued identification, proof of address, tax-identification information, or other verification documents in connection with a Payout Method or a Withdrawal request, particularly one approaching a lifetime-earnings threshold.

Chat and support data. Our support chat widget, embedded on public pages, allows Visitors and users to start a conversation with our support team or, in some cases, an AI-assisted first responder, without necessarily creating an Account first. We collect the content of chat messages, the sender type (visitor, admin, or AI), and metadata linking a chat session to a Visitor record and, where the person is logged in, to their Account. We similarly retain records of email or other support correspondence you send us.

Device, visitor, and analytics data. Whether or not you create an Account, visiting the Platform causes certain technical data to be recorded in our visitor-tracking system: a session identifier, your IP address, geolocation derived from that IP address (country and city level), a device fingerprint derived from characteristics of your browser and device, your user-agent string, and timestamps for when we first and most recently observed that session. Our systems apply automated heuristics to this data — for example, comparing your IP-derived geolocation against other signals to flag a likely mismatch consistent with VPN or proxy use — and record a vpn_suspected flag and, where our fraud and abuse review concludes it is warranted, a blocked flag, on the visitor record. This analytics layer exists primarily to protect the marketplace against fraud, abuse, and automated attacks, and secondarily to help us understand aggregate usage patterns; it is described in more detail in Section 5 (Cookies and Tracking Technologies).

Dispute and moderation data. If you open or are named in a dispute, we collect the evidence submitted (photographs, written statements, carrier tracking references) and the resulting resolution note and status. If your conduct is investigated for a suspected Terms violation, we retain records of that investigation, including the underlying transaction, chat, or listing data that informed it.

Commission-request data. If you submit a custom-work Commission request, we collect the title, description, optional budget, and optional target-artist selection you provide; if you are logged in when you submit it, it is linked to your Account, and if you submit it without a session, we do not attach an Account identity to it beyond whatever contact details the request text itself might contain.

Communications you send us. If you email us, use the contact form, or otherwise write to us, we keep a record of that correspondence, including any attachments, to respond to you and to maintain a record of the interaction.

Data we receive from third parties. In addition to data you provide directly, we receive limited data from third parties in connection with operating the Platform: our payment processor confirms whether a payment succeeded and provides a processor-level transaction reference (but not your full card number, which the processor tokenizes and does not share with us); shipping carriers provide tracking-status updates for physical Orders; and, where you sign in or link an external account for a feature we may offer in the future, that provider would supply the basic profile data required for that integration, disclosed to you at the point you opt in.

Inferred and derived data. Beyond data you actively provide, our systems derive certain data from your activity: your workCount and sales history as an Artist, aggregate spend as a Buyer, dispute history, and the fraud-risk signals (VPN-mismatch flag, blocked flag) described above are all derived rather than directly submitted by you. We treat derived data with the same care as directly collected data, and it is covered by the access and correction rights described in Section 9 to the extent it reflects a factual, correctable inaccuracy (for example, if a device fingerprint erroneously links your account to another visitor's suspicious session).

Precision of location data. The geolocation we derive from your IP address is city-level at most and is materially less precise than GPS-based location data; we do not request device GPS location, and the Platform does not ask for or use your device's native location-services permission. IP-derived location is used exclusively for the fraud-prevention and compliance purposes described in this Policy, such as flagging a mismatch between a Buyer's apparent location and their stated shipping country, not for behavioral profiling or advertising.

3. How We Use Data

We use the data described above for the following purposes: operating core marketplace functionality (creating and authenticating Accounts, publishing listings, processing Orders, computing commission and insurance, running the Escrow hold-and-release mechanism, and crediting Wallets); communicating with you about your Account, Orders, disputes, and Withdrawal requests; verifying identity and payout eligibility for AML/KYC compliance; detecting, investigating, and preventing fraud, abuse, and violations of our Terms of Service, including through the visitor-analytics signals described above; providing customer support through chat, email, and our AI-assisted draft tools described in Section 13; improving the Platform, including understanding which features are used and where friction arises; complying with legal obligations, such as tax reporting and responding to lawful requests from authorities; and, where you have consented or where permitted by law, sending you marketing communications about the Platform, which you may opt out of at any time as described in Section 9.

We do not use your personal data to make a decision with legal or similarly significant effect about you based solely on automated processing without human involvement; automated signals such as the VPN-mismatch flag inform, but do not by themselves finalize, an account-level or Order-level enforcement decision — a human reviewer is involved before an Account is suspended or a Withdrawal is declined on fraud-review grounds.

Purpose limitation. We use each category of data only for purposes consistent with the reason it was collected, or for a compatible purpose we identify and, where required, notify you of. For example, KYC identity-verification documents collected to approve a Payout Method are used for that compliance purpose (and any legally mandated retention that follows from it) and are not repurposed for marketing, nor merged into your public artist profile. Similarly, the content of a dispute's evidentiary photographs is used to resolve that dispute and, in aggregate and de-identified form, to understand common failure modes in shipping or packaging across the Platform — it is not shared publicly or attached to your profile.

Aggregated and de-identified data. We may create aggregated or de-identified data from the categories described in Section 2 — for instance, "average time to Escrow release" or "percentage of Orders with insurance selected" — and use or share that aggregated data without restriction, because it does not identify you or any other individual.

Product analytics. Where we use analytics to understand feature usage (for example, how many Artists use the Collections feature, or how often a Commission request converts into an accepted Order), we prefer aggregated reporting over individually identifiable analysis wherever the underlying business question allows it, and we limit the internal audience for individually identifiable usage data to personnel who need it for support, fraud-review, or product-development purposes.

Marketing communications. Where you have opted in, or where applicable law permits us to send transactional-adjacent marketing without opt-in (for example, notifying existing customers about a materially similar new feature, subject to your right to opt out), we may send you emails about new Exhibitions, Collections, features, or promotions. Every marketing email includes an unsubscribe mechanism, and you can also manage your marketing preferences from your Account settings. Opting out of marketing does not opt you out of transactional communications necessary to operate the Platform — such as Order-status updates, dispute notices, security alerts, and Withdrawal confirmations — which we will continue to send regardless of your marketing preference, because they are necessary to the service itself rather than promotional in nature.

Product development and testing. We may use data in aggregate or de-identified form, and in limited identifiable form restricted to personnel directly involved in the work, to test new features before a general release (for example, testing the Commissions or Exhibitions functionality with a small group before wider rollout), to diagnose and fix bugs, and to evaluate whether a feature is achieving its intended purpose.

4. Legal Bases for Processing

Where applicable law (such as the EU/UK General Data Protection Regulation) requires us to identify a legal basis for processing your personal data, we rely on the following, as appropriate to the specific processing activity: performance of a contract, where processing is necessary to provide the Platform's core marketplace services to you as a registered user (for example, processing an Order you placed); legal obligation, where processing is necessary to comply with law, such as AML/KYC verification or tax reporting; legitimate interests, where processing supports interests we or a third party pursue that are not overridden by your rights and interests — including fraud prevention, Platform security, service improvement, and defending legal claims — and where we have assessed that reliance on this basis is appropriate and proportionate; and consent, where we ask for it explicitly, such as for optional marketing communications or certain non-essential cookies, which you may withdraw at any time without affecting processing already carried out.

Mapping processing activities to a legal basis. To make this concrete: creating your Account and processing an Order rely on contract performance; computing and displaying your public artist profile relies on contract performance to the extent it is core to offering selling functionality, informed by the choices you make about what optional fields to complete; KYC/payout verification and any tax-reporting document we issue rely on legal obligation; the visitor-analytics, device-fingerprinting, and VPN-mismatch signals described in Section 2 rely on legitimate interests in operating a secure, fraud-resistant marketplace, balanced against the comparatively limited privacy impact of technical, non-sensitive signals used for that narrow purpose; and marketing emails, along with any non-essential cookie, rely on consent, which you can withdraw at any time as described in Sections 5 and 9.

Withdrawing consent. Where processing relies on consent, you can withdraw it at any time — for marketing, by unsubscribing or adjusting your Account preferences; for non-essential cookies, through the cookie controls described in Section 5. Withdrawing consent does not affect the lawfulness of processing carried out before the withdrawal, and does not affect processing that instead relies on one of the other legal bases described above (for example, withdrawing marketing consent does not stop us from sending you a required Order-status notification, which relies on contract performance rather than consent).

Balancing legitimate interests. Before relying on legitimate interests for a given processing activity, we ask three questions: whether the purpose is a genuine, specific interest rather than a vague or speculative one; whether the processing is actually necessary to achieve that purpose, rather than merely convenient; and whether your interests, rights, and reasonable expectations are outweighed by our interest, taking into account the nature of the data, the context in which we collected it, and the safeguards in place. Fraud-prevention processing built around comparatively low-sensitivity technical signals (IP address, device characteristics), used narrowly for security purposes and subject to human review before any significant enforcement action, is the kind of processing that most readily satisfies this balance; by contrast, we would not rely on legitimate interests for processing that Buyers or Artists using an escrow-based marketplace would not reasonably expect, such as using transaction data for a purpose unrelated to operating the Platform.

5. Cookies and Tracking Technologies

We use cookies and similar technologies (such as local storage and the device-fingerprinting techniques described above) for several purposes: strictly necessary cookies that keep you logged in (our authentication cookie carries a signed session token) and remember your cart contents between visits; security and fraud-prevention technologies, including the visitor session identifier, device fingerprint, and IP-derived geolocation used to power the VPN-mismatch and abuse-detection signals described in Section 2; and, where enabled, analytics technologies that help us understand aggregate usage of the Platform, such as which pages are viewed and how users navigate between them.

Where a cookie or tracking technology is not strictly necessary for the Platform to function, we will seek your consent before setting it, consistent with applicable law in your jurisdiction, and you can manage cookie preferences through the controls we provide on the Platform or through your browser's own settings; note that disabling strictly necessary cookies will prevent you from logging in or maintaining a working cart. We do not currently participate in third-party interest-based advertising networks that would place tracking cookies on your device for cross-site ad targeting; if this changes, we will update this Policy and provide the consent mechanisms applicable law requires before doing so.

Device fingerprinting, explained. Our device fingerprint is derived from characteristics your browser exposes as part of ordinary web requests — such as user-agent string, screen and viewport characteristics, installed-font signals, and similar browser-reported attributes — combined into a hash that lets us recognize a returning device across sessions without relying solely on a cookie, which a bad actor attempting fraud might otherwise clear or block. We use this fingerprint to strengthen our fraud- and abuse-detection signal, for example to notice that a device previously associated with a blocked Visitor is attempting to create a new Account, and to reduce false positives that pure IP-based blocking would otherwise cause for shared or dynamic IP addresses. Fingerprinting data is retained under the same rolling analytics-retention window described in Section 7 and is not used for cross-site advertising.

Do Not Track and Global Privacy Control. Some browsers offer a "Do Not Track" setting or, more recently, a Global Privacy Control (GPC) signal intended to communicate an opt-out preference to websites. Because there is no single, universally adopted technical standard for interpreting these signals across the web, our systems do not currently respond to a browser Do Not Track header as an automatic instruction; however, where applicable law treats a GPC signal as a valid method of exercising an opt-out-of-sale/sharing right, we honor a GPC signal we receive from your browser as such a request with respect to your browsing session, consistent with the CCPA provisions in Section 14.

Session versus persistent storage. Our authentication cookie is a session-scoped, httpOnly cookie carrying a signed token — it is not readable by page scripts, which reduces the risk of it being exfiltrated by malicious code, and it expires automatically after the validity period embedded in the token. Cart-contents storage persists briefly between visits so you do not lose items you have added, and is cleared upon successful checkout or after a reasonable period of inactivity.

6. Data Sharing

We share personal data only as described in this Section, and we do not sell your personal data to third parties for their own independent marketing purposes.

Payment processors. To capture Buyer payments, hold Escrow, and disburse Withdrawals to Artists, we share relevant transaction and payout data with our payment-processing and banking partners, who process it under their own regulatory obligations as payment institutions.

Carriers and print ateliers. For physical Orders, we (or the fulfilling Artist directly) share the Buyer's delivery address and Order details with the shipping carrier selected at checkout, and, where an Artist uses a third-party print atelier or framing service to produce the physical work, the Artist may share necessary production details with that provider; Artists are independently responsible for their own arrangements with such providers, consistent with our Terms of Service.

Service providers. We engage third-party service providers to help us operate the Platform — for example, cloud hosting, database and infrastructure providers, email-delivery services, identity-verification vendors supporting KYC, customer-support tooling, and, where used, the AI service providers supporting our draft-assist support feature described in Section 13. These providers act on our instructions under contractual confidentiality and data-protection obligations and may not use your data for their own independent purposes.

Legal and compliance disclosures. We may disclose personal data where required to comply with a valid legal process (such as a court order or subpoena), to comply with AML/KYC obligations to financial regulators, to enforce our Terms of Service, to protect the rights, property, or safety of Bello, our users, or the public, or in connection with a suspected fraud or security incident referred to law enforcement.

Business transfers. If Bello is involved in a merger, acquisition, financing, or sale of assets, personal data may be transferred as part of that transaction, subject to standard confidentiality arrangements and, where required by law, notice to affected users.

With your direction. Buyer and Artist identities are shared with each other only to the extent necessary to complete a transaction (for example, a delivery name and address shared with the fulfilling Artist, or an Artist's public profile visible to a Buyer); we do not share a Buyer's full payment-instrument details with an Artist, or an Artist's banking details with a Buyer, at any point.

Publicly visible data. Certain data is, by the nature of operating a public marketplace, visible to any Visitor browsing the Platform without needing an Account: an Artist's public profile (name, city, biography, portrait, since-year, and shipping timeline), their published listings and Collections, and their inclusion in a public Exhibition. Buyer identities are not made public in this way — a Buyer's name and address are visible only to the specific Artist fulfilling their specific Order, and to Bello's own systems and personnel as needed to operate the Platform.

No sale of personal data. We do not sell personal data to data brokers, and we do not license our user database to third parties for their own marketing use. Where we use the term "sale" in Section 14 in connection with the CCPA, we are describing that broader statutory definition, which can technically capture certain routine service-provider disclosures depending on contract terms; substantively, however, every disclosure we make is limited to the operational, compliance, and service-provider purposes described in this Section, not an open-market data sale.

Vendor due diligence. Before engaging a new service provider that will process personal data on our behalf, we assess its security practices and data-handling commitments and put a data-processing agreement in place that limits use of the data to the services it provides us, requires appropriate security measures, and requires it to assist us in responding to data-subject rights requests and to notify us promptly of any security incident affecting the data.

Categories of recipients, summarized. To make Section 6 easy to scan, the recipients we share personal data with fall into five general categories: (1) payment and financial infrastructure providers who process payments, hold Escrow, and disburse Withdrawals; (2) logistics providers — carriers and, where an Artist uses one, third-party print or framing ateliers — involved in fulfilling a physical Order; (3) technology and support-service providers, including hosting, database, email-delivery, identity-verification, customer-support, and AI draft-assist providers, who process data strictly on our instructions; (4) legal, regulatory, and law-enforcement recipients, where disclosure is required by law or necessary to protect the Platform or its users; and (5) a successor entity, in the limited circumstance of a corporate transaction described above. We do not add a new category of recipient to this list without updating this Policy first.

Minimizing what we share. Within each of the categories above, we aim to share only the specific fields a given recipient actually needs to perform its function — for example, a shipping carrier receives the delivery name, address, and package details necessary to ship an Order, not a Buyer's full transaction or Wallet history, and a print atelier engaged by an Artist receives only the production details necessary to produce the physical work, not the Buyer's payment information, which the atelier never has access to at all.

7. Data Retention

We retain personal data for as long as necessary to fulfill the purposes described in this Policy, taking into account the nature of the data and our legal obligations. As a general framework: Account data is retained for as long as your Account remains active and for a reasonable period after closure to handle any residual obligations (such as an outstanding Wallet balance or an open dispute); transaction, Wallet, and Withdrawal records are retained for the period required by applicable financial-recordkeeping and tax law, which in many jurisdictions is several years after the transaction date; KYC and payout-verification documents are retained for the period required by applicable AML law; chat and support correspondence is retained for a period sufficient to support quality review and to resolve any related follow-up, after which it may be deleted or anonymized; and visitor/device analytics data (session, IP, geolocation, fingerprint) is retained for a shorter, rolling period sufficient to support fraud-pattern detection, after which older records are purged or aggregated in a form that no longer identifies an individual device or session.

Where you exercise a deletion right described in Section 9, we will delete or anonymize data we are not otherwise legally required to retain, and will explain to you at the time of your request which categories, if any, must be retained and why.

Illustrative retention table. To make these general principles concrete, the following reflects our typical retention approach for the main data categories described in Section 2, though exact periods may vary based on the legal requirements applicable to your jurisdiction and the specific facts of your Account:

  • Account credentials and profile data: retained while the Account is active; deleted or anonymized within a reasonable period after a verified closure request, except for the minimum residual record needed to prevent re-registration by a user we have banned for cause.
  • Completed-transaction and commission/fee records: retained for the period required by applicable tax and financial-recordkeeping law, commonly several years from the transaction date, because these records are the basis for both parties' own tax obligations and for resolving any later-raised dispute or chargeback.
  • Wallet ledger entries: retained for as long as the corresponding Account exists, and thereafter for the same financial-recordkeeping period as transaction records, so that a closed Account's final balance and payout history remain reconstructable if a question arises later.
  • KYC/payout-verification documents: retained for the period required by applicable AML law in the relevant jurisdiction, which is often longer than general transaction retention because financial-crime regulators frequently mandate multi-year retention specifically for identity-verification records.
  • Dispute records and evidence: retained for a period sufficient to support a possible escalation or a related follow-up claim (for example, a delayed chargeback), then deleted or anonymized.
  • Chat and support correspondence: retained for a period sufficient for quality review and follow-up support, typically shorter than financial records, after which it is deleted or anonymized unless it forms part of a retained dispute record.
  • Visitor/device analytics (session, IP, fingerprint, geolocation): retained on a rolling, comparatively short window sufficient for fraud-pattern detection across sessions, after which individual records age out or are aggregated into a form that no longer identifies a specific device or session.
  • Commission (custom-work) requests: retained for as long as the request remains open or recently actioned, and for a further period afterward to support any resulting Order or dispute, then deleted or anonymized if the request never converts into a transaction.

Where retention periods differ because of a specific legal requirement in your country, that requirement controls over the general framework above, and you may ask us at any time, through the contact channel in Section 20, how long we expect to retain a specific category of your data.

8. International Data Transfers

Bello operates as a global marketplace, and the service providers described in Section 6 may process data in countries other than your own, including countries that may not have data-protection laws equivalent to those of your home jurisdiction. Where we transfer personal data internationally, we take steps designed to ensure it remains protected consistent with this Policy and applicable law — for example, relying on standard contractual clauses or an equivalent recognized transfer mechanism where required by the GDPR or similar frameworks, and requiring our service providers to maintain appropriate technical and organizational safeguards regardless of where they process data.

Why transfers happen on this Platform specifically. Because Bello connects Artists and Buyers across many countries, cross-border data flow is inherent to the service rather than an incidental byproduct: a Buyer in one country purchasing from an Artist in another necessarily involves sharing a delivery address across that border with the fulfilling Artist and the shipping carrier; a payment made in one currency and settled in another necessarily passes through payment-processing infrastructure that may be located in a third country; and our own cloud-hosting and service-provider infrastructure may be located in yet another country or countries, chosen for reliability, security, and performance reasons rather than to route around any particular jurisdiction's protections.

Your options if you are uncomfortable with a specific transfer. If a specific cross-border data flow is a concern for you — for example, you do not want your delivery address shared with a fulfillment partner located outside your country — your primary control is the transactional choice not to complete an Order requiring that flow (for instance, choosing a different Artist, or, where offered, a digital rather than physical edition of a work); the underlying data flow described above is generally a necessary feature of engaging in a specific cross-border transaction rather than an optional setting we can turn off for an individual Order while still fulfilling it.

Sub-processor list. We maintain an internal record of the service providers described in Section 6 and the general regions in which they process data; where applicable law entitles you to further detail about a specific transfer mechanism relevant to your own data, contact us at support@bello.art and we will provide what we are able to share consistent with our own confidentiality obligations to those providers.

9. Data Subject Rights

Depending on your jurisdiction, you may have some or all of the following rights with respect to your personal data: the right to access the personal data we hold about you and receive a copy of it; the right to correct inaccurate or incomplete data (for many Account and profile fields, you can do this directly through your Account settings); the right to delete your data, subject to our ability to retain what we are legally required to keep, such as completed-transaction and tax records, or what is necessary to resolve an open dispute or investigation; the right to portability, receiving certain data you provided to us in a structured, commonly used, machine-readable format, or having it transmitted to another provider where technically feasible; the right to object to processing based on legitimate interests, including profiling connected with fraud prevention, in which case we will weigh your objection against our own grounds unless the objection concerns direct marketing, which you can always opt out of unconditionally; and, where applicable, the right to restrict processing while a dispute about its accuracy or lawfulness is resolved, and the right to withdraw consent at any time for processing that relies on consent, without affecting the lawfulness of processing already carried out.

How to exercise these rights. Send a request to support@bello.art, or use the account-settings tools we provide for common requests such as data export or profile correction. To protect your data from unauthorized access, we will verify your identity before fulfilling a request — typically by confirming the request comes from the email address on your Account, and, for higher-risk requests such as full data export or deletion, by asking for additional verification. We aim to respond to a verified request within 30 days, or the timeframe required by applicable law if shorter; where a request is complex, we will tell you and provide a revised timeline. There is no fee for a standard request; we may charge a reasonable fee, or decline a request, if it is manifestly unfounded, excessive, or repetitive, as permitted by applicable law. If you disagree with our response, you have the right to lodge a complaint with your local data-protection authority, and, for EEA/UK residents, with the supervisory authority for the country in which you live or work.

What a deletion request actually does to an Artist Account. Because an Artist Account is tied to ongoing marketplace obligations — a Wallet balance, open Orders, Payout Method verification, and financial-recordkeeping requirements — a deletion request from an Artist with an active balance or open Order cannot be completed immediately in full; instead, we will first help you resolve outstanding Orders and Withdraw any available Wallet balance, and then delete or anonymize the profile and account data that is not subject to a specific retention requirement described in Section 7, explaining clearly which specific records (for example, completed-transaction history for tax purposes) must remain and for how long, in de-identified or access-restricted form wherever the underlying legal requirement allows that.

What a deletion request does to a Buyer Account. For a Buyer Account, deletion generally proceeds more quickly, since Buyer data is not subject to the same payout-related retention requirements, though completed-Order records tied to your purchases may still need to be retained on the same financial-recordkeeping basis described in Section 7, generally with your Account-level profile disconnected or anonymized from that retained transaction record where feasible.

Correcting inaccurate data. Many fields — your name, artist biography, city, and similar profile fields — can be corrected directly by editing your Account or artist-profile settings, taking effect immediately. For fields you cannot edit directly (for example, a fraud-review flag you believe was applied in error), contact support@bello.art with an explanation and any supporting evidence, and we will review and correct the record if your explanation is substantiated.

Requesting a copy of your data (portability). Where you request an export of the data you provided to us, we will provide the exportable categories — generally your Account profile, listing history (for Artists), Order history (for Buyers), and Wallet ledger (for Artists) — in a structured, commonly used format such as CSV or JSON. Categories that are not "provided by you" in the technical sense used by portability rules, such as fraud-review flags we derived internally, are addressed through the access right rather than the portability right, though we will still provide them to you as part of a general access request.

Objecting to specific processing. If you object to a specific processing activity relying on legitimate interests — for example, our use of device fingerprinting for fraud prevention — tell us which activity you are objecting to and why; we will consider your objection and either stop that specific processing with respect to you, or explain the compelling legitimate grounds that lead us to continue it (which, for core fraud-prevention signals underlying the integrity of an escrow-based marketplace, will often be the outcome, since disabling fraud detection for a single account on request would undermine the protection it provides to other users transacting with that account), consistent with how legitimate-interest objections are handled under the GDPR framework referenced in Section 15.

10. Children's Privacy

The Platform is not directed at children, and we do not knowingly collect personal data from anyone under 18 (or the age of majority in their jurisdiction, if higher), consistent with the eligibility requirement in our Terms of Service. If we become aware that we have collected personal data from a child in violation of this Policy, we will take steps to delete it promptly. If you believe a child has provided us with personal data, please contact us at support@bello.art so we can investigate and take appropriate action.

Why the age threshold exists here specifically. Beyond general good practice, the age threshold in this Policy reflects the nature of what an Account on Bello can do: an Artist Account holds a Wallet, requests Withdrawals of real money to a bank account, and enters into binding sale contracts with Buyers; a Buyer Account authorizes real payments and enters escrow-backed purchase obligations. These are not activities appropriate for a minor to undertake, which is why eligibility is gated at 18 (or the local age of majority) both in this Policy and in the Terms of Service, rather than offering a reduced-functionality account for younger users the way some consumer platforms do.

Parental inquiries. If a parent or guardian becomes aware that their child has created an Account or otherwise submitted personal data to the Platform, they may contact support@bello.art to request deletion of that data; we will process such a request under the same verification approach described in Section 9, adapted to confirm the requester's relationship to the child where necessary to protect the child's data from an unauthorized third party rather than an actual parent or guardian.

11. Security Measures

We maintain technical and organizational measures designed to protect personal data against unauthorized access, alteration, disclosure, or destruction, including encrypted transport (HTTPS) for data in transit, hashed storage of passwords, access controls limiting internal access to personal data to personnel who need it to perform their role, and separation of sensitive financial and identity-verification data from general application data. Payment-card data, where applicable, is handled by our PCI-compliant payment processor rather than stored directly on our own systems.

No system is perfectly secure, and we cannot guarantee absolute security of data transmitted to or stored on the Platform; you also play a role in protecting your own Account by using a strong, unique password and safeguarding your login credentials, consistent with the responsibilities described in our Terms of Service.

Layered controls. In addition to the measures above, we apply defense-in-depth principles across the Platform: parameterized database queries throughout our backend to prevent injection attacks against the data described in Section 2; role-based access controls that separate ordinary user functionality from administrative functionality, so that only Accounts we designate as administrators can access tools for reviewing disputes, approving Payout Methods, or moderating visitor and chat data; audit logging of sensitive administrative actions (such as approving a Withdrawal or resolving a dispute), so that we can reconstruct who took a given action and when; and regular review of our dependencies and infrastructure for known vulnerabilities.

Your account security responsibilities. Beyond choosing a strong password, we recommend you avoid reusing your Bello password on other sites, log out of shared or public devices after use, and promptly report to support@bello.art any Platform email, message, or request for information that seems suspicious or that does not match the patterns described in this Policy — for example, we will never ask you to disclose your full password to us over chat or email, and any message purporting to be from Bello that does so should be treated as a likely phishing attempt and reported.

Vendor security. Where a service provider described in Section 6 processes personal data on our behalf, our data-processing agreements with them require appropriate technical and organizational security measures proportionate to the sensitivity of the data involved, and, for our payment processor specifically, compliance with the Payment Card Industry Data Security Standard (PCI DSS) applicable to their role in the payment chain.

12. Breach Notification

If we become aware of a security incident that results in unauthorized access to, or disclosure of, your personal data in a manner that creates a meaningful risk to you, we will notify you and, where required by applicable law, the relevant regulator, without undue delay and consistent with the timelines that law prescribes (for example, the GDPR's 72-hour regulatory-notification framework, where applicable). Notification to you will describe, to the extent known at the time, the nature of the incident, the categories of data involved, and the steps we are taking and recommend you take in response.

What triggers notification. Not every security event rises to the level requiring notification under this Section — for example, a blocked intrusion attempt that never resulted in unauthorized access does not create the meaningful risk this Section addresses. We assess each incident based on the sensitivity of the data potentially exposed (a breach touching KYC or Payout Method data would be treated with the highest urgency, given its financial and identity-fraud implications, while a breach limited to, say, aggregated and de-identified analytics would not typically warrant individual notification because no individual is identifiable from it), the number of people affected, and whether the exposure creates a realistic risk of harm such as identity theft, financial loss, or account takeover.

Our internal response process. When a suspected incident is identified, we work to contain it, assess its scope, and remediate the underlying vulnerability as a first priority, in parallel with preparing the notifications described above; where the incident involves a third-party service provider described in Section 6, our data-processing agreements with them require prompt notification to us so we can meet our own notification obligations to you and to regulators.

What you should do if notified. If we notify you of an incident, follow the specific guidance in that notification, which may include resetting your password, reviewing recent Account and Order activity for anything unfamiliar, and, where the incident potentially exposed Payout Method or KYC data, monitoring for signs of identity misuse and contacting the relevant financial institution if appropriate.

13. AI Draft-Assist Feature and Support Conversations

Our support chat includes an AI-assisted draft feature, which our support staff may use to help compose faster, more consistent first-response replies to common questions, and which may, in some configurations, respond directly to a Visitor or user before a human reviews the exchange. When you chat with us, your messages may be processed by this AI system, whether hosted by us or by a third-party AI service provider under contract, to generate a suggested or automatic reply; message content is not used by that AI provider to train models available to other, unrelated customers of that provider, under the terms of our agreement with them, and is retained by us only as part of the standard chat-record retention described in Section 7.

Where an AI-generated response is provided without prior human review, our systems are designed to make that clear to you in the conversation, and you may always request to speak with a human member of our support team instead. We use the AI draft-assist feature to improve response speed and consistency for routine questions (for example, questions already answered in our knowledge base about escrow, shipping, or disputes); it is not used to make binding determinations about your Account, an Order, or a dispute outcome — those decisions are made or approved by a human member of our team, consistent with the automated-decision-making commitment in Section 3.

How the feature draws on your data. To generate a useful draft or automatic reply, the AI system is given the text of the current conversation and, where relevant to answering the question accurately, limited contextual information about the underlying Order, listing, or Account status necessary to answer accurately (for example, an Order's current status, so the system can tell a Buyer their Order has shipped rather than giving a generic answer). The system is not given blanket access to your full Account or transaction history beyond what is relevant to the conversation at hand, and it does not have the ability to take account-changing actions (such as approving a refund or a Withdrawal) on its own; any action beyond providing information requires a human team member to execute it through the administrative tools described in Section 11.

Retention of AI-processed conversations. Chat conversations that pass through the draft-assist feature are retained under the same chat-and-support retention approach described in Section 7, regardless of whether a given message was drafted by a human, generated automatically by the AI system, or some combination of both; we do not apply a separate, longer retention period simply because a message passed through the AI system.

Provider relationship. Where we use a third-party AI service provider to power this feature, our agreement with that provider restricts their use of the conversation content to providing the service to us — generating a response — and prohibits them from using your conversation content to train models made available to their other customers. If we ever change this arrangement in a way that would alter how your chat data is used by an AI provider, we will update this Section and provide notice consistent with Section 16.

Choosing not to use the AI feature. If you would prefer not to have your support conversation processed by the AI draft-assist system at all, tell the support team at the start of your conversation (for example, by typing "please connect me with a human") and we will route your conversation to be handled by a human team member without AI-generated drafting, where staffing allows; during off-hours, an AI-generated first response may still be provided to avoid leaving you without any reply, but it will be clearly labeled and followed up by a human at the next opportunity.

14. California Privacy Rights (CCPA/CPRA)

If you are a California resident, the California Consumer Privacy Act, as amended by the California Privacy Rights Act (together, "CCPA"), gives you specific rights in addition to those described in Section 9, including the right to know the categories and specific pieces of personal information we have collected about you, the categories of sources from which it was collected, the business or commercial purpose for collecting it, and the categories of third parties with whom it is shared; the right to delete personal information we collected from you, subject to the same statutory exceptions described in Section 9; the right to correct inaccurate personal information; the right to opt out of the "sale" or "sharing" of personal information (as those terms are defined under the CCPA) — we do not sell personal information for money, and we do not "share" it for cross-context behavioral advertising as we do not currently operate third-party interest-based advertising; the right to limit the use of "sensitive personal information," to the extent we process any category the CCPA defines as sensitive, such as precise geolocation derived from IP address for fraud-prevention purposes, which we use only for that limited security purpose rather than for profiling or advertising; and the right not to receive discriminatory treatment for exercising any of these rights. To exercise a CCPA right, contact us at support@bello.art; we will verify your identity using the same process described in Section 9 before fulfilling the request.

Categories of personal information under the CCPA framework. Mapped to the CCPA's own category definitions, the data described in Section 2 falls into the following categories, to the extent applicable to you: identifiers (name, email, Account identifier, IP address); customer records information (payment-related transaction records, to the extent held by us rather than solely by our payment processor); commercial information (purchase and sale history, Wallet ledger); internet or other electronic network activity (chat logs, session and device data, pages visited); geolocation data (IP-derived, city-level, as described in Section 2); professional or employment-related information (for Artists, portfolio and practice information submitted in the application process); and, where applicable, sensitive personal information as defined by the CPRA, limited to precise-enough geolocation for fraud-prevention purposes and, for Artists undergoing KYC verification, government-issued identification numbers. We do not collect or infer categories the CCPA treats as sensitive beyond what is described here, such as racial or ethnic origin, religious beliefs, health information, or biometric identification (our device "fingerprint," despite the name, is a browser/device-configuration hash, not a biometric measurement of your physical person, and is not biometric information under the CCPA's definition).

Sources of personal information. Consistent with Section 2, we collect personal information directly from you (registration, listing, checkout, chat, and support interactions), automatically through your use of the Platform (device and session data), and from limited third-party sources described above (payment processors, shipping carriers).

Business and commercial purposes for collection. We collect and use personal information for the business and commercial purposes described in Section 3 of this Policy — operating the marketplace, providing customer support, verifying identity for compliance purposes, preventing fraud, and improving the Platform — which map to the CCPA's enumerated business purposes including performing services, security, and debugging.

Twelve-month lookback. Upon a verified request, we will provide the specific pieces and categories of personal information collected about you, disclosed to third parties, and, where applicable, the categories of third parties involved, for the 12-month period preceding your request, or a longer period where our records reasonably allow and you request it.

Authorized agents. You may designate an authorized agent to submit a CCPA request on your behalf; we will require proof of the agent's authority to act for you and may still require you to verify your own identity directly with us as an additional safeguard, consistent with CCPA regulations permitting this verification step.

Financial incentive disclosure. We do not currently offer a financial incentive, discount, or other benefit in exchange for the collection, sale, or retention of personal information, so there is no financial-incentive program to disclose under this Section; if that changes, we will describe the material terms of any such program here before offering it.

15. GDPR and UK Data Protection Rights

If you are located in the European Economic Area, the United Kingdom, or another jurisdiction with an equivalent data-protection framework, the rights described in Section 9 (access, correction, deletion, portability, objection, restriction, and consent withdrawal) are provided consistent with the requirements of the GDPR or the equivalent UK framework, and the legal bases described in Section 4 apply to processing carried out in reliance on that framework. You have the right to lodge a complaint with your national or regional supervisory authority if you believe our processing of your personal data does not comply with applicable law, though we would appreciate the opportunity to address your concern directly first at support@bello.art.

Where we rely on legitimate interests as a legal basis, we have conducted a balancing assessment weighing our interest (typically fraud prevention, security, or service improvement) against your rights and reasonable expectations, and you may request further information about that assessment, or object to the processing, as described in Section 9.

Data controller contact and, where applicable, EU/UK representative. For the purposes of the GDPR and the equivalent UK framework, our contact details are provided in Section 20. Where we are required by applicable law to appoint a representative in the EEA or the UK because we are established outside those regions, we will identify that representative here and keep this Section updated; until such an appointment is required and made, you may direct any GDPR or UK-framework inquiry to us directly at the contact details in Section 20.

Special category data. We do not intentionally collect what the GDPR defines as "special category" data (such as data revealing racial or ethnic origin, religious belief, health data, or sexual orientation) as part of operating the Platform, and we ask that you not include such data in fields not designed to collect it — for example, an artist biography or a chat message — beyond what you choose to voluntarily disclose about yourself in describing your own artistic practice, which remains your choice and is not something we request or require.

Profiling. The fraud-prevention signals described in Section 2 (VPN-mismatch flag, device fingerprinting) constitute a limited form of profiling under the GDPR's definition, in that they evaluate certain personal aspects of your online activity to assess risk. As explained in Section 3, this profiling informs but does not solely determine an enforcement outcome — a human reviews the underlying evidence before an Account is suspended or a Withdrawal declined on this basis — and you have the right to obtain human intervention, express your point of view, and contest a decision that was based on this kind of automated signal, through the contact channel in Section 9.

International transfers under the GDPR specifically. Where personal data governed by the GDPR or the equivalent UK framework is transferred to a country that the European Commission (or, for the UK framework, the UK government) has not recognized as providing an adequate level of protection, we rely on an appropriate safeguard recognized under Article 46 of the GDPR (or its UK equivalent) — most commonly the European Commission's Standard Contractual Clauses, supplemented where necessary by additional technical and organizational measures — to ensure the transfer is lawful, consistent with the general approach described in Section 8.

Right to lodge a complaint. As noted above, you have the right to complain to your supervisory authority. For residents of the European Economic Area, this is generally the data-protection authority of the EU or EEA member state in which you live, work, or where the alleged infringement occurred; for UK residents, this is the Information Commissioner's Office (ICO). We would, however, welcome the opportunity to resolve your concern directly first — most concerns can be addressed more quickly through direct contact with our support team than through a formal regulatory complaint, though you are never required to contact us first before exercising your right to complain to a regulator.

16. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our data practices, the Platform's functionality, or legal requirements. When we make a material change, we will update the "Last updated" date at the top of this document and, where the change is significant — for example, a new category of data collected or a new purpose for sharing it — provide additional notice, such as an email to registered users or a prominent notice on the Platform, before the change takes effect. We encourage you to review this Policy periodically.

17. Third-Party Links and Embedded Content

The Platform may contain links to third-party websites — for example, an Artist's own external portfolio site linked from their public profile, or a payment processor's own hosted checkout page for certain payment methods — and may embed limited third-party content such as maps or, where used, analytics scripts described in Section 5. When you follow a link away from the Platform, or interact with third-party content embedded within it, you become subject to that third party's own privacy practices, which we do not control and this Policy does not cover. We encourage you to review the privacy policy of any third-party site or service before providing it with personal data.

Where a listing or artist profile links to an external site the Artist controls (for example, a personal website or a social-media profile), that link is provided by the Artist as part of their own listing content, and we are not responsible for the privacy or content practices of that external destination; if you believe an Artist-provided external link is being used to circumvent the Platform's protections (for instance, to solicit an off-Platform payment in violation of our Terms of Service), please report it to support@bello.art.

18. How This Policy Interacts With Our Terms of Service

This Privacy Policy and our Terms of Service work together and should be read as a whole. Several of the practices described in this Policy exist specifically to support marketplace mechanics defined in the Terms — for example, the Escrow-related transaction data described in Section 2 exists because the Terms define how a purchase moves through pending, in-production, shipped, delivered, and released stages; the KYC and Payout Method verification data described in Sections 2 and 6 exists because the Terms condition Withdrawal eligibility on approved verification and impose the AML rule that deposited funds are not withdrawable; and the dispute-evidence data described in Section 2 exists because the Terms establish an administrator-mediated dispute-resolution process for Orders. Where this Policy describes why we collect or retain a category of data, the corresponding provision of the Terms is usually the more detailed explanation of the underlying business rule; where the two documents appear to describe the same topic from different angles, they are intended to be consistent, and if you notice an apparent conflict, please point it out to us at support@bello.art so we can clarify or correct it.

Nothing in this Policy is intended to expand the scope of data we are permitted to collect or use beyond what is reasonably necessary to operate the Services described in the Terms, and nothing in the Terms is intended to override the rights and protections described in this Policy.

19. Roles: What Changes for Buyers, Artists, and Visitors

Because this Policy applies broadly across very different kinds of Platform use, it can help to summarize what is distinctive about each role's data footprint.

If you are only a Visitor (you have never registered an Account), the data we hold about you is generally limited to the visitor-analytics record described in Section 2 — session, IP-derived geolocation, device fingerprint, user-agent, and any chat conversation you initiate — used for the security, fraud-prevention, and support purposes described in Sections 3 and 13. You do not have a Wallet, a listing history, or an Order history, because those require an Account.

If you are a Buyer, we additionally hold your Account and profile data, your cart and Order history, any Commission requests you submit, and any dispute you open or are party to, used to operate checkout, Escrow, delivery confirmation, and dispute resolution as described in the Terms of Service and summarized in Section 18 above.

If you are an Artist, we additionally hold your artist-application data, public artist-profile data, listing data for every Artwork you publish, your Wallet ledger, your Payout Method and any associated KYC verification data, and your dispute and fulfillment history, used to operate the selling side of the marketplace, compute commission and Withdrawals, and support the tier and approval mechanics described in the Terms of Service.

If you are both (many users are both Buyers and Artists on the same Account), the data described above for each role is held together under your single Account, and the access, correction, and deletion rights described in Section 9 apply to the whole of it, subject to the same retention exceptions described in Section 7 for whichever category of record is at issue.

20. Contact Information

If you have questions about this Privacy Policy, want to exercise a data-subject right described in Section 9, or have a concern about how we handle your personal data, contact us at:

  • Email: support@bello.art
  • Support chat: available via the chat widget on any page of the Platform

We aim to respond to privacy inquiries within 30 days, or sooner where required by applicable law.

Postal correspondence. Where a request or notice must be sent by postal mail rather than email under applicable law, we will provide a mailing address on request at support@bello.art, or, where we publish one directly on the Platform's legal-notices page, that published address controls.

Escalation within our organization. If your initial inquiry to support@bello.art does not resolve your concern, you may ask that it be escalated to the team member responsible for privacy compliance; we will identify the appropriate person and loop them into the conversation. We take privacy inquiries seriously and would much rather resolve a misunderstanding or a legitimate concern directly than have it become a regulatory complaint or a dispute, though, as noted in Section 15, you are never required to exhaust our internal process before contacting a regulator if you believe that is the more appropriate path for your situation.

Keeping this Policy accessible. This Policy is published on the Platform at a stable, linkable location, and we keep prior versions available on request so that you can review what a previous version said if you interacted with the Platform before a change described in Section 16 took effect. If you have difficulty accessing this Policy in a format that works for you — for example, because of an accessibility need — contact us at support@bello.art and we will provide it in an alternative format.

Thank you for taking the time to read this Policy. We know that privacy documents are rarely anyone's favorite reading, but because Bello handles real money, escrowed funds, and personal identity information as part of operating an honest marketplace between artists and collectors, we think it is worth being thorough and specific about exactly what we do with your data, rather than relying on vague boilerplate that would not actually tell you anything useful about how this particular Platform works.