1. Introduction
سلینو (Selinoo) is committed to protecting the privacy of users, business owners, and website visitors in accordance with the laws of the Islamic Republic of Iran, including the E-Commerce Law and related personal data protection regulations.
This policy explains how personal information is processed across selinoo.com, the mobile application, management panels, and related services. Use of the services indicates awareness of this policy; if you do not agree, please do not use the services.
2. Data Controller and Processing Details
The controller responsible for collecting and processing personal data under this policy is:
- Owner: محمد حسین محمودخواه شالمائی
- Ownership Type: شخصی
- Manager: محمد حسین محمودخواه شالمائی
- National ID: 0370167211
- Address: خراسان رضوی, مشهد, بلوار امیریه، نبش امیریه ۲۲، پلاک ۲, Postal Code 9186441102
- Landline: 05199942198 | Mobile: +37477755970
- General Email: [email protected]
- Privacy Email: [email protected]
- Website: https://selinoo.com
3. Definitions
- Personal Data: any information directly or indirectly related to an identified or identifiable natural person.
- User: any person who creates an account or uses Selino services.
- Business Owner: a user who sets up a business profile, services, appointments, or a dedicated website.
- Visitor/End Customer: a person who submits a booking or contact request through a business website or online channel.
- Processing: any operation on personal data, including collection, storage, use, transfer, or deletion.
4. Data We Collect
Depending on how you use the services, we may process the following categories of data:
- Identity and contact data: first name, last name, phone number, email, language, and country.
- Authentication data: Google/Firebase account identifier and profile image (if provided by the sign-in provider).
- Business data: business name, activity category, address, geolocation, working hours, services, staff, and summarized financial information.
- Business customer data: names, phone numbers, and notes recorded by business owners in CRM.
- Booking data: date, time, service, staff member, notes, and booking status.
- Communications: in-app support messages and Telegram/online requests (if related modules are enabled).
- Technical and security data: IP address, device type, operating system, app version, error logs, and security events.
- Cookies and browser identifiers: for site functionality, security, and traffic analytics (details in the Cookies section).
5. Processing Purposes and Legal Basis
Personal data is processed only for the following legitimate purposes:
The legal basis for processing includes contract performance (Terms of Use), explicit user consent (where required, such as certain marketing communications), and the controller's legitimate interests in maintaining system security.
- Providing, operating, and improving booking, dedicated website, CRM, and business management tools.
- Authentication, account security, and abuse prevention.
- User support and response to requests.
- Sending booking-related notifications and SMS messages in accordance with user settings and applicable law.
- Compliance with legal obligations, protection of user rights, and dispute handling.
- Anonymous or aggregated statistical analysis to improve service quality.
6. Collection Methods
- Information you provide directly through the app, website, or support channels.
- Information received from authentication providers (such as Google), based on permissions you grant.
- Technical information automatically recorded when visiting the website or using the API.
- Information business owners record about their own customers; in such cases, the business owner is responsible for obtaining legally required customer consent, and Selino acts as a technical processor.
8. Data Security
Although we apply reasonable technical and organizational measures, no system is absolutely secure. If a data breach occurs that may affect your rights, we will act in accordance with law and provide notice where required.
- Data transmission through encrypted protocols (HTTPS/TLS).
- Role-based access controls and authentication for sensitive areas.
- Business data segregation (multi-tenancy) and restricted internal access.
- Periodic backups and recovery procedures.
- Security event monitoring and software updates.
9. Retention and Deletion
- Account data is retained while the account is active and for a reasonable period after a deletion request, unless longer retention is required by law.
- Booking and summarized financial records are retained according to operational, accounting, and tax requirements.
- Security logs are retained for a limited period proportional to security investigation needs.
- After retention periods expire, data is deleted or anonymized.
10. User Rights
You may submit the following requests regarding your personal data via [email protected] or in-app support:
Requests are handled within a reasonable timeframe (typically no more than 30 business days). Additional information may be requested to verify the requester's identity.
- Access a copy of retained personal data.
- Correct inaccurate or incomplete information.
- Delete data where legally permitted (right to erasure within regulatory limits).
- Restrict or object to processing in specific cases.
- Receive data in a portable format, where technically feasible.
- Withdraw consent for consent-based processing, without affecting prior lawful processing.
12. Children
Selino services are designed for businesses and are not intended to knowingly collect data from children under 18. If unintended collection is identified, the relevant data will be deleted.
13. International Data Transfers
Some infrastructure (such as Firebase/Google) may be hosted outside Iran. In such cases, appropriate contractual and technical safeguards are applied to protect data. By using the services, you acknowledge this possibility.
14. Changes to This Policy
This policy may be updated. The new version will be published on this page with date "۱۴۰۵/۰۳/۱۸". Material changes will be announced through the website or in-app notifications. Continued use after publication of the new version constitutes acceptance of the changes.
15. Contact and Complaints
For questions, data access/deletion requests, or privacy incident reports, contact [email protected].
If you are not satisfied with our response, you may escalate the matter to competent legal authorities or the Electronic Commerce Development Center (for businesses with the relevant trust symbol).