Sellly

Security at Sellly

Updated: 28 September 2026

How we protect stores and their customers

More detail: Annex 2 of the Data Processing Addendum.

Reporting a vulnerability

If you think you've found a security problem in Sellly, please tell us at [email protected]. Include what you found, how to reproduce it, and what an attacker could do with it.

Please: test only against your own account and store; don't access, change or delete other people's data (stop and tell us if you reach any); don't degrade the service (no load or denial-of-service testing); don't use social engineering or physical attacks; and give us 90 days to fix before telling others.

If you follow these rules in good faith, we won't pursue legal action against you for your research, and we'll say so if anyone asks.

Out of scope: reports from automated scanners without a demonstrated impact, missing best-practice headers without an exploit, rate limits on non-sensitive pages, and issues in Meta's, Razorpay's or other providers' own services (report those to them).

Our machine-readable contact is at /.well-known/security.txt.