Privacy Policy
Last updated: 4 August 2026
This policy explains how Wendr handles personal data when you use our shop-management service (the “Service”). We’ve written it in plain English. It is designed to meet the UK GDPR and the Data Protection Act 2018.
We look after the account details of shop owners and managers who sign up, and we keep the Service running and secure. When you enter information about your staff, we hold it on your behalf — you decide how it’s used.
Two things worth knowing up front: where a shop turns them on, clocking in can record where the person is standing and take an optional photograph of them; and recording someone as off sick is health information, which the law protects more strictly. Both are explained below.
We don’t sell your data, we don’t use it to train AI models, and we only share it with a short list of trusted suppliers needed to run the Service. You can ask for a copy of your data, or to correct or delete it, any time at privacy@wendr.co.uk.
This summary is for convenience only — the full sections below are what actually apply.
Who we are
The Service is provided by Premak Services Ltd, a company registered in England & Wales (company number 16865244), registered office 61 Bridge Street, Kington, HR5 3DJ, United Kingdom, trading as “Wendr” (“Wendr”, “we”, “us”). We are registered with the Information Commissioner’s Office (ICO) as a data controller, registration reference ZC210479. You can check that entry yourself on the ICO’s public register.
For any privacy question, or to exercise your rights, contact us at privacy@wendr.co.uk. We aim to reply within a few working days and, for formal requests, within one month as the law requires.
Controller vs processor — an important distinction
Wendr is the data controller for the account information of the shop owner and managers who sign up (for example, your name, email and login details), and for how we run and secure the Service.
When a shop owner enters information about their staff (such as names, dates of birth, pay rates, hours, time-off and documents), Wendr acts as a data processor on the shop’s behalf — the shop is the controller of that staff data. If you run a shop on Wendr, you are responsible for having a lawful basis to enter your staff’s data, and a separate Data Processing Agreement governs how we process it for you.
What data we collect
- Account data: your name, email, phone, role and password (stored only as a secure one-way hash — we never store it in readable form).
- Shop data: shop name, address, postcode, Shop ID and settings, including the shop location if you turn on clock-in-near-the-shop.
- Staff data you enter: employee names, contact details, dates of birth, National Insurance numbers, bank details for paying wages, pay and contract details, shifts, time-off, payroll figures, and documents or photos you upload (e.g. right-to-work documents, which may include passports, visas or biometric residence permits and Home Office share codes).
- Clock-in records: when each person started and finished, and — where the shop uses these features — the location of the person clocking in and a photograph taken at that moment. See Clocking in: location and photographs below.
- Time off, including sickness: the dates, the type of absence (holiday, sick or other) and any note added. See Health information below.
- Operational data: messages, checklists, incidents, stock and sales records you create in the app. Incident and compliance records are free text and may name or describe people.
- Technical data: basic logs needed to run and secure the Service (e.g. timestamps, device/session information and error reports).
Clocking in: location and photographs
Two clock-in features involve personal data about the member of staff themselves, so we describe them separately and plainly.
- Location. If a shop owner sets their shop’s location, the app checks where the person clocking in is standing and will refuse the clock-in if they are further away than the distance the owner has set. The location at clock-in is stored on that clock-in record. If the owner has not set a shop location, no check is made. Location is not tracked between clock-ins, and never while someone is off shift — it is read at the moment of clocking in and at no other time.
- Photograph. When clocking in, the app offers to take a photograph of the person. It is optional — you can clock in without one. Where taken, it is stored encrypted against that clock-in record. It is used only so the owner can see that the right person clocked in. We do not use facial recognition, and we do not compare these photographs against each other or against anything else.
Both are a form of monitoring at work. If you are a shop owner using them, you are the controller of that data: you should tell your staff you have turned them on and why, and be able to explain why it is necessary. If you are a member of staff and you want to know what is held about you, ask your employer first, or contact us at privacy@wendr.co.uk and we will point you to the right place.
If a member of staff leaves and their data is erased, the clock-in photograph and the location are deleted, while the hours worked stay, because those are a payroll record we are required to keep.
Health information, including sick leave
Recording that someone was off sick is information about their health. Under the UK GDPR this is special category data, which gets extra protection.
Wendr holds this because shops must record absence to pay people correctly and to meet employment law duties. Where Wendr is the controller, our condition for processing it is employment, social security and social protection law (Article 9(2)(b) of the UK GDPR, with Schedule 1 of the Data Protection Act 2018). Where a shop owner enters it, the shop is the controller and needs its own condition — which will normally be the same one.
The app asks only for the type of absence, not a diagnosis. There is an optional notes box. If you are a shop owner, please do not record medical detail you do not need — a note saying someone is off sick is enough for the rota and the payroll, and the less health detail written down, the better for everyone.
Staff under 18
Shop staff can lawfully be under 18, and Wendr is designed for that. We store each person’s date of birth and use it to apply the right National Minimum Wage band, which is different for under-18s and apprentices. Wendr is not a service aimed at children and we do not knowingly collect data about anyone under 16.
If you employ someone under 18, you remain responsible for the extra duties that come with that — working-hours limits for young workers, and the rules about who may sell alcohol and when. Wendr does not enforce those rules for you and does not warn you about them. We would rather say that plainly than let you assume the app is checking something it is not.
How and why we use it (lawful basis)
- To provide the Service you signed up for — basis: performance of a contract.
- To keep the Service secure and working (logins, fraud/abuse prevention, error monitoring) — basis: our legitimate interests.
- To take payment for subscriptions — basis: performance of a contract.
- To contact you about your account and important service notices — basis: performance of a contract / legitimate interests.
- To meet legal obligations (e.g. tax and accounting records) — basis: legal obligation.
We do not sell your data, and we do not use your shop or staff data to train AI models.
Automated decisions and marketing
We do not profile you or your staff, and we do not make decisions about people that produce legal effects based solely on automated processing. Any AI assistance in the app supports you — it doesn’t decide anything about you on its own.
One thing the app does decide on its own, and we would rather name it than let it hide under the sentence above: where a shop has set its location, the clock-in check described earlier will refuse a clock-in automaticallyif the person is too far from the shop, with no human involved at that moment. It can always be put right by a person — a manager or owner can add or correct the hours by hand, and every such change is recorded. If this happens to you, ask your manager to add the hours.
We only email you about your account and important service notices. We don’t send marketing emails unless you’ve asked to receive them, and where you have, you can unsubscribe at any time.
When Wendr staff can see a shop’s account
Sometimes the only way to sort out a problem is to look at the account it is happening on. So Wendr staff can open a customer’s account and see it as the owner sees it, including staff personal details. We would rather tell you this than have you find out some other way.
What we have built around it:
- It is limited to named Wendr staff — not something any employee can do.
- It is read-only. Nothing can be changed, added or deleted while viewing a customer’s account; the app refuses those actions outright.
- Each session is short-lived and records which member of Wendr staff opened it.
- Every occasion is written down, and you can see the list. It is included in your data export, in a section called “Every time someone at Wendr acted on your account, and who”. An export that hid this would be an export that flattered us.
Who we share data with
We use a small number of trusted suppliers (“sub-processors”) to run the Service. They only process data on our instructions:
- Render — application and database hosting.
- Vercel — hosting of the web app.
- Resend — sending account and notification emails.
- Stripe — subscription payments (Stripe handles card details; we never see or store full card numbers).
- Anthropic — powering optional in-app AI assistance, where you choose to use it.
- Google (Firebase Cloud Messaging) — delivering push notifications to the mobile app, where you turn them on.
- Sentry — error monitoring, where enabled.
We may also disclose data where we’re legally required to (for example, to respond to a valid request from a public authority), or to protect our rights, users or the security of the Service. If Wendr is ever involved in a business sale or reorganisation, data may transfer to the new owner under the same protections.
Sending data outside the UK
Some of these providers may process data outside the UK/EEA. Where they do, the transfer is protected by appropriate safeguards such as the UK International Data Transfer Agreement, or the Addendum to the EU Standard Contractual Clauses, so your data keeps an equivalent level of protection. You can ask us for more detail about these safeguards at privacy@wendr.co.uk.
How long we keep it
We keep personal data only as long as needed to provide the Service and to meet legal obligations:
- Account and shop data — for as long as your account is open. If you close your account, we delete or anonymise it within 90 days, unless the law requires us to keep specific records for longer.
- Payroll, tax and accounting records — kept for at least the period UK law requires (generally up to 6 years) even after your account closes.
- Backups — deleted data may persist in secure backups for a short period before those backups are cycled out.
- Technical logs — kept only as long as needed to run and secure the Service, then deleted.
How we protect it
- Passwords are stored only as secure one-way hashes.
- Data is sent over encrypted connections (HTTPS).
- Access is restricted by role, and each shop’s data is kept separate from every other shop’s.
- We keep our systems patched and monitor for errors and unusual activity.
Your rights
You have the right to:
- access a copy of your personal data;
- have inaccurate data corrected;
- have your data erased, where the law allows;
- restrict or object to certain processing;
- data portability; and
- withdraw consent where we rely on it.
To exercise any of these, email privacy@wendr.co.uk — it’s free, and we won’t treat you differently for asking. You can also download a copy of your data yourself at any time from Settings → Export my data, without asking us first. If you own a shop, Settings → Export all my shop’s data gives you everything Wendr holds for that shop — as a page you can open on your phone, or as a data file for an accountant or another system. If your request concerns staff data held on behalf of a shop, we may direct you to that shop as the controller.
Deleting your account. If you can sign in, Settings → Close account does it immediately, and tells you first exactly what goes and what we must keep. If you can’t sign in — you’ve left the shop, or you only want part of your information removed — ask us at wendr.co.uk/delete-account. No account is needed to use that page.
Cookies and local storage
Wendr uses only the storage strictly necessary to keep you signed in and to run the app. We do not use advertising or third-party tracking cookies, so there’s no tracking-consent banner to click through.
Complaints
If you think we’ve mishandled your personal information, you can complain to us. You don’t need an account, and you don’t need to be a customer — anyone whose data we hold can complain.
The quickest way is our complaint form at wendr.co.uk/complaint. You can also email privacy@wendr.co.uk, or write to us at Premak Services Ltd, 61 Bridge Street, Kington, HR5 3DJ. Any of these counts as a complaint — you don’t have to use the form.
What happens next: we will acknowledge your complaint within 30 days (in practice you’ll get an email with a reference straight away), look into it without undue delay, and tell you the outcome. If your complaint is about staff data we hold on behalf of a shop, that shop is the controller — we will still help, and we’ll tell you honestly which decisions are theirs rather than ours.
You do not have to come to us first. You can complain to the Information Commissioner’s Office at any time — before, during or after we look at it — at ico.org.uk/make-a-complaint or on their helpline, 0303 123 1113.
Changes to this policy
We may update this policy from time to time. We’ll change the “last updated” date above and, for significant changes, let you know in the app or by email.