Privacy Policy
Last updated: 11 July 2026
This policy explains how Wendr handles personal data when you use our shop-management service (the “Service”). We've written it in plain English. It is designed to meet the UK GDPR and the Data Protection Act 2018.
We look after the account details of shop owners and managers who sign up, and we keep the Service running and secure. When you enter information about your staff, we hold it on your behalf — you decide how it's used.
We don't sell your data, we don't use it to train AI models, and we only share it with a short list of trusted suppliers needed to run the Service. You can ask for a copy of your data, or to correct or delete it, any time at privacy@wendr.co.uk.
This summary is for convenience only — the full sections below are what actually apply.
Who we are
The Service is provided by [REGISTERED COMPANY NAME], a company registered in England & Wales (company number [COMPANY NUMBER]), registered office [REGISTERED OFFICE ADDRESS] (“Wendr”, “we”, “us”). We are registered with the Information Commissioner's Office (ICO) under reference [ICO REGISTRATION NUMBER].
For any privacy question, or to exercise your rights, contact us at privacy@wendr.co.uk. We aim to reply within a few working days and, for formal requests, within one month as the law requires.
Controller vs processor — an important distinction
Wendr is the data controller for the account information of the shop owner and managers who sign up (for example, your name, email and login details), and for how we run and secure the Service.
When a shop owner enters information about their staff (such as names, dates of birth, pay rates, hours, time-off and documents), Wendr acts as a data processoron the shop's behalf — the shop is the controller of that staff data. If you run a shop on Wendr, you are responsible for having a lawful basis to enter your staff's data, and a separate Data Processing Agreement governs how we process it for you.
What data we collect
- Account data: your name, email, phone, role and password (stored only as a secure one-way hash — we never store it in readable form).
- Shop data: shop name, address, postcode, Shop ID and settings, including the shop location if you turn on clock-in-near-the-shop.
- Staff data you enter: employee names, contact details, dates of birth, pay and contract details, shifts, time-off, payroll figures, and documents or photos you upload (e.g. right-to-work, till receipts).
- Operational data: messages, checklists, incidents, stock and sales records you create in the app.
- Technical data: basic logs needed to run and secure the Service (e.g. timestamps, device/session information and error reports).
How and why we use it (lawful basis)
- To provide the Service you signed up for — basis: performance of a contract.
- To keep the Service secure and working (logins, fraud/abuse prevention, error monitoring) — basis: our legitimate interests.
- To take payment for subscriptions — basis: performance of a contract.
- To contact you about your account and important service notices — basis: performance of a contract / legitimate interests.
- To meet legal obligations (e.g. tax and accounting records) — basis: legal obligation.
We do not sell your data, and we do not use your shop or staff data to train AI models.
Automated decisions and marketing
We do not make decisions about you that produce legal or similarly significant effects based solely on automated processing (no automated profiling of you or your staff). Any AI assistance in the app supports you — it doesn't decide anything about you on its own.
We only email you about your account and important service notices. We don't send marketing emails unless you've asked to receive them, and where you have, you can unsubscribe at any time.
Who we share data with
We use a small number of trusted suppliers (“sub-processors”) to run the Service. They only process data on our instructions:
- Render — application and database hosting.
- Vercel — hosting of the web app.
- Resend — sending account and notification emails.
- Stripe — subscription payments (Stripe handles card details; we never see or store full card numbers).
- Anthropic — powering optional in-app AI assistance, where you choose to use it.
- Sentry — error monitoring, where enabled.
We may also disclose data where we're legally required to (for example, to respond to a valid request from a public authority), or to protect our rights, users or the security of the Service. If Wendr is ever involved in a business sale or reorganisation, data may transfer to the new owner under the same protections.
Sending data outside the UK
Some of these providers may process data outside the UK/EEA. Where they do, the transfer is protected by appropriate safeguards such as the UK International Data Transfer Agreement, or the Addendum to the EU Standard Contractual Clauses, so your data keeps an equivalent level of protection. You can ask us for more detail about these safeguards at privacy@wendr.co.uk.
How long we keep it
We keep personal data only as long as needed to provide the Service and to meet legal obligations:
- Account and shop data — for as long as your account is open. If you close your account, we delete or anonymise it within 90 days, unless the law requires us to keep specific records for longer.
- Payroll, tax and accounting records — kept for at least the period UK law requires (generally up to 6 years) even after your account closes.
- Backups — deleted data may persist in secure backups for a short period before those backups are cycled out.
- Technical logs — kept only as long as needed to run and secure the Service, then deleted.
How we protect it
- Passwords are stored only as secure one-way hashes.
- Data is sent over encrypted connections (HTTPS).
- Access is restricted by role, and each shop's data is kept separate from every other shop's.
- We keep our systems patched and monitor for errors and unusual activity.
Your rights
You have the right to:
- access a copy of your personal data;
- have inaccurate data corrected;
- have your data erased, where the law allows;
- restrict or object to certain processing;
- data portability; and
- withdraw consent where we rely on it.
To exercise any of these, email privacy@wendr.co.uk — it's free, and we won't treat you differently for asking. You can also download a copy of your data yourself at any time from Settings → Export my data. If your request concerns staff data held on behalf of a shop, we may direct you to that shop as the controller.
Cookies and local storage
Wendr uses only the storage strictly necessary to keep you signed in and to run the app. We do not use advertising or third-party tracking cookies, so there's no tracking-consent banner to click through.
Complaints
If you're unhappy with how we've handled your data, please tell us first so we can put it right. You also have the right to complain to the ICO at ico.org.uk, or by calling their helpline.
Changes to this policy
We may update this policy from time to time. We'll change the “last updated” date above and, for significant changes, let you know in the app or by email.