Skip to content
Wafflio
How it worksFeaturesPricingFAQ
Get early access
Legal

Privacy policy

Last updated: 25 September 2026

Wafflio is a mobile app for restaurant owners. It turns your photos and videos into social media content, helps you plan when to post it, and can publish it to the social accounts you connect.

This policy explains what we collect, why, and who else sees it. If anything here is unclear, email privacy@wafflio.com.

Wafflio is operated by [COMPANY NAME], [ADDRESS]. We are the data controller for the information described below.

What we collect

Your account

Your email address, and a password that we never see in readable form — it is hashed before it is stored. When you log in we also email you a one-time code. If you sign in with Google, we receive your email address and basic profile details from Google instead.

Your restaurant

The name, address, cuisine type, brand colour, brand line and logo you enter, how customers can reach you (phone, website, booking and order links), and the quiet trading times you select.

Connected social accounts

If you connect Instagram or a Facebook Page, we store the account name, its ID and an access token that lets Wafflio publish the posts you confirm. Tokens are kept on our servers only, never in the app, and are deleted when you disconnect or delete your account. We do not read your messages, followers or other people’s content.

What you create

Photos and videos you upload, the descriptions and briefs you write, the captions generated for you, the music you choose, the finished images and videos, and their scheduling and publishing details.

Sales figures you choose to enter

If you use the sales features, the amounts, dates and item names you type in or import. This is entirely optional and the app works without it.

Technical data

Your device’s push notification token (only if you allow notifications), crash reports, and standard server logs including IP address, kept for security and debugging.

We do not collect your location, your contacts, your customers’ personal details, or any payment card numbers.

Why we use it

  • To run your account and keep it secure
  • To generate captions, images and videos you ask for
  • To publish the posts you confirm to the accounts you connected
  • To show your scheduled posts and your own past work
  • To notify you when something you made is ready, posted, or needs attention
  • To send account emails such as sign-up, login and password reset codes
  • To take payment for a subscription
  • To find and fix faults, and to prevent abuse

Our lawful bases under UK GDPR are performance of a contract, legitimate interests, and consent where you have given it, such as for push notifications and connecting social accounts.

We do not sell your data. We do not use it to train AI models, and the providers below are used under terms that do not permit training on your content.

Who we share it with

ProviderWhat it handlesWhere
SupabaseYour account, restaurant data and uploaded mediaLondon, UK
ResendAccount emails, including sign-up, login and password reset codesIreland
AnthropicGenerates caption and on-video wording from your briefUSA
OpenAIGenerates images from your descriptionUSA
RailwayRenders your videos and postersEU
Meta (Instagram, Facebook)Publishes the posts you confirm to the accounts you connectUSA / EU
JamendoProvides the licensed music tracks you chooseLuxembourg
StripeSubscription paymentsUK / EU
Expo and Google FirebaseDeliver push notifications to your phoneUSA
SentryCrash reports that help us fix faults (no restaurant content)USA / EU
GoogleSign-in, only if you choose itUSA

Transfers outside the UK are covered by the UK International Data Transfer Addendum or equivalent safeguards.

We may also disclose information if the law requires it, or to protect our rights or someone’s safety.

Payments

Subscriptions are handled by Stripe. Your card details go directly to Stripe and never reach us or our servers. We store only your subscription status and the Stripe identifiers needed to manage it.

How long we keep it

We keep your data for as long as your account is open. When you delete your account we cancel your subscription and remove your restaurant details, uploaded media, generated content, connected-account tokens and scheduling data. Posts already published on Instagram or Facebook stay there until you delete them in those apps. Server logs and records we must keep for tax or legal reasons are retained for up to seven years.

Your rights

Under UK GDPR you can ask us to:

  • give you a copy of your data
  • correct anything that is wrong
  • delete your account and its data — you can do this yourself in the app (see how)
  • restrict or object to how we use it
  • send your data to another provider

Email privacy@wafflio.com and we will respond within one month. If you are unhappy with our response you can complain to the Information Commissioner’s Office at ico.org.uk.

Security

Data is encrypted in transit and at rest. Access to your restaurant’s records is enforced at the database level, so one restaurant cannot read another’s data. Logins need your password and a one-time email code. Administrative actions on the platform are logged.

No system is perfectly secure, and we cannot guarantee absolute security.

Children

Wafflio is for businesses and is not intended for anyone under 18. We do not knowingly collect data from children.

Changes

If we change this policy we will update the date above and, for significant changes, tell you in the app or by email.

Contact

privacy@wafflio.com

Wafflio

Marketing that fills tables, made for independent restaurants.

Product

  • How it works
  • Features
  • Pricing
  • FAQ

Company

  • support@wafflio.com
  • Privacy policy
  • Terms of service
  • Delete your data
© 2026 Wafflio. All rights reserved.Founded by Eldhose Johny · Made in the UK for restaurants everywhere.