Privacy
Privacy notice
Last updated 21 July 2026
Wavro holds data about the people who run a business and about the people who work shifts in it. This notice explains what we hold, why, who else touches it, and how to get it changed or removed. It is written for UK GDPR and the Data Protection Act 2018.
1. Two different roles
We are the controller for the people who deal with us directly: account owners and managers, people who email us, and visitors to this website. We decide what to collect and why.
We are a processor for staff data. When a cafe adds its team to Wavro, that employer decides what goes in and why - they are the controller. We only act on their instructions, as set out in our data processing agreement. If you are a member of staff and want your record changed or removed, ask your employer first; we will point you back to them.
2. What we hold
- Account - name, email address, password hash or Google sign-in, profile photo, company name, address, timezone.
- Staff records - name, email, phone, date of birth, start date, pay rates or salary, contract type, holiday balance, and whether the person is active or archived.
- Working data - shifts, availability and time-off requests, swap requests, clock-in and clock-out times, breaks, timesheets and approvals.
- Location - only if the employer switches on the clock-in geofence. Then a coarse coordinate is stored with the clock event to show whether the person was near the venue. It is not continuous tracking: nothing is recorded between clock-ins.
- Billing - company billing details, subscription status and seat count. Card numbers go to Stripe and never reach our servers.
- Technical - sign-in session, device push subscription if notifications were enabled, and error reports when something breaks.
3. Why, and on what basis
- To provide the service you signed up for - performance of our contract with you.
- To bill you, chase unpaid invoices and meet accounting duties - contract and legal obligation.
- To keep accounts secure, prevent abuse, and fix faults - our legitimate interest in a service that works.
- To email you about releases and service changes - legitimate interest, with an unsubscribe in every message.
- Staff data is processed on the employer instructions; the lawful basis for it is theirs to determine, normally the employment contract or their legitimate interest.
We do not sell personal data, we do not use it to train models, and we do not run advertising or profiling on it.
4. Who else sees it
Only the suppliers we need to run the product - hosting, database, payments, email, error monitoring. They act on our instructions and are listed, with what each one receives and where, in the sub-processor table of our data processing agreement. We also disclose data where the law requires it, and to a buyer if the business is ever sold - in which case this notice follows the data.
5. Where it is held
Wavro is built for UK teams, but our database and several of our suppliers are hosted in the United States. Where personal data is transferred there we rely on the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, together with the supplier own safeguards. The sub-processor table shows the location of each one.
6. How long we keep it
- While your subscription is live, we keep everything in the account - rotas, clock records and timesheets stay accurate because your payroll and any employment dispute may depend on them.
- Staff who leave are archived rather than deleted, so past rotas and timesheets still add up. The employer chooses when to purge them.
- After you cancel, the account is kept for 90 days so you can come back or export, then deleted.
- Billing records are kept for 6 years to satisfy HMRC.
- Error reports are kept for 90 days.
Employers should bear in mind that UK working time records normally need to be kept for 2 years and payroll records for 3 years. You control that retention; we act on your instruction.
7. Security
Traffic is encrypted in transit and data is encrypted at rest by our hosting and database providers. Passwords are hashed, never stored in the clear. Access to production data is limited to the people who need it. Every query is scoped to a single company, so one customer account cannot read another.
If a breach affects your data we will tell you without undue delay and, where required, notify the ICO within 72 hours.
8. Your rights
You can ask for a copy of your data, ask us to correct or delete it, object to or restrict what we do with it, and ask for it in a portable format. Email hello@wavroapp.com and we will respond within one month.
If you are unhappy with how we handled it, you can complain to the Information Commissioner’s Office at ico.org.uk.
10. Changes and contact
If we change this notice we will update the date at the top, and we will email account owners about anything significant. Questions go to hello@wavroapp.com, or by post to Wavro Technologies Ltd, Ground Floor, Blenheim Tower, Batavia Road, London SE14 6AX, United Kingdom.