WaitraWaitra

Privacy Policy

Last updated: 11 July 2026

This Privacy Policy explains how Waitra ("Waitra", "we", "us") collects, uses, and protects personal data when you use our website at getwaitra.com and our AI virtual-waiter service (the "Service"). We are based in Spain and comply with the EU General Data Protection Regulation (GDPR) and Spanish data-protection law. If you have any questions, contact us at hello@getwaitra.com.

1. Who this policy covers

This policy covers two groups:

  • Restaurant owners who create an account to run an AI waiter.
  • Diners who scan a restaurant's QR code and chat with the AI waiter.

2. Data we collect

From restaurant owners: your name, email address, password (stored encrypted), your restaurant details (name, address, cuisine, branding, and the menu/knowledge documents you upload), and subscription status. Payment card details are handled directly by Stripe — we never see or store your full card number.

From diners: the messages you send to the AI waiter during a chat session. Chat sessions are not linked to your identity — we do not ask diners for names, emails, or accounts. We store anonymous conversation logs so restaurant owners can see what customers ask and improve their menu.

Automatically: basic technical data such as your browser language (used to show the site in your language) and standard server logs.

3. How we use your data

  • To provide and operate the Service (create your AI waiter, generate QR codes, answer diner questions).
  • To process your subscription and payments.
  • To send you essential account and billing emails.
  • To improve and secure the Service.

4. Legal basis (GDPR)

We process personal data on the basis of: performance of a contract (to deliver the Service you signed up for), legitimate interests (to secure and improve the Service), and legal obligation (e.g. tax and accounting records).

5. Service providers (processors)

We share data only with trusted providers who help us run the Service, under data-processing agreements:

  • Supabase — database, authentication, and file storage.
  • Stripe — payment processing and billing.
  • OpenAI — powers the AI waiter's responses (diner messages are sent to OpenAI to generate replies).
  • Vercel — website and application hosting.
  • Google — optional "Sign in with Google" authentication.

We do not sell your personal data to anyone.

6. International transfers

Some of our providers are based outside the European Economic Area (for example, in the United States). Where data is transferred internationally, it is protected by appropriate safeguards such as the EU Standard Contractual Clauses.

7. Data retention

We keep account and restaurant data for as long as your account is active. If you cancel and close your account, we delete or anonymise your personal data within a reasonable period, except where we must retain records to meet legal obligations (e.g. invoices).

8. Your rights

Under the GDPR you have the right to access, correct, delete, restrict, or object to the processing of your personal data, and to data portability. To exercise any of these, email hello@getwaitra.com. You also have the right to lodge a complaint with the Spanish Data Protection Agency (Agencia Española de Protección de Datos, aepd.es).

9. Cookies

We use only essential cookies required to keep you signed in and to run the Service securely. We do not use advertising or third-party tracking cookies.

10. Children

The Service is intended for restaurant businesses and is not directed at children. We do not knowingly collect personal data from children.

11. Changes to this policy

We may update this policy from time to time. We will post the updated version here and change the "Last updated" date above.

12. Contact

Questions about this policy or your data? Email hello@getwaitra.com.

This English version is the reference version of this policy.