Privacy Policy
Effective date: 27 April 2026
This policy explains what personal information Walu ("we", "us") collects when you use our service, why we collect it, who we share it with, and the rights you have under UK data protection law (the UK GDPR and the Data Protection Act 2018).
Walu is the data controller for the personal information described here. If you have any questions, email [email protected].
1. What information we collect
Information about your business
To build your website, we use information that is publicly available on your Google Business Profile: business name, address, phone number, opening hours, services, photos, and customer reviews. In some cases this includes the first names of reviewers as displayed publicly on Google.
We also use any additional information you give us — for example, by email, WhatsApp, or a signup form — such as your name, the email and phone number you contact us from, and any photos or copy you ask us to publish.
Payment information
Card payments are handled by Stripe. We never see or store your full card number, expiry, or security code. We do receive limited information from Stripe to administer your subscription: cardholder name, billing postcode, last four digits of your card, expiry month/year, transaction amounts, and the status of each charge.
Communication with us
When you email us or message us on WhatsApp, we keep those messages so we can respond and look back at the history of your account.
Server logs
Our hosting provider keeps standard request logs (IP address, request URL, user-agent, timestamp) for short periods to operate the service securely. We do not use these logs for advertising or behavioural analytics.
2. Why we collect it
- To provide the service — building, hosting, and maintaining your website and email.
- To bill you — process your subscription payment via Stripe.
- To support you — answer questions, make edits you've asked for, and resolve problems.
- To comply with the law — for example, keeping records required by HMRC for tax purposes.
We do not use your information for marketing partners, behavioural advertising, or to train machine-learning models that go to anyone outside Walu.
3. Lawful bases (UK GDPR)
- Performance of a contract — to deliver the service you've subscribed to.
- Legitimate interests — to keep our platform secure, prevent abuse, and run our business.
- Legal obligations — to keep accounting and tax records.
- Consent — where we ask for it explicitly (for example, before publishing a testimonial you've sent us).
4. How long we keep it
- While your subscription is active: we keep your account and website data for as long as you remain a customer.
- After cancellation: we keep a backup of your site and email mailboxes for 30 days, then permanently delete them.
- Billing records: we are required to keep records of payments and invoices for at least 6 years for tax purposes.
- Support messages: we keep email and WhatsApp threads for up to 24 months after our last contact with you.
5. Who we share it with
We use a small number of trusted third-party services to run Walu. We share with each of them only the data they need to do their job:
- Stripe — payments. Stripe's privacy notice.
- Cloudflare — DNS and content delivery (your visitors' requests pass through Cloudflare's network).
- Our hosting provider — UK / EU-based dedicated hosting where your website and email run.
- Domain registrar — to register and renew your
.co.ukdomain.
We do not sell or rent your information to anyone. We do not share it with marketing networks. If we are ever required by law (court order, lawful request from authorities) to disclose information, we will only disclose what is strictly required.
6. Where your information is processed
Walu is a UK business and our main hosting is in the UK. Some of our service providers (e.g. Stripe, Cloudflare) operate internationally. Where data is transferred outside the UK / EEA, those providers rely on appropriate safeguards such as the UK International Data Transfer Agreement or equivalent standard contractual clauses.
7. Your rights
Under UK GDPR you have the right to:
- Access the personal information we hold about you;
- Have inaccurate information corrected;
- Have your information deleted (subject to legal retention requirements such as accounting records);
- Restrict or object to certain processing;
- Receive your information in a portable format;
- Withdraw consent where we rely on it.
To exercise any of these rights, email [email protected]. We aim to respond within one calendar month.
If you're not satisfied with how we've handled your information, you have the right to complain to the UK Information Commissioner's Office (ICO) at ico.org.uk.
8. Cookies
The Walu marketing site (walu.net) uses no analytics cookies and no advertising cookies. We may set a strictly necessary session cookie on a future customer login area, but only at the point you sign in. Customer-facing websites we build do not include analytics or tracking by default; if a customer asks us to add a privacy-friendly tool such as Plausible, we'll publish a corresponding cookie note on their site.
9. Children
Walu is a B2B service. We don't knowingly collect personal information from anyone under 18. If you believe a child's information has reached us by mistake, contact us and we'll delete it.
10. Changes to this policy
We may update this Privacy Policy from time to time. The latest version will always be at this URL with an updated effective date. Material changes will be communicated by email to active customers.
11. Contact
For data protection requests or any privacy questions: [email protected].
Walu — operated by [TBD: company name, registered address, company number]. These details will be added before launch and will appear here as the registered data controller.