Members!

Effective date:

Privacy Policy

Your studio's working records are stored on its iPhone or iPad. Features such as studio sign-in, subscriptions, Wallet cards and connected payments send the information needed to provide those services. This policy explains those differences and how to contact us.

1. Who is responsible

Members! is provided by WaiterOne SL, Calle Las Pitas 6, 129B, 35100 San Agustín, Spain. Contact support@waiterone.net about privacy or write to this address.

WaiterOne SL is responsible for the personal information it uses to operate studio accounts, subscriptions, security and support. Your studio decides which member information to collect and how to use it for its membership business. When the studio uses our hosted Wallet service, we process the supplied member information to provide that service on the studio's instructions. Contact your studio first about its member records, attendance, payments or membership decisions.

This policy covers the Members! app, its website and the connected services described here when you use them. Available features depend on your app version and the services your studio enables. The online class-booking portal is not part of the current public release; we will update this policy before making that service available.

2. Records on the studio's device

The app stores member names, contact details, notes, photos, member codes, memberships and balances, classes, bookings, attendance, teacher and room information, and payment amounts, status and references entered by the studio. These working records are held on the studio's iPhone or iPad. They are not all uploaded to us simply because the app is installed. The connected features below send their specified information separately.

The camera is used for QR check-in and photographs when staff choose those features. Staff may also select images from Photos or Files. Camera permissions can be managed in the device's settings. The studio is responsible for appropriate notices and permissions for the people whose information and photographs it records.

3. Studio accounts and subscriptions

Studio subscription sign-in uses Sign in with Apple. The subscription flow does not request your name or email address. Our licensing service verifies Apple's identity information and uses an identifier derived from it, a studio identifier and protected sign-in sessions to recognize your account and prevent unauthorized use. Wallet staff sign-in is a separate service with its own studio and staff records and sessions.

Apple handles payment for a Members! subscription. Our licensing service verifies signed purchase information and keeps transaction identifiers and their association with the studio to grant access, restore purchases and prevent the same purchase being assigned to another studio. It does not receive your payment-card number. The app keeps sign-in credentials and verified access information in protected device storage.

See Sign in with Apple and Privacy and Apple's Privacy Policy.

4. Apple Wallet, Google Wallet and card emails

When a studio enables Wallet synchronization, it sends our Wallet server the member's name, member code and identifiers, secure check-in QR credential, active status, membership names and terms, validity dates, remaining sessions and access times. It also sends the studio name, reply-to email, time zone and selected artwork. If the member has a profile photo, the app sends a small rendered copy to our Wallet server, rather than the original photo file. The card service retains this information to issue and update cards.

An Apple Wallet card can include that rendered member photo. For updates, our service stores card registrations, a hashed device-library identifier and a push token. These allow it to notify Apple Wallet when the studio has synchronized a change.

When you tap Add to Google Wallet, our service sends Google the member name and code, secure check-in QR credential, studio and membership names, card identifiers, balance or access type, dates, status and selected studio or plan artwork to prepare the Google card. This happens before Google's final save confirmation. The automatic Google card does not include the member profile-photo field, although selected artwork may itself contain an image supplied by the studio. Later synchronized changes update the Google card record, including when the initial save was not completed or the card was later removed from Wallet. Google handles its copy under Google's Privacy Policy.

When staff request a Wallet email, our mail service processes the recipient address, membership-card message and attachments. Delivery records include status and an address hash used for duplicate prevention and delivery controls. Email passes through our mail server and the recipient's email provider. A card's private invitation link is intended for its recipient; its expiry limits use of the link, not how long every related record is kept. Treat invitation links and check-in QR codes as private.

5. Connected payments, printers and backups

If the studio connects SumUp for card-terminal payments, Members! sends the amount, currency, reference and payment description. For a membership purchase, that description includes the membership name and member's name. Members! stores the resulting payment status and transaction reference for reconciliation, not payment-card details. SumUp processes payment, merchant and device information under its own terms and privacy notice. Its integrated SDK declares account and contact information, device and user identifiers, payment information, precise location and product interaction for app functionality. See SumUp's Privacy Policy.

Printing sends the selected card content to the chosen printer. Members! disables the Star printer SDK's diagnostic-information upload before discovery and printing. Staff control the printers and other devices they connect.

Reports and workspace backups can contain member information, photos, secure check-in credentials and payment references. Members! workspace backup files do not include Keychain sign-in credentials and are not encrypted by Members!. Staff choose where to save or share them and must keep them private. File-storage, sharing and device-backup providers handle those copies under their own terms. Restoring a subscription restores access; it does not restore the studio's local records.

6. Why information is used

We use studio-account and purchase information to provide the service requested under our contract, including sign-in, subscription access, restoration and support. We use necessary security and diagnostic information for our legitimate interests in protecting accounts, preventing misuse and keeping the service reliable. Information may also be kept or disclosed where needed to comply with applicable legal obligations or handle legal claims. Where a particular use relies on consent, that consent may be withdrawn without affecting processing that was lawful before withdrawal.

When you visit our website or use an online service, the server receives connection and request information such as your IP address, request time, requested address, response status and browser information. Operational logs are used for security and troubleshooting. The public information pages do not use advertising or analytics cookies.

The studio determines the purposes and lawful basis for its own member records, including any information about children or sensitive matters. It should only enter information it needs and is entitled to process. Your studio sets membership terms and decides who may join. Members! checks the recorded membership terms when staff use check-in.

The Members! app has no advertising-network integration. Transactional membership-card delivery is separate from the private marketing system.

7. Service providers and international processing

Information is available to the studio's authorized staff and to people authorized to operate and support the relevant Members! service. Recipients also include the providers needed for the chosen feature: IONOS for hosting, Apple for sign-in, subscriptions and Apple Wallet, Google for Google Wallet, SumUp for connected payments, the recipient's email provider, and printers or export destinations chosen by staff.

Our Members! server is hosted by IONOS in Spain. Wallet email is sent through our own mail service on that server. This does not mean that all processing stays in Spain: Apple, Google, SumUp and destinations selected by users may process information in other countries. Their linked privacy notices explain their locations and transfer arrangements. Contact us for information about the providers and safeguards applicable to a specific Members! service or transfer.

We do not make studio member records publicly searchable. A person who receives a private card or invitation can nevertheless share it, and exported or printed copies are controlled by their recipients.

8. How long information is kept

Local records remain on the studio's device until the studio removes them. Signing out, ending a subscription or removing a Wallet card does not automatically erase the local workspace or our hosted card records. Separately exported files and backups remain in their chosen locations until removed there.

Hosted studio, membership-card and registration information is retained to provide the enabled service and handle valid correction or deletion requests. Account sessions and invitation links have validity limits, but reaching those limits is not itself deletion of all associated database records. Contact the studio or us to request erasure rather than relying on a link, session or membership expiry.

After a subscription account is deleted, limited purchase-ownership and deletion-retry records may remain where needed to reconcile the original purchase, prevent reassignment to another studio, complete a requested deletion or meet applicable legal obligations and claims. A pending Apple authorization revocation can require temporary encrypted token retention until that operation is completed. The relevant retention criteria are those purposes and the records needed for the individual request; ending a subscription does not erase all purchase history.

Operational logs, mail delivery records, support correspondence and recovery copies have separate retention according to their security, troubleshooting, delivery and recovery purpose. Routine web-server logs use daily rotation with 14 rotated files; system and mail logs use weekly rotation with four rotated files. Rotation is not a deletion schedule for application records, mailboxes or backup copies. Contact us for the information held about you and its applicable retention criteria.

9. Your choices, requests and rights

Contact your studio to access or correct its member records or request deletion. Contact support@waiterone.net about your Members! studio account, information controlled by WaiterOne SL, or help directing a request. We may need information sufficient to verify your identity and authority without collecting more than necessary.

Depending on the applicable law and circumstances, you can request access, correction, erasure, restriction, objection and data portability, and withdraw consent where processing relies on it. You may complain to the Spanish Data Protection Agency (AEPD) or your competent supervisory authority. These rights are subject to applicable conditions, including obligations to keep particular records.

Use the account-deletion control where your app version provides it, or contact us about the appropriate account and hosted data. Subscription and Wallet accounts are separate: deleting one does not automatically erase the other or the local studio workspace. Revoking Sign in with Apple authorization may require fresh sign-in for other Members! features. Contact us to request deletion of Wallet service data.

Manage or cancel Apple subscriptions through Apple's subscription settings. Deleting an account or uninstalling Members! does not cancel Apple billing. Removing a card from Apple Wallet or Google Wallet does not cancel the underlying studio membership or request deletion of every provider's records. Contact your studio about that membership and use the Wallet provider's controls for its copy.

10. Security, changes and contact

Members! uses HTTPS for its account, licensing and Wallet connections and protected device storage for sign-in credentials. Access to hosted operations is restricted to authorized operators. Studios must also protect their devices, account access, printed cards and exported files. No storage or transmission method can eliminate every risk.

This policy's effective date appears at the top. We update it when the described services or practices change. Please review it when enabling a new connected feature. Privacy questions and requests can be sent to support@waiterone.net, or by post to WaiterOne SL, Calle Las Pitas 6, 129B, 35100 San Agustín, Spain.