Privacy Policy
How we collect, use, protect and delete information.
Last updated: August 11, 2026
1. Controller and scope
This service is provided by Isa Pankei Group, SRL through its Simple Solutions business solutions division. Isa Pankei Group is the data controller for the personal data described in this policy.
This policy applies to the Simple Restaurant website, the administration portal, the WhatsApp Business integrations and the related menu analysis and loyalty program services. It follows Dominican Republic Law 172-13 on Personal Data Protection.
2. Information we collect
2.1 Account and business data
- Name, email, phone number and role of the business's authorized users.
- Trade name, legal name, locations, opening hours and operational settings.
- Billing details and subscribed plan.
2.2 WhatsApp Business data authorized by the business
- WhatsApp Business account (WABA) and phone number identifiers.
- Verified name, connection status, number quality rating and message templates.
- Access credentials, stored encrypted.
2.3 Conversations and orders
- End customer phone number and name, as shared when writing to the business.
- Message content, attachments and timestamps.
- Order items, amounts, delivery address, payment method and status.
2.4 Operational and menu data
- Product catalog, prices, costs and inventory uploaded by the business.
- Sales history and aggregate metrics used for menu analysis.
- Points, visits and rewards from loyalty programs.
2.5 Technical data
- IP address, browser and device type, pages visited.
- Access logs, message delivery events, errors and request identifiers.
- Cookies and similar technologies (see our Cookies Policy).
3. How we use information
- Provide the service: authenticate users, isolate each business's data, connect WhatsApp Business, deliver messages and process orders.
- Menu analysis: compute costs, margins and recommendations from the data the business provides us.
- Loyalty programs: record visits, accrue rewards and run campaigns authorized by the business.
- Support and security: handle incidents, prevent abuse and keep the service available.
- Legal compliance: meet tax, accounting and regulatory obligations.
Legal basis: data subject consent, performance of the contract with the business customer, legitimate interest in service security, and compliance with legal obligations.
4. Meta platform data
We use data obtained from Meta only to provide the contracted services, including identifying the connected business account, displaying and managing customer conversations, sending and receiving messages and notifications, and following up on customer interactions.
Each business must explicitly authorize the connection with Meta. Messages are processed on the business's instruction and to serve conversations initiated or authorized by its customers. We do not use this data for our own advertising, nor do we sell it to third parties.
5. Who we share information with
We do not sell personal information. We may share it with:
- Meta / WhatsApp: to deliver and receive the messages authorized by the business.
- Infrastructure providers: hosting, database, transactional email and analytics, under confidentiality and security commitments.
- Certified payment processors: when the business enables online payments.
- Competent authorities: where a legal obligation or valid request exists.
Some providers may process information in the United States or other jurisdictions, under their contractual and security measures.
6. Retention
We retain information while the account remains active or while it is needed to provide the service, resolve disputes and comply with legal obligations. Financial records are kept for the period required by tax regulation. Once those periods expire, we securely delete or anonymize the data.
7. Security
- Encryption in transit (TLS) and encrypted credentials at rest.
- Per-business data isolation and role-based access control.
- Audit logs for access and sensitive actions.
- Periodic security reviews and incident management.
More detail in our Security Policies.
8. Your rights
- Access: request a copy of your personal information.
- Correction: fix inaccurate or outdated data.
- Deletion: request erasure of your data.
- Objection: object to certain processing.
- Portability: receive your data in a structured format.
To exercise them, write to hola@waffledo.com or follow our data deletion instructions. If you are an end customer of a restaurant using our platform, contact that business first: it decides about its own data and we act as processor.
9. Children
Simple Restaurant is a business service and is not directed to children under 13. We do not knowingly collect information from minors. If you believe we have received a minor's data, contact us so we can delete it.
10. Changes to this policy
We may update this policy from time to time. We will post the new version on this page and update the "Last updated" date. Material changes are notified to business customers by email.
11. Contact
For privacy inquiries write to hola@waffledo.com with the subject "Simple Restaurant Privacy", or use the contact details at the bottom of this page.
Contact Information
- Legal entity:
- Isa Pankei Group, SRL
- RNC:
- 131998151
- Email:
- hola@waffledo.com
- Phone / WhatsApp:
- 1 809-752-0045
- Address:
- Máximo Avilés Blonda 13, 102, Plaza Las Lilas, Ens. Julieta, D.N., Santo Domingo, República Dominicana
- Support hours:
- Monday to Friday, 9:00 AM - 6:00 PM (GMT-4)