Privacy Policy
Last updated: 24 September 2026
This Privacy Policy explains how Fullstack3 LTD ("Fullstack3", "WAMA", "we", "us", or "our") collects, uses, shares, and protects personal data when you use WAMA products and services.
We process personal data in accordance with the UK General Data Protection Regulation (UK GDPR), the EU General Data Protection Regulation (EU GDPR) where applicable, and other applicable privacy laws.
1. Who we are
Controller: Fullstack3 LTD (trading as WAMA), company number 10486539
Registered office: 20-22 Wenlock Road, London, England, N1 7GU (virtual registered office; we do not currently operate a separate physical trading office)
Privacy contact: [email protected]
For questions about this policy or to exercise your rights, contact us at the email above. You may also use our contact page.
2. Services covered
This policy applies to:
- Our marketing website at www.wama.cloud
- The WAMA web application (warehouse management SaaS)
- The WAMA Android app (Google Play, package
com.fullstack3.wama) - The WAMA iOS app (Apple App Store, bundle ID
com.fullstack3.wama) - Optional ecommerce / shop features (merchant storefronts such as
*.wama.app) operated for a Point of Sale - Related APIs, transactional emails, and push notifications
Together, these are the "Service".
3. Our roles: controller and processor
We are the data controller when we decide how and why to process personal data about:
- Account holders and users of WAMA (registration, login, profile, support)
- Billing and subscription administration
- Marketing communications (where you have opted in)
- Website and shop analytics (where used)
- App diagnostics, performance, and crash reporting needed to operate and secure the Service
We act as a data processor when business customers (merchants) store personal data about their own customers, suppliers, loyalty members, or other contacts in WAMA (for example names, addresses, phone numbers, email addresses, dates of birth, tax identifiers, order history). In that case the merchant is the controller of that data and is responsible for having a lawful basis to collect and use it. We process that data only to provide the Service on the merchant's instructions.
Business customers may request our Data Processing Agreement (DPA) by emailing [email protected]. Where a DPA is signed, it governs our processing of merchant customer personal data as processor, together with this Privacy Policy and our Terms.
4. Categories of personal data we process
Account and profile data
- Email address, first name, last name
- Password (stored as a secure hash; we do not store plain-text passwords)
- Language preference, profile photo (if provided)
- Newsletter / marketing opt-in status
Billing and subscription data
- Subscription plan, billing status, and related account identifiers
- Payment processor customer / payment-method identifiers (for example Stripe customer IDs)
- We do not store full card numbers (PANs); card payments are handled by payment providers
Device, usage, and diagnostics
- IP address, browser type, device type, approximate location derived from IP where relevant for security
- Pages or screens visited, app version, feature-usage events, and similar usage data
- Crash logs and diagnostic data (including via Firebase Crashlytics)
- On Android: Firebase Analytics events, Firebase Performance data, and Firebase Remote Config parameters used to operate and improve the app
- Push notification tokens (APNs / Firebase Cloud Messaging)
- On mobile: device identifiers used for app functionality, push delivery, and crash/analytics association (not for advertising tracking on iOS)
Content you upload
- Product photos and images
- Signatures captured for stock transfers (where used)
- In-app feedback (message, rating, app version)
Business / tenant data (processor role)
Depending on how merchants use WAMA, this may include:
- Customer and supplier contact details (name, email, phone, postal address, tax ID)
- Date of birth (for example for loyalty or age-related business rules)
- Loyalty card numbers and points
- Sale and purchase orders, invoices, and related commercial records
- Warehouse location details, including optional coordinates entered manually (not continuous GPS tracking by the apps)
- Shop customer accounts authenticated via Firebase where the ecommerce module is enabled
- On Android only: contact details a user chooses to import from the device address book into a customer record (name, phone, email, postal address fields selected by the user). We do not upload or sync the full device address book.
5. How we collect data
- Directly from you — registration, profile, support, contact forms, feedback
- Automatically — cookies and similar technologies on the marketing website and shop storefronts; app and server logs; crash reporting; analytics SDKs; push token registration
- From merchants — data they enter or import about their customers and operations
- From the device (Android) — fields the user explicitly selects when importing a contact into WAMA
- From service providers — for example payment status from Stripe, authentication events from Firebase for shop customers
6. Purposes and lawful bases
| Purpose | Examples | Lawful basis |
|---|---|---|
| Provide the Service | Account creation, authentication, warehouse features, syncing data across web and mobile | Contract (Art. 6(1)(b)) |
| Billing and subscriptions | Charging plans via Stripe on the website; invoices; plan limits | Contract; legal obligation for tax/accounting records |
| Security and abuse prevention | Login monitoring, fraud/abuse detection, protecting accounts | Legitimate interests; contract |
| Product improvement and reliability | Crash reporting, Firebase Analytics / Performance (Android), diagnostics, aggregate usage analysis | Legitimate interests |
| Marketing emails | Product news where you opted in | Consent (you may withdraw anytime) |
| Marketing-site analytics cookies | Google Tag Manager / Google Analytics on www.wama.cloud | Consent (via cookie banner) |
| Shop storefront analytics | Google Analytics (measurement ID G-4NQC1FYWN4) on merchant shop sites (*.wama.app) when enabled in production | Consent (via the shop cookie banner) |
| Process merchant customer data | CRM, loyalty, orders, optional Android contact import into a customer record | We process as processor under the merchant's instructions (merchant's lawful basis) |
Where we rely on legitimate interests, we balance those interests against your rights and expectations. You may object as described in section 13.
7. Mobile apps (iOS and Android)
Our native apps connect to WAMA over HTTPS and use OAuth-based authentication. Access and refresh tokens on iOS are stored in the device Keychain.
- Camera and photos: used for barcode scanning and product images. Images you choose may be uploaded to our servers. Photo library access is used only when you select images.
- Push notifications: with your permission we register an APNs / FCM device token with WAMA to deliver operational notifications.
- Crash reporting: Firebase Crashlytics may receive crash and diagnostic data, associated with your user ID when you are signed in.
- Android product analytics: Firebase Analytics (feature and usage events), Firebase Performance, and Firebase Remote Config may run to understand app reliability and usage and to configure the app. These are not used for third-party advertising.
- Android contact import: with the OS contacts permission, a user may pick a device contact to pre-fill a WAMA customer record. Only the selected contact's fields are read and saved if the user saves the customer; the full address book is not synced.
- iOS tracking: we do not track users for advertising and do not use App Tracking Transparency / advertising identifiers for that purpose. Our App Privacy disclosures list email, name, user ID, device ID, crash data, and photos for app functionality / analytics (non-tracking) purposes.
- Android payments: where enabled, SumUp may process card payments via a card reader. Card data is handled by SumUp, not stored by WAMA as full card numbers.
- Subscriptions: WAMA subscriptions are purchased and managed on the website (Stripe). The mobile apps do not sell digital subscriptions in-app.
- Not collected by the apps: continuous GPS tracking, microphone audio for recording, or Face ID biometrics (beyond any OS-level device unlock you configure yourself). iOS does not access the device address book.
You can delete your account from the app or web settings (or contact support). Account deletion removes your user account and related profile data from active systems; we may retain limited data where required by law or for legitimate backup/security purposes (see Retention). Deletion may be restricted while an active paid subscription is linked to the account until billing is resolved.
8. Cookies and similar technologies
Our marketing website uses cookies and local storage. Analytics cookies on www.wama.cloud load only if you accept them via our cookie banner. You can reopen cookie settings from the website footer. Details are in our Cookie Policy.
Merchant ecommerce shop storefronts (for example on *.wama.app) may load Google Analytics (measurement ID G-4NQC1FYWN4) in production to measure shop usage. Those tags load only after the visitor accepts analytics cookies via the shop cookie banner (preference stored as wama-shop-cookie-consent). End-customer-facing privacy notices for shop visitors remain primarily the merchant's responsibility as controller of their customer relationships.
9. Service providers (processors / subprocessors)
We use trusted providers to operate the Service. They process personal data only on our instructions (or, for merchant data, as our subprocessors):
- Google — Tag Manager / Analytics (marketing site after cookie consent; shop storefronts via Google Analytics G-4NQC1FYWN4 after shop cookie consent); Firebase Authentication (shop); Firebase Cloud Messaging; Firebase Crashlytics; Firebase Analytics, Performance, and Remote Config (Android); Google Cloud Storage; Google Cloud hosting / database infrastructure (primarily EEA); on-device ML Kit barcode scanning on Android
- Stripe — subscription billing and ecommerce payments including Stripe Connect payouts to merchants (card data processed by Stripe)
- SumUp — optional Android card-reader payments
- Shopify — optional product/order sync when a merchant connects Shopify
- Mailgun — transactional email delivery
- Sentry — server-side error monitoring
- Cloudflare — DNS, CDN, and related edge services
Providers may change as we improve the Service. Material changes will be reflected in updates to this policy.
10. International transfers
We primarily host and process Service data using Google Cloud infrastructure in the European Economic Area (currently the europe-west1 region, Belgium). Our registered office is in the United Kingdom.
Some providers (for example Google, Stripe, Sentry) may process data in the United States or other countries. Where we transfer personal data outside the UK/EEA, we rely on appropriate safeguards such as adequacy decisions and/or Standard Contractual Clauses, together with additional measures where required.
11. Retention
We retain personal data only as long as needed for the purposes described in this policy, including legal, accounting, and security requirements. In practice:
- Active accounts: for the life of the account while you use the Service
- Account deletion: when you delete your account (or we delete it on your request), we remove the user account, access tokens, profile/user-info records we control, and unsubscribe marketing where applicable from active databases. Limited residual copies may remain in encrypted backups for a short operational period before rotation
- Never-activated registrations: accounts that remain inactive / never activated are automatically deleted after 3 days
- Billing, invoices, and tax records: typically up to 6 years (or longer if required by applicable tax or accounting law)
- Crash, performance, and analytics logs: for shorter operational periods set by our providers and configuration (commonly on the order of weeks to a few months, for example Crashlytics retention as configured with Google)
- Marketing-site analytics (with consent): according to Google Analytics / Tag Manager retention settings and our configuration
- Merchant tenant data (customers, orders, loyalty, stock history, etc.): until the merchant deletes it or the merchant account ends, subject to backups and any legal retention that applies to the merchant or to us
- Marketing preferences: until you unsubscribe or we remove inactive marketing contacts
We do not currently run a separate automated purge of all historical tenant commercial records after a fixed number of years beyond merchant-driven deletion and account closure; merchants should delete data they no longer need.
12. Security
We use appropriate technical and organisational measures, including HTTPS for data in transit, access controls, password hashing, and secure token storage on mobile devices. No method of transmission or storage is completely secure; we work to protect your data but cannot guarantee absolute security.
13. Your rights
Subject to applicable law, you may have the right to:
- Access your personal data
- Rectify inaccurate data
- Erase data ("right to be forgotten")
- Restrict or object to certain processing
- Data portability
- Withdraw consent where processing is based on consent (without affecting prior lawful processing)
- Lodge a complaint with a supervisory authority (in the UK: the Information Commissioner's Office (ICO); in the EU: your local data protection authority, in Italy the Garante per la protezione dei dati personali)
To exercise these rights for data we control, email [email protected]. You can also update profile information and delete your account from the Service settings where available.
If you are an end customer of a merchant using WAMA, please contact that merchant first for requests about data they hold about you in their WAMA account. We will assist merchants as required by law and our agreements (including any DPA).
14. Children
The Service is a business warehouse management product and is not directed at children under 16. We do not knowingly collect personal data from children under 16. If you believe we have collected such data, contact us and we will take appropriate steps to delete it.
15. Changes to this policy
We may update this Privacy Policy from time to time. The "Last updated" date at the top will change when we do. For material changes we will take reasonable steps to notify you (for example via the Service or email) where appropriate.
Where a change relates to processing that relies on your consent (for example marketing emails or marketing-site analytics cookies), we will seek a fresh consent or provide a clear new choice where required by law. For processing based on contract or legitimate interests, continued use of the Service after we have posted the updated policy (and any notice we provide) means you acknowledge the revised policy.
16. Contact
Questions about privacy: [email protected]
Fullstack3 LTD (company number 10486539) — 20-22 Wenlock Road, London, England, N1 7GU