Last updated September 10, 2026

Privacy Policy

WEPOWER PAY ("WEPOWER", "we", "us") is committed to protecting the personal data of restaurant partners, guests, and website visitors in full compliance with Georgian and international data protection law.

1. Information We Collect

We collect information you voluntarily provide, including consultation lead details (business name, contact name, phone number, email address, number of tables), restaurant onboarding data (IBAN, POS credentials, venue details), and payment references generated during transactions (order amounts, tip amounts, timestamps, gateway order IDs).

We do not collect, transmit, or store full credit or debit card numbers, CVV codes, or card expiry dates on WEPOWER servers. Card entry is tokenized and processed directly by our certified payment partners (Bank of Georgia, Apple Pay, Google Pay).

2. Payment Security

All data in transit is encrypted using TLS 1.3. Payment card data is handled exclusively by PCI-DSS compliant gateway partners; WEPOWER never stores raw card numbers, magnetic stripe data, or CVV codes.

Split-payout transfers (platform fee and restaurant payout) are executed through secured, authenticated banking APIs with restaurant IBANs verified at onboarding.

3. Legal Basis & Compliance

This policy is issued in accordance with the Law of Georgia on Personal Data Protection (as administered by the Personal Data Protection Service of Georgia) and, where applicable to EU/EEA data subjects, the General Data Protection Regulation (GDPR, Regulation (EU) 2016/679).

We process personal data on the legal bases of contractual necessity (processing your payment or onboarding request), legitimate interest (fraud prevention, service analytics), and consent (marketing communications, where opted in).

4. Your Rights

You have the right to access, correct, delete, or export the personal data we hold about you, to object to or restrict certain processing, and to withdraw consent at any time where processing is based on consent.

To exercise these rights, contact our Data Protection point of contact at wepowerofficial1@gmail.com. We respond to verified requests within the statutory timeframes set by Georgian and, where applicable, EU law.

5. Data Retention & Sharing

Lead and onboarding data is retained for as long as necessary to provide services or as required by Georgian tax and accounting law. Transaction records are retained in accordance with applicable financial recordkeeping regulations.

We share data only with processors strictly necessary to deliver the service — payment gateways (Bank of Georgia, Apple Pay, Google Pay), the restaurant's own connected POS system (iiko, Syrve, or Poster, whichever the restaurant uses, solely to sync order and payment status), cloud infrastructure providers (Railway/PostgreSQL hosting), and, if legally compelled, competent authorities. We do not sell personal data to third parties.

6. Terms of Service Summary

Use of WEPOWER PAY by restaurant partners is governed by a separate Merchant Services Agreement executed at onboarding, covering fee schedules (1.3% platform fee, capped at 5 GEL per order), settlement timelines, chargeback handling, and termination terms. Guests using the payment link agree that transactions are final once confirmed by the payment gateway, subject to the restaurant's own refund policy.

7. Contact Us

For any privacy-related questions, data subject requests, or complaints, contact:

WEPOWER PAY · Tbilisi, Georgia
wepowerofficial1@gmail.com