Last updated 3 September 2026

Privacy

Plain English first, because a policy nobody reads protects nobody.

A note while we are launching

This describes exactly how the product handles data today. It is being reviewed by legal counsel in India and the UK before our first paying client signs. If anything below changes, we will tell every client directly — not by quietly editing this page.

The short version

  • ·Your bookings and your guests belong to you, not to us.
  • ·We never sell data. Not raw, not anonymised, not aggregated, not to anyone.
  • ·Our own staff can see which dates are taken — never who booked them, nor for how much.
  • ·Everything lives on managed servers in London, encrypted in transit and at rest.
  • ·Ask and we send you all of it as spreadsheets, then delete it.

Who we are

WOW Systems is operated by Akomic Design Studio, trading as WOW Campaigns, serving venues in India and the United Kingdom. For anything about your data, write to sales@wowsystems.cloud and a person will answer.

For your own guests' information, you are the controller and we are the processor. You decide what goes in; we hold it and process it on your instructions. For your own staff's account details, and for anyone who fills in the form on this site, we are the controller.

What we store, and why

Your venue

Name, city, address, the spaces you list and their capacities. Without it there is no calendar.

Your team

Name, email, phone and role for each login, plus a monthly target if you set one. Passwords are hashed by our authentication provider and are never visible to us or to you.

Your bookings

The guest's name and contact details, the date, the space, the occasion, the number of guests, what you quoted, what you closed at, what you were paid, and what you promised. This is the product.

What changed, and who changed it

Every enquiry, confirmation, payment and cancellation is recorded with the person and the time. That is what lets you answer “who cancelled this, and why” — and it is also why the record cannot be quietly edited afterwards.

Notifications

If you switch on alerts, your browser gives us an anonymous address to send them to. It identifies a device, not a person, and deleting the app or switching alerts off removes it.

WOW leads

If you are on Pro or above, enquiries we collect ourselves — a family's name, number, date and budget — are shared with the venues we send them to. Those families are told their details go to venues.

What our own staff can see

This is the part venue owners ask about first, so it is worth being exact. When our team looks for a venue for a family, they see:

  • ·the venue's name, city and the spaces it lists;
  • ·whether a given date and sitting is taken or free.

They do not see guest names, phone numbers, prices, enquiries, revenue or staff performance. This is enforced inside the database functions themselves rather than by hiding fields on a screen, so there is no setting anyone here could flip to see more.

Separately, a small number of our administrators can access a venue's account to set it up or to fix a fault you have reported. That access is logged.

Where it lives

On managed infrastructure in London, United Kingdom (Supabase, on Amazon Web Services), with the application hosted by Railway. Encrypted in transit with TLS and at rest, and backed up daily.

UK venues’ data therefore stays inside the United Kingdom, which is why we chose London over a closer region for our Indian clients.

Who else touches it

Only the companies that make the product run, and each of them only sees its own slice:

  • ·Supabase — the database and sign-in, in London.
  • ·Railway — hosting for the application itself.
  • ·Your browser's notification service (Google or Apple) — only if you switch alerts on, and only to deliver the message.
  • ·Resend — email, when we send you one.

We do not use advertising trackers, and there is no analytics script following you around this website.

How long we keep it

For as long as you are a client, and for twelve months after you leave so that a returning client is not starting from nothing. Ask us to delete it sooner and we will, within thirty days, except where we are legally required to keep an invoice.

Your rights

You can ask us for a copy of everything we hold, ask us to correct it, or ask us to delete it. We answer within thirty days and we do not charge for it. UK clients have these rights under UK GDPR; Indian clients have equivalent rights under the Digital Personal Data Protection Act, and we apply the same standard to both.

If your guests ask you to remove their details, you can delete the booking yourself, or ask us and we will.

Cookies

One cookie, for signing in. It remembers that it is you so you are not asked for your password on every page. There are no advertising cookies and nothing to consent to, which is why this site has no cookie banner.

Your theme choice (light or dark) is stored in your own browser and never reaches us.

If something goes wrong

If data is ever exposed, we will tell affected clients within 72 hours of finding out, with what happened, what was involved, and what we are doing — before we announce anything publicly.

Ask us anything about this

A real person answers, and “can you show me exactly what your staff can see about my venue” is a question we are happy to demonstrate live.