Privacy Policy

We respect your privacy and are committed to protecting your personal data. This privacy policy sets out how Wahaca, a trading division of Oaxaca Limited (referred to in this notice as “Wahaca”, “we” or “us”), collects and uses the personal data of its customers and website visitors (referred to in this notice as “you“). It also explains how personal data is shared and protected, what choices you have relating to your personal data and how you can contact us. 

  1. Who are Wahaca?

Wahaca (Oaxaca Limited) is a company registered in England and Wales with company number 05836870. Wahaca is the data controller  of your personal data. 

  1. What personal data do we collect?

Personal data means any information relating to a person who can be identified either directly or indirectly. We will collect and use your personal data when you interact with our website (www.wahaca.co.uk), our social media, contact us, enter into a competition, promotion or survey or, as a customer, request our products or services (together referred to in this policy as the “Services“).

We may collect the following personal data from you when you use our Services:

  • identity and contact details, such as your name, age, address, email address and telephone number. For example, when you request to book a table at one our restaurants we will use your name and contact details to confirm your booking;
  • payment details, such as your credit or debit card number. For example, when you pay the bill at one of our restaurants or order food on our website we will collect your payment card details to complete the payment.
  • demographic data such as your preferences and interests (for example, your favourite dish and most visited restaurant);
  • personal data you provide to us in customer surveys, competitions and/or offers (for example, your age and address); and
  • technical data, such as data about your use of our website and your IP address, login data, geographical location and browsing actions and patterns.

We may also collect data about you from other sources. This may include the following:

  • personal data you have shared publicly, including on social media; and
  • personal data from providers of technical, payment and delivery services.
  1. What do we use this personal data for?

We will only use the personal data that we collect to provide the Services to you which includes the following: 

  • to process and administer your booking requests; 
  • obtaining payment from you, if you purchase any of our goods or services like our delicious tacos or gift cards or delivery or takeaway; 
  • enabling our suppliers and service providers to carry out certain functions on our behalf, including payment processing, verification, technical, logistical or other functions, as may be required, in order to fulfil your orders or requests; 
  • resolving any refunds or disputes, if you lawfully exercise your rights or if you wish to dispute any part of our offering; 
  • sending you our marketing communications, where you have agreed that we may do so, in order to keep you informed of our products and services, which we consider may be of interest to you; 
  • personalising our services for you, for example by using your data to help us form target audiences and for customer segmentation; 
  • ensuring the security of our business, preventing or detecting fraud or abuses of our website, for example, by requesting verification information in order to confirm your subscription to our newsletter; 
  • to help us identify you, for example, when you are using our requesting our services; 
  • If you’ve consented to our advertising cookies, we may serve you targeted adverts on other websites and social media platforms based on the interests you’ve shown when visiting our website 
  • crime prevention and prosecution of offenders 
  • developing and improving our products and services and to carry out market research, for example, by reviewing visits to our website and its various subpages, demand for specific goods and services; and 
  • to comply with applicable law, for example, in response to a request from a court or regulatory body, where such request is made in accordance with the law. 
  • administering our prize draws and competitions (which will be subject to separate terms and conditions) 
  1. Marketing

When you give us your consent, we will send you marketing communications concerning Wahaca’s  products, services and other promotions (for example, to hear more about the latest Wahaca products). You can opt out at any time after you have given your consent. If you are an existing customer (for example, if you have placed an order with us) we may use the contact details you provided to send you marketing communications about similar Wahaca products or services where permitted by applicable law (unless you have opted out). You can opt out of receiving our marketing communications by following the unsubscribe instructions included in the marketing communications or by contacting us at [email protected].  

  1. Our grounds for using your personal data

To process your personal data lawfully we need to rely on one or more To process your personal data lawfully we need to rely on one or more valid legal grounds. If you are a customer, our primary legal ground is that we need your personal data to fulfil our contract with you or to take certain steps prior to entering into our contract with you. However, there may be circumstances where we may also rely on other valid legal grounds for the processing of your personal data, such as: 

  • your consent to particular processing activities (for example, where you have consented to us using your personal data for marketing purposes); 
  • our legitimate interests as a business (except where such interests are overridden by your interests and fundamental rights). For example, it is within our legitimate interests to use your personal data to prevent or detect fraud or abuses of our website; or 
  • our compliance of our legal obligations. 

Where the personal data we collect from you is needed to meet our legal or regulatory obligations or to enter into a contract, if we cannot collect this personal data, there is a possibility that we may be unable to provide you with our services or perform all of our obligations under our contract with you. 

  1. Disclosure of your personal data to third parties

There are circumstances where we wish to disclose or are compelled to disclose your personal data to third parties. This will only take place in accordance with the applicable law and for the purposes listed above. These scenarios include disclosure: 

  • to our subsidiaries or branches; 
  • to our service providers or suppliers to facilitate the provision of our services or goods to you, for example, the disclosure to your personal data to our delivery and order providers, booking providers, gift voucher providers, payment providers, wifi providers or our customer relationship management provider.   
  • where required by law or to comply with judicial proceedings, court orders or legal or regulatory proceedings; 
  • necessary to protect the safety of our employees, our property or the public; 
  • necessary for the prevention or detection of crime, including exchanging data with other companies or organisations for the purposes of fraud protection and credit risk reduction; 
  • to another legal entity, on a temporary or permanent basis, for the purposes of a joint venture, collaboration, financing, sale, merger, reorganisation, change of legal form, dissolution or similar event. In the case of a merger or sale, your personal data will be permanently transferred to a successor company; or 
  • to any other third party we have identified to you and where you have provided consent. 
  1. International transfer of your personal data

We may transfer your personal data to third parties in countries that do not have same level of data protection as the UK for further processing in accordance with the purposes set out in this policy. In particular, your personal data may be transferred to our outsourced service providers located abroad. In these circumstances we will, as required by applicable law, ensure that your privacy rights are adequately protected, for example, by signing the standard contractual clauses. 

  1. Storage of your personal data

Your personal data is stored in electronic and physical records, which are maintained by Wahaca or our service providers. Your personal data will be retained until your last use or purchase of our Services and normally for a period of 2 years thereafter, unless longer retention is required by applicable local law or where we have a legitimate and lawful purpose to do so. The retention of your personal data will be subject to periodic review. 

We may keep an anonymised form of your personal data, which will no longer refer to you, for statistical purposes without time limits, to the extent that we have a legitimate and lawful interest in doing so. 

  1. Security of your personal data

We will take all steps reasonably necessary to ensure that your personal data is treated securely and in accordance with this privacy notice. Unfortunately, the transmission of data via the internet is not completely secure. Although we will do our best to protect your personal data, we cannot guarantee the security of your personal data transmitted to our website and any transmission is therefore at your own risk. Once we have received your data, we will use strict procedures and security features to try to prevent unauthorised access. 

  1. Your rights

Data protection law provides you with numerous rights, including the right to object to our processing of your personal data where permitted by applicable law. You also have the right to request: 

  • access, to rectify, erase, restrict, transport of your personal information 

These rights are not absolute. Where we have your consent to process your personal data, you have the right to withdraw your consent at any time. If you would like to request a copy of your personal data or exercise any of your other rights please contact us at [email protected]

You also have the right to lodge a complaint about how we treat your personal data. In the first instance, if you would like to make a complaint, we suggest that you contact us using the contact details provided below. You can also lodge a complaint with the Information Commissioner’s Office (ICO) and you can visit their website www.ico.org.uk for more information. 

11. Cookies

Cookies are little files that our website puts on your device to make visits quicker, easier, and more relevant. Some cookies are essential for our website to work, and others remember things about you to give you a better, more enjoyable online experience. Each time you use our website, the cookie is accessed. This way, we can track the features you use and the pages and content that you view on the website to help personalise your experience. We use the following categories of cookies for our website: 

Strictly necessary cookies. These cookies are essential in order to enable you to move around our websites and use its features. The information collected by these cookies relate to the operation of our website, for example website scripting language and security tokens to maintain secure areas of our website.  

Performance cookies. These cookies collect anonymous information about how you use our website, for example which pages you visit most often, whether you receive any error messages, and how you arrived at our website. Information collected by these cookies is used only to improve your use of our website and never to identify you. These cookies are sometimes placed by third-party providers of web traffic analysis services, such as google analytics. 

Functionality cookies. These cookies help perform certain functionalities like sharing the content of the website on social media platforms, collecting feedback, and other third-party features 

Targeting or advertising cookies. Advertisement cookies are used to provide visitors with customized advertisements based on the pages you visited previously and to analyze the effectiveness of the ad campaigns. 

Please note that third parties (including, for example, advertising networks and providers of external services like web traffic analysis services) may also use cookies, over which we have no control. These cookies are likely to be analytical / performance cookies or targeting cookies. We use google analytics. For information on how google processes and collects your information in regard to this product and how you can opt-out, please see their website here. You may opt-out of the use of this cookie by visiting Google’s advertising and privacy page. 

For more information on managing cookies, please go to www.allaboutcookies.org, or visit www.youronlinechoices.com which has further information about behavioural advertising and online privacy. 

You may disable cookie support on your browser but be aware that by doing so, you will lose certain features that require a cookie to work properly. We may use the information collected by the cookie to provide us with various statistics without identifying any individual. 

  1. Contact details

If you have any queries in relation to the processing of your personal data by Wahaca, please contact us on the following contact details: 

  • Oaxaca Limited, 5 Little Portland St, London, W1W 7JD 
  1. Updates to this privacy policy

We keep our privacy policy under regular review. This version was last updated on 20.05.25 

Looking for our Staff Privacy Policy?
Read it here
[instagram feed="163"]
InstagramTiktok
Book Now