Trust

Security & Privacy

Last updated September 28, 2026

Restaurants trust Wingman with their team's and their guests' information, and we treat that as something we're responsible to protect. This page explains, in plain language, how we keep your data safe and private. For the full detail on what we collect and your choices, see our Privacy Policy. Wingman is operated by The Maverick Agency.

Your data is isolated by restaurant

Wingman is multi-tenant: every restaurant's data is scoped to its own organization and enforced at the database level with row-level security, so one account can never see another's guests, staff, reviews, or standards.

Access inside your account is role-based. Owners control what each manager, shift lead, and team member can see, and can hide individual sections from specific people. Permissions are checked on every page and every action, not just hidden in the interface.

Encryption

All data is encrypted in transit (HTTPS/TLS) between your devices and Wingman, and encrypted at rest in our database and file storage.

Secrets and integrations stay server-side

When you connect an outside service — Square, Clover, your Google Business Profile, or a payment method — the access tokens and credentials are stored in locked-down tables that the browser can never read. Every use happens in our secure server environment.

Integrations request the minimum access needed. For example, the Google Business Profile connection is read-only: Wingman reads your reviews to summarize them for you, and never posts, edits, or deletes anything. You can disconnect any integration at any time.

Payment details are handled by our PCI-compliant payment processor; Wingman never stores full card numbers.

We protect against accidental data loss

Deleting a guest, team member, or partner is a soft delete: the record moves to an owner-only Trash where it can be restored, rather than being erased. Sensitive changes are recorded in an audit trail.

Database changes are additive by design and pass automated safety checks before they ship, so an update can't silently drop your data. Our database is backed up on an ongoing basis by our infrastructure provider.

Your data belongs to you

The data you and your guests put into Wingman is yours. We process it to run the service on your behalf — we do not sell it, and we do not use your guests' information to advertise to them.

You can export or delete your data from Settings, or by contacting us. After cancellation, your data remains available to export for 30 days, then is removed from active systems. Full detail is in our Privacy Policy.

Built on trusted infrastructure

Wingman runs on leading cloud infrastructure providers (including Vercel and Supabase) that maintain their own SOC 2 / ISO 27001 certifications and operate in secure, access-controlled data centers. We rely on a small set of vetted sub-processors (hosting, database, email, payments, and AI processing), each bound by contract to protect your data.

Compliance & certifications

Wingman is built to align with SOC 2 principles — the access controls, encryption, tenant isolation, and auditing described above are the foundation those frameworks look for. We are not independently SOC 2 or ISO 27001 certified today, and we're happy to discuss a formal certification timeline for enterprise and multi-unit agreements.

HIPAA: Wingman is a hospitality product. It is designed for restaurant operations, guest retention, hiring, and team culture — it does not collect or process protected health information, so HIPAA does not apply.

If your organization has a specific security questionnaire or requirement, reach out and we'll work through it with you.

Reporting a security concern

If you believe you've found a security issue, please email us right away at security@joinwingman.app. We take every report seriously and will respond promptly.

Security or privacy questions? Email security@joinwingman.app.