Privacy Policy
Effective Date: August 15, 2026 | Last Updated: August 15, 2026
1. Scope & Who This Policy Applies To
This Privacy Policy governs how WaitlistTest (“we,” “our,” or “us”) collects, uses, discloses, and protects personal information when you:
- Visit or use our website at waitlisttest.com and all subdomains;
- Register for and use our SaaS platform, dashboard, APIs, or embedded widgets;
- Submit your email address or personal information through a customer-operated waitlist form powered by WaitlistTest (as a waitlist subscriber);
- Communicate with us via email, chat, or other channels.
If you are a WaitlistTest customer (building waitlists for your own product), you are additionally subject to our Terms and Conditions, which govern your Data Processing obligations toward your own subscribers.
2. Information We Collect
2.1 Information You Provide Directly
- Account Registration: Name, email address, password (hashed and salted — never stored in plaintext), company name, and billing contact.
- Payment Information: Billing address and payment card details. Card numbers are processed and stored exclusively by our PCI-DSS–certified payment processor (Lemon Squeezy / Stripe). WaitlistTest does not store full card numbers on our servers.
- Waitlist Campaign Data: Waitlist page content, branding settings, custom form fields, referral reward configurations, and email templates you create.
- Subscriber Data (on your behalf): Email addresses and any additional custom fields your waitlist form collects from your visitors. You are the data controller of this information; we process it on your behalf as a data processor.
- Support Communications: Any information you include when contacting our support team.
2.2 Information We Collect Automatically
- Log & Usage Data: IP address, browser type and version, operating system, referring URL, pages visited, timestamps, and session duration.
- Conversion & Analytics Events: Form submission events, referral link clicks, waitlist position changes, and conversion funnel metrics — collected to provide you with campaign analytics.
- Cookies & Similar Technologies: See Section 6 below.
2.3 Information From Third Parties
- Authentication providers (e.g., Google OAuth), if you choose to sign in with a third-party account.
- Payment processors for billing status and fraud signals.
3. How We Use Your Information
We use collected information for the following purposes:
- Service Delivery: To create, maintain, and operate your account, waitlist campaigns, and embedded widgets.
- Billing & Payments: To process subscription fees, invoices, and refunds.
- Analytics & Reporting: To generate conversion dashboards and referral metrics for your campaigns.
- Transactional Communications: To send account confirmations, password resets, billing receipts, and critical service notifications. These are non-promotional and cannot be opted out of while your account is active.
- Product Communications: With your consent, to send product updates, feature announcements, and educational content. You may unsubscribe at any time.
- Security & Fraud Prevention: To detect, investigate, and prevent abuse, unauthorized access, spam campaigns, or violations of our Terms.
- Legal Compliance: To comply with applicable laws, regulations, court orders, or lawful government requests.
- Service Improvement: Aggregated and anonymized usage data is used to improve product features. We do not use individually identifiable behavioral data to make profiling decisions about you.
4. Legal Basis for Processing (GDPR)
For users in the European Economic Area (EEA), United Kingdom, and Switzerland, our legal bases for processing personal data are:
- Contract Performance (Art. 6(1)(b) GDPR): Processing necessary to deliver the Services you purchased or signed up for.
- Legitimate Interests (Art. 6(1)(f) GDPR): For security monitoring, fraud prevention, and service improvement, provided these interests are not overridden by your rights.
- Consent (Art. 6(1)(a) GDPR): For marketing communications and non-essential cookies. You may withdraw consent at any time without affecting the lawfulness of prior processing.
- Legal Obligation (Art. 6(1)(c) GDPR): Where required by applicable law.
5. Data Sharing & Disclosure
We do not sell your personal data. We share information only in the following limited circumstances:
- Service Providers (Sub-processors): Trusted vendors who help us operate our platform, including hosting (Vercel / AWS), database (Supabase / PostgreSQL), email delivery (Resend / SendGrid), payment processing (Lemon Squeezy / Stripe), and analytics (Google Analytics with IP anonymization). All sub-processors are contractually bound to process data only on our instruction and to maintain appropriate security.
- Your Waitlist Subscribers: When you use WaitlistTest to run a public waitlist, subscriber data is accessible to your account and processed according to your instructions. You are solely responsible for ensuring you have appropriate consent from your subscribers and a compliant privacy policy on your own platform.
- Business Transfers: In the event of a merger, acquisition, or asset sale, personal data may be transferred. We will provide notice before your data is subject to a different privacy policy.
- Legal Requirements: We may disclose information if required by law, subpoena, court order, or governmental authority, or where we believe in good faith that disclosure is necessary to protect our rights, prevent fraud, or protect the safety of our users or the public.
6. Cookies & Tracking Technologies
We use the following types of cookies:
- Strictly Necessary Cookies: Required for authentication sessions, security (CSRF tokens), and core platform functionality. These cannot be disabled.
- Analytics Cookies: Google Analytics with IP anonymization enabled. These are loaded only with your consent where required by law.
- Preference Cookies: To remember your UI settings (e.g., billing frequency toggle).
You can manage cookie preferences through your browser settings or any cookie consent banner displayed on our site. Refusing analytics cookies will not affect your ability to use our core Services.
7. Data Retention
- Active Account Data: Retained for the duration of your account and for up to 90 days after account deletion (to allow recovery), then permanently deleted.
- Subscriber Data (on your campaigns): Retained until you delete a campaign or your account, whichever comes first. You may export or delete subscriber data at any time from your dashboard.
- Billing Records: Retained for 7 years to comply with financial regulation requirements.
- Server Logs: Retained for up to 90 days for security and debugging purposes.
- Anonymized Analytics: May be retained indefinitely as they do not identify you.
8. Your Rights & Choices
Depending on your jurisdiction, you may have the following rights:
8.1 For EU / EEA / UK Residents (GDPR & UK GDPR)
- Right of Access: Request a copy of the personal data we hold about you.
- Right to Rectification: Correct inaccurate or incomplete data.
- Right to Erasure (“Right to be Forgotten”): Request deletion of your personal data, subject to legal retention obligations.
- Right to Restrict Processing: Ask us to limit how we use your data.
- Right to Data Portability: Receive your data in a structured, machine-readable format.
- Right to Object: Object to processing based on legitimate interests or for direct marketing purposes.
- Right to Withdraw Consent: Withdraw consent at any time without penalty.
- Right to Lodge a Complaint: You have the right to file a complaint with your local supervisory authority (e.g., ICO in the UK, your national Data Protection Authority in the EU).
8.2 For California Residents (CCPA / CPRA)
- Right to Know what personal information is collected, used, disclosed, or sold.
- Right to Delete personal information we hold about you.
- Right to Opt-Out of sale or sharing of personal information. (We do not sell personal information.)
- Right to Non-Discrimination for exercising your CCPA rights.
- Right to Correct inaccurate personal information.
- Right to Limit use of Sensitive Personal Information.
To submit a CCPA request, contact privacy@waitlisttest.com. We will respond within 45 days. We may request identity verification before processing your request.
8.3 For All Users — Email Opt-Out
Every marketing email we send includes an unsubscribe link. You may also email privacy@waitlisttest.com to opt out of non-essential communications. Opt-outs are processed within 10 business days, consistent with CAN-SPAM and CASL requirements.
9. International Data Transfers
WaitlistTest operates globally. Your data may be transferred to and processed in countries outside your country of residence, including the United States, where data protection laws may differ from those in your jurisdiction.
For transfers from the EEA / UK to third countries, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission, or other appropriate transfer mechanisms, to ensure your personal data is protected to the standard required by GDPR.
10. Security
We implement industry-standard technical and organizational security measures, including:
- TLS 1.2+ encryption for all data in transit.
- AES-256 encryption at rest for sensitive database fields.
- Hashed and salted password storage using bcrypt.
- Role-based access controls restricting employee access to production data.
- Regular dependency and vulnerability scanning.
No method of transmission or storage is 100% secure. While we strive to use commercially acceptable means to protect your personal information, we cannot guarantee absolute security. In the event of a data breach affecting your rights, we will notify affected users and, where required, supervisory authorities in accordance with applicable law (within 72 hours for GDPR-reportable breaches).
11. Children’s Privacy (COPPA)
WaitlistTest is not directed to individuals under the age of 16 (or the applicable minimum age in your jurisdiction, e.g., 13 under U.S. COPPA). We do not knowingly collect personal information from children. If you are a parent or guardian and believe your child has provided us with personal information, please contact us at privacy@waitlisttest.com and we will delete such information promptly.
12. Third-Party Links & Integrations
Our platform may contain links to or integrations with third-party services (e.g., Notion, Slack, Google Sheets). WaitlistTest is not responsible for the privacy practices of third-party services. We encourage you to review the privacy policies of any third-party services you interact with.
13. Customer Responsibility as Data Controller
When you use WaitlistTest to collect email addresses and personal information from your own customers or waitlist subscribers, you are the data controller, and WaitlistTest is the data processor acting on your instructions. You are solely responsible for:
- Obtaining lawful consent from your subscribers to collect and use their personal information;
- Publishing a compliant privacy policy on your own waitlist page or website;
- Complying with all applicable data protection laws (GDPR, CCPA, etc.) in your jurisdiction and your subscribers’ jurisdictions;
- Ensuring your use of subscriber data is limited to legitimate purposes and does not involve spam or deceptive practices.
By agreeing to our Terms and Conditions, you confirm these obligations. WaitlistTest shall not be held liable for your non-compliance with applicable data protection law.
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we do, we will:
- Update the “Last Updated” date at the top of this page;
- Notify registered users of material changes via email or an in-app notification at least 14 days before the changes take effect;
- Archive prior versions and make them available upon request.
Your continued use of the Services after the effective date of any changes constitutes acceptance of the updated Privacy Policy.
15. Contact Us & Data Protection Officer
If you have any questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact us:
WaitlistTest
Privacy Inquiries & Data Requests: privacy@waitlisttest.com
Support & General: hello@waitlisttest.com
We aim to respond to all privacy requests within 30 calendar days (or within the timeframe required by applicable law). If you are unsatisfied with our response, you may lodge a complaint with your local data protection supervisory authority.