Waitloop
Features How It Works Pricing Use Cases 🚀 SaaS Early Access 🐾 Puppy Breeder 🍽️ Restaurant Opening 💪 Fitness Studio Launch 🎓 Online Course Launch Docs Contact Log in
Back to Home

Privacy Policy

Effective date: June 30, 2026

This Privacy Policy explains how Waitloop.io ("Waitloop", "we", "us", or "our") collects, uses, shares, and protects personal data in connection with our websites, dashboard, embeddable form widget, and related services (together, the "Services").

Waitloop is a waitlist and form-capture platform. We interact with two groups of people, and our role differs for each:

  • Customers — the businesses and individuals who create a Waitloop account to collect signups. For Customer account data, we act as a data controller.
  • Signups — the people who submit a form or join a waitlist that a Customer operates using Waitloop. For this data, the Customer is the controller and Waitloop acts as a processor on the Customer's behalf. If you submitted a form to a business that uses Waitloop, please direct privacy requests to that business; see Section 10.

1. Information We Collect

a. Information from Customers

When you create and use a Waitloop account, we collect:

  • Account details — your name, email address, password (stored only as a salted hash), and email-verification status.
  • Security settings — if you enable two-factor authentication, the information needed to support it, and, if you sign in with Google or GitHub, the unique account identifier and email address from that provider.
  • Billing information — your plan, subscription status, and customer/subscription identifiers held by our payment processor. Payment card details are entered with and handled by our processor; Waitloop never receives or stores full card numbers.
  • Configuration & content — the lists, forms, settings, email templates, allowed domains, and integration details (such as a notification webhook) that you create.
  • Usage and diagnostic data — submission counts, storage used, log and audit records of actions taken in your account (for example sign-in events, exports, and configuration changes), together with the IP address and browser/device information associated with those actions.

b. Information from Signups (collected on behalf of Customers)

When a person submits a form or joins a waitlist that a Customer runs with Waitloop, we process the data on the Customer's instructions. This can include:

  • Form field data — whatever fields the Customer's form requests, which commonly includes an email address and name, and may include other details such as company, phone number, or answers to custom questions.
  • File attachments — files (such as images) that a Signup uploads through a form, where the Customer has enabled uploads.
  • Submission metadata — technical information automatically recorded with a submission, such as the referring and page URL, marketing campaign (UTM) parameters, a timestamp, browser/device information, and a non-reversible (hashed) representation of the submitter's IP address used for security and de-duplication.

c. Information collected automatically on our website

When you visit our public website, our servers and infrastructure providers process limited technical data — such as IP address, browser type, and pages viewed — to deliver and secure the site. See our Cookies Policy for details on local storage and similar technologies.

2. How We Use Information

We use personal data to:

  • provide, operate, and maintain the Services, including capturing and displaying submissions;
  • create and secure accounts, authenticate sign-ins, and prevent fraud, spam, and abuse;
  • process payments and manage subscriptions;
  • send transactional and service messages, such as email verification, password resets, security alerts, team invitations, and notifications you have configured;
  • provide analytics and reporting to Customers about their own lists;
  • respond to support requests and communicate with you; and
  • comply with legal obligations and enforce our terms.

For Signup data, we only use it to provide the Services to the Customer and do not sell it or use it for our own advertising.

Where the GDPR or UK GDPR applies, we rely on the following legal bases: performance of a contract (to provide the Services to Customers); legitimate interests (to secure, improve, and operate the Services, where not overridden by your rights); consent (where required, for example for certain cookies or optional communications); and legal obligation (to comply with applicable law). For Signup data, the Customer is responsible for establishing a lawful basis for collection.

4. How We Share Information

We do not sell personal data. We share it only as needed to run the Services:

  • Sub-processors — vendors who process data on our behalf under contract (see Section 5).
  • At a Customer's direction — for example, delivering submissions to a Customer's own webhook, Slack workspace, or analytics property that the Customer has chosen to connect.
  • Legal and safety — where required by law, or to protect the rights, property, or safety of Waitloop, our users, or the public.
  • Business transfers — in connection with a merger, acquisition, or sale of assets, subject to this Policy.

5. Sub-processors

We use a limited number of trusted third-party service providers ("sub-processors") that process personal data on our behalf, under contract and only as needed to run the Services. They fall into these categories: cloud hosting and storage, email delivery, payment processing, bot and spam protection, and optional single sign-on. Each processes only the data required for its function, and we remain responsible for their handling of the data.

Customers may also choose to connect optional third-party destinations (such as their own Slack workspace, webhook endpoint, or analytics property). Data sent to those destinations is governed by the third party's own terms and privacy policy.

6. International Data Transfers

We and our sub-processors may process data in countries other than your own. Where we transfer personal data internationally, we use appropriate safeguards such as the European Commission's Standard Contractual Clauses (or equivalent mechanisms) to protect that data.

7. Data Retention

We keep personal data only as long as needed for the purposes described in this Policy:

  • Customer account data is retained while your account is active and for a reasonable period afterward to meet legal, accounting, and security needs.
  • Submission data is retained according to the retention setting chosen by the Customer (for example, automatic deletion after 30, 60, or 90 days, or kept until deleted). Attachments are deleted together with their submission.
  • Security and audit logs are retained for a limited period to protect the Services, after which they are deleted or archived.

8. How We Protect Data

We apply administrative, technical, and organizational measures designed to protect personal data, including encryption of data in transit (HTTPS/TLS), encryption of sensitive personal fields at rest, access controls, and audit logging. No method of transmission or storage is completely secure, so we cannot guarantee absolute security, but we work to protect your information and to respond promptly to any incident.

9. Your Privacy Rights

Depending on where you live, you may have rights to access, correct, delete, or receive a copy of your personal data, to object to or restrict certain processing, and to withdraw consent. To exercise these rights for a Waitloop account, contact us using the details in Section 14. We will not discriminate against you for exercising your rights. You also have the right to lodge a complaint with your local data protection authority.

California residents (CCPA/CPRA)

If you are a California resident, you have the right to know what personal information we collect and how we use it, to request access to and deletion of your personal information, to correct inaccurate personal information, and not to be discriminated against for exercising your rights. We do not sell your personal information, and we do not "share" it for cross-context behavioral advertising, as those terms are defined under the CCPA. We also do not use or disclose sensitive personal information beyond the purposes permitted by the CCPA. To exercise your rights, contact us at info@waitloop.io; you may also use an authorized agent to submit a request on your behalf.

Customers can export their account and list data, and can delete a specific person's submissions, directly from the dashboard's Data & Privacy settings.

10. Notice for Signups

If you submitted a form or joined a waitlist operated by a business using Waitloop, that business — not Waitloop — decides what data to collect and how to use it, and is the controller of your data. To access, correct, or delete your information, please contact that business directly. We will assist our Customers in responding to such requests, including by deleting a person's data on the Customer's instruction.

11. Children's Privacy

The Services are not directed to children under 16, and we do not knowingly collect personal data from them. If you believe a child has provided us personal data, please contact us so we can delete it.

12. Cookies & Tracking

Our websites and dashboard use a limited set of cookies and similar technologies (including browser storage used to keep you signed in). For full details, see our Cookies Policy.

13. Changes to This Policy

We may update this Policy from time to time. When we make material changes, we will update the effective date above and, where appropriate, notify you. Your continued use of the Services after an update means you accept the revised Policy.

14. Contact Us

If you have questions about this Policy or how we handle your data, contact us at:

Waitloop.io
Privacy team: info@waitloop.io