Privacy Policy

Effective Date: February 13, 2026

1. Introduction

WaitlistFire ("we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our service. We comply with applicable data protection laws including GDPR and LGPD.

2. Information We Collect

2.1 Information You Provide

  • Account Information: Name, email address, and password when you create an account
  • Payment Information: Billing details processed securely through Stripe (we do not store card numbers)
  • Campaign Data: Content you create including waitlist configurations, branding, and settings
  • Communications: Messages you send to us via email or support channels

2.2 Information Collected Automatically

  • Usage Data: Pages visited, features used, and interactions with the Service
  • Device Information: Browser type, operating system, IP address, and device identifiers
  • Analytics Data: Performance metrics and error logs to improve our Service

2.3 Subscriber Data

When people join waitlists you create, we collect their email addresses and any additional information you configure (e.g., names). You are the data controller for this subscriber data, and we process it on your behalf as a data processor.

3. How We Use Your Information

We use collected information to:

  • Provide, maintain, and improve our Service
  • Process transactions and send related information
  • Send administrative emails (account verification, security alerts, updates)
  • Respond to your requests and provide customer support
  • Monitor and analyze usage patterns and trends
  • Detect, prevent, and address technical issues and fraud
  • Comply with legal obligations

4. Legal Basis for Processing (GDPR)

We process your data based on:

  • Contract Performance: To provide the Service you requested
  • Legitimate Interests: To improve our Service and protect against fraud
  • Legal Compliance: To meet our legal obligations
  • Consent: For marketing communications (you can opt out anytime)

5. Information Sharing

We may share your information with:

  • Service Providers: Third parties that help us operate our Service:
    • Stripe - Payment processing
    • Email providers - Transactional and marketing emails
    • Analytics services - Usage analytics and performance monitoring
    • Cloud hosting - Data storage and infrastructure
  • Legal Requirements: When required by law or to protect our rights
  • Business Transfers: In connection with a merger, acquisition, or sale of assets

We do not sell your personal information to third parties.

6. Cookies and Tracking

We use cookies and similar technologies for:

  • Essential Cookies: Required for the Service to function (authentication, security)
  • Analytics Cookies: Help us understand how you use our Service
  • Preference Cookies: Remember your settings and preferences

You can control cookies through your browser settings. Disabling certain cookies may affect Service functionality.

7. Data Retention

We retain your data for as long as your account is active or as needed to provide services. After account deletion:

  • Account data is deleted within 30 days
  • Subscriber data from your campaigns is deleted within 30 days
  • Backup copies may be retained for up to 90 days
  • Some data may be retained longer for legal or legitimate business purposes

8. Your Rights

Depending on your location, you may have the following rights:

  • Access: Request a copy of your personal data
  • Rectification: Correct inaccurate or incomplete data
  • Erasure: Request deletion of your data ("right to be forgotten")
  • Restriction: Limit how we process your data
  • Portability: Receive your data in a portable format
  • Objection: Object to certain processing activities
  • Withdraw Consent: Withdraw consent at any time (where applicable)

To exercise these rights, contact us at privacy@waitlistfire.com. We will respond within 30 days.

9. Data Security

We implement appropriate technical and organizational measures to protect your data, including:

  • Encryption in transit (TLS/SSL) and at rest
  • Secure password hashing
  • Regular security audits and updates
  • Access controls and authentication
  • Monitoring for suspicious activity

However, no method of transmission over the internet is 100% secure. We cannot guarantee absolute security.

10. International Data Transfers

Your data may be transferred to and processed in countries other than your own. We ensure appropriate safeguards are in place, including standard contractual clauses approved by relevant authorities.

11. Children's Privacy

Our Service is not directed to children under 16. We do not knowingly collect personal information from children. If you believe a child has provided us with personal data, please contact us immediately.

12. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes via email or through the Service. Your continued use after such notification constitutes acceptance of the updated policy.

13. Contact Us

For questions, concerns, or to exercise your rights, please contact us:

If you are in the EU/EEA, you have the right to lodge a complaint with your local supervisory authority.