A waitlist is not a profile.
This notice explains the waitlist processing operated through waitinglists.dev. It was last updated on 31 July 2026.
Who controls the data
Flavio Copes is the data controller for waitinglists.dev and the waitlists operated through it. For privacy questions or requests, email privacy@waitinglists.dev. A connected website must also tell you the specific purpose of its waitlist when it asks you to join.
What is collected
We collect the email address you submit, the waitlist it belongs to, and limited system metadata needed to prove and manage consent: pending or confirmed status, consent-text version, request and confirmation times, and limited delivery status and diagnostic details for the confirmation message. When you confirm, we also store the approximate two-letter country code Cloudflare derives from your network connection. This may be inaccurate, including when you use a VPN. We do not ask for names, phone numbers, street addresses, or profiles. We do not store your IP address or browser details in D1.
Cloudflare necessarily processes network and security metadata when serving requests and delivering confirmation email. That infrastructure processing is governed by Cloudflare’s data protection terms.
Why it is used
We use the address only to record your requested place on the named waitlist and contact you about that waitlist or its launch. The legal basis is your consent. The confirmation message is a transactional email used to verify that the address owner made the request. No address becomes active until that confirmation is completed.
We use the approximate country to understand the geographic distribution of interest in each waitlist. The legal basis is our legitimate interest in measuring that distribution, balanced by retaining only a country code rather than the underlying IP address.
We do not sell the data, use it for behavioural advertising, or make automated decisions about you.
Retention and deletion
Unconfirmed requests expire after 24 hours and are deleted by the next daily cleanup. Confirmed records are kept until the relevant waitlist closes, you remove the record, or 24 months after confirmation—whichever comes first. Secure links in confirmation messages let you withdraw and permanently delete the record without creating an account.
Processors and transfers
Cloudflare provides the Worker, D1 database, security controls, and transactional email delivery as a processor. Cloudflare may process data through its global infrastructure. The contractual safeguards, including international-transfer terms, are described in the Cloudflare Data Processing Addendum.
Your rights
Depending on your circumstances, you may request access, correction, erasure, restriction, or portability, object to processing, and withdraw consent at any time. Withdrawal does not affect processing that was lawful before withdrawal. Use the removal link in your confirmation email or contact privacy@waitinglists.dev. We may need to verify that you control the address. You may also complain to your local data protection authority.
Browser storage, cookies, and security
After a successful request on waitinglists.dev, the public page stores a non-identifying marker in your browser so it can say that you have already joined. The marker does not contain your email address and is not sent to our server. Public waitlist pages do not set cookies. The private admin area uses one strictly necessary, secure, HTTP-only session cookie. Access controls, rate limiting, hashed one-time tokens, and encrypted transport protect the service; no system can promise absolute security.