Unwaited is a waitlist and bookings service run by a single founder. This page says what we collect, why, who processes it for us, how long it stays, and how to reach us. It is written to be read, not skimmed for a checkbox.
Two kinds of people
Account owners create waitlists, share them, and see who joined. For your account data, Unwaited is the controller: we decide what is collected and why.
Joiners fill in a form an owner made. For what a joiner types into an owner's form, the owner is the controller and Unwaited is the processor: we store it and hand it back to the owner, and we do not use it for anything else. If you joined someone's line and want your entry changed or removed, ask the person who runs the line; if you cannot reach them, write to us and we will help.
What we collect from account owners
- Your email address, and your name and profile picture if you sign in with Google. We use these to sign you in and to email you about your waitlists.
- The waitlists you create: their names, forms, settings, and the entries people submit to them.
- Billing details if you upgrade: your plan, the Stripe customer and subscription ids. Card numbers go to Stripe and never touch our servers.
- Ordinary server logs: request paths, timestamps, status codes, and the hashed IP described below.
What we collect from joiners
- Whatever the form asks for. The built-in field is an email address; the owner may add more.
- The position number we assign, the time of the signup, and the status of the entry.
- A salted hash of the IP address, used to rate-limit and to spot abuse. We keep the hash, not the address; the salt is a server secret that is never rotated, so the hash cannot be turned back into an IP by us or by anyone who reads the database.
- The result of the Cloudflare Turnstile check, which is a token that says "this looks like a person." Turnstile itself may set a cookie on the form page; see Cloudflare's privacy notice for what it collects.
We do not run advertising, sell data, or build profiles of joiners across waitlists.
Why we process it
- To run the service: assigning numbers, enforcing caps and hours, showing owners their lists, sending the emails a signup triggers.
- To keep it honest: rate limits, captcha, and duplicate detection.
- To bill paid plans.
- To answer support requests.
Who processes it for us
We use a small number of subprocessors. Each one sees only what its job needs.
| Subprocessor | What it does for us | Where |
|---|---|---|
| Railway | Hosts the application and the database | United States |
| Cloudflare | DNS, network protection, the Turnstile captcha | Global edge network |
| Resend | Sends the emails owners and joiners receive | United States |
| Stripe | Takes payments and manages subscriptions | United States |
| Sign-in with Google, if you choose it | United States |
If we add or replace a subprocessor, this page changes and the date at the top moves.
How long it stays
Entries stay for as long as the owner keeps them. Owners can delete single entries, delete a whole waitlist, or set a retention period per waitlist, from 7 days to 3 years; an hourly job then purges anything older. We never delete or hide entries because of a plan change.
Accounts stay until you ask us to delete them. Deleting an account deletes its waitlists and every entry in them.
Logs are kept for a short operational window and then discarded.
Billing records are kept for as long as tax law requires.
Cookies
The dashboard uses one session cookie so you stay signed in. The hosted form uses no cookies of our own; Cloudflare Turnstile may set its own on the form page to tell a person from a bot. We do not use tracking or advertising cookies. If we add cookieless analytics, they will not identify you and this page will say so.
Your rights
Wherever you are, you can ask us what we hold about you, ask for a copy, ask us to correct it, or ask us to delete it. Owners can see, export, correct, and delete their waitlists and entries from the dashboard. For account deletion, anything else, or entries in someone else's line, email us and we will answer within a month, usually much faster.
If you are in the EU, the UK, or another place with a data-protection authority, you can also complain to it.
Security
Connections are encrypted in transit. Passwords are not stored because there are none: sign-in is by emailed link or by Google. API keys are shown once and stored as a hash. Webhook signing secrets are stored so you can view and rotate them from the dashboard. If we ever learn of a breach affecting your data, we will tell affected owners without undue delay.
Children
Unwaited is not aimed at children, and we do not knowingly collect their data. Owners who run lines for children's activities should collect a parent's details.
Changes
When this page changes in a way that matters, we update the date at the top and, for account owners, send an email. Continuing to use the service after that means you accept the new version.
Contact
Email [email protected]. The person answering is the person who built the service.