Back to Home

Privacy Policy

Last updated: February 3, 2026

1. Introduction

WaitlistCare ("we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our waitlist management service ("Service").

2. Our Role

WaitlistCare acts in two capacities depending on the type of data:

  • Data Processor (Service Provider): When organizations use WaitlistCare to manage their waitlists, we process personal data on behalf of the organization (the "data controller"). The organization determines what data to collect and how it is used. Our obligations as a processor are detailed in our Data Processing Agreement.
  • Data Controller: For account information (staff login credentials, billing details) and website visitor data, WaitlistCare acts as the data controller and determines the purposes and means of processing.

3. Information We Collect

Account Information

When you create an account, we collect:

  • Name and email address
  • Organization name and type
  • Password (encrypted)

Waitlist Entry Data

When you or your contacts add entries to your waitlist, we collect information provided, which may include:

  • Names and dates of birth
  • Contact information (email, phone)
  • Gender
  • Parent/guardian information
  • Emergency contact information
  • Notes, preferences, and custom field data
  • Uploaded documents (images, PDFs)
  • Tags and status information

Payment Data

When payments are processed through our Service, payment card details are handled exclusively by Stripe and are never stored on our servers. We may store transaction references, amounts, and payment status.

Usage Data

We automatically collect certain information when you use our Service, including IP address, browser type, device information, and pages visited. This data is collected through Google Analytics (Firebase Analytics).

4. Legal Basis for Processing

We process personal data based on the following legal grounds:

  • Contract Performance: Processing necessary to provide the Service you have subscribed to, including storing waitlist data, sending emails on your behalf, and processing payments.
  • Legitimate Interest: Processing necessary for our legitimate business interests, such as improving the Service, ensuring security, and preventing fraud, where those interests are not overridden by your rights.
  • Consent: Where you have given consent, such as when contacts submit their information through a self-signup form. Consent can be withdrawn at any time.
  • Legal Obligation: Processing necessary to comply with applicable laws, such as maintaining transaction records or responding to lawful requests from authorities.

5. How We Use Your Information

We use the information we collect to:

  • Provide and maintain our Service
  • Send email notifications on your behalf (welcome emails, status updates, team notifications)
  • Process payments and manage billing
  • Store and manage uploaded documents
  • Provide public-facing status pages and self-signup forms
  • Maintain activity logs for audit purposes
  • Improve and personalize your experience
  • Respond to your requests and support needs
  • Prevent fraud and abuse (e.g., bot detection on public forms)
  • Comply with legal obligations

6. Data Sharing and Service Providers

We do not sell your personal information. We do not share personal information for cross-context behavioral advertising. We may share information with:

Service Providers (Subprocessors)

We use trusted third-party services to operate our platform:

Provider Purpose Location
Google Cloud Platform / Firebase Cloud hosting, database, authentication, file storage, analytics United States
Brevo (Sendinblue) Transactional email delivery EU / United States
Stripe Payment processing United States
Freemius Subscription billing and license management United States
Google reCAPTCHA Bot prevention on public forms United States
Crisp In-app live chat support EU

Other Disclosures

  • Legal Requirements: When required by law, subpoena, or to protect our rights
  • Business Transfers: In connection with a merger, acquisition, or sale of assets, with notice to affected users

7. Cookies and Tracking

We use the following technologies:

  • Essential Cookies: Required for authentication and session management. These are necessary for the Service to function and cannot be disabled.
  • Analytics (Firebase/Google Analytics): We use Firebase Analytics to understand how the Service is used, including page views and feature usage. This data is aggregated and used to improve the Service.
  • reCAPTCHA: Google reCAPTCHA is used on public-facing forms (self-signup, contact form) to prevent bot abuse. This may set cookies and process interaction data. Use of reCAPTCHA is subject to Google's Privacy Policy and Terms of Service.
  • Crisp Chat: When you open the live chat widget, Crisp may set cookies to maintain the chat session. This is only loaded when you initiate a chat.

We do not use advertising cookies or tracking pixels. We do not engage in cross-site tracking.

8. Data Security

We implement appropriate technical and organizational measures to protect your personal information, including:

  • 256-bit SSL/TLS encryption for all data in transit
  • Encryption of data at rest via Google Cloud Platform
  • Firebase Authentication with secure credential handling
  • Firestore security rules enforcing role-based access controls
  • Activity logging for audit trail

However, no method of transmission over the Internet is 100% secure, and we cannot guarantee absolute security.

9. Data Retention

We retain your information for as long as your account is active or as needed to provide the Service. Upon account termination, you may request export or deletion of your data. We will delete your data within 30 days of a verified request, except where retention is required by law (e.g., transaction records). For more details, see our Data Processing Agreement.

10. Your Rights

Depending on your location and applicable laws, you may have the following rights:

All Users

  • Access the personal information we hold about you
  • Request correction of inaccurate data
  • Request deletion of your data
  • Export your data in a portable format (CSV)

EEA/UK Residents (GDPR)

  • Object to or restrict processing of your data
  • Withdraw consent at any time where processing is based on consent
  • Lodge a complaint with your local data protection supervisory authority

California Residents (CCPA/CPRA)

  • Right to know what personal information is collected, used, and disclosed
  • Right to delete personal information
  • Right to opt out of the sale or sharing of personal information (note: we do not sell or share personal information)
  • Right to non-discrimination for exercising your privacy rights

To exercise any of these rights, please contact us. We will respond to verified requests within 30 days.

11. International Data Transfers

Your data is stored on Google Cloud Platform servers in the United States. If you are located outside the United States, your data will be transferred to and processed in the United States. Where required by law (e.g., GDPR), we use Standard Contractual Clauses (SCCs) to ensure adequate protection for international data transfers. See our Data Processing Agreement for details.

12. Children's Privacy

Our Service is designed to help organizations manage waitlists that may include children's information (e.g., childcare centers, preschools). This data is provided by authorized adults — parents, guardians, or organization staff. We do not knowingly collect information directly from children under 13. Organizations using WaitlistCare to process children's data are responsible for obtaining appropriate parental consent as required by COPPA or other applicable laws.

13. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new Privacy Policy on this page and updating the "Last updated" date. For significant changes, we may also notify you by email.

14. Contact Us

If you have questions about this Privacy Policy or wish to exercise your data rights, please contact us:

Contact us here