Privacy Policy

Waitlister — operated by Lemon Tree Ventures, LLC


1. About this policy

This policy explains how Lemon Tree Ventures, LLC ("Waitlister", "we", "us"), a Delaware limited liability company of 1111B S Governors Ave, STE 55103, Dover, DE 19904, United States, handles personal data in connection with waitlister.me and the Waitlister application (the "Service").

2. Our two roles — please read this first

Waitlister handles personal data in two different capacities, and different rules apply to each.

We are the controller of the personal data of our own customers — the people who create Waitlister accounts. That is the data described in Section 3 of this policy, and this policy governs it.

We are a processor of the personal data of waitlist subscribers — the people who sign up to waitlists and forms that our customers create. Our customer is the controller of that data and decides what happens to it. Our handling of it is governed by our Data Processing Agreement, not by this policy.

If you signed up to a waitlist and want your data corrected or deleted, contact the business whose waitlist you joined. We will refer your request to them, because they, not we, decide the outcome.

3. What we collect about our customers

Information you give us

  • Account data — name, email address, password, and any profile details you add.
  • Billing data — billing name, billing address, tax identifiers, and the last four digits and expiry of your payment card. Full card numbers are handled by Stripe and never reach our systems.
  • Support data — the content of messages you send us, including through the in-product support assistant.
  • Content you create — waitlists, landing pages, form configurations, email content and uploaded images.

Information we collect automatically

  • Log and device data — IP address, browser type and version, operating system, referring and exit pages, timestamps, and the pages and resources you access.
  • Usage data — how you use the Service, including feature usage, API request volumes and email sending volumes.
  • Cookies and similar technologies — see Section 6.

Information from others

  • Payment and subscription status from Stripe.
  • Purchase and redemption data from a marketplace, where you bought through one such as AppSumo.

4. Why we use it, and our legal basis

Where the GDPR or UK GDPR applies, we rely on the following legal bases.

What we doWhyLegal basis
Create and administer your account; provide the ServiceTo deliver what you signed up forPerformance of a contract
Take payment; manage subscriptions and renewalsTo bill youPerformance of a contract
Send service and transactional messages — receipts, security alerts, changes to the ServiceTo operate the accountPerformance of a contract
Provide customer supportTo answer youPerformance of a contract; legitimate interests
Monitor usage, API activity and email sending patterns to detect abuse, spam and fraudTo keep the Service and its recipients safe, and to protect deliverability for all customersLegitimate interests; legal obligation
Secure the Service, investigate incidents, and enforce our TermsTo protect the Service, our customers and third partiesLegitimate interests
Analyse how the Service is used to fix problems and improve itTo make the product betterLegitimate interests; consent where cookies require it
Send product updates, onboarding and marketing email about WaitlisterTo tell you about the product you useLegitimate interests, or consent where required. You can opt out at any time
Keep records for tax, accounting and legal claimsTo comply with the law and defend our positionLegal obligation; legitimate interests

Where we rely on legitimate interests, we have considered whether those interests are overridden by your rights. You can ask us for our assessment.

Where we rely on consent, you can withdraw it at any time. Withdrawal does not affect processing carried out before you withdrew.

5. What we do not do

We do not sell your personal data. We do not use the personal data of waitlist subscribers for our own purposes, and we do not use customer content to train artificial intelligence models, nor do we permit our AI providers to do so.

6. Cookies and similar technologies

We use cookies and similar technologies to:

  • Keep the Service working — authentication, session management, security and load balancing. These are strictly necessary and are always active.
  • Understand usage — Google Analytics, via Firebase, to see which features are used and where people run into trouble. This is the only analytics we operate.

We run no advertising or marketing measurement tags of our own.

Analytics runs only if you say yes. Nothing is collected until you press Accept on the banner shown on your first visit. Ignoring the banner has the same effect as declining it. If you accept and later change your mind, collection stops immediately — you can reopen the banner at any time from the "Cookie settings" link in the footer. Cookies already stored on your device are not removed when you decline; they remain until your browser clears them or you delete them yourself. Declining does not affect strictly necessary cookies.

We never ask a visitor who is not our customer. The banner appears only on our own pages — our marketing site, documentation, sign-in and the dashboard.

On landing pages and forms. We run no analytics of our own on any surface where the visitor is a data subject rather than our customer: customer landing pages, embedded forms, confirmation, unsubscribe and leaderboard pages, and every customer custom domain. If a customer adds their own tracking — for example a Google Tag Manager container — that is the customer's processing and their privacy notice applies, not ours.

7. Who we share it with

We share personal data only as described here.

Service providers. We use the following providers, who process personal data on our behalf under written contracts:

ProviderWhat for
Google LLC (Google Cloud, Firebase)Hosting, database, authentication, file storage, logging, analytics
Cloudflare, Inc.DNS, content delivery, bot protection, edge caching
Plus Five Five, Inc., trading as ResendSending email
Stripe, Inc.Payments and subscription billing
IPinfo Inc.Resolving IP addresses to approximate location
Anthropic, PBCAI content generation and automated abuse screening
Google LLC (Gemini API)The in-product support assistant
OpenAI, L.L.C.Image generation in the logo tool

The list of providers who process waitlist subscriber data on behalf of our customers is maintained separately, in Annex III of our Data Processing Agreement.

Others. We may also disclose personal data:

  • where required by law, or in response to a valid legal request;
  • to protect our rights, safety or property, or those of our customers or the public;
  • to investigate or prevent abuse, fraud, or breaches of our Terms; and
  • to a buyer or successor in connection with a merger, acquisition, financing or sale of assets, subject to this policy continuing to apply.

We do not otherwise disclose your personal data to third parties for their own purposes.

8. International transfers

We are based in the United States and our infrastructure is located there. If you are outside the United States, using the Service involves transferring your personal data to the United States.

Lemon Tree Ventures, LLC is not certified under the EU–US Data Privacy Framework. Where we transfer personal data out of the European Economic Area, the United Kingdom or Switzerland, we rely on the European Commission's Standard Contractual Clauses, together with the UK International Data Transfer Addendum for UK data and the equivalent recognition for Swiss data.

The same safeguards apply between us and our providers. You can ask us for a copy of the relevant clauses, and for the assessment we have documented of the laws of the United States relevant to these transfers.

9. How long we keep it

DataRetention
Account dataWhile your account is open
Account data after you close your accountDeleted within 60 days, except where we must keep it longer
Billing and tax recordsSeven (7) years from the end of the relevant tax year
Support correspondenceThree (3) years from the last message in the thread
Log and security dataThirty (30) days (Google Cloud Logging default retention)
Records relating to abuse, fraud or a terminated accountAs long as necessary to prevent recurrence and to defend legal claims
Waitlist subscriber dataGoverned by the Data Processing Agreement, not this policy

Residual copies may persist in routine backups for a short period after deletion. They are not actively used and are deleted as backups rotate.

10. Automated decision-making

We use automated systems to protect the Service:

  • Outbound email screening. Email sent through the Service is screened automatically for fraud and abuse, and may be delayed or blocked.
  • Sign-up scoring. Sign-up requests are assessed for characteristics associated with automated traffic.
  • Bot verification. Sign-up forms may present a bot-verification challenge.

Our in-product support assistant is an artificial intelligence system and is identified as such when you begin a conversation with it.

These systems can affect whether a message is sent or a sign-up is accepted. They do not produce legal effects concerning you or similarly significantly affect you within the meaning of Article 22 GDPR. If an automated decision affects you and you disagree with it, contact us and a person will review it.

11. Security

We implement technical and organisational measures appropriate to the risk, including encryption in transit and at rest, access controls, database-level security rules, tenant separation, rate limiting and bot protection. A fuller description is in Annex II of our Data Processing Agreement.

No system is completely secure. If a breach affects your personal data and is likely to result in a high risk to your rights, we will notify you without undue delay.

12. Your rights

Depending on where you live, you may have the right to:

  • access the personal data we hold about you, and receive a copy;
  • correct data that is inaccurate or incomplete;
  • delete your data;
  • restrict or object to our processing, including objecting to processing based on legitimate interests and to direct marketing at any time;
  • portability — receive your data in a structured, commonly used, machine-readable format, and have it transmitted to another provider where technically feasible;
  • withdraw consent, where we rely on it; and
  • not be discriminated against for exercising these rights.

Many of these you can exercise directly in your account settings, including exporting and deleting your data. Where the self-service tools do not cover everything you have asked for, contact us and we will provide the rest.

For anything else, contact devin@waitlister.me. We will respond within the time applicable law allows — one month under the GDPR, extendable where a request is complex. We may need to verify your identity first.

Complaints. If you are in the EEA, the UK or Switzerland, you have the right to lodge a complaint with your local supervisory authority. In Ireland this is the Data Protection Commission; in the UK, the Information Commissioner's Office; in Switzerland, the Federal Data Protection and Information Commissioner. We would appreciate the chance to address your concern first.

13. Providing your data

Providing your account and billing data is necessary for us to provide the Service. If you do not provide it, we cannot open or maintain your account. Everything else is optional.

14. Children

The Service is not directed to children and is not intended for anyone under 18. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us and we will delete it.

15. United States state privacy rights

Several US states have comprehensive privacy laws that apply to businesses meeting certain thresholds of revenue or of the number of residents whose data they process. Where such a law applies to us, and you are a resident of that state, you may have the right to know what personal information we collect and why, to access and delete it, to correct it, to obtain a portable copy, to opt out of targeted advertising and of any sale or sharing of personal information, and to appeal a decision we make about your request.

We do not sell personal information for money.

To exercise any of these rights, contact devin@waitlister.me. You may use an authorised agent. We will not discriminate against you for exercising your rights. If we decline a request, you may appeal by replying to our response.

16. Public content

Landing pages you publish through the Service are public and can be viewed and indexed by search engines.

We also operate a public directory at waitlister.me/explore. A new landing page is not listed there unless you turn listing on. You control the setting for each page in your landing page settings and can change it at any time. Pages created before this setting became opt-in keep whatever they were previously set to, so if you have an older page you would rather not see listed, check its setting.

Do not put anything on a landing page that you do not want to be public.

17. Changes to this policy

We may update this policy. If a change is material, we will give you notice by email or in the Service before it takes effect, and we will update the effective date below. Older versions are available on request.

18. Contact us

Lemon Tree Ventures, LLC
1111B S Governors Ave, STE 55103
Dover, DE 19904
United States
devin@waitlister.me

We have not appointed a Data Protection Officer, as we are not required to under Article 37 GDPR. Data protection questions go to the address above.


Effective date: 1 September 2026. Version 2.0. Supersedes the version effective 15 April 2026.