Privacy Policy
Last updated: 29 August 2026
This Privacy Policy explains how MJM Dev (“we”, “us”, “our”) collects and uses personal data when you use Waitlio at waitlio.co.uk (the “Service”). Waitlio is a product of MJM Dev, a sole trader based in the United Kingdom.
We are based in the United Kingdom. We process personal data in line with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. Where relevant, the UK Privacy and Electronic Communications Regulations (PECR) also apply to cookies and electronic communications.
1. Who we are (data controller)
For account holders (people who register to create and manage waitlists), MJM Dev is the data controller.
For people who join a waitlist on a customer's public page (“subscribers”), the campaign owner is typically the controller of that signup data. We act as their data processor and process subscriber data only to provide the Service.
- Operator: MJM Dev, a sole trader based in the United Kingdom
- Contact: support request form
2. Personal data we collect
Account holders
- Name and email address
- Password (stored as a one-way hash - we never store plaintext passwords)
- Plan tier and billing status
- Stripe customer and subscription identifiers (payment card details are handled by Stripe and are not stored on our servers)
- Campaign content you create (name, slug, tagline, description, colours)
- Technical logs such as IP address used for rate limiting and abuse prevention
Waitlist subscribers
- Email address (required)
- First name (optional)
- Referral code, referrer, and queue position
- Signup time and related campaign identifiers
Automatically collected
- Essential session cookies (JWT) used to keep you signed in securely
- Basic request metadata needed to operate and secure the Service (for example IP address for rate limits)
We do not currently use non-essential analytics, advertising, or tracking cookies.
3. Why we use your data (lawful bases)
Under UK GDPR we rely on the following lawful bases:
- Contract - to create and manage your account, run campaigns, process subscriptions, and provide the Service you requested.
- Legitimate interests - to secure the Service (rate limiting, fraud/abuse prevention), improve reliability, and communicate important service notices. You may object where applicable.
- Legal obligation - where we must retain or disclose information to meet tax, accounting, or other legal requirements.
- Consent - only where required (for example optional marketing email if we introduce it later). You can withdraw consent at any time.
For waitlist subscribers, the campaign owner is responsible for ensuring they have a lawful basis to collect emails (typically legitimate interests for a product waitlist, or consent where they use the list for marketing).
4. How we use personal data
- Provide, maintain, and improve the Service
- Authenticate users and protect accounts
- Process payments and manage subscriptions via Stripe
- Enforce plan limits and prevent abuse
- Respond to support requests
- Comply with applicable law
We do not sell personal data. We do not use waitlist subscriber emails for our own marketing.
5. Sharing and processors
We share personal data only with trusted processors who help us run the Service:
- Stripe - payment processing and billing. Stripe acts as an independent controller or processor for payment data under its own terms. See Stripe's privacy policy.
- Google reCAPTCHA - bot protection on forms. Google may collect device and usage data under its own terms. See Google's privacy policy.
- Hosting / infrastructure - cloud providers used to host the application and database (for example Vercel and a managed PostgreSQL provider). Data may be processed in the UK, EEA, or other regions with appropriate safeguards.
We may disclose data if required by law, court order, or to protect the rights, property, or safety of Waitlio, our users, or others.
6. International transfers
If personal data is transferred outside the UK, we ensure appropriate safeguards are in place (such as the UK International Data Transfer Agreement / Addendum, or adequacy regulations) where required by UK GDPR.
7. Retention
- Account data is kept for as long as your account remains active, and for a reasonable period afterwards where needed for disputes, security, or legal retention (for example billing records).
- Waitlist subscriber data is retained while the related campaign and account exist, or until the campaign owner deletes it / asks us to erase it, subject to legal holds.
- Security and rate-limit logs are kept only as long as needed for those purposes.
8. Cookies
We use strictly necessary cookies to authenticate your session after you sign in. These are required for the Service to work and do not require consent under PECR.
If we later add non-essential cookies (analytics or marketing), we will update this policy and, where required, ask for consent.
9. Your rights (UK GDPR)
Depending on your circumstances, you have the right to:
- Access your personal data
- Rectify inaccurate data
- Erase data (“right to be forgotten”) in certain cases
- Restrict or object to processing
- Data portability
- Withdraw consent where processing is based on consent
- Complain to the UK Information Commissioner's Office (ICO)
You can permanently delete your account yourself from Account settings (email confirmation required). That removes your account data, campaigns, and subscribers, and cancels any active subscription.
For other rights, use our support request form. We may need to verify your identity before responding.
ICO contact: ico.org.uk. You can also find their helpline and complaint process on that site.
Waitlist subscribers should usually contact the campaign owner first. We can assist where we act as processor.
10. Children
The Service is aimed at adults running product launches. You must be at least 18 to create an account. We do not knowingly collect personal data from children. If you believe a child has provided data, contact us and we will take appropriate steps.
11. Security
We use industry-standard measures such as hashed passwords, HTTPS, signed session tokens, and rate limiting. No method of transmission or storage is completely secure; please use a strong unique password.
12. Changes
We may update this Privacy Policy from time to time. The “Last updated” date at the top will change when we do. Significant changes may be highlighted on the Service or by email where appropriate.
13. Contact
For privacy questions or general support, use our support request form. We do not publish an email address on this site.