Privacy Policy

Last updated: July 28, 2026

This Privacy Policy explains how Tommachi AS, the company behind MyWaitlist.app (“we”, “us”), collects and processes personal data. We follow the EU General Data Protection Regulation (GDPR) and the Norwegian Personal Data Act (personopplysningsloven).

MyWaitlist.app is a waitlist and booking-request tool for appointment-based businesses. This means we handle data in two different roles, and it is important to know which one applies to you — see section 2.

1. Who we are (data controller)

The controller for the personal data described in this policy — except for client data covered by section 2 — is:

  • Tommachi AS, org. no. 914 824 680 MVA
  • Waldemars hage 6, 0175 Oslo, Norway
  • Privacy contact: support@mywaitlist.app

We have not appointed a statutory Data Protection Officer, as we are not required to. Privacy questions go to the address above.

2. Our two roles: controller vs. processor

Account data — we are the controller

For the people who create and run a MyWaitlist.app account (business owners and their team members), we decide how and why the data is used, so we are the data controller. This policy governs that data.

Client data you enter — we are your processor

For the information a business enters about the people on its waitlist (names, contact details, preferences, notes and photos), the business is the controller and we act only as its data processor. We process that data solely on the business's instructions, under our Data Processing Agreement. If you are a client of a business that uses MyWaitlist.app and want your data corrected or deleted, please contact that business directly — they control it, and can delete it permanently from within the app.

3. What data we collect (as controller)

Data you give us

  • Account & profile: your name, email address, password (stored only as a secure hash), and — if you use it — the Google account you sign in with.
  • Business details: business name, your public handle, industry, logo and cover photo, welcome text, booking policy and other page settings.
  • Team: the names, roles and email addresses of colleagues you invite.
  • Billing: your plan, subscription status and billing contact. Card payments are handled by Stripe — we never see or store full card numbers.
  • Support: anything you send us by email.

Data we collect automatically

  • Technical & security logs: IP address, browser type and timestamps, used to run, secure and debug the service.
  • Bot-protection signals: when you join a waitlist, Cloudflare Turnstile processes your IP address and browser signals to block automated abuse.
  • Analytics: Vercel Web Analytics counts page views without cookies and without identifying you. Google Analytics runs only if you accept it in the cookie banner. See our Cookie Policy.

4. Why we use it and our legal basis

  • To provide the service — creating your account, showing your waitlist, and sending the offers and invitations you trigger. Basis: performance of a contract (GDPR art. 6(1)(b)).
  • To handle payments and keep accounts — processing your subscription and retaining invoices. Basis: contract and legal obligation (art. 6(1)(b) and (c), incl. the Norwegian Bookkeeping Act).
  • To secure and improve the service — logging, fraud and bot prevention, and privacy-friendly analytics. Basis: legitimate interests (art. 6(1)(f)) in running a safe, reliable product.
  • Optional analytics cookies — Google Analytics. Basis: your consent (art. 6(1)(a)), which you can withdraw at any time.
  • To communicate with you — service and account emails you need to receive. Basis: contract and legitimate interests.

We do not sell your data, we do not use it for third-party advertising, and we do not make automated decisions that produce legal or similarly significant effects about you.

5. Who we share it with (processors)

We use a small set of carefully chosen sub-processors, each bound by a data-processing agreement and permitted to use the data only to deliver its part of the service:

  • Supabase — database, authentication and image storage, hosted in the EU (AWS, Ireland).
  • Vercel — application hosting and cookieless web analytics.
  • Stripe — subscription billing and card processing.
  • Resend — sending transactional email (offers, invitations and account notifications).
  • Cloudflare — bot protection (Turnstile) on the public waitlist forms.
  • Google— the optional “Sign in with Google” button and, only with your consent, Google Analytics.

We may also disclose data where required by law, or to establish or defend legal claims. If we are ever involved in a merger or acquisition, we will notify you before your data becomes subject to a different privacy policy.

6. International transfers

Your account and client data is stored in the EU. Some of the providers above are based outside the EU/EEA (for example in the United States). Where data leaves the EEA, the transfer is protected by the European Commission's Standard Contractual Clauses and, where the provider is certified, the EU–U.S. Data Privacy Framework, together with additional safeguards — so your data keeps GDPR-level protection. You can request a copy of the relevant safeguards from us.

7. How long we keep it

  • While your account is active — we keep your account and business data for as long as you use MyWaitlist.app.
  • Client photos — deleted automatically 30 days after a client has nothing active on the waitlist. Photos of people are held for as long as the appointment they were brought for, and no longer.
  • Waitlist entries you remove — deleted automatically 30 days after you remove them, so an accidental removal can still be undone.
  • After you delete your account — your data is removed from our live systems within 30 days, and cycled out of encrypted backups on our normal rotation shortly after.
  • Billing records — kept for up to 5 years where the Norwegian Bookkeeping Act requires it.
  • Security logs — kept only as long as needed for security and troubleshooting, then deleted.

8. How we protect it

Data is encrypted in transit and at rest. Access is isolated per account using database row-level security, and administrative access is limited to what is strictly necessary. If a personal-data breach ever affects your rights, we will notify the Norwegian Data Protection Authority and, where required, you, without undue delay.

9. Your rights

Under the GDPR you have the right to:

  • access the personal data we hold about you;
  • have inaccurate data corrected;
  • have your data erased;
  • restrict or object to certain processing;
  • receive your data in a portable format;
  • withdraw consent at any time (for example for analytics cookies), without affecting processing already carried out.

To exercise any of these, email support@mywaitlist.app. You can also export or delete most of your data yourself from your account settings. We respond within one month.

10. Complaints

If you believe we handle your data unlawfully, you can complain to the Norwegian Data Protection Authority (Datatilsynet), P.O. Box 458 Sentrum, 0105 Oslo, datatilsynet.no. We would appreciate the chance to resolve it with you first.

11. Children

MyWaitlist.app is a business tool and is not directed at children. Businesses that add clients under 16 are responsible for having a valid legal basis to do so.

12. Changes to this policy

We may update this policy from time to time. We will change the “last updated” date above and, for material changes, notify you in the app or by email.