Privacy Policy
Last updated: April 2, 2026
1. Who we are
fstlaunch ("we", "us", "our") is a SaaS platform that lets founders create referral-powered waitlists. This policy explains how we handle personal data when you use our website and services.
2. Data we collect
Account data (founders): When you create an account we collect your email address and, if you use Google sign-in, your name and profile picture. This data comes from Supabase Auth.
Waitlist signup data: When someone signs up for a waitlist we collect their name, email address, and referral information (referral code used, referrals made).
Billing data: If you subscribe to a paid plan, Stripe processes your payment details. We store your Stripe customer ID and subscription status but never your card number.
Usage data: We collect standard server logs (IP address, browser type, pages visited) to operate and secure the service.
3. How we use your data
- To provide, maintain, and improve the service
- To authenticate you and protect your account
- To process payments and manage subscriptions
- To send transactional emails (e.g. daily founder digests, waitlist confirmations)
- To generate aggregated, non-identifying analytics for founders (signup counts, referral leaderboards)
We do not sell your personal data. We do not use your data for advertising or profiling.
4. Third-party services
We share data only with the providers necessary to run the service:
- Supabase — database hosting and authentication
- Stripe — payment processing
- Resend — transactional email delivery
- Vercel — application hosting
Each provider processes data under their own privacy policy and is contractually obligated to protect it.
5. Cookies
We use only strictly necessary cookies:
- Authentication cookies (set by Supabase) — keep you logged in across sessions
- Site access cookie — remembers password-gate authentication for 7 days
We do not use analytics, advertising, or third-party tracking cookies. Because our cookies are strictly necessary for the service to function, no consent banner is required under GDPR/ePrivacy regulations.
6. Data retention
We retain your data for as long as your account is active or as needed to provide the service. Waitlist signup data is retained for the lifetime of the waitlist. If you delete your account or a founder deletes their waitlist, associated data is removed within 30 days.
7. Your rights
Depending on your jurisdiction you may have the right to access, correct, delete, or export your personal data. To exercise any of these rights, contact us at the email below. We will respond within 30 days.
8. Security
We use encryption in transit (TLS), row-level security at the database level, and restrict access to production data to essential personnel only.
9. Changes to this policy
We may update this policy from time to time. Material changes will be communicated via email or an in-app notice. Continued use of the service after changes constitutes acceptance.
10. Contact
For privacy-related questions or requests, email us at support@fstlaunch.com.