Privacy Policy

Last updated: April 2, 2026

1. Who we are

fstlaunch ("we", "us", "our") is a SaaS platform that lets founders create referral-powered waitlists. This policy explains how we handle personal data when you use our website and services.

2. Data we collect

Account data (founders): When you create an account we collect your email address and, if you use Google sign-in, your name and profile picture. This data comes from Supabase Auth.

Waitlist signup data: When someone signs up for a waitlist we collect their name, email address, and referral information (referral code used, referrals made).

Billing data: If you subscribe to a paid plan, Stripe processes your payment details. We store your Stripe customer ID and subscription status but never your card number.

Usage data: We collect standard server logs (IP address, browser type, pages visited) to operate and secure the service.

3. How we use your data

  • To provide, maintain, and improve the service
  • To authenticate you and protect your account
  • To process payments and manage subscriptions
  • To send transactional emails (e.g. daily founder digests, waitlist confirmations)
  • To generate aggregated, non-identifying analytics for founders (signup counts, referral leaderboards)

We do not sell your personal data. We do not use your data for advertising or profiling.

4. Third-party services

We share data only with the providers necessary to run the service:

  • Supabase — database hosting and authentication
  • Stripe — payment processing
  • Resend — transactional email delivery
  • Vercel — application hosting

Each provider processes data under their own privacy policy and is contractually obligated to protect it.

5. Cookies

We use only strictly necessary cookies:

  • Authentication cookies (set by Supabase) — keep you logged in across sessions
  • Site access cookie — remembers password-gate authentication for 7 days

We do not use analytics, advertising, or third-party tracking cookies. Because our cookies are strictly necessary for the service to function, no consent banner is required under GDPR/ePrivacy regulations.

6. Data retention

We retain your data for as long as your account is active or as needed to provide the service. Waitlist signup data is retained for the lifetime of the waitlist. If you delete your account or a founder deletes their waitlist, associated data is removed within 30 days.

7. Your rights

Depending on your jurisdiction you may have the right to access, correct, delete, or export your personal data. To exercise any of these rights, contact us at the email below. We will respond within 30 days.

8. Security

We use encryption in transit (TLS), row-level security at the database level, and restrict access to production data to essential personnel only.

9. Changes to this policy

We may update this policy from time to time. Material changes will be communicated via email or an in-app notice. Continued use of the service after changes constitutes acceptance.

10. Contact

For privacy-related questions or requests, email us at support@fstlaunch.com.