Skip to content

How does Walk-In Waitlist protect your data?

Every table is protected by row-level security, so each shop only reaches its own data, and data is encrypted in transit and at rest. We keep as little as we can: customers have no accounts, and phone numbers are deleted 30 days after the visit.

Where is the data stored?

In a Postgres database run by Supabase in the United States, with row-level security on every table. Customers never write to the database directly: every action goes through a checked function tied to their visit.

How long do you keep customer data?

Phone numbers: deleted 30 days after the visit. A scrambled code of the number stays so a shop can see repeat no-shows.

Text message contents: 30 days. Replies from customers: 90 days.

The private link to a customer's spot: expires after about 12 hours.

Customers can delete their name and number sooner with Delete my info.

How does the team sign in?

With a 6-digit code sent to their email, so there are no passwords to steal. On a shared tablet, the owner can lock Settings with a PIN. Payments go through Stripe, and we never see or store card numbers.

How do you stop spam on the join page?

An invisible Cloudflare Turnstile check blocks bots, and too many joins from one connection are refused.

How do I report a security problem?

Email our support email (coming soon) with "Security" in the subject. Tell us what you found, how to reproduce it and how to reach you. Please give us time to fix it before you share it, and don't access other people's data.

Try it at your shop

Free for 14 days, no card needed. Most shops are set up in about 10 minutes.