Privacy
What we collect, why, and how to make us delete it.
Last updated: 7 May 2026
1. Who is the data controller
2. What we collect when you join the waitlist
- Your email address.
- The timestamp you submitted, and the timestamp you confirmed.
- The UTM parameters of the link that brought you (so we know which channels work).
- A salted hash of your IP address and user agent. We never store the raw values; the salt rotates monthly so the hash isn’t durable.
That’s the entire list. We don’t track you across the web. We don’t use cookies for advertising. We don’t fingerprint your browser.
3. Why we collect it
The email is so we can tell you when Viani opens. The timestamps and IP hash exist for fraud-prevention and rate limiting. The UTM parameters are aggregated to know which marketing channels are working.
Legal basis: Article 6(1)(a) GDPR — consent, given by submitting your email and confirming via the double-opt-in link.
4. How long we keep it
- Unconfirmed signups: 48 hours. The confirmation token expires; an automated job purges the row.
- Confirmed signups: until you unsubscribe + 30 days. Then the row is deleted.
- IP/UA hashes: overwritten monthly when we rotate the salt — they become useless after that.
5. Subprocessors
We send your data to two services strictly necessary to run the waitlist:
- Cloudflare — hosts the database (D1) and the edge that serves this page. Data center: EU.
- Resend — sends the confirmation and welcome emails. Data center: EU.
Both have signed Data Processing Agreements with us. They cannot use your data for their own purposes.
6. Your rights
You have the right to:
- Access the data we have about you.
- Correct it (we only have your email and timestamps; the email you can change yourself by re-submitting).
- Delete it.
- Receive it in a portable format.
- Lodge a complaint with your local data protection authority.
To exercise any of the above, email support@viani.app. We respond within 30 days.
7. If we have a security incident
If a security incident affects your data, we’ll email you within 24 hours of becoming aware of it. We’ll tell you what happened, what was exposed, what wasn’t (to the extent we can determine it), and what we’re doing about it.
Where the law requires it, we’ll also notify the AEPD (Agencia Española de Protección de Datos) within 72 hours.