Information the signup collects
The form requires an email address, role, primary workflow need, and explicit permission to receive relevant product or research updates. It also records the selected product interest when one is provided.
Name and organization are optional. To understand which page or campaign led to a signup, the form may record the source page, referring page, and standard campaign parameters. The server also stores a shortened user-agent string for support and abuse investigation.
Current role, workflow, product interest, and source live in a per-email profile. A bounded history keeps the most recent signup or verification events, and separate historical segment sets record categories the person has selected over time. Current preferences and historical interests are intentionally separate.
A hidden bot trap and temporary keyed identifiers are used for spam prevention and rate limiting. One identifier is based on the Cloudflare connection address and another on the normalized email address. The raw network address is not added to the waitlist profile.
How the information is used
- Send product, beta, research, or launch updates related to a confirmed address.
- Understand which professional audiences and workflow problems deserve attention.
- Respond to access requests or direct questions.
- Detect duplicate, abusive, or automated submissions.
DepoStack does not sell waitlist information. Joining the waitlist does not create a product account, require a password, or enroll the person in a paid service.
Email verification and update eligibility
A submitted address is stored as pending confirmation. It is not eligible for automated product or research email until control of the address has been verified. Only records in the confirmed-address set may be used for automated outbound updates.
When email confirmation is enabled, a signed link is sent through Resend and expires after 48 hours. Opening the link displays a review page; confirmation requires a separate action on that page. A new form submission replaces the current confirmation value, so older links can no longer approve changed preferences.
Submitting the form again updates the current role, workflow, and product preference, preserves a bounded history, and returns the record to pending confirmation. This prevents an unverified request from silently changing an address that was previously eligible for updates.
Service providers and storage
The marketing site and signup endpoint run on Cloudflare Workers. Signup records are stored in Upstash Redis. These providers process information only as needed to host, secure, and operate the signup flow.
When Cloudflare Turnstile is configured, Cloudflare also processes the challenge token and related security signals. Turnstile tokens are validated by the server and are not stored in the waitlist profile.
Resend processes the submitted email address and the transactional confirmation message when email verification is enabled. The Resend API credential and confirmation-signing secret remain server-side. A confirmation email does not by itself add the address to the confirmed marketing audience.
Information may also be disclosed when required by law, to protect the service or its users, or in connection with a legitimate business reorganization. DepoStack does not provide waitlist records to unrelated advertisers.
Retention and your choices
Waitlist information is retained while it remains useful for the requested updates or product research, unless deletion is requested sooner. Per-email event history is bounded, and temporary rate-limit identifiers expire automatically.
You may ask to access, correct, or delete a waitlist record. The deletion operation removes the current profile, bounded history, compatibility metadata, confirmation state, and known current or historical segment memberships. A deletion request may require verification that the requester controls the submitted email address.
You may stop updates by replying to an email or contacting Andrew directly. An address may also be returned to pending status when its preferences are changed.
Security
DepoStack uses encrypted provider connections, strict same-origin requests, streamed request size limits, server-side allowlists, atomic Redis transactions, keyed rate-limit identifiers, a bot trap, and optional challenge verification. No internet service can promise absolute security.
Contact
Questions or privacy requests can be sent to me@andrewmayes.com.