Privacy policy
Last updated 6 October 2026
This policy explains what we collect when you visit sendlark.io or join the Sendlark waitlist, why we collect it, and the rights you have under the EU and UK General Data Protection Regulation (GDPR) and Thailand's Personal Data Protection Act B.E. 2562 (PDPA). We keep it short because we collect very little.
Who we are
Sendlark is run by Jittramas Kumpeepong, an individual based in Thailand, who is the data controller for the information described here. “We” in this policy means Jittramas, as Sendlark's founder. Contact us at privacy@sendlark.io for any privacy question or request.
What we collect
- Your email address, when you join the waitlist.
- Plan interest, if you tell us which plan you're considering.
- Payment details, only if you pay the optional founding-member deposit. Stripe processes your card; we receive your name, email, amount and payment status, never your card number.
- Technical data: your IP address and browser type, which our hosting provider logs when you visit, and which we use briefly to block abuse of the sign-up form.
We don't use advertising or analytics cookies, and we don't buy, sell or rent personal data.
Why we use it, and our legal basis
- To run the waitlist: confirm your sign-up, tell you when early access opens and send occasional launch updates. Basis: your consent, given when you join. You can withdraw it at any time with the unsubscribe link in every email.
- To handle your deposit, apply your founding credit to your invoices or refund it. Basis: contract (taking steps at your request before entering a contract).
- To keep records the law requires, such as payment and tax records. Basis: legal obligation.
- To keep the site secure and stop spam sign-ups. Basis: our legitimate interests, which we balance against your rights.
Giving us your email is voluntary, but we can't add you to the waitlist without it. We don't make automated decisions about you that have legal or similarly significant effects.
Who we share it with
Only the service providers that help us run Sendlark. They process data on our instructions under data processing agreements and may not use it for their own purposes.
| Provider | What it does | Where |
|---|---|---|
| Vercel | Hosts this website. Sees your IP address when you visit. | USA / global |
| Neon | Database that stores the waitlist. | USA |
| Resend | Sends the confirmation and launch emails. | USA |
| Upstash | Limits repeated sign-up attempts using your IP address, kept briefly. | USA |
| Stripe | Takes the optional $29 founding-member deposit. We never see your card number. | USA / global |
We may also disclose data if the law requires it, for example to a court or regulator.
International transfers
Some providers store or process data outside Thailand, the EU and the UK, mainly in the United States. When data leaves those regions we rely on safeguards the law recognises, such as the European Commission's Standard Contractual Clauses (and the UK addendum) or the provider's certification under the EU-US Data Privacy Framework, and on equivalent safeguards under Section 28–29 of the PDPA. Ask us for a copy of the relevant safeguards.
How long we keep it
- Waitlist emails: until you unsubscribe or ask us to delete them, and no longer than 12 months after Sendlark launches if you don't create an account.
- Deposit and payment records: as long as accounting and tax law requires, generally 5 years in Thailand.
- Security logs: up to 30 days.
Your rights
Under the GDPR and the PDPA you can ask us to:
- give you a copy of your data (access)
- correct it if it's wrong
- delete it
- restrict or object to how we use it
- send it to you or another company in a machine-readable format (portability)
- withdraw your consent at any time, without affecting what we did before
Email privacy@sendlark.io. We reply within 30 days and may ask you to confirm it's your email address first. It's free.
If you think we've mishandled your data, you can complain to a regulator: in Thailand, the Office of the Personal Data Protection Committee (PDPC); in the EU, the data protection authority where you live or work; in the UK, the Information Commissioner's Office (ICO). We'd appreciate the chance to fix it first.
Security
Data is encrypted in transit and at rest with our providers, and access is limited to the people who run Sendlark. If a breach puts your data at risk, we'll notify the regulator within 72 hours and tell you without undue delay where the law requires it.
Children
Sendlark is a business tool and isn't meant for children. Please don't join the waitlist if you're under 16, or under 20 in Thailand without a parent's or guardian's consent.
Changes
We'll update this page when what we collect changes, for example when the product launches, and change the date at the top. If a change is significant, we'll email people on the waitlist first.