Skip to the notice
TasteLog

A Noxysoft project

What we keep, and why

The waitlist form asks for your email address. This page says what happens to it, what else gets recorded, how long any of it stays, who else can see it, and how to make us delete it.

Who we are

TasteLog is made by Noxysoft, a one-engineer studio in the Netherlands. Noxysoft decides what happens to everything below, so Noxysoft is who you are dealing with.

  • Noxysoft
  • KvK 92505481
  • btw-id NL004957538B97
  • contact@noxysoft.com

We have no data protection officer. The law asks for one when an organisation monitors people at scale or handles sensitive data as its core business, and a waitlist is neither.

What we store when you sign up

Joining the waitlist records six things.

Your email address
So we can tell you the day TasteLog launches. We keep it because you agreed to that when you signed up — in the language of the GDPR, consent under Article 6(1)(a). You can take that back whenever you like.
When you signed up
The moment your entry was recorded. It is what the two-year backstop below counts from, and we keep it for as long as we keep the address.
The words you agreed to
The exact sentence that was under the form, which version of it, and the moment you submitted. We keep this so that we can show what you were actually told, rather than what the page happens to say today.
Your IP address
Recorded automatically when you submit. It does two separate jobs and we would rather name both: it lets us spot and slow down anyone hammering the form, and it forms part of the record above.
Your browser's user agent
A line your browser sends with every request, naming itself and the operating system. Recorded automatically and kept with the rest of the record. Nothing in our software reads it today — the limit that slows down bulk submissions works from the IP address alone — and it is kept so that a burst of automated signups can be told apart from real people after the fact.
Where you arrived from
The page that linked you here, and the campaign name if the link carried one. This tells us which of our own pages are worth keeping. It is often empty.

The last three are kept on what the GDPR calls legitimate interest, under Article 6(1)(f). Those interests, spelled out rather than just named: your IP address keeps the form working, by making automated abuse stoppable as it happens, and your browser's user agent makes a burst of it recognisable afterwards; your IP address also evidences your consent, by recording who agreed and when; and where you arrived from tells us which of our own pages are worth keeping. You can object to any of it — see below.

Giving us your address is entirely voluntary. There is no law and no contract requiring it. The only consequence of not giving it is that we cannot tell you when TasteLog launches.

How long we keep it

We keep your address until whichever of these happens first:

  • you ask us to remove you;
  • TasteLog launches and the launch email has gone out;
  • 24 months have passed since you signed up.

The last one is a backstop. A waitlist address that is two years old belongs to somebody who has forgotten us, and nobody is served by our holding it.

Who else can see your address

We do not sell your address and we do not hand it to anybody to use for their own ends. That is what never shared or sold means on the form, and it is true.

Four companies do hold it, because they run the machinery this site sits on:

Cloudflare
Serves this page and filters malicious traffic.
Railway
Runs the site and the service behind the form.
Neon
Runs the database that stores your address. Neon is a product of Databricks, Inc.
Amazon Web Services
Owns the machines that database runs on, in Frankfurt. We chose Neon, and Neon runs on Amazon, so Amazon holds your address too.

They store and move your address so that the site can work at all. Each acts on the instructions of whoever brought it in — Amazon takes none from us directly, it takes Neon's — and none of them may use it for anything of their own. They can pass it to companies they in turn depend on — Amazon above is exactly that — but only to the ones on their own published lists, bound by the same obligations, and never for those companies' own purposes.

Those lists are public, and we would rather send you to them than summarise them: Cloudflare's, Railway's, and the Databricks one that covers Neon. They are longer than this page. That is the honest answer to "who else touches it", and a short one would be a nicer-sounding lie.

Listing them is not the same as sharing your address, and we would rather name them than leave you guessing.

The service that sends the launch email will be Keila. It will be added to this list before the first email goes out, not after.

Where your address is stored

The database holding your address runs in Frankfurt, and the site itself runs in Amsterdam. Both are inside the European Union.

That is not the whole answer, because where a machine sits and where a company operates are two different things. All four companies above are American:

Cloudflare
Sits in front of every request, so your IP address passes through its network on the way to us.
Railway
Runs the site from Amsterdam, but its own data protection agreement states that its primary processing takes place in the United States.
Neon
Keeps the database in Frankfurt, but Neon is part of Databricks, Inc., an American company whose staff can reach that database in order to run it.
Amazon Web Services
Keeps those machines in Frankfurt, and is an American company as well. The same gap between where a machine sits and where a company operates applies to it.

So some of your details do leave the European Economic Area. Each of them is covered differently, and we would rather set that out than give you one sentence that is only mostly true.

Cloudflare
Covered by the standard contractual clauses — terms written and approved by the European Commission for exactly this situation. They reach us through Cloudflare's data processing addendum, which its terms fold into every account rather than negotiate one at a time. Nobody here sat down and signed a bespoke contract, and we would rather say that than let "agreed with us" suggest a negotiation that never happened.
Neon
Covered by an adequacy decision instead. Databricks, Inc., which owns Neon, currently holds a certification under the EU-U.S. Data Privacy Framework, and Neon, LLC — the company that actually runs the database — is named in it. The European Commission has ruled that framework gives protection equivalent to keeping your details in Europe. You can check it yourself on the official participant list — search for Databricks, not Neon: there is an unrelated, lapsed "Neon Inc." on that list, and it is not this one.
Railway
Also covered by the standard contractual clauses, and by the same mechanism as Cloudflare: Railway's terms of service fold its data processing addendum into every account, and that addendum states the clauses are entered into by both parties. Nobody here negotiated or signed anything bespoke. It is the same agreement this page quotes further up, where it says Railway's primary processing takes place in the United States.

Two more sit a step further away, and we can tell you less about them. Amazon holds your address because Neon runs on Amazon, and Amazon is named on the published list above. Grafana Labs, in the United States, is not: it appears in Neon's product-specific schedule, at clause 3.2, which names it for infrastructure services in addition to everyone on that list. So do not go looking for it there — we are telling you about it because leaving it out would have been the easier thing to do. We do not know whether your address ever reaches it, because that happens inside Neon's systems where we cannot see. In both cases the protection is in Neon's contract with them, not in ours.

This site sets no cookies

No cookies, no analytics, no trackers, no embedded videos, maps or fonts. Every file this page loads comes from tastelog.net. We store nothing about you on your machine — no cookies, no site data — though your browser does keep copies of the page's own files for a while, as it does on any site. And nothing about you reaches our database unless you fill in the form and press the button.

The request itself is another matter, and it is not ours to leave out. Every page you ask for arrives through Cloudflare and then Railway, and both keep request logs — what was asked for, when, and the IP address and browser it was asked from. That is how the page is served at all, and how malicious traffic is filtered. Cloudflare also asks your browser to report failed requests back to it; successful ones are not reported. We read those logs to keep the site working, never to build a picture of you, and nothing in them is copied into our database — but "nothing is recorded" would not be true, so we are not going to say it.

If any of that changes, this page changes on the same day — not afterwards.

Nothing here profiles you

There is no profiling and no automated decision-making. Your address sits in a list until we email it. Nothing scores you, sorts you, or ranks you against anybody else.

One thing is automatic, and we would rather name it than have you find it: if the same IP address submits the form many times within a few minutes, the form turns the later ones away until the burst stops. That is the abuse limit described further up. It reads how many requests arrived and from where, never who you are or what you wrote, and the only thing it decides is whether that submission goes through.

What you can ask us to do

Write to contact@noxysoft.com and ask us to:

  • tell you everything we hold about you;
  • correct it, if we have it wrong;
  • delete it;
  • stop using it for a while, without deleting it;
  • object to our keeping your IP address and browser details;
  • send you your details in a portable file, or pass them to someone else;
  • take back your consent, which stops the emails.

You do not have to give a reason, and asking costs you nothing. Taking back your consent does not undo the emails we already sent, and it does not make them improper. We answer within one month, which is the limit the law sets.

If you think we have got this wrong

You can complain to the Dutch data protection authority, the Autoriteit Persoonsgegevens. You are welcome to tell us first, but you do not have to.

When this page changes

We update this page when what we do changes, and the date below is the day it last changed.

Last updated 25 August 2026.

Back to the front page

© 2026 Noxysoft

  • Privacy and company details
  • noxysoft.com
  • Back to top