Waitlist  /  Consent & legal

Consent & legal

Collecting an email is processing personal data, so the form is GDPR-ready out of the box. The Consent & Legal section lives on the app's Waitlist tab, right below Text & languages.

Two distinct things

Marketing consentPrivacy notice
Required?Always optional (a real choice)Shown automatically
PurposePermission to send promotional emails later.Tells the visitor how their email is used (GDPR Art. 13).
UIAn unticked checkbox the visitor may tick.A short line of text under the form.
PlanEvery planEvery plan
Under GDPR, marketing consent must never be required to join — Onelo keeps it optional by design. Joining the waitlist and agreeing to marketing are separate decisions.

The privacy notice

Whenever a Privacy Policy link resolves for the app, a short notice appears under the form. The wording is editable per language (with a built-in default), and supports these variables:

VariableResolves to
{{app_name}}Your application name.
{{privacy_policy_url}}Your Privacy Policy link (see below).
{{terms_url}}Your Terms link (see below).

Where the legal links come from

You never paste a URL into the form. The Privacy Policy and Terms links are pulled automatically from your app's Legal documents:

1

Author your documents once

In the app's Legal section, create your Privacy Policy and Terms — either Onelo-hosted documents or links to your own external pages.
2

They appear under every form

The waitlist form (and your store, and consent screens) link to those documents automatically. Update the document and every surface updates with it.
3

The right language is matched

Legal documents can have language variants. When the form renders in German, it links the German Privacy Policy; if that version has no German variant yet, it falls back to the default-language text of the same version — never an older one — so the link and the consent record stay consistent.
Keep your Privacy Policy & Terms filled in. They are also required by EU/UK consumer law once a paywall is involved.

What gets recorded

Every consent is stored as an auditable record: which purposes were agreed, the exact text the visitor saw, the specific legal-document version linked, and a SHA-256-hashed IP address (never stored in the clear) as evidence. You can export these records to CSV. This is your proof of consent if you are ever asked for it.

Consent & legal — Onelo Docs