Is It Legal to Email My Waitlist or Beta Signups?
6 min read
Yes, you can legally email the people on your waitlist, as long as they genuinely signed up and you follow two sets of rules: CAN-SPAM in the US and GDPR (plus the ePrivacy rules) in the EU and UK. The short version: send only to people who asked to hear from you, tell them who you are, and make it one click to leave. Do that and a launch email to your signups is fine.
Why this trips people up
You built a "join the waitlist" form because it was the obvious thing to add, and your AI agent wired it straight into a table. Nobody stopped to ask what you were allowed to do with those addresses later. So now you have a list of a few hundred people and a nagging worry that hitting "send" is somehow illegal.
The rules are not really about the send. They are about consent. Someone who typed their email into your form to be told when you launch has given you permission to email them about launching. That is exactly what you are about to do. The problem only starts when you drift beyond what they agreed to, or when they can't get out.
How to check if you're clear
Ask yourself four things about your list:
- Did they opt in on purpose? A waitlist form, a "notify me" box, a beta signup, all count. A list you bought, scraped, or copied from another project does not.
- Did you say what you'd send? "Join the waitlist" reasonably implies launch news. It does not imply a daily newsletter or a partner's ads.
- Can they tell who it's from? Your emails need a real sender name and a real physical postal address in the footer. That is a hard CAN-SPAM requirement.
- Can they leave in one step? Every email needs a working unsubscribe link that takes effect within a few days and asks for nothing more than one click.
If you can answer yes to all four, send with confidence.
The fix, step by step
- Use a real email provider. Send through Resend, Mailchimp, Loops, or similar, not a raw script or your personal Gmail. They add the required unsubscribe headers, handle bounces, and keep you off spam blocklists.
- Add a physical postal address to the footer. A company address or even a registered mailbox is fine. CAN-SPAM requires one on every commercial email.
- Include a one-click unsubscribe and honour it automatically. Every reputable provider does this for you; do not disable it.
- Only email what they signed up for. Launch news, beta invites, product updates. If you later want to send a broader newsletter, ask separately.
- Record consent. Store the date, and ideally the form or page, where each person opted in. If anyone ever asks, or a regulator does, you can show it.
- Match your privacy policy. It should say you collect emails for launch updates and how to opt out. See do I need a privacy policy for a beta app.
The trap to avoid
The classic mistake is treating a waitlist as permission for everything. You collected addresses to announce a launch, then you start sending weekly tips, then a founder's diary, then a discount from a partner. Each drift takes you further from what people agreed to, and that is where complaints and unsubscribes spike, which in turn wrecks your deliverability. Under GDPR, consent is tied to a specific purpose. Stay inside the purpose people signed up for, and when you want a new one, ask again.
The other trap is hiding the unsubscribe or making people log in to use it. A broken or buried opt-out is the single most common CAN-SPAM violation, and it is trivially avoidable.
Where this fits
Emailing your signups is often the first real-world thing your app does, and it touches consent, privacy, and data handling all at once. The free Readiness Report checks whether your signup flow and privacy policy actually line up with what you're about to send, before you press the button. If you want the gaps closed for you, that is what the Finishing Pass is for. Worth reading alongside this: does GDPR apply to my small app.