← Back to Home

Privacy Policy

Last updated: 15th April 2026

This Privacy Policy explains how WatchVault collects, uses, stores, and protects your personal data. WatchVault is operated from the Netherlands and processes data in accordance with the General Data Protection Regulation (GDPR).

By using WatchVault, you acknowledge the practices described in this Privacy Policy.

01

Who we are

WatchVault is operated by WatchVault, based in the Netherlands. We are the data controller for personal data collected through this platform.

For any privacy-related questions or requests, contact us at: support@watchvault24.com

02

What data we collect and why

Account data

Your email address, collected when you register. Used to authenticate your account, send transactional emails, and contact you about your account.

Collection data

Information you choose to enter about your watches, including serial numbers, purchase prices, estimated values, insured values, dealer names, purchase locations, storage locations, and notes. This data is stored exclusively to provide you the collection management service.

Uploaded documents

Files you upload such as invoices, warranty cards, service records, and certificates of authenticity. Stored to provide document management functionality.

Usage data

Basic technical data such as server logs generated automatically when you use the platform. Used for security monitoring and platform stability.

We do not collect data for advertising purposes. We do not sell personal data to third parties. We do not use your data to train machine learning models.

03

Legal basis for processing

We process your personal data on the following legal bases under GDPR Article 6:

  • Contract performance (Article 6(1)(b)) — processing your collection data and documents is necessary to provide the service you signed up for.
  • Legitimate interests (Article 6(1)(f)) — basic security monitoring and platform stability logging.
  • Legal obligation (Article 6(1)(c)) — retaining audit records as required by applicable law.
04

How we protect your data

All sensitive fields in your collection — including serial numbers, purchase prices, and location data — are encrypted at the application level using AES-256-GCM before being stored in the database. This means our database contains only ciphertext. Uploaded documents are also encrypted before storage.

Encryption keys are managed through Doppler, a dedicated secrets management platform, and are never stored in the database. All data in transit is protected by HTTPS/TLS.

We operate a versioned key management system with a documented rotation procedure.

Important limitation: WatchVault as a platform operator holds the master encryption key and has the technical capability to decrypt your data. We do not access user data except as required to provide the service or as required by law. Per-user key derivation, which would make operator access cryptographically impossible, is on our technical roadmap.

05

Data processors

Supabase

Database, authentication, and file storage. Data is stored in the European Union. DPA signed.

Privacy policy: supabase.com/privacy

Vercel

Application hosting and deployment. DPA will be executed upon upgrade to a paid plan.

Privacy policy: vercel.com/legal/privacy-policy

OpenAI

AI-assisted features. Watch images and watch details are transmitted to OpenAI's API to generate AI-assisted outputs (image analysis and watch comparison). Data is processed solely to generate the requested output and is not used to train OpenAI models under the API terms of service.

Privacy policy: openai.com/policies/privacy-policy

Resend

Transactional email delivery. Used only to send account-related emails such as deletion confirmations and welcome emails.

Privacy policy: resend.com/legal/privacy-policy

Doppler

Secrets and encryption key management.

Privacy policy: doppler.com/legal/privacy

Upstash

Distributed rate limiting. Client IP addresses are stored transiently as rate limit counters to prevent platform abuse.

Privacy policy: upstash.com/trust/privacy.pdf

06

Data retention

We retain your personal data for as long as your account is active. When you delete your account, all personal data is permanently deleted immediately, including all collection data, uploaded documents, and your authentication record.

Supabase automated backups may retain encrypted data for up to 7 days following account deletion before being permanently purged from backup systems.

Anonymised audit records — containing only a hashed identifier and timestamps, with no personally identifiable information — are retained for a maximum of 12 months for legal compliance purposes.

07

Your rights under GDPR

As an EU resident you have the following rights:

  • Right of access (Article 15) — you can request a copy of the personal data we hold about you.
  • Right to rectification (Article 16) — you can correct inaccurate data directly within the platform at any time.
  • Right to erasure (Article 17) — you can permanently delete your account and all associated data at any time from the account settings page. Deletion is immediate, permanent, and irreversible. See Section 8 for full details.
  • Right to restriction of processing (Article 18) — you can request that we restrict processing of your data in certain circumstances.
  • Right to data portability (Article 20) — you can export your collection data at any time using the export function in the platform.
  • Right to object (Article 21) — you can object to processing based on legitimate interests.

To exercise any of these rights, contact us at support@watchvault24.com. We will respond within 30 days.

08

Account deletion and right to erasure

You can delete your account at any time from the account settings page. When you request deletion, the following happens immediately and permanently:

  • All encrypted files stored in our file storage system are deleted.
  • All watch collection data is deleted from the database.
  • All associated documents and images are deleted.
  • Your profile is deleted.
  • Your authentication record is permanently deleted, which simultaneously invalidates all active sessions across all your devices.
  • A confirmation email is sent to your email address.

Deletion is hard and permanent. There is no soft delete, no recovery path, and no way to restore your account or data after deletion is completed.

09

Cookies

WatchVault uses only technically necessary cookies required for authentication — specifically session cookies issued by Supabase to maintain your logged-in state. We do not use advertising cookies, tracking cookies, or analytics cookies.

10

Children

WatchVault is not directed at children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us and we will delete it promptly.

11

Changes to this policy

We will notify you by email of any material changes to this Privacy Policy before they take effect. The date at the top of this document reflects the most recent update.

12

Contact

For any questions about this Privacy Policy or to exercise your rights:

support@watchvault24.com

© 2026 WatchVault. All rights reserved.

Terms of Use →