Last updated: 15th April 2026
This Privacy Policy explains how WatchVault collects, uses, stores, and protects your personal data. WatchVault is operated from the Netherlands and processes data in accordance with the General Data Protection Regulation (GDPR).
By using WatchVault, you acknowledge the practices described in this Privacy Policy.
WatchVault is operated by WatchVault, based in the Netherlands. We are the data controller for personal data collected through this platform.
For any privacy-related questions or requests, contact us at: support@watchvault24.com
Account data
Your email address, collected when you register. Used to authenticate your account, send transactional emails, and contact you about your account.
Collection data
Information you choose to enter about your watches, including serial numbers, purchase prices, estimated values, insured values, dealer names, purchase locations, storage locations, and notes. This data is stored exclusively to provide you the collection management service.
Uploaded documents
Files you upload such as invoices, warranty cards, service records, and certificates of authenticity. Stored to provide document management functionality.
Usage data
Basic technical data such as server logs generated automatically when you use the platform. Used for security monitoring and platform stability.
We do not collect data for advertising purposes. We do not sell personal data to third parties. We do not use your data to train machine learning models.
We process your personal data on the following legal bases under GDPR Article 6:
All sensitive fields in your collection — including serial numbers, purchase prices, and location data — are encrypted at the application level using AES-256-GCM before being stored in the database. This means our database contains only ciphertext. Uploaded documents are also encrypted before storage.
Encryption keys are managed through Doppler, a dedicated secrets management platform, and are never stored in the database. All data in transit is protected by HTTPS/TLS.
We operate a versioned key management system with a documented rotation procedure.
Important limitation: WatchVault as a platform operator holds the master encryption key and has the technical capability to decrypt your data. We do not access user data except as required to provide the service or as required by law. Per-user key derivation, which would make operator access cryptographically impossible, is on our technical roadmap.
Supabase
Database, authentication, and file storage. Data is stored in the European Union. DPA signed.
Privacy policy: supabase.com/privacy
Vercel
Application hosting and deployment. DPA will be executed upon upgrade to a paid plan.
Privacy policy: vercel.com/legal/privacy-policy
OpenAI
AI-assisted features. Watch images and watch details are transmitted to OpenAI's API to generate AI-assisted outputs (image analysis and watch comparison). Data is processed solely to generate the requested output and is not used to train OpenAI models under the API terms of service.
Privacy policy: openai.com/policies/privacy-policy
Resend
Transactional email delivery. Used only to send account-related emails such as deletion confirmations and welcome emails.
Privacy policy: resend.com/legal/privacy-policy
Doppler
Secrets and encryption key management.
Privacy policy: doppler.com/legal/privacy
Upstash
Distributed rate limiting. Client IP addresses are stored transiently as rate limit counters to prevent platform abuse.
Privacy policy: upstash.com/trust/privacy.pdf
We retain your personal data for as long as your account is active. When you delete your account, all personal data is permanently deleted immediately, including all collection data, uploaded documents, and your authentication record.
Supabase automated backups may retain encrypted data for up to 7 days following account deletion before being permanently purged from backup systems.
Anonymised audit records — containing only a hashed identifier and timestamps, with no personally identifiable information — are retained for a maximum of 12 months for legal compliance purposes.
As an EU resident you have the following rights:
To exercise any of these rights, contact us at support@watchvault24.com. We will respond within 30 days.
You can delete your account at any time from the account settings page. When you request deletion, the following happens immediately and permanently:
Deletion is hard and permanent. There is no soft delete, no recovery path, and no way to restore your account or data after deletion is completed.
WatchVault uses only technically necessary cookies required for authentication — specifically session cookies issued by Supabase to maintain your logged-in state. We do not use advertising cookies, tracking cookies, or analytics cookies.
WatchVault is not directed at children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us and we will delete it promptly.
We will notify you by email of any material changes to this Privacy Policy before they take effect. The date at the top of this document reflects the most recent update.
For any questions about this Privacy Policy or to exercise your rights:
support@watchvault24.com© 2026 WatchVault. All rights reserved.
Terms of Use →