Privacy Policy
Last Updated: June 2026
The Watch Platform ("we", "us", "our") is committed to protecting your privacy and handling your personal information transparently and securely.
This Privacy Policy explains what information we collect, how we use it, who we share it with, and the rights available to you under applicable data protection laws, including the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
1. Who We Are
The Watch Platform
Newtown House
Newtown Road
Henley-on-Thames
Oxfordshire
RG9 1HG
United Kingdom
Data Protection Officer: DPO@thewatchplatform.app
For any questions regarding this Privacy Policy or your personal data, please contact us using the details above.
2. Information We Collect
We collect information directly from users, information generated through use of the platform, and information from selected third-party providers.
Account Information
When you create an account, we may collect:
- Email address
- Password (processed securely through our authentication provider)
- Full name
- Telephone number
- Country
- Address information
- Account role (seller, dealer, administrator)
- Account status
If you choose to sign in using Google, we may also receive:
- Google account identifier
- Email address
- Name
- Profile image URL
Dealer Information
If you register as a dealer, we may additionally collect:
- Company name
- Registered company name
- Trading name
- Companies House registration number
- VAT registration number
- Business type
- Trading start date
- Year established
- Trading address
- Website address
- Business biography
- Company logo
- Contact role
- Annual watch sales volume
- Information regarding KYC procedures
- Organisation memberships and professional affiliations
- Submission contact email address
Watch Submission Information
When sellers submit a watch for valuation or sale, we collect information including:
- Brand
- Model
- Reference number
- Year
- Condition
- Ownership details
- Alterations or modifications
- Frequency of wear
- Box, papers and receipt status
- Estimated purchase date
- Whether the watch was purchased new
- Description
- Asking price
- Buy-it-now price
- Uploaded photographs and images
Marketplace and Communication Data
We collect information relating to transactions and communications on the platform, including:
- Dealer bids
- Trade bids
- Bid amounts
- Supporting comments and messages
- Bid amendment history
- Messages exchanged through the platform
- Dealer reviews and ratings
- Trade listing information
- Listing images and associated watch details
3. Payment Information
Payments on The Watch Platform are processed by Stripe.
We do not collect or store full payment card details, card numbers, security codes (CVC/CVV), or payment credentials on our systems.
Information We Store
To administer transactions, we may store:
- Stripe payment session identifiers
- Payment amounts
- Currency
- Payment status
- Payment timestamps
- Associated seller, submission, or listing identifiers
Information Processed by Stripe
Stripe may collect:
- Card details
- Billing name
- Billing address
- Country
- Postcode
- Fraud prevention information
- Device information
- IP address
- Payment authentication information
Stripe acts as an independent data controller for payment processing activities.
4. Information Collected Automatically
When you use our platform, certain technical information may be collected automatically.
Cookies and Browser Storage
We use cookies and browser storage technologies as described in our Cookie Policy.
These may include:
- Authentication session tokens
- Cookie consent preferences
- User interface preferences
- Dealer sign-in state information
Server Logs
Our hosting infrastructure may automatically record:
- IP address
- Browser type
- Device information
- Access times
- Error logs
- Security events
Email Activity
We maintain records relating to email communications, including:
- Delivery status
- Bounce records
- Suppression records
- Unsubscribe requests
- Email engagement necessary to operate the service
5. How We Use Your Information
We use personal information for the following purposes.
Providing the Platform
To:
- Create and manage user accounts
- Process watch submissions
- Match sellers with vetted dealers
- Enable bidding and messaging
- Operate the marketplace
- Facilitate transactions
Dealer Verification
To:
- Verify dealer identities
- Conduct business verification
- Check Companies House registrations
- Verify VAT registrations
- Maintain marketplace integrity
Processing Payments
To:
- Process platform fees
- Record payment activity
- Calculate and account for VAT
- Prevent payment fraud
Communications
To send:
- Account verification emails
- Password reset emails
- Bid notifications
- Submission updates
- Transactional service messages
- Daily or periodic platform notifications
Reviews and Reputation Systems
To:
- Publish dealer reviews
- Display ratings
- Improve trust and transparency within the marketplace
Platform Improvement
To:
- Analyse usage trends
- Improve user experience
- Monitor platform performance
- Develop new features
Security and Fraud Prevention
To:
- Detect suspicious activity
- Investigate misuse
- Protect user accounts
- Enforce our Terms of Service
Legal and Regulatory Compliance
To:
- Meet tax obligations
- Maintain accounting records
- Respond to lawful requests
- Support anti-money laundering requirements
- Protect legal rights and interests
6. Lawful Basis for Processing
Under UK GDPR, we rely on one or more of the following lawful bases:
Contract
Where processing is necessary to provide services requested by users.
Legitimate Interests
For platform administration, security, fraud prevention, service improvement, and dealer verification.
Legal Obligation
Where we must comply with tax, accounting, anti-fraud, regulatory, or legal requirements.
Consent
Where consent is required, such as for optional communications or non-essential cookies.
Users may withdraw consent at any time where consent is the basis for processing.
7. Sharing Your Information
We only share information where necessary to operate the platform and provide our services.
Vetted Dealer Network
When a watch is submitted, we may share:
- Watch details
- Photographs
- Condition information
- Pricing information
Seller contact details are not disclosed to dealers until an unlock has been purchased or disclosure is otherwise necessary to facilitate a transaction.
Service Providers
We may share information with trusted providers including:
Stripe
For payment processing and fraud prevention.
Where users choose Google Sign-In.
Lovable Cloud and Supabase
For hosting, authentication, database services, file storage, and platform operation.
Email Service Providers
For sending transactional communications and notifications.
Verification Services
Including Companies House and VAT verification services used to verify dealer credentials.
Legal Requirements
We may disclose information where required by law or where necessary to:
- Comply with legal obligations
- Enforce our terms
- Protect users
- Protect our rights and property
No Sale of Personal Data
We do not sell personal information to third parties.
8. International Data Transfers
Some of our service providers may process information outside the United Kingdom.
Where this occurs, we take reasonable steps to ensure appropriate safeguards are in place, including the use of approved contractual protections where required by law.
9. Data Retention
We retain information only for as long as necessary for the purposes outlined in this Privacy Policy.
Account Information
Retained while an account remains active and for a reasonable period afterwards where required for legal, regulatory, security, or operational purposes.
Watch Submissions, Bids and Payments
Typically retained for up to six years to comply with UK tax, accounting, and dispute-resolution requirements.
Reviews and Marketplace Records
Retained while relevant to maintaining platform integrity and user trust.
Email Suppression Lists
Retained indefinitely where necessary to ensure that unsubscribe requests are respected.
Cookies
Retained according to the periods specified in our Cookie Policy.
10. Data Security
We implement technical and organisational measures designed to protect personal information against unauthorised access, disclosure, alteration, or destruction.
These measures include:
- Encrypted connections (HTTPS)
- Access controls
- Authentication protections
- Secure hosting infrastructure
- Payment processing through PCI-compliant providers
While no system can guarantee absolute security, we continually work to maintain appropriate safeguards.
11. Your Rights
Under UK GDPR, you may have the right to:
- Access your personal data
- Correct inaccurate information
- Request deletion of personal data
- Restrict processing
- Object to processing
- Request data portability
- Withdraw consent where applicable
- Lodge a complaint with the Information Commissioner's Office (ICO)
To exercise any of these rights, please contact:
We may need to verify your identity before responding to certain requests.
12. Complaints
If you are unhappy with how we handle your personal information, we encourage you to contact us first.
You also have the right to lodge a complaint with the UK Information Commissioner's Office (ICO):
Website: https://www.ico.org.uk
13. Changes to This Privacy Policy
We may update this Privacy Policy periodically to reflect changes in our services, legal obligations, or business practices.
Any updates will be published on this page and the "Last Updated" date will be amended accordingly.
Continued use of the platform after changes become effective constitutes acceptance of the revised Privacy Policy.
