Privacy Policy

Last Updated: June 2026

The Watch Platform ("we", "us", "our") is committed to protecting your privacy and handling your personal information transparently and securely.

This Privacy Policy explains what information we collect, how we use it, who we share it with, and the rights available to you under applicable data protection laws, including the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

1. Who We Are

The Watch Platform

Newtown House
Newtown Road
Henley-on-Thames
Oxfordshire
RG9 1HG
United Kingdom

Data Protection Officer: DPO@thewatchplatform.app

For any questions regarding this Privacy Policy or your personal data, please contact us using the details above.

2. Information We Collect

We collect information directly from users, information generated through use of the platform, and information from selected third-party providers.

Account Information

When you create an account, we may collect:

  • Email address
  • Password (processed securely through our authentication provider)
  • Full name
  • Telephone number
  • Country
  • Address information
  • Account role (seller, dealer, administrator)
  • Account status

If you choose to sign in using Google, we may also receive:

  • Google account identifier
  • Email address
  • Name
  • Profile image URL

Dealer Information

If you register as a dealer, we may additionally collect:

  • Company name
  • Registered company name
  • Trading name
  • Companies House registration number
  • VAT registration number
  • Business type
  • Trading start date
  • Year established
  • Trading address
  • Website address
  • Business biography
  • Company logo
  • Contact role
  • Annual watch sales volume
  • Information regarding KYC procedures
  • Organisation memberships and professional affiliations
  • Submission contact email address

Watch Submission Information

When sellers submit a watch for valuation or sale, we collect information including:

  • Brand
  • Model
  • Reference number
  • Year
  • Condition
  • Ownership details
  • Alterations or modifications
  • Frequency of wear
  • Box, papers and receipt status
  • Estimated purchase date
  • Whether the watch was purchased new
  • Description
  • Asking price
  • Buy-it-now price
  • Uploaded photographs and images

Marketplace and Communication Data

We collect information relating to transactions and communications on the platform, including:

  • Dealer bids
  • Trade bids
  • Bid amounts
  • Supporting comments and messages
  • Bid amendment history
  • Messages exchanged through the platform
  • Dealer reviews and ratings
  • Trade listing information
  • Listing images and associated watch details

3. Payment Information

Payments on The Watch Platform are processed by Stripe.

We do not collect or store full payment card details, card numbers, security codes (CVC/CVV), or payment credentials on our systems.

Information We Store

To administer transactions, we may store:

  • Stripe payment session identifiers
  • Payment amounts
  • Currency
  • Payment status
  • Payment timestamps
  • Associated seller, submission, or listing identifiers

Information Processed by Stripe

Stripe may collect:

  • Card details
  • Billing name
  • Billing address
  • Country
  • Postcode
  • Fraud prevention information
  • Device information
  • IP address
  • Payment authentication information

Stripe acts as an independent data controller for payment processing activities.

4. Information Collected Automatically

When you use our platform, certain technical information may be collected automatically.

Cookies and Browser Storage

We use cookies and browser storage technologies as described in our Cookie Policy.

These may include:

  • Authentication session tokens
  • Cookie consent preferences
  • User interface preferences
  • Dealer sign-in state information

Server Logs

Our hosting infrastructure may automatically record:

  • IP address
  • Browser type
  • Device information
  • Access times
  • Error logs
  • Security events

Email Activity

We maintain records relating to email communications, including:

  • Delivery status
  • Bounce records
  • Suppression records
  • Unsubscribe requests
  • Email engagement necessary to operate the service

5. How We Use Your Information

We use personal information for the following purposes.

Providing the Platform

To:

  • Create and manage user accounts
  • Process watch submissions
  • Match sellers with vetted dealers
  • Enable bidding and messaging
  • Operate the marketplace
  • Facilitate transactions

Dealer Verification

To:

  • Verify dealer identities
  • Conduct business verification
  • Check Companies House registrations
  • Verify VAT registrations
  • Maintain marketplace integrity

Processing Payments

To:

  • Process platform fees
  • Record payment activity
  • Calculate and account for VAT
  • Prevent payment fraud

Communications

To send:

  • Account verification emails
  • Password reset emails
  • Bid notifications
  • Submission updates
  • Transactional service messages
  • Daily or periodic platform notifications

Reviews and Reputation Systems

To:

  • Publish dealer reviews
  • Display ratings
  • Improve trust and transparency within the marketplace

Platform Improvement

To:

  • Analyse usage trends
  • Improve user experience
  • Monitor platform performance
  • Develop new features

Security and Fraud Prevention

To:

  • Detect suspicious activity
  • Investigate misuse
  • Protect user accounts
  • Enforce our Terms of Service

Legal and Regulatory Compliance

To:

  • Meet tax obligations
  • Maintain accounting records
  • Respond to lawful requests
  • Support anti-money laundering requirements
  • Protect legal rights and interests

6. Lawful Basis for Processing

Under UK GDPR, we rely on one or more of the following lawful bases:

Contract

Where processing is necessary to provide services requested by users.

Legitimate Interests

For platform administration, security, fraud prevention, service improvement, and dealer verification.

Legal Obligation

Where we must comply with tax, accounting, anti-fraud, regulatory, or legal requirements.

Consent

Where consent is required, such as for optional communications or non-essential cookies.

Users may withdraw consent at any time where consent is the basis for processing.

7. Sharing Your Information

We only share information where necessary to operate the platform and provide our services.

Vetted Dealer Network

When a watch is submitted, we may share:

  • Watch details
  • Photographs
  • Condition information
  • Pricing information

Seller contact details are not disclosed to dealers until an unlock has been purchased or disclosure is otherwise necessary to facilitate a transaction.

Service Providers

We may share information with trusted providers including:

Stripe

For payment processing and fraud prevention.

Google

Where users choose Google Sign-In.

Lovable Cloud and Supabase

For hosting, authentication, database services, file storage, and platform operation.

Email Service Providers

For sending transactional communications and notifications.

Verification Services

Including Companies House and VAT verification services used to verify dealer credentials.

Legal Requirements

We may disclose information where required by law or where necessary to:

  • Comply with legal obligations
  • Enforce our terms
  • Protect users
  • Protect our rights and property

No Sale of Personal Data

We do not sell personal information to third parties.

8. International Data Transfers

Some of our service providers may process information outside the United Kingdom.

Where this occurs, we take reasonable steps to ensure appropriate safeguards are in place, including the use of approved contractual protections where required by law.

9. Data Retention

We retain information only for as long as necessary for the purposes outlined in this Privacy Policy.

Account Information

Retained while an account remains active and for a reasonable period afterwards where required for legal, regulatory, security, or operational purposes.

Watch Submissions, Bids and Payments

Typically retained for up to six years to comply with UK tax, accounting, and dispute-resolution requirements.

Reviews and Marketplace Records

Retained while relevant to maintaining platform integrity and user trust.

Email Suppression Lists

Retained indefinitely where necessary to ensure that unsubscribe requests are respected.

Cookies

Retained according to the periods specified in our Cookie Policy.

10. Data Security

We implement technical and organisational measures designed to protect personal information against unauthorised access, disclosure, alteration, or destruction.

These measures include:

  • Encrypted connections (HTTPS)
  • Access controls
  • Authentication protections
  • Secure hosting infrastructure
  • Payment processing through PCI-compliant providers

While no system can guarantee absolute security, we continually work to maintain appropriate safeguards.

11. Your Rights

Under UK GDPR, you may have the right to:

  • Access your personal data
  • Correct inaccurate information
  • Request deletion of personal data
  • Restrict processing
  • Object to processing
  • Request data portability
  • Withdraw consent where applicable
  • Lodge a complaint with the Information Commissioner's Office (ICO)

To exercise any of these rights, please contact:

DPO@thewatchplatform.app

We may need to verify your identity before responding to certain requests.

12. Complaints

If you are unhappy with how we handle your personal information, we encourage you to contact us first.

You also have the right to lodge a complaint with the UK Information Commissioner's Office (ICO):

Website: https://www.ico.org.uk

13. Changes to This Privacy Policy

We may update this Privacy Policy periodically to reflect changes in our services, legal obligations, or business practices.

Any updates will be published on this page and the "Last Updated" date will be amended accordingly.

Continued use of the platform after changes become effective constitutes acceptance of the revised Privacy Policy.