Privacy Policy
Last updated: October 9, 2026
Privacy Policy Summary
WatchFlow collects only the data necessary to run your watch dealing business: account info, inventory data, usage analytics, and payment details (handled by Stripe). We never sell your data. You retain full ownership and can export or delete it anytime. Credentials and backups are encrypted with 256-bit encryption, and we comply with GDPR and CCPA. Admin access to your account is logged, read-only by default, and time-limited.
Information We Collect
When you use WatchFlow, we collect information necessary to provide and improve our services. This includes:
Account Information
- Name, email address, and phone number provided during registration (a phone number is required to create an account and is used for account communication and support)
- Business name and billing address
- Password (stored in hashed form; we never store plaintext passwords)
Business Data
- Inventory records, listings, and associated images you create within the platform
- Deals, contacts, invoices, and notes managed through the CRM and pipeline features
Usage & Analytics Data
- Log data such as IP address, browser type, pages visited, and timestamps
- Device information including operating system and screen resolution
- Diagnostics such as error reports, performance signals, and security events used to keep the service reliable
Website & App Analytics
We run our own first-party analytics on our marketing website, our signup and login pages, and inside the WatchFlow app. It records:
- Pages you view and how long you spend on them, how far you scroll, and which buttons and links you click
- How you arrived: the referring page, campaign tags in the link (UTM parameters), and ad click identifiers (such as Google, Microsoft, Meta, TikTok, or LinkedIn click IDs)
- Device type, browser, operating system, screen and window size, language, and time zone
- Your IP address and the approximate location (country, region, city) derived from it
- On signup forms, which fields you start filling in -- never the values you type
- JavaScript errors that occur on the page
- Inside the logged-in app, which sections of the app you open
Analytics never captures what you type, and never captures inventory, customer, contact, or other business data inside the app. We may also derive the same kind of visit records (pages, referrer, device, IP address) from our server access logs. To recognize repeat visits, we store a random first-party identifier in your browser's local storage and in a cookie named wf_vid. If you create an account, your earlier visits from the same browser are linked to your account so we can understand how you found WatchFlow. We use this data to understand how people find and use WatchFlow, to improve the product, and to measure our own ads (see Ad Measurement below). We do not sell it, and we do not use it to target you with ads.
Unfinished Sign-ups
If you type your email address into our sign-up form but leave before creating an account, we keep that email address and the first name you entered so we can send you one reminder email with a link to finish signing up. We send only that one email, every reminder has a link to stop it, and we delete the information after 30 days. We do not keep it if your browser sends a Global Privacy Control signal.
Ad Measurement (ChatGPT Ads by OpenAI)
We advertise WatchFlow in ChatGPT. If you click one of those ads and then create a WatchFlow account, our server tells OpenAI that a sign-up happened, so we can see which ads work and what they cost. This report is sent from our server; we do not put any OpenAI or other advertising tracking code on our website or in the app. It includes the ad identifiers carried by the link you clicked, the time you signed up, your IP address and browser type, and your email address, phone number, name and WatchFlow account ID in hashed form (converted with SHA-256 into a code that does not show the original value). OpenAI uses this to match the sign-up to an ad click and report ad results to us. We only send this for people who arrived from one of our ChatGPT ads, never for anyone else.
We do not send this report if you turned off marketing cookies in our cookie settings or if your browser sends a Global Privacy Control or Do Not Track signal. OpenAI handles this data under its privacy policy.
Session Replay & Heatmaps (Microsoft Clarity)
On our marketing website and our signup page -- never inside the logged-in app -- we use Microsoft Clarity to understand how visitors use those pages. Clarity records how you interact with the page, such as mouse movements, clicks, taps, and scrolling, together with device and browser details, so we can view session replays and aggregated heatmaps. Clarity is not loaded if your browser sends a Do Not Track or Global Privacy Control signal.
Payment Information
- Billing details required to process your subscription
- Payment card information is handled entirely by Stripe and is never stored on our servers
Communication Data
- When distributing listings via WhatsApp or Telegram, message content passes through their respective infrastructure
Photos, Camera, and Files
- If you upload watch photos, logos, invoices, or other files, we store and process those files only to provide the product features you request
- If you use camera-based scanning or capture features in a browser or mobile wrapper, camera access is used only after you grant permission and is not used in the background
How We Use Your Information
We use the information we collect for the following purposes:
- To operate, maintain, and improve the WatchFlow platform
- To process transactions and manage your subscription
- To distribute your listings to the platforms and channels you select
- To generate AutoCaption listing captions (processed securely)
- To run AI Import, when it is enabled for your account (see below)
- To provide dealer storefront functionality
- To send transactional emails such as billing receipts and account notifications
- To provide customer support and respond to your inquiries
- To detect and prevent fraud, abuse, or security incidents
- To analyze usage trends, understand how people find WatchFlow, and improve our product
We will never sell your personal information to third parties. We do not use your listing data or inventory information for any purpose other than delivering the services you have requested.
AI Import
AI Import turns an existing inventory record -- a spreadsheet, PDF, photo, document, pasted text, or a link -- into draft inventory rows. It is off by default and is enabled by WatchFlow for individual accounts. It runs only when you upload or paste something and start an import. When you give a link, WatchFlow fetches that page on your behalf.
- The contents of what you import -- which may include watch details, prices, customer and contact names, and notes -- are sent to Anthropic's Claude API to extract structured rows. Nothing else from your account is sent.
- The results are drafts. Nothing is added to your inventory or contacts until you review the rows and confirm them.
- The imported text and the draft rows are stored in your account with the import so you can review them.
- We log usage metadata for each request (such as the number of tokens processed) for billing and abuse monitoring.
- Under Anthropic's commercial terms, Anthropic does not use API inputs or outputs to train its models by default, and deletes them from its systems within 30 days, except where longer retention is needed to enforce its usage policy or comply with the law. See Anthropic's Privacy Center for details.
Legal Basis for Processing
We process your personal data under the following legal bases:
- Contract Performance -- Processing necessary to provide the WatchFlow service you signed up for, including account management, listing distribution, and deal tracking
- Legitimate Interest -- Platform security, fraud prevention, service improvement, and website and product analytics
- Consent -- Marketing communications and optional third-party integrations. You may withdraw consent at any time
- Legal Obligation -- Tax records, regulatory compliance, and responding to lawful data requests
Administrative Access Disclosure
Authorized WatchFlow staff may access your account under controlled conditions for customer support, troubleshooting, security, billing, and legal purposes. All administrative access is:
- Logged and auditable -- Every administrative session, every account page an administrator views, and every change an administrator makes is recorded with who, what, and when
- Read-only by default -- Administrators can view your data but cannot modify it through an access session unless write access is specifically enabled; any change is logged separately
- Time-limited -- Access sessions expire automatically within 24 hours
- Restricted -- Only authorized WatchFlow staff can access accounts, and only for the purposes listed above
You may request a record of administrative access to your account at any time by emailing support@mywatchflow.com. We will never access your account without a legitimate business or support reason.
Data Sharing & Third Parties
WatchFlow shares data only with a small set of carefully selected sub-processors that are essential to operating the platform. Each service receives the minimum data necessary to perform its function on your behalf. We do not sell your data to third-party advertising networks or data brokers.
Third-Party Service Providers
The table below enumerates every third party that may process data on our behalf, the data they receive, and where they are located. Each provider operates under its own privacy policy and a Data Processing Agreement (DPA) with WatchFlow where applicable.
| Provider | Purpose | Data Received | Region |
|---|---|---|---|
| Stripe | Payment processing & subscription billing | Name, email, billing address, tokenized payment card details. WatchFlow never stores raw card numbers. | US / EU |
| WatchFlow-controlled servers | Storage of uploaded photos, invoice PDFs, and exported files | Listing images, watch photos, generated invoice PDFs, document attachments. | WatchFlow infrastructure |
| Cloudflare | CDN, DDoS mitigation, TLS termination | IP address, request headers, user-agent, request metadata. | Global edge network |
| DigitalOcean | Cloud hosting of the WatchFlow application, database, and uploaded files | All account and business data you store in WatchFlow. | US |
| Cloudflare R2 | Storage of encrypted database backups | Encrypted backup files only. Cloudflare cannot read their contents. | US / Global |
| Better Stack | Uptime monitoring & operational alerts to our team | Error summaries and system health metadata. No business data is sent intentionally. | US / EU |
| Twilio | SMS delivery and phone-number verification for account alerts you opt into | Your mobile number and the text of the alert or verification code. | US |
| OpenAI (ChatGPT Ads) -- ad measurement only | Tells OpenAI when someone who clicked one of our ChatGPT ads creates an account, so we can measure which ads work. Sent from our server only; not sent if you turned off marketing cookies or your browser sends Global Privacy Control / Do Not Track. | Ad click identifiers, sign-up time, IP address, browser type, and hashed (SHA-256) email, phone number, name and account ID. Only for people who arrived from our ChatGPT ads. | US |
| Microsoft Clarity -- marketing and signup pages only | Session replay and heatmaps showing how visitors use our public pages. Not loaded inside the logged-in app, or when your browser sends Do Not Track or Global Privacy Control. | Page interactions (clicks, taps, scrolling, mouse movement), pages viewed, referrer, IP address, device and browser metadata, Clarity cookie identifiers. Microsoft processes this data under its own terms and may act as our processor or as an independent controller depending on the purpose. | US / Global |
| Sentry (when enabled) | Error reporting & diagnostics | Anonymized stack traces, user-agent strings, browser/device metadata. IP addresses may be captured incidentally. No business data is sent intentionally. | US / EU |
| Resend | Transactional email delivery (receipts, account notices, invoice delivery, deletion confirmations) | Recipient email address, message content, delivery metadata. | US / EU |
| Anthropic, PBC -- AI Import, only when enabled for your account | AI extraction of documents a user chooses to import | The contents of the file, text, or linked page you import, which may include watch details, prices, customer and contact names, and notes. | US |
| Playwright / Chromium | Server-side rendering of invoice PDFs and previews | Runs on WatchFlow-controlled infrastructure. No data leaves our servers. | WatchFlow infrastructure |
| Apple (App Store / In-App Purchase, when applicable) | If WatchFlow is distributed via Apple platforms, Apple processes purchase, download, device, crash and account data under Apple's own terms. | Purchase status, Apple ID identifier, device metadata, crash logs. | Apple infrastructure |
| WhatsApp (Meta), via Whapi -- optional integration | Outbound listing distribution to WhatsApp groups you select. Messages are relayed through Whapi.Cloud, our WhatsApp gateway provider. | Message content and media you choose to distribute. | Meta global |
| Telegram -- optional integration | Outbound listing distribution to Telegram channels/groups you select | Message content and media you choose to distribute. | Telegram global |
Integrations You Choose to Connect
The following services receive data only if you connect them yourself. Each is off until you connect it, and you can disconnect it at any time.
| Service | Purpose | Data Shared |
|---|---|---|
| Google / Microsoft / Apple sign-in | Signing in to WatchFlow with your existing account | Your name and email address, as provided by the sign-in provider. |
| Facebook & Instagram (Meta) | Publishing listings to pages or accounts you select | Listing text and photos you choose to publish. |
| eBay | Publishing and syncing listings to your eBay account | Listing text, photos, prices, and listing status. |
| Shopify | Syncing inventory to your Shopify store | Listing text, photos, prices, and stock status. |
| QuickBooks (Intuit) | Syncing invoices and payments to your accounting | Invoice, customer, and payment records you choose to sync. |
We share only the minimum data necessary for each service to perform its function. We do not sell your data to advertising networks or data brokers, and we do not load third-party advertising trackers on our website or in the app. The only advertising-related sharing is the ad-measurement report to OpenAI described in Section 01. See the providers' own privacy policies for details: Stripe, Cloudflare, DigitalOcean, Resend, Anthropic, Twilio, Sentry, Better Stack, Microsoft (Clarity), OpenAI, WhatsApp, Whapi, Telegram, Google.
Connected Mailboxes & Google User Data
WatchFlow lets you connect your own Gmail or Microsoft mailbox so that invoices you send reach your customers from your own address rather than ours. Connecting a mailbox is entirely optional — the feature is off until you choose to connect one, and you can disconnect at any time. If you never connect a mailbox, nothing in this section applies to you.
What permission we ask for
We request a single, send-only permission from each provider:
- Google:
gmail.send— permission to send mail on your behalf, and nothing else. - Microsoft:
Mail.Send— the equivalent send-only permission.
We deliberately do not request permission to read, search, download, organise, modify or delete your mail, and we do not request access to your contacts, calendar, or files. These are the narrowest permissions that allow the feature to work.
What we store, and for how long
- Authorisation tokens issued by Google or Microsoft, encrypted at rest, used solely to send the messages you ask us to send. They are stored until you disconnect the mailbox or delete your account.
- The email address of the connected mailbox, so we can show you which account is connected.
- A record of each invoice email you send — recipient, subject, message, and time sent — so that the invoice has an accurate history. This is the same record we keep for invoices sent by any other method.
We do not copy, index, or retain the contents of your mailbox, because we never have access to it.
What we never do
- We do not read your incoming mail.
- We do not use Google or Microsoft user data to train, and we do not transfer it for the purpose of training, any artificial-intelligence or machine-learning model — personalised or generalised.
- We do not sell or transfer this data to advertising networks, data brokers, or information resellers.
- We do not use this data for advertising, profiling, or any purpose other than sending the messages you have asked us to send.
Limited Use
WatchFlow's use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Disconnecting
You can disconnect a mailbox at any time from Settings → Email inside WatchFlow, which deletes the stored authorisation tokens immediately. You can also revoke WatchFlow's access directly from your Google Account permissions page or your Microsoft account privacy settings. Revoking access stops all future sending; invoice history already recorded in your own account is unaffected.
Text Messages (SMS)
If you add a mobile number under Billing & Plan → Payment alerts, WatchFlow uses it only to send you account notifications about your own WatchFlow subscription (for example, a declined payment, a reminder before your account becomes read-only, or a payment-received confirmation) and one-time verification codes to confirm the number. Texts are off until you confirm your number with a code.
Message frequency varies. Message and data rates may apply. Reply STOP to opt out or HELP for help. You can also turn text alerts off or remove your number at any time on the same screen.
We do not sell, rent or share your mobile number or SMS opt-in consent with third parties or affiliates for their marketing or promotional purposes. Numbers are sent only to our SMS provider (Twilio) to deliver these messages.
The phone number you give when you sign up is used to contact you about your account and to help with support requests. Giving it at signup does not turn on text alerts or sign you up for marketing texts; the automated texts described above go only to a number you confirm under Payment alerts.
Data Retention
We retain your data only as long as necessary to deliver the WatchFlow service, meet legal and tax obligations, and protect against fraud. To close your account and erase your data, follow the steps on Delete Your Account. The table below sets out the retention schedule for each category of data we hold.
Data Retention Schedule
| Data Category | Retained While | After Account Deletion |
|---|---|---|
| Account credentials (email, password hash, profile) | Account is active | Hashes and profile records purged within 30 days |
| Listings, inventory, contacts, deals | Account is active | Purged within 30 days of deletion request |
| Invoices & payment records | Account is active + 7 years (legal & tax retention) | Anonymized; financial records retained per applicable tax law |
| Uploaded photos & documents | Account is active | Purged within 30 days; files in the account's storage are deleted as part of the account purge |
| Audit logs (admin access, admin page views, security events) | 2 years rolling | Purged with the account |
| Server access logs | Up to 90 days rolling | Logs contain IP addresses and pages requested; visit records derived from them are kept with website analytics (13 months) |
| Website & app analytics (visits, page and click events, attribution) | 13 months rolling, then deleted | Deleted on the same 13-month schedule |
| Unfinished sign-ups (email and first name typed into the sign-up form) | 30 days, then deleted | Deleted on the same 30-day schedule |
| Ad measurement records (ChatGPT Ads sign-up reports) | 13 months, then deleted | Deleted from our systems with your account; data already sent to OpenAI is kept under OpenAI's policy |
| Session replays & heatmaps (Microsoft Clarity) | Per Microsoft Clarity's retention policy | N/A (public pages only; not linked to your account by us) |
| Email delivery logs (via provider) | Per provider policy (typically 30 days) | N/A |
| Backups | Encrypted. Daily backups are kept for 30 days, and one backup per month is kept for 12 months | Deleted data may persist in encrypted backups for up to 12 months. Backups are used only to recover from data loss or to investigate a data-integrity problem, and a backup tied to an open investigation may be kept until it is resolved |
| Session data | Until session expiry | Cleaned up automatically |
| Notifications | Read: 90 days. Unread: up to 1 year. | Purged with the account |
You may request early deletion at any time via Settings > Privacy > Delete Account or by emailing support@mywatchflow.com. After deletion is confirmed, your data follows the schedule above. We honor a 30-day grace period during which deletion can be cancelled by signing in again.
International Transfers
Your data may be transferred and processed in jurisdictions outside your own:
- Data is primarily stored and processed in secure data centers in the United States
- If data is transferred internationally, we ensure adequate protection through standard contractual clauses and equivalent safeguards
- We will always inform you if your data is processed outside your jurisdiction
Data Storage & Security
We take the security of your data seriously and implement industry-standard measures to protect it:
- All data is encrypted in transit using TLS/SSL protocols
- Account credentials and connected-service tokens are encrypted at rest using AES-256 encryption, and passwords are stored only as one-way hashes
- Backups are encrypted before they leave our servers
- Access to production systems and customer accounts is restricted to authorized staff and logged
- We perform regular backups to prevent data loss
- Our infrastructure is hosted on secure, reputable cloud providers
While we employ rigorous security practices, no method of transmission or storage is 100% secure. We encourage you to use a strong, unique password for your WatchFlow account and to notify us immediately if you suspect any unauthorized access.
Your Rights (GDPR & CCPA)
You have the following rights regarding your personal data:
- Right of Access (GDPR Art. 15) -- Request a copy of all personal data we hold about you
- Right to Rectification (GDPR Art. 16) -- Update or correct your information from your dashboard or by contacting us
- Right to Erasure (GDPR Art. 17) -- Request deletion of your account and data via the in-app feature or email; processed within 30 days
- Right to Restriction (GDPR Art. 18) -- Request restriction of processing while a complaint is being investigated
- Right to Data Portability (GDPR Art. 20) -- Export your data in a standard machine-readable JSON format via Settings
- Right to Object (GDPR Art. 21) -- Object to processing based on legitimate interests
How to Exercise Your Rights
- Export your data -- Go to Settings > Privacy > Export My Data to download a machine-readable JSON archive of your account, or email support@mywatchflow.com. Exports are typically delivered within 7 days.
- Delete your account -- Go to Settings > Privacy > Delete Account. You will receive a confirmation email; a 30-day grace period applies during which you can cancel deletion by signing in again. After the grace period, your data is purged according to the retention schedule above.
- Rectify or access -- Most data can be updated directly in the app. For data not editable in-app, email support@mywatchflow.com.
- Object or restrict processing -- Email support@mywatchflow.com with the specific processing activity you wish to object to.
- Lodge a complaint -- You have the right to lodge a complaint with your local data protection supervisory authority (for EU/UK users) at any time.
We will respond to all verified data subject requests within 30 days. Identity verification may be required to protect your data.
CCPA Rights
California residents have additional rights including the right to know what data is collected, the right to delete, the right to opt-out of sale (we do not sell your data), and the right to non-discrimination for exercising your privacy rights.
App Store Privacy Summary
For Apple App Store privacy disclosures, WatchFlow may collect contact information, account identifiers, user content, purchase or billing status, usage data, diagnostics, and uploaded photos or files. This data is used for app functionality, account management, payments, customer support, security, analytics, and product improvement. WatchFlow does not use IDFA, does not sell personal data, and does not track users across third-party apps or websites for advertising.
Automated Decision-Making
We do not make any automated decisions that have significant legal effects on you.
You may lodge a complaint with your local data protection supervisory authority at any time. To exercise any of these rights, please contact us at the address provided below. We will respond to all requests within 30 days.
Cookies
WatchFlow uses a limited number of cookies and local storage entries to operate the platform:
- Authentication cookies -- Required to keep you logged in and maintain your session
- Preference storage -- Used to remember your settings such as theme preference (light/dark mode)
- First-party analytics identifier -- A random visitor ID stored in local storage and in the
wf_vidcookie (up to about 13 months), used to recognize repeat visits and, if you sign up, to link earlier visits to your account (see Section 01) - Microsoft Clarity cookies -- On our marketing website and signup page only, Clarity sets its own cookies to group page views into sessions for replay and heatmaps. Clarity is not loaded inside the logged-in app, or when your browser sends Do Not Track or Global Privacy Control. See Microsoft's privacy statement.
We do not use advertising cookies, and we do not use cookies to track you across other companies' websites for advertising. You can manage or clear cookies and local storage through your browser settings, though disabling essential cookies may affect your ability to use WatchFlow.
Contact & Data Protection
If you have any questions about this Privacy Policy, your data, or your rights, please reach out to us:
- Privacy email: support@mywatchflow.com
- Contact page: mywatchflow.com/contact
If you are in the EU or UK, you have the right to lodge a complaint with your local Data Protection Authority / supervisory authority.
We are committed to resolving any concerns about your privacy promptly and transparently. We aim to respond to all data protection requests within 30 days.
Ready to get started?
Your data is protected by enterprise-grade security. Try WatchFlow free today.
Sign Up Free