Catch Watch

Privacy Policy

Last updated: 5 April 2026

1. What We Collect

We collect different categories of information depending on how you interact with the Service:

Data Purpose Retention
Email address Account creation, login, and transactional emails (verification, password reset) Until you delete your account
Password Authentication (stored as a one-way bcrypt hash — we never store or see your plaintext password) Until you delete your account
Display name (optional) Shown alongside your activity within the platform Until you delete your account
IP address Rate limiting and abuse prevention (login lockout, signup throttle) In-memory only, not persisted to disk
Currency preference Display prices in your preferred currency Until you delete your account
Watchlist entries Your saved brand/model alerts Until you delete your account
Contact form messages To receive and respond to your inquiries Until resolved and deleted by admin

2. Listing Data (Third-Party Information)

The watch listings displayed on Catch Watch are sourced from WhatsApp trading groups. Listing messages — including trader contact details, prices, and watch descriptions — are parsed by AI and stored to power the marketplace view. This data originates from messages voluntarily posted by traders in group chats and is not submitted by platform users.

We process this third-party data on the basis of legitimate interest: providing market intelligence to the luxury watch trading community. Traders whose information appears on the platform may contact us at support@catch.watch to request removal of their data.

3. How We Use Your Information

  • Account management: to create and maintain your account, verify your email, and reset your password.
  • Service delivery: to display listings, apply your currency preference, and deliver watchlist alerts.
  • Security: to detect and prevent abuse, enforce rate limits, and protect against unauthorized access.

We do not use your information for advertising, profiling, or marketing purposes.

4. Third-Party Services

We use the following third-party services to operate the platform:

  • Resend — for sending transactional emails (verification, password reset). Your email address is shared with Resend solely for this purpose.
  • Google Gemini AI — for parsing listing messages into structured data. Raw message text from WhatsApp groups (not your account data) is sent to Google's API for processing.
  • Hetzner — cloud server hosting (European Union).

We do not sell, rent, or share your personal information with any other third parties.

5. Cookies & Sessions

We use a single session cookie to keep you logged in. This cookie is:

  • HttpOnly (not accessible to JavaScript)
  • Secure (transmitted only over HTTPS)
  • SameSite=Lax (not sent on cross-site requests)

We do not use tracking cookies, analytics scripts, or third-party cookies of any kind.

6. Data Security

We protect your data with industry-standard security measures including encrypted connections (TLS), bcrypt password hashing, CSRF protection, rate limiting, and security headers. However, no system is 100% secure and we cannot guarantee absolute security.

7. Your Rights

You can at any time:

  • Access your account data from your account settings page.
  • Update your display name, password, or currency preference.
  • Delete your account and all associated data from your account settings page. Deletion is immediate and irreversible.

8. Data Retention

Account data is retained until you delete your account. When you delete your account, all personal data (email, password hash, display name, watchlist entries, and activity logs) is permanently removed.

9. Children

The Service is not intended for anyone under 18 years of age. We do not knowingly collect information from children.

10. International Data Transfers

Your data is stored on servers located in Germany (Hetzner). If you access the Service from outside the European Union, your data may cross international borders. By using the Service, you consent to the transfer of your information as described in this policy.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will indicate the date of the most recent update at the top of this page. Continued use of the Service after changes constitutes acceptance of the revised policy.

12. Contact

For questions about this Privacy Policy or to exercise your data rights, contact us or email support@catch.watch.

© 2026 Catch Watch — Terms Privacy Contact