Privacy Policy
This Privacy Policy explains how Isildur LLC (d/b/a "WatchAI") ("we", "us", "our") collects, uses, discloses, and protects personal data when you use our websites and services.
- Controller: Isildur LLC, 704 Wallace St, Suite 471, Clovis, NM 88101, USA
- Contact: [email protected]
- Websites covered: www.getwatch.ai and app.getwatch.ai
Scope
This Policy applies to visitors and users worldwide, including the EEA/UK. For cookie-specific information, see our Cookie Policy.
Data we collect
Account and onboarding
- Identifiers and contact: name (if provided), email, company (if provided)
- Authentication data: password hash (managed via our identity provider)
- Profile and preferences: competitors you track, sectors of interest, notification preferences
Billing and transactions
- Payment details are processed by our payment provider (Stripe). We receive limited billing metadata (e.g., last 4 digits, expiry, billing address) and transaction IDs.
Product usage and diagnostics
- App events, device/browser info, IP address, logs (for security and performance)
- Support interactions and feedback
Marketing and website analytics
- Cookies/trackers for GA4 analytics (default retention) and advertising/retargeting (Meta, LinkedIn), subject to consent in the EEA/UK.
Customer-provided content
- Inputs required to deliver the service (e.g., competitor list, focus areas) and content generated or uploaded by you.
Purposes and legal bases
- Provide and operate the services, including personalization and delivery (Contract Art. 6(1)(b) GDPR)
- Payments, invoicing, fraud prevention, and security (Legitimate interests Art. 6(1)(f); Legal obligations Art. 6(1)(c))
- Analytics and marketing (Consent Art. 6(1)(a) in the EEA/UK)
- Compliance with law and enforcement requests (Legal obligations Art. 6(1)(c))
Sharing and processors
We do not sell personal data. We share it with service providers (processors) under contracts that protect your data, including:
- Stripe, Inc. (payments)
- OVHcloud (hosting for website)
- Supabase (authentication/database)
- Analytics/ads: Google (GA4), Meta, LinkedIn
- Optional integrations you connect (e.g., Slack) — if you authorize them
- Professional advisors (legal, accounting) and authorities as legally required
International transfers
Where data is transferred outside your region (e.g., to the United States), we use appropriate safeguards such as the EU Standard Contractual Clauses and Transfer Impact Assessments (TIAs), as applicable.
Retention
- Account data: kept for the life of the account and then deleted or anonymized within 30 days
- Billing records: retained for tax/accounting for up to 7 years
- Logs and diagnostics: typically retained up to 12 months
- Marketing data: retained until you opt-out or for the minimal period required by law
Your rights
Depending on your location, you may have rights of access, rectification, deletion, restriction, portability, and objection. Where we rely on consent, you can withdraw it at any time. To exercise your rights, contact: [email protected].
EEA/UK residents also have the right to lodge a complaint with their supervisory authority.
Security
We implement appropriate technical and organizational measures to protect personal data. No method of transmission or storage is 100% secure; we cannot guarantee absolute security.
Children
Our services are not directed to children under 16. We do not knowingly collect personal data from children. If you believe a child has provided personal data, please contact us so we can delete it.
Contact and representative
- Contact: [email protected]
- EU/UK representative (Art. 27 GDPR): Isildur LLC
Changes to this Policy
We may update this Privacy Policy from time to time. We will post the updated version on this page.