Last updated 17 September 2026
This Privacy Policy explains how WatchPassport collects, uses, stores and shares personal data when you use the WatchPassport website, create an account, register or manage a watch passport, use the public lookup service, contact us, make a payment or otherwise interact with the Service.
This Privacy Policy should be read together with the WatchPassport Terms of Service.
The information we collect depends on how you use WatchPassport.
When you create or manage an account, we may collect information such as:
We do not store your password in readable form.
When you register, manage, reactivate or receive a watch passport, we may collect information about the watch and your relationship with it, including:
Some of this information forms part of the continuing history of the watch and may remain associated with the passport after your ownership ends.
Some information is stored specifically for you and is not intended to transfer to another owner.
This may include:
If a watch passport is transferred, we may process information such as:
A user initiating a transfer may provide us with another person's email address so that we can send the transfer invitation.
If a passport or registration is disputed, or a watch is reported stolen, we may collect and process information necessary to review and administer the matter.
This may include:
When you use a paid feature, we may process information such as:
Payment card details are generally processed by our payment provider rather than stored directly by WatchPassport.
The public lookup service allows users to search for watches without creating an account.
When the lookup service is used, we may collect:
Public lookup results are designed not to reveal the identity or private information of current or previous owners.
If you contact WatchPassport, we may process:
If you choose to join a mailing list or waitlist, we may collect your email address and information necessary to manage your subscription and allow you to unsubscribe.
When you use WatchPassport, some technical information may be processed automatically, including:
We try to collect only the information reasonably necessary to operate, secure and improve the Service.
We may use personal data to:
We do not sell personal data.
We do not share personal data with third parties for their own advertising purposes.
Under data protection law, we must have a legal basis for processing personal data.
Depending on the circumstances, we rely on one or more of the following.
We process information where it is necessary to provide the Service you request or to take steps at your request before providing it.
This includes processing required to:
We may process information where necessary for legitimate interests pursued by WatchPassport or its users, provided those interests are not overridden by your rights and interests.
These interests may include:
We may process and retain information where necessary to comply with applicable legal obligations, including obligations relating to accounting, taxation, legal requests or other regulatory requirements.
Where processing is optional and consent is the appropriate legal basis, we may ask for your consent.
This may apply, for example, to certain optional communications or use of optional information for product or demographic insights.
Where processing is based on consent, you may withdraw that consent at any time. Withdrawal does not affect processing that was lawful before consent was withdrawn.
WatchPassport is designed around the idea that a watch can have a continuing digital history across multiple owners.
This means some information entered by one owner may continue to exist after that owner transfers, archives or otherwise stops owning the watch.
Transferable passport information may include:
The identities and private account information of previous owners are not made public merely because their ownership period forms part of this history.
Where reasonably possible, historical records are designed to describe the history of the watch without unnecessarily identifying the people who previously owned it.
Private owner information, including personal notes, private photographs and personal financial information, does not transfer to later owners.
Different information is visible depending on how WatchPassport is being used.
A current owner can access the information and history available for the passport they currently control, subject to the privacy rules of the Service.
Previous owners may retain access to information relating to their own period of ownership or a historical snapshot, but do not receive access to private information belonging to later owners.
Users involved in an ownership transfer may receive limited information about the other party where necessary to complete and administer that transfer.
Public lookup may display limited watch-related information such as:
Public lookup does not intentionally disclose the identity, contact information, private notes, private photographs or private financial information of watch owners.
Authorised administrators may access information where reasonably necessary for support, security, fraud prevention, dispute handling, stolen-watch administration or maintenance of the Service.
We do not sell personal data.
We may share personal data only where reasonably necessary for the purposes described in this Policy.
This may include sharing information with:
We use third-party providers for functions such as:
These providers may process personal data on our behalf or, in some circumstances, act as independent controllers for parts of their own services.
We limit the information shared to what is reasonably necessary for the relevant service.
Information may be shared with another WatchPassport user where necessary to perform a feature requested by you, such as an ownership transfer.
Transferable watch information may also become available to later owners as part of the continuing passport history.
We may disclose information where reasonably necessary to:
We do not treat an informal request for information as automatically requiring disclosure.
Some service providers used by WatchPassport may process or store personal data outside Norway or the European Economic Area ("EEA").
Where personal data is transferred outside the EEA, we take reasonable steps to ensure that the transfer is made using a lawful transfer mechanism where required.
We do not keep all information for the same period.
Retention depends on why the information was collected and whether it remains necessary for the operation, integrity, security or legal obligations of the Service.
Account information is generally retained while your account remains active.
If you request account deletion or anonymisation, identifying account information is removed or anonymised as described below.
Certain records may need to be retained where required by law or necessary for security, fraud prevention, transaction records or legal claims.
Watch passport identity and historical records may be retained for as long as the relevant passport and the WatchPassport service continue to exist.
This reflects the purpose of WatchPassport as a continuing history attached to the watch rather than only to one user's account.
If an account is deleted, historical watch records may remain in an anonymised or owner-neutral form.
Private notes and private personal photographs remain associated with the relevant user unless the user deletes them or anonymises their account.
Private notes and photographs are deleted as part of the account anonymisation process.
Incomplete registration information and temporary uploads may be deleted after they expire or are no longer required.
Transfer, dispute, stolen-watch and administrative records may be retained for as long as reasonably necessary to maintain the integrity of passport history, resolve disputes, prevent abuse and establish what actions were taken.
Transaction and payment records may be retained for the periods required for accounting, taxation, fraud prevention, dispute handling and other applicable legal obligations.
Lookup, security and technical logs are retained only for as long as reasonably necessary for purposes such as security, rate limiting, abuse prevention, troubleshooting and service analysis.
Communications may be retained for as long as reasonably necessary to respond to the enquiry and maintain an appropriate record of the communication.
You may request account deletion or anonymisation through the Service.
Account deletion does not necessarily mean that every record associated with watches you previously owned will be erased.
When an account is anonymised, WatchPassport may:
This distinction is necessary because deleting the historical record of a watch whenever an individual owner deletes their account would undermine the continuing passport history that the Service is designed to provide.
Some information may also need to be retained where required by law or where another lawful basis for retention applies.
If you have concerns about how WatchPassport processes your personal data, we encourage you to contact us first so that we can try to resolve the issue.
We use technical and organisational measures intended to protect personal data against unauthorised access, loss, alteration, disclosure or misuse.
These measures include access controls, authentication, password hashing, restricted administrative access and security protections appropriate to the nature of the Service.
No online system can be guaranteed to be completely secure.
If we become aware of a personal data breach, we will assess and handle it in accordance with applicable data protection law.
WatchPassport may use cookies, local storage and similar technologies where necessary to operate the Service.
These technologies may be used for purposes such as:
Third-party services used for security, payments or other functionality may also use technologies necessary to provide their services.
If WatchPassport introduces optional analytics, advertising or other technologies that require consent, we will provide any notices or controls required by applicable law.
Some WatchPassport features allow you to provide information relating to another person.
For example, you may provide another person's email address when inviting them to take over a passport, or information about another person may appear in a dispute or support request.
You should only provide another person's personal data where you have a legitimate reason to do so and should avoid including unnecessary personal information.
If we receive your personal data from another WatchPassport user rather than directly from you, we will use it only for purposes reasonably connected to the relevant feature or process, subject to applicable law.
WatchPassport may be used by younger watch enthusiasts, subject to the eligibility and transaction rules in the Terms of Service.
Users should not provide unnecessary personal information about children or other people in photographs, notes or uploaded documents.
We may update this Privacy Policy as WatchPassport develops, our data practices change, or legal requirements change.
The current version will be available through the Service and will show the date it was last updated.
Where required, we will provide appropriate notice of material changes.
Privacy questions, requests or complaints can be submitted through our Contact page.