Privacy Policy

Version 1.0.0 · Last updated: September 2026

1. Who We Are

StockWatch is a website monitoring platform that tracks product availability, price changes, and restocks on retail websites. This privacy policy explains how we collect, use, and protect your personal data when you use our web application and Chrome browser extension.

We are based in the United Kingdom and operate under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

StockWatch is currently in early access / pre-launch. The legal entity that will operate StockWatch as a public business has not yet been incorporated. During this period the operator acts as the data controller; for any data subject request (access, rectification, erasure, portability, objection) please contact us at the address in §12 and we will respond within the 30-day window required by UK GDPR Art. 12. The named data controller (legal entity, company number where applicable, and registered office address) will be published in this section before StockWatch is generally available to the public.

2. Data We Collect

2.1 Account Data (Essential)

When you create an account, we collect:

  • Email address
  • Display name
  • Password (stored as a bcrypt hash, never in plaintext)
  • Two-factor authentication secret if you enable 2FA (encrypted at rest with AES-256-GCM)

2.2 Service Data (Essential)

To provide our monitoring service, we process:

  • Monitor configurations (URLs, selectors, polling intervals, keyword rules)
  • Notification settings (Discord webhook URLs, recipient email addresses, push subscription endpoints)
  • Detected product data (names, prices, availability, scan history)
  • Subscription and billing data (handled via Stripe — see §6)
  • Browser push subscriptions: device endpoint URL, encryption keys (p256dh, auth) and user-agent string, when you enable push notifications
  • IP address, user-agent, and browser characteristics on each request (for security, abuse prevention, and service delivery)

2.3 Security and Abuse Prevention Data (Legitimate Interest)

To spot account takeover, brute-force logins, one person running several accounts and other security problems, we process:

  • A browser record: a SHA-256 hash of your browser's user-agent and language setting, not your full configuration
  • A random device ID, kept in the sw_device cookie. We use it only to keep accounts secure and to spot one person running several accounts, never for analytics or advertising
  • Your email address in a normalised form (lower case, without the dots or +tags your provider ignores), so nobody can open a second account on the same inbox
  • Keyed hashes of your sign-in inbox, your alert destinations (Discord webhooks, Telegram chats and alert email addresses) and the IP addresses and browsers you use StockWatch from, so we can tell when two accounts share them. A person reviews any match, and nothing happens to an account automatically
  • Login timestamps, IP-derived country, and any anomaly flags (new device, new country, impossible-travel)
  • Trusted-device cookies that let you skip 2FA on devices you confirm
  • A limited audit log of essential actions (registration, login, monitor creation, checkout start, plan-limit hits) including timestamp, IP, and user-agent — kept under legitimate interest and anonymised after 90 days (see §4)

You may object to this processing under UK GDPR Art. 21, but we may need to refuse if doing so would compromise account security or our legitimate interests in preventing abuse.

2.4 Where Your Signup Came From (Legitimate Interest)

When you create an account we record how you arrived: the campaign tags on the link you clicked (utm_source and friends), the click identifier the ad platform adds to its own links (gclid from Google Ads, fbclid from Meta, and the equivalents from Microsoft, TikTok and Reddit), the site that referred you if it was not one of our own pages, and the first page you landed on. We use it to work out which channels bring real users, so we know where to spend.

We read these from the address bar and your browser's referrer at the moment you sign up. Nothing is stored on your device to collect it, so it does not depend on your cookie choices. It is kept against your account under legitimate interest, deleted when you delete your account, and included in a data export. You can object at any time under UK GDPR Art. 21 by emailing us, and we will erase it.

Changed your mind? You can turn analytics and marketing on or off whenever you like. Switching something off stops it immediately and clears what it stored.

2.4a Anonymous Visitor Tracking (Requires Analytics Consent)

If you accept analytics cookies, we also set a one-year visitor cookie (sw_vid) and keep a Visitor record: campaign tags, referrer, landing page, device/browser/OS, IP-derived country and the pages you view. This lets us follow a visit across days and, if you later register, connect the browsing you did beforehand to your account.

Decline analytics and none of this happens: no visitor cookie is set, no first-touch record is written to your browser's local storage, and no page views are stored. We keep only the signup record described in §2.4 above.

If you accept analytics and then create an account, we also store the identifier Google Analytics gave your browser (client_id) against that account, and report the sign-up and any subscription payment to Google Analytics from our server rather than from your browser. It is the same measurement you already consented to and no extra information about you is sent: the identifier is what lets those two events join the visit they came from instead of appearing as a stranger. Decline analytics and there is no identifier, so nothing is sent.

While you are signed in, we also send Google Analytics your account ID and the plan you are on. That ID is the random string your account already uses internally, not your name or your email address, and it is what lets the same person browsing on a laptop and on a phone count once rather than twice. We clear it when you log out. Decline analytics and none of this is sent.

2.5 Analytics Data (Requires Consent)

With your consent, we collect:

  • Page views and feature usage within StockWatch
  • Session duration and navigation patterns
  • Device type, browser, and operating system
  • Approximate location (country-level, derived from IP)
  • Performance metrics (page load times)
  • Email engagement — a 1×1 tracking pixel and link-tracking redirects in outbound emails so we can measure delivery and click-through

2.6 Marketing Data (Requires Consent)

With your consent, we collect:

  • Campaign attribution data (UTM parameters) linked to your account
  • Referral source information
  • Usage patterns for personalisation and segmentation

2.7 Extension Telemetry (Requires Consent)

With your explicit opt-in, the Chrome extension may collect:

  • Extension feature usage (which features you use, not which sites you visit)
  • Platform detection statistics (aggregated, not per-URL)
  • Extension error reports

The extension processes page content ONLY on (a) sites you have configured as a monitor in browser-execution mode, and (b) the specific page where you actively use the visual selector to create a monitor. It does not passively log other browsing.

3. Lawful Basis for Processing

Data CategoryLawful Basis
Account & Service DataContract performance
Subscription & Billing (Stripe)Contract performance + legal obligation (UK tax records)
Security, Abuse Prevention & Device RecordsLegitimate interest
Signup Source (§2.4)Legitimate interest
Anonymous Visitor Tracking (§2.4a)Consent
AnalyticsConsent (opt-in)
Marketing & SegmentationConsent (opt-in)
Extension TelemetryConsent (opt-in)

4. Data Retention

  • Account data: Retained until you delete your account. Aggregated, anonymised behavioural records (with all user identifiers removed) survive deletion for product analytics.
  • Monitor events (restock / price-drop / error alerts): retained for 90 days by default, then automatically deleted. Aggregated product price history is retained for up to 12 months for trend charts.
  • Activity and session logs: identifying fields (IP, user-agent) are removed at 90 days; the anonymised behavioural rows are deleted at 180 days.
  • Consent records: retained for audit purposes for as long as you have an account, and for 24 months after deletion for legal-defence purposes.
  • Billing records: our payment processor Stripe and our own subscription event log may retain records for up to 6 years after your last payment, to comply with UK HMRC tax and accounting law. The Stripe customer record retains the email and name you registered with for the same reason.
  • Account-sharing checks: we delete IP address and browser hashes 90 days after we last saw them. We keep the device ID, the inbox and alert destination hashes, and any review of whether two accounts belong to one person, until either account is deleted.
  • Push subscriptions and trusted-device cookies: deleted when you revoke them, when the device unsubscribes, or when you delete your account.

Every outbound notification email includes a one-click unsubscribe link (RFC 8058). You can also disable all email globally from your notification settings.

5. Your Rights

Under UK GDPR, you have the right to:

  • Access your personal data (download via Account settings)
  • Rectify inaccurate data (edit your profile)
  • Erase your data (delete your account)
  • Restrict processing (adjust consent preferences)
  • Data portability (export your data as JSON)
  • Object to processing based on legitimate interest
  • Withdraw consent at any time without affecting prior processing

You can exercise these rights from your Account settings, or by emailing us at the address in §12. DSAR responses are returned within 30 days.

6. Third-Party Processors

We share data with the following processors, each under a Data Processing Agreement:

  • Stripe (US/EU): Payment processing, subscription management, invoice history (PCI DSS compliant)
  • Resend (US): Transactional and notification email delivery, plus bounce/complaint webhooks
  • Cloudflare (UK/US, EU bucket for backups): Turnstile bot-protection on signup/login forms (sends your IP and a challenge token), DNS routing, and EU-region R2 storage for our nightly off-site database backups
  • Sentry (US): Server and browser error / performance telemetry. We strip credentials and request bodies before transmission; the URL path, browser user-agent, and your StockWatch user ID may be transmitted to support debugging
  • ImprovMX (US): Inbound email forwarding for our @stock-watch.co.uk addresses
  • Browser push services (Mozilla autopush, Google FCM, Apple APNs): when you enable push notifications, your subscription endpoint identifies the vendor whose servers relay each notification to your device
  • Discord and Telegram: only when YOU configure a webhook URL or chat ID. We send the notification content you opted in to

We do not sell your personal data to third parties.

6.1 Analytics and Marketing Processors (consent-gated)

The following processors only receive data when you have given the matching consent on our cookie banner (Analytics or Marketing). They never load if you decline.

  • Google Analytics 4 (Google LLC, US) — Analytics consent. Site usage stats (pages viewed, session duration, traffic source), plus your account ID and plan while you are signed in. IP anonymisation is enabled. Google's privacy policy: policies.google.com/privacy
  • Microsoft Clarity (Microsoft Corporation, US) — Analytics consent. Aggregated heatmaps and anonymised session recordings to help us see where the product is confusing. Microsoft's privacy statement: privacy.microsoft.com
  • Google Tag Manager (Google LLC, US) — Analytics consent. Container that lets us update tags without redeploying. No tracking of its own. Same policy link as Google above.
  • Meta Pixel (Meta Platforms Ireland Ltd) — Marketing consent. Lets us measure the success of Facebook and Instagram advertising and build audiences. Meta's privacy policy: facebook.com/privacy/policy
  • TikTok Pixel (TikTok Information Technologies UK Ltd, with parent companies in US/Singapore) — Marketing consent. Same purpose as Meta Pixel for TikTok advertising. TikTok's privacy policy: tiktok.com/legal/privacy-policy

You can change your consent at any time from the cookie banner (click “Cookie preferences” in the footer) or from your account settings. Revoking consent stops these processors and clears their cookies on your next page load.

7. Data Security

  • Passwords hashed with bcrypt (12 salt rounds)
  • Two-factor authentication secrets and recovery codes are encrypted (AES-256-GCM) and hashed (SHA-256) respectively before storage
  • Proxy credentials encrypted with AES-256-GCM
  • JWT tokens with httpOnly, secure, sameSite cookies
  • CSRF protection on all state-changing requests
  • Rate limiting on authentication, account-deletion, and password-change endpoints
  • Account lockout after repeated failed login attempts
  • Webhook endpoints (Stripe, Resend) verify HMAC signatures on every request

8. Chrome Extension

The StockWatch Chrome extension requires broad permissions to detect retail platforms and enable the visual selector feature. The extension only processes data on pages where you actively use StockWatch features (creating monitors, picking selectors). It does not passively collect browsing data.

9. Cookies and Local Storage

NamePurposeCategory
tokenAuthentication session (JWT)Essential
sw_session30-min session linkage for behavioural continuityEssential
sw_vid1-year anonymous visitor tracking (see §2.4a). Only set if you accept analytics.Analytics
sw_deviceRandom device ID, used only for account security and to spot one person running several accounts. Never used for analytics or advertising. 1 year.Essential
sw_trusted_device30-day 2FA-bypass for devices you confirmEssential
_ga, _ga_*, _gidGoogle Analytics 4 (anonymised usage stats). 2 years.Analytics
_clck, _clsk, CLIDMicrosoft Clarity (aggregated heatmaps, anonymised session recordings). 1 year.Analytics
_fbp, _fbcMeta Pixel (advertising measurement). 90 days.Marketing
_ttpTikTok Pixel (advertising measurement). 13 months.Marketing

We also use browser local storage: stockwatch_consent holds your privacy preferences (essential), and, only if you accept analytics, sw_first_touch remembers how you first arrived so the attribution survives between visits. Declining analytics, or withdrawing it later, removes sw_first_touch. Local storage is not transmitted with HTTP requests; it lives in your browser only.

10. International Data Transfers

Your account data is stored on servers in Germany (Hetzner) with encrypted off-site backups in the EU (Cloudflare R2). Some of our processors (Sentry, Resend, ImprovMX, Stripe, plus the analytics and marketing tags in §6.1 if you have consented to them: Google Analytics 4, Microsoft Clarity, Meta Pixel and TikTok Pixel) may process data outside the UK / EEA under Standard Contractual Clauses, the UK International Data Transfer Addendum, or equivalent safeguards. We rely on those providers' published transfer mechanisms; their current locations are listed in §6 and §6.1.

11. Changes to This Policy

When we update this policy, we will increment the version number and notify you via the consent banner. You will be asked to review and re-consent to the updated policy.

12. Contact

For privacy-related queries, data requests, or complaints, please contact us at privacy@stock-watch.co.uk. We aim to respond to data subject requests within 30 days, as required by UK GDPR Art. 12.

You also have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK's independent data protection regulator (tel. 0303 123 1113).