Last updated: August 27, 2026
This policy is provided as a general description of THEWATCH's data practices and has not been reviewed by outside legal counsel. If you need this reviewed for a specific compliance requirement (GDPR, CCPA, HIPAA, SOC 2, etc.), contact us before relying on it.
1. Who this applies to
This Privacy Policy explains how THEWATCH ("THEWATCH," "we," "us"), a product of PROVE iT! Forensics, collects, uses, and protects information when you visit thewatchhq.com, request a demo, or use the THEWATCH platform as a customer. It covers two different kinds of data, and we treat them differently:
- Account & visitor data: information about the people who use THEWATCH: names, emails, login activity, and information submitted through forms on this site. For this data, THEWATCH is the data controller.
- Customer security data: the events, alerts, and telemetry a customer organization sends into THEWATCH from its own connected tools (endpoints, cloud, identity, email, etc.) in order to monitor its own environment. For this data, THEWATCH acts as a data processor on the customer's behalf. We process it to provide the service, not for our own purposes, and the customer organization controls what's collected, retained, and deleted.
2. Information we collect
Depending on how you interact with THEWATCH, we may collect:
- Account information: name, work email, organization, role, and password (stored as a salted hash, never in plain text).
- Usage & log data: login timestamps, IP address, session activity, and actions taken in the product, which we record in an append-only audit log for security and accountability purposes.
- Contact & demo-request information: anything you submit through a "Request Access," "Request Demo," or contact form on this site (name, email, and whatever you tell us about your team or environment).
- Customer security data: the alerts, events, and metadata generated by the connectors a customer organization sets up. This can include technical identifiers (IP addresses, hostnames, usernames, file hashes, cloud resource IDs) tied to that customer's own environment.
- Billing information: when subscription billing is active, payment is handled by our payment processor (Stripe); THEWATCH does not store full card numbers on its own servers.
3. How we use information
- To provide, operate, and secure the THEWATCH platform, including authentication, role-based access control, monitoring, alerting, and automated response for the organization that owns the data.
- To respond to demo requests and inquiries submitted through this site.
- To maintain the tamper-evident audit log that records administrative and security-relevant actions within an organization's own account.
- To improve the product, troubleshoot issues, and maintain the reliability and security of the service.
- To send service-related communications (for example, security notices or billing notices). We do not sell personal information, and we do not use customer security data for advertising.
4. Data sharing & subprocessors
We share data only as needed to run the service:
- Infrastructure providers: THEWATCH is hosted on Google Cloud Platform (Cloud Run, Cloud SQL) in the United States.
- Payment processing: Stripe, for organizations on a paid subscription.
- Within your own organization: customer security data and account activity are visible to users your organization has granted access to, according to the roles and permissions your organization's admins configure.
- We do not share customer security data across organizations. Each organization's data is logically isolated from every other organization's.
- We may disclose information if required by law, or to protect the rights, property, or safety of THEWATCH, our customers, or others.
5. Data security
THEWATCH is built by a team with a forensics and incident-response background, and security is treated as a core product requirement, not an afterthought. This includes encryption in transit and at rest, hashed credentials, multi-factor authentication, configurable session timeouts, role-based access control, and a hash-chained audit log designed so that administrative actions can't be silently altered after the fact. No system is perfectly secure, and we can't guarantee absolute security, but we design and operate the platform with that goal in mind.
6. Data retention
We retain account data for as long as an account is active, plus a reasonable period afterward for legal, security, and record-keeping purposes. Customer security data is retained according to the retention settings and plan of the organization that owns it; an organization can request deletion of its own data by contacting us. Audit log entries are retained in an append-only form for accountability and are not deleted on request, consistent with their purpose as a tamper-evident record.
7. Your rights
Depending on where you're located, you may have rights to access, correct, export, or delete personal information we hold about you, or to object to certain processing. If you're an end user inside a customer organization, the fastest path is usually through your organization's own admin, since they control your account. You can also contact us directly at support@thewatchhq.com and we'll work with you (and, where relevant, your organization) to resolve the request.
8. International data transfers
THEWATCH's infrastructure is currently hosted in the United States. If you're accessing THEWATCH from outside the United States, your information will be transferred to and processed in the United States.
9. Children's privacy
THEWATCH is a business product intended for use by security and IT professionals on behalf of their organizations. It is not directed at, and we do not knowingly collect information from, children under 16.
10. Changes to this policy
We may update this policy as THEWATCH evolves. We'll update the "Last updated" date above when we do, and for material changes we'll make a reasonable effort to notify account admins directly.
11. Contact us
Questions about this policy or how your data is handled: support@thewatchhq.com.