Calibrating your experience
TimeAuthentic LLC
Effective October 1, 2026 · Version 1.0
This Policy applies to users in the 50 United States and the District of Columbia at launch. TimeAuthentic accounts are for individuals age 18 or older. Privacy requests may be submitted to Privacy.TimeAuthentic@Gmail.com or through the TimeAuthentic website contact form. TimeAuthentic acknowledges ordinary privacy requests within seven days and targets completion within 30 days, subject to lawful extensions or unusual complexity.
We may collect name, email address, phone number, account credentials through Supabase Auth, user profile information, shipping and billing address, role or status, marketing preferences, account-security status, and information you voluntarily add to your profile or Watchroll.
Payment collection occurs on Stripe-hosted Checkout pages. TimeAuthentic does not receive or store full card numbers, bank account numbers, routing numbers, or full payment credentials. We store Stripe reference identifiers, transaction amounts, currency, payment status and timestamps, pricing snapshots, transaction records, refund and payout records, and information needed to administer a transaction.
For ACH, Stripe Financial Connections is configured for payment-method permission. TimeAuthentic does not ordinarily receive bank balances, transaction history, or full bank-account credentials through that connection.
We maintain legal and transactional acceptance records that may include the Terms version, Pre-Sale Agreement version, exact checkbox or modal language displayed, user or account identifier, listing or transaction identifier, timestamp, IP address, user agent, acceptance method, material-discrepancy decisions, service authorizations, subscription authorizations, and shipping-insurance elections. When a buyer declines outbound shipping insurance, the decline and the exact acknowledgment accepted are retained with the customer profile and transaction record.
TimeAuthentic does not ordinarily collect seller SSNs, EINs, W-9s, or 1099 information through the marketplace unless required for legal, tax, seller-verification, or payment-compliance purposes. If applicable law requires additional seller identity or tax information, TimeAuthentic may collect and verify it as necessary.
We collect watch brand, model, reference, serial information, listing and transaction details, condition and completeness information, service history, authentication results, ownership and provenance events, TimeAuthentic Watch Passport identifiers, watch photographs and video, service-case notes, shipping and tracking information, insurance and claim information, and related records. Serial numbers are restricted to the verified current owner and authorized TimeAuthentic personnel and are withheld from prospective buyers before transaction completion.
We collect public posts, comments, group activity, reactions, moderation records, contact-form submissions, direct email communications, and service-case correspondence. TimeAuthentic does not currently provide private direct messaging, SMS, web or mobile push notifications, or an integrated third-party customer-support inbox.
Depending on the context, our infrastructure and service providers may process IP address, user agent, page or route information, device and browser characteristics, authentication events, error and performance information, and security or rate-limit data. TimeAuthentic does not use browser precise-geolocation APIs. Approximate location may be inferred transiently from IP address by infrastructure providers or security tools.
TimeAuthentic uses Vercel Web Analytics for cookieless page and route analytics and Sentry for error monitoring, performance tracing, and privacy-masked session replay. Session replay may be used to troubleshoot errors and understand user experience and sales-funnel behavior, including where users hesitate or abandon a workflow.
TimeAuthentic's policy is to mask form-field contents and personal or sensitive text, block sensitive customer-uploaded media where appropriate, exclude Stripe-hosted payment and ACH pages, and exclude or fully mask highly sensitive administrative, financial, identity, security, and account surfaces.
Optional Sentry session replay is retained for up to 90 days and access is limited to authorized personnel with a legitimate debugging or user-experience analysis need. Session replay is not used for public marketing or AI model training. A user may request exclusion from optional session replay or behavioral analytics by emailing Privacy.TimeAuthentic@Gmail.com. Essential security, fraud-prevention, operational logging, and error monitoring may continue where necessary to operate and protect the Services.
Where applicable law requires recognition of a browser-based privacy preference signal or another statutory opt-out mechanism, TimeAuthentic will honor that requirement. A voluntary email-based session-replay opt-out does not replace nonwaivable statutory privacy rights.
TimeAuthentic uses strictly necessary Supabase authentication and session cookies and related technologies needed to sign users in, maintain sessions, and secure accounts. Vercel Web Analytics is configured as cookieless analytics. Google reCAPTCHA v3 is used on the contact form and may receive IP address, user agent, and interaction signals to generate a bot or risk score; TimeAuthentic stores only the pass or fail result. Upstash Redis may use an IP address or authenticated user ID as a short-lived rate-limit key.
TimeAuthentic does not currently use Google Ads, Meta Pixel, TikTok Pixel, Google Tag Manager, or other third-party advertising or retargeting pixels. TimeAuthentic will provide privacy-preference mechanisms where required by applicable law. Marketing preferences are managed separately.
We disclose personal information as reasonably necessary to operate the Services, complete transactions, protect users and TimeAuthentic, administer shipping and insurance, or comply with law. Recipients may include transaction counterparties to the extent necessary, assigned watchmakers or service personnel, payment providers, shipping carriers, insurance providers and claim administrators, cloud and infrastructure vendors, email providers, security and anti-abuse vendors, professional advisers, insurers, law enforcement, courts, regulators, or a successor in a corporate transaction.
TimeAuthentic does not currently sell personal information to third parties for money and does not currently use third-party advertising or cross-context behavioral advertising pixels. If that practice changes, TimeAuthentic will update this Policy and implement any legally required opt-out or consent mechanisms before the change.
| Provider / Category | Purpose / Data Context |
|---|---|
| Vercel | Application hosting, serverless compute, CDN, runtime and deployment logs, and cookieless web analytics; may process request traffic, IP address, user agent, and page or route information. |
| Supabase (AWS us-west-2) | Database, authentication, and private file storage; hosts core application data, credentials, and uploaded media in U.S.-based infrastructure. |
| Stripe | Card and ACH payment processing; receives payment credentials directly along with transaction and contact information needed for payment. |
| Sentry | Error monitoring, performance tracing, and privacy-masked session replay; may process technical context and masked interaction recordings. |
| Resend | Transactional and workflow email delivery; receives recipient email address and message content. |
| EasyPost | Shipping rates, label and parcel workflow, and tracking; may receive sender and recipient name, address, phone, and parcel information. |
| Shipping carriers and insurance providers | Shipment transport, tracking, insured shipping, and claim administration; may receive shipment, watch-value, sender, recipient, delivery, and claim information as necessary. |
| Upstash Redis | Short-lived abuse and rate limiting using IP address or authenticated user identifier as ephemeral keys. |
Public display of a TimeAuthentic Watch Passport is limited to watch brand and model and only where the verified owner permits public display. The verified current owner may access all TimeAuthentic Watch Passport fields made available by TimeAuthentic, including serial number, TimeAuthentic Watch Passport identifier, authentication and service history, and associated media. Prospective buyers may see non-identifying condition, authentication, and service history but not the serial number or TimeAuthentic Watch Passport identifier until the transaction is complete.
When a TimeAuthentic Watch Passport transfers, all transferable watch history follows the watch except prior-owner personal information. Legitimate non-personal TimeAuthentic Watch Passport and provenance history is retained indefinitely. Account deletion does not erase the historical watch record that must remain to preserve provenance, fraud prevention, authentication, service integrity, and transaction history. Prior-owner profile photographs do not transfer. A separate provenance photograph associated with a prior owner transfers only where the owner deliberately opted in and the image was approved under TimeAuthentic's process.
Authentication and service video may include audio. Ordinary authentication and service case photos, video, audio, and related media are retained for 10 years. TimeAuthentic's protected Capture Agent Office Archive master surveillance record, including outbound packaging video, is retained indefinitely unless an authorized Super Admin deletes it under internal policy. These are separate retention categories.
Case media is stored in private access-controlled storage. TimeAuthentic limits access according to role and case relationship. TimeAuthentic may use case media internally for authentication, quality assurance, claims, security, dispute resolution, recordkeeping, training, and service administration. Public marketing use of customer-associated recordings, face, voice, likeness, or testimonial requires separate affirmative opt-in consent.
Seller-uploaded watch photographs may be reused beyond the original listing, including as long-term catalog or reference images and hero images. The seller-photo license is described in the Terms and Pre-Sale Agreement and survives listing removal, transaction completion, and account deletion where the photograph has become part of catalog, provenance, transaction, editorial, or platform assets. TimeAuthentic-created watch-only photography from intake, authentication, or service may also be used for catalog, hero imagery, TimeAuthentic Watch Passport and provenance, editorial, and other platform content after identifying information is removed or masked.
TimeAuthentic may use de-identified seller-uploaded watch photographs and de-identified authentication photography or video to develop internal authentication, cataloging, or related models. TimeAuthentic's policy is to remove or exclude names, addresses, account information, unnecessary serial or TimeAuthentic Watch Passport identifiers, and identifying audio when practical before model development. If TimeAuthentic wishes to use identifiable customer or seller media for AI development, it will obtain separate affirmative consent. TimeAuthentic does not currently send customer authentication media or customer personal information to third-party AI providers for model training.
TimeAuthentic and WristMarket may share basic account identity and account infrastructure because both are operated by TimeAuthentic LLC. Community and social activity such as groups, follows, posts, comments, and reactions remains specific to the service in which it occurs by default unless the user deliberately activates a specifically shared feature. Marketing opt-outs apply across TimeAuthentic and WristMarket. Marketing opt-ins are service-specific unless the user affirmatively joins a combined TimeAuthentic and WristMarket marketing program. Transactional, service, security, legal, and other non-marketing communications remain separate and may be sent as needed.
| Data Category | Retention |
|---|---|
| TimeAuthentic Watch Passport and non-personal provenance history | Indefinite while the TimeAuthentic Watch Passport system is maintained; survives account deletion. |
| Authentication / inspection case video and audio | 10 years. |
| Capture Agent Office Archive master record, including packaging video | Indefinite unless manually deleted by an authorized Super Admin under internal policy. |
| Service-case records and ordinary case media | 10 years. |
| Listings, orders, transaction records, financial ledgers, and payout records | 7 years; longer for an active dispute, fraud investigation, legal hold, insurance claim, or permanent TimeAuthentic Watch Passport or provenance need. |
| Terms, Pre-Sale Agreement, and other legal acceptance records | 10 years after the account relationship ends; longer for disputes, legal holds, limitation periods, linked transaction records, or permanent TimeAuthentic Watch Passport or provenance needs. |
| Shipping-insurance decline records | Indefinite as part of the customer profile and transaction legal record, subject to applicable law. |
| Meaningful administrative, financial, legal, and security audit logs |
TimeAuthentic provides an in-account "Request Account Deletion" process. An authenticated request may be verified through the logged-in account. Requests may also be submitted through Privacy.TimeAuthentic@Gmail.com or the website contact form; TimeAuthentic may confirm control of the registered email or request additional account-specific verification. Government ID is not ordinarily required for a privacy request and is requested only where a serious identity dispute cannot reasonably be resolved by less intrusive means.
Active purchases, sales, service cases, payouts, disputes, balances, legal holds, insurance claims, or other open obligations may need to be completed or resolved before account deletion is finalized. When processed, TimeAuthentic deletes or de-identifies ordinary account data while retaining records subject to TimeAuthentic Watch Passport and provenance, transaction and financial, legal acceptance, shipping-insurance decline, fraud, dispute, tax and accounting, insurance, and legal-hold exceptions. Deletion is account-wide across TimeAuthentic and WristMarket.
At launch, access, correction, portability, and other privacy requests are handled through Privacy.TimeAuthentic@Gmail.com or the website contact form rather than separate in-account controls. TimeAuthentic acknowledges requests within seven days and ordinarily completes them within 30 days, subject to lawful extensions or unusual complexity.
Depending on your state of residence and whether a particular privacy law applies to TimeAuthentic, you may have rights to know or access personal information, correct inaccurate information, delete certain information, obtain a portable copy, opt out of certain sales or sharing, limit certain sensitive-data uses, or appeal a denied request. TimeAuthentic will not unlawfully discriminate against you for exercising an applicable privacy right. Rights are subject to statutory exceptions, including records TimeAuthentic must retain for transactions, fraud prevention, legal obligations, security, disputes, insurance, and TimeAuthentic Watch Passport or provenance integrity.
TimeAuthentic does not currently sell personal information for money or use third-party advertising pixels for cross-context behavioral advertising. If TimeAuthentic becomes legally required to honor Global Privacy Control or another browser preference signal for a covered processing activity, it will do so.
TimeAuthentic uses administrative, technical, and physical safeguards designed to protect information, including role-based access, least-privilege principles, private media storage, authentication controls, step-up authentication for sensitive administrative functions, audit logs, monitoring, rate limiting, and incident-response processes. Full database or service-role access is limited to trusted personnel whose responsibilities require it, and access should be removed promptly when no longer needed. No method of transmission or storage is completely secure.
TimeAuthentic does not use Face ID, Touch ID, passkeys, or biometric templates as part of its own authentication system at present. If your operating system or password manager uses device biometrics to autofill credentials, that biometric exchange occurs outside TimeAuthentic.
TimeAuthentic accounts are not available to anyone under 18. TimeAuthentic does not knowingly permit minors to create transactional accounts. If TimeAuthentic learns that an underage account was created, it may close the account and handle associated records as required by law and transaction integrity.
TimeAuthentic may update this Privacy Policy to reflect product, legal, vendor, or operational changes. Material changes will be communicated by reasonable notice. Because this Privacy Policy is a notice rather than a general contract, users are not required to agree to the Privacy Policy as a whole. Where applicable law requires affirmative consent for a particular new or changed data practice, TimeAuthentic will obtain that consent before conducting the covered practice. The effective date at the top identifies the version in force.
Privacy.TimeAuthentic@Gmail.com | TimeAuthentic website contact form
| Google reCAPTCHA v3 | Contact-form bot and abuse prevention; receives IP address, user agent, and interaction signals. |
| OpenAI | Admin-only watch-reference research using brand, model, and reference text queries; customer media and customer personal information are not intended to be sent for this use. |
| YouTube privacy-enhanced embeds | Editorial video embeds using privacy-enhanced mode; YouTube may receive ordinary embed request data when a user interacts with embedded media. |
TimeAuthentic's primary application, database, authentication, and private-file infrastructure is intended to be hosted in the United States. Vercel serverless compute is currently configured in Portland, Oregon, and Supabase database, authentication, and storage are currently hosted on AWS us-west-2 in Oregon. Vendor infrastructure and routing may change, and this Policy will be updated when a material change affects the accuracy of this statement.
| 7 years. |
| Account profile | Life of account, then deleted or de-identified on an approved deletion request subject to retention carve-outs. |
| Community posts and comments after account deletion | May remain in anonymized form such as "Deleted User"; specific content may be removed for privacy, safety, or legal reasons. |
| Sentry optional session replay | Up to 90 days. |
| Short-lived rate-limit records | Minutes or applicable ephemeral TTL. |
| Stripe and other provider records | Retained under the provider's own legal and operational retention obligations. |