For purposes of this Policy, “WatchMesh,” “we,” “us,” and “our” refer to the operator of the WatchMesh Service. For paid customers, the applicable merchant or seller is identified on the relevant order confirmation, invoice, or receipt. WatchMesh is intended primarily for business users in the United States and Canada who are at least 18 years old.
1. Information we collect
Account and contact information
We collect information needed to create and administer an account, such as your email address, authentication or login information, and other account details you choose to provide. If you contact us or submit an Exposure Review or access request, we collect the contact details and message or form information necessary to review and respond.
Protected-asset information
We collect basic information about assets you ask us to protect, such as asset or product name, official website or domain, selected protection scope, and related account settings. The standard Service does not require full product videos, images, course files, software binaries, ebooks, or other copies of the protected work. We may request additional rights-verification information when reasonably necessary to establish authority or satisfy an enforcement process.
Business impersonation monitoring information
For paid impersonation monitoring, we collect official business information supplied by the customer, including relevant people and representatives, approved public profiles, domains, jobs or listings, and supported contact details. We use it to investigate and validate suspected abuse and pursue authorized enforcement.
Billing information
Payments are processed by Stripe or another payment processor identified at checkout. WatchMesh does not store full payment-card numbers. We may receive billing status, transaction identifiers, plan information, amounts, card brand or partial card details, billing country, and similar information needed to administer subscriptions and resolve billing issues.
Service, device, and log information
To provide the Service, we create and store operational records such as suspected infringement URLs, domains, platform or provider information, verification results, complaint status, enforcement history, timestamps, follow-up activity, recurrence events, and outcomes. These records may contain information about third parties found in public sources or provider responses, such as a publicly listed site operator or abuse contact.
When you use the website or Service, we may automatically receive technical information such as IP address, browser and device type, operating system, referring page, pages viewed, timestamps, and security or diagnostic logs.
Communications
If you contact us, we collect the contents of your message and contact information needed to respond.
2. How we use information
We use information to create and secure accounts; provide monitoring, validation, enforcement, escalation, recurrence monitoring, and reporting; identify protected assets and distinguish official sources from suspected piracy; submit and manage authorized complaints; process subscriptions and administer Quiet Month billing; provide support and communicate about the Service; monitor performance and troubleshoot; prevent fraud and protect security; understand website usage and improve the Service; comply with legal obligations and enforce agreements; and establish, exercise, or defend legal claims.
We may create aggregated or de-identified information that no longer reasonably identifies an individual and use it for analytics, security, product improvement, and business planning.
3. How we share information
We do not sell personal information. We may share it in the following circumstances.
Service providers
We use providers to operate WatchMesh. Current core providers include Amazon Web Services (AWS) for hosting and infrastructure, Stripe for payment processing and subscription billing, and Google Analytics for basic website measurement. Formspree receives information submitted through website access-request, Exposure Review forms so the inquiry can be delivered to and reviewed by WatchMesh. Providers receive information as reasonably necessary to perform services for us and are subject to their own contractual and legal obligations. We may add or replace providers as the Service evolves.
Enforcement recipients
When carrying out authorized enforcement, we may provide information reasonably required by the recipient, such as a search engine, platform, website operator, file host, hosting provider, CDN, registrar, DNS provider, payment provider, advertising provider, or other relevant service provider. We try to limit disclosure to information reasonably necessary to identify the protected work and suspected infringement, demonstrate authority, and process the request.
Legal, safety, and business disclosures
We may disclose information where we reasonably believe disclosure is required by law, legal process, or a valid government request, or is necessary to protect rights, safety, security, or property of WatchMesh, customers, or others. Information may also be transferred as part of a merger, financing, acquisition, reorganization, sale of assets, or similar transaction, subject to appropriate confidentiality and legal protections.
4. Sale and third-party targeted advertising
WatchMesh does not sell personal information and does not currently use customer account or protected-asset information for third-party targeted advertising. If our practices materially change, we will update this Policy and provide choices required by applicable law.
5. Data retention
We retain information only as long as reasonably necessary for the purposes described here, including providing the Service, maintaining security, resolving disputes, and meeting legal, tax, and accounting obligations. As a general operational default, after a paid Service ends we aim to delete or anonymize ordinary account, protected-asset, and case data from active systems within approximately 30 days, unless continued retention is reasonably necessary for legal, fraud-prevention, security, dispute, billing, or compliance purposes.
Previously received submissions and related communications are retained only as reasonably necessary for review, security, dispute and legal purposes. Submissions held by Formspree are also subject to that provider's retention and deletion controls.
Residual copies may remain in routine backups for up to approximately 90 days before being overwritten or cycled out. Billing and transaction records may be retained longer where reasonably necessary for tax, accounting, chargeback, fraud-prevention, or legal obligations. Aggregated or de-identified data may be retained longer where it no longer reasonably identifies an individual. Google Analytics data is retained according to our Analytics configuration and Google’s applicable data-retention controls.
6. Cookies and analytics
Cookies are small pieces of information stored by a browser or device. Some last only for a session; others remain longer or until deleted. WatchMesh may use essential cookies or similar storage reasonably necessary for sign-in, session management, security, fraud prevention, and basic settings. Blocking essential cookies may prevent parts of the Service from functioning correctly.
WatchMesh currently uses Google Analytics for basic website measurement. Analytics may collect session and usage statistics, approximate geographic location, browser and device information, and interactions with pages and features. Google Analytics uses first-party identifiers such as the _ga cookie and related Analytics cookies to distinguish users and sessions. Google states IP addresses may be used at collection for functions such as geographic reporting and routing, but are not logged or stored in Google Analytics as raw IP addresses.
We use Analytics for measurement and improvement, not to sell personal information or build third-party advertising profiles. WatchMesh does not currently use advertising pixels or cookies for cross-site behavioral advertising. You can control or delete cookies in browser settings and use Google’s Analytics opt-out tools in supported browsers. Disabling analytics cookies should not prevent ordinary access to core Service features, though it may reduce our ability to understand website use. Where WatchMesh provides a cookie or analytics preference control, we will use that choice to control non-essential analytics as supported by our implementation. If we add advertising or materially different tracking, we will update this Policy and provide choices required by law.
7. Security
We use reasonable administrative, technical, and organizational safeguards designed to protect information against unauthorized access, loss, misuse, or alteration. No internet service or storage system is completely secure, and we cannot guarantee absolute security. You are responsible for protecting account credentials and notifying us promptly if you believe an account has been compromised.
8. Privacy choices and rights
Depending on where you live, you may have rights concerning personal information, such as requesting access, correction, deletion, or a copy of certain information, or withdrawing consent for certain processing. You may also object to or limit non-essential analytics through available cookie controls, browser settings, or Google’s Analytics opt-out tools.
To submit a privacy request, email legal@watchmesh.com. We may need to verify your identity. We may decline or limit a request where permitted or required by law, including where records must be retained for security, fraud prevention, billing, legal claims, or compliance. If you use WatchMesh for an organization, some requests may need to be handled through its account administrator.
9. International processing
WatchMesh is intended primarily for users in the United States and Canada. Our providers may process information in the United States, Canada, or other jurisdictions in which they operate. Information may therefore be subject to laws different from those where you live.
10. Children
WatchMesh is not intended for children or minors. You must be at least 18 years old to create an account or purchase the Service. We do not knowingly solicit personal information from children. If you believe a minor has provided information to WatchMesh, contact legal@watchmesh.com.
11. Third-party websites and services
The Service may link to third-party websites, search engines, platforms, payment processors, or other services. Their privacy practices are governed by their own policies, not this Privacy Policy.
12. Changes to this Policy
We may update this Policy as WatchMesh, our practices, or legal requirements change. We will update the effective date above and provide additional notice where a material change requires it.
13. Contact
For privacy questions or requests, contact legal@watchmesh.com.