RGATT
Legal

Privacy Policy

How RGATT collects, uses and protects your personal data, in accordance with Regulation (EU) 2016/679 (GDPR).

Version 1.1Effective 22 July 2026

01Data controller

The data controller is RGATT SAS, SIREN 107 414 757, whose registered office is at 47 rue Vivienne, 75002 Paris, France (see legal notice). For any data-related question: privacy@rgatt.com.

02Data we collect

  • Identity & account: email, username, sign-in method (email, Google, wallet).
  • Registration & provenance data: watch details, encrypted serial number, authentication and status-change events, ownership transfer history.
  • Subscription & payment data: collected and processed directly by Stripe; RGATT has no access to full banking details.
  • Technical data: IP address, device, browser, usage logs (security, fraud prevention).
  • On-chain data: public wallet address and provenance events. A wallet address is pseudonymous, not anonymous: it is personal data under the GDPR, and it is public and permanent by nature. No name, email or serial number is ever written on-chain in clear text.

03Purposes & legal bases

  • Provide the service (account, registration, traceability, ownership transfers) - performance of the contract.
  • Payment & anti-fraud- legal obligation & performance of the contract (via Stripe).
  • Tax (VAT, invoicing) - legal obligation.
  • Transactional communications (status emails) - performance of the contract.
  • Service improvement & security - legitimate interest.
  • Marketing communications - consent (revocable at any time).

04Recipients & processors

RGATT does not sell your data. It is shared with providers acting as processors, strictly for the purposes above:

  • Stripe - subscription and one-time payments.
  • Privy- authentication & wallet.
  • Supabase - database (EU).
  • Vercel- hosting & file storage.
  • Resend - transactional emails.
  • Upstash - technical cache.
  • Sentry - error monitoring. Diagnostic reports may incidentally contain technical identifiers.
  • Discord - internal operational alerts. RGATT sends itself a notification when significant events occur on the platform (a sign-in, a payment incident). These notifications identify the account by its wallet address only.

The Discover feature sends a query to Mistral and Tavily to look up a watch reference. That query contains only the brand and reference you typed, never your identity, your account, or any other personal data, so these providers do not process personal data on our behalf.

05Transfers outside the European Union

Your database record is stored in the European Union. Several of the providers listed above are established outside the EU, or may process data outside it: Vercel, Privy, Resend, Sentry and Discord (United States). Payments are handled by Stripe Payments Europe, established in Ireland, which may transfer data to its US parent company.

Such transfers are framed by appropriate safeguards under Chapter V of the GDPR: European Commission standard contractual clauses, or certification under the EU-US Data Privacy Framework where the provider is certified.

06Retention periods

  • Account: for the duration of use, then deletion/anonymisation.
  • Billing & invoicing data: retained per legal obligations (accounting/tax, generally 10 years).
  • Technical logs: limited duration for security purposes.
  • On-chain data: permanent and technically impossible to erase or amend, which is the point of a tamper-proof provenance registry. This is a real limit on the rights to erasure and rectification, and we state it plainly rather than imply otherwise: what is written on-chain stays there. We therefore keep on-chain records to the strict minimum (a wallet address and an event type), and everything that can be erased is held off-chain in our database, where deletion and correction do apply.

07Your rights

Under the GDPR, you have the rights of access, rectification, erasure, restriction, objection and portability, as well as the right to withdraw consent and to set post-mortem directives.

To exercise them: privacy@rgatt.com. Account deletion is also available from your profile.

One honest limit: data already written to the public blockchain cannot be erased or corrected by anyone, including us. Erasure and rectification apply in full to everything held in our own database, which is where all identifying data lives. See the retention section above for what this covers.

08Security

RGATT implements appropriate technical and organisational measures (encryption of sensitive data, access control, compliant providers) to protect your data against unauthorised access, loss or alteration.

09Contact & complaints

Any question: privacy@rgatt.com. You may lodge a complaint with the French CNIL (cnil.fr).

Keep the processor list above in sync with the tools actually reached from server code - a recipient that is not listed here is a GDPR breach, however minor the data. When adding one, check three things: what it receives, whether it sits outside the EU (section 5), and whether the data sent to it can be reduced first. Reducing beats declaring. Mirror every change in the French version above.
Questions about this document? legal@rgatt.com