Privacy Policy
This Privacy Policy explains what personal data Atlas Watch Registry collects, why we collect it, how we store and protect it, and what choices you have. It applies to all users of theatlasregistry.com and related services (the “Platform”).
1. Who We Are
Lake Road Labs LLC, doing business as The Atlas Register (“we,” “us,” “our”) operates the Platform. For questions about this policy, use our contact form at theatlasregistry.com/contact.
2. What the Platform Does
Atlas Watch Registry is a provenance and ownership record platform for luxury watches. It lets you create a permanent digital record for each watch you own, log service and repair history, generate shareable verification links for potential buyers, and transfer ownership records when you sell a watch.
The Platform is a record-keeping service. It does not physically authenticate watches or confirm that the watch in a buyer’s hand matches the digital record. See our Terms of Service for details.
3. Data We Collect
3.1 Data you give us directly
Account data: your email address, first and last name, and — for dealers — your business name and optional business address. Your password is handled by our authentication system; we never see or store it.
Watch records: brand, model, reference number, serial number, year, purchase details (seller, date, price, currency, country), condition, box and papers status, and listing status. Serial numbers are treated as sensitive — see Section 9.
Service history: service, repair, and ownership events including date, type, title, and description.
Photos and documents: watch photos and ownership-verification documents such as purchase receipts and warranty cards. Lost or stolen reports may include a police report.
Lost or stolen reports: report type, incident date, location, and a description of the circumstances.
Transfer data: the email address of the person you are transferring a watch to, an optional message, and the agreed sale price.
Share links: labels and visibility settings for each verification link you create.
Dealer inventory data: acquisition cost, listing price, and internal notes to help manage inventory. These fields are never shown on public-facing pages.
Contact messages: name, email, subject, and message text submitted via the contact form.
Billing and payment data: when you subscribe to a paid plan, your name and email are used for billing. Payment card details are processed directly by our payment processor and are never stored on our servers. See Section 13.
3.2 Data collected automatically
Usage data: our hosting and analytics systems collect aggregate page views and performance data, along with standard request data including IP address, browser type, and page URLs.
Authentication data: our authentication system collects request metadata including IP address and browser information to manage your session and detect suspicious activity.
Server logs: our infrastructure providers maintain standard server and database logs that may include IP addresses and request timestamps. These logs are used for security and operational purposes.
Verification link view counts: we record how many times each of your share links has been viewed. We track the count only, not who viewed it.
3.3 Data we do not collect
- Payment card numbers or CVV codes — these go directly to our payment processor.
- Biometric data.
- Health or medical data.
- Data from children under 13.
4. How We Use Your Data
- To create and maintain your account and verify your identity.
- To store watch records, service history, and provenance chains and make them available to you.
- To generate and serve public verification links according to the privacy settings you choose.
- To send you transactional emails such as transfer invitations and ownership-verification notices.
- To display lost or stolen status on public verification pages — a consumer-protection measure that overrides individual privacy settings.
- To process your subscription payments and manage your billing account.
- To analyze aggregate usage patterns and improve the Platform.
- To detect and prevent abuse, fraud, and security threats.
- To comply with applicable law.
We do not use your data for advertising. We do not sell your data to third parties.
5. How Data Is Stored and Protected
5.1 Storage locations
All application data, watch records, and uploaded files are stored on servers located in the USA. Authentication data is managed by our authentication provider, also operating in the USA.
5.2 File storage
- Sensitive documents such as purchase receipts, warranty cards, and police reports are stored in a restricted-access file store. They are never accessible by direct public URL. Access is granted only through short-lived, time-limited links generated on demand.
- General watch photos are stored in a publicly accessible file store by design, so they can be displayed on verification links you share. These photo URLs may remain accessible even after a share link is revoked. If you need a specific photo removed, contact us at theatlasregistry.com/contact.
5.3 Security measures
We take the security of your data seriously. Our measures include:
- Access controls at the record level so each user can only read and write their own data.
- Encrypted connections (HTTPS) enforced for all traffic to and from the Platform.
- Security headers to protect against common web vulnerabilities.
- Browser API restrictions preventing access to camera, microphone, and location data.
- Password management handled by our authentication provider — passwords are never stored in our database.
- Automatic session expiration after a period of inactivity.
- Bot detection and CAPTCHA protection.
6. Third-Party Service Providers
We work with third-party service providers to operate the Platform. Each provider receives only the data necessary to perform their specific function. The categories of providers we use are:
| Processing Category | Purpose | Data Shared |
|---|---|---|
| Authentication | User login, session management, organization access, password reset, email verification, and bot protection | Email address, name, session tokens, IP address, organization membership |
| Database and file storage | Storing all application data and uploaded files | All app data: watch records, ownership events, transfers, messages, photos, and documents |
| Email delivery | Sending transactional emails such as transfer invitations and ownership-verification notices | Recipient email address, message subject, and message body |
| Web hosting and analytics | Hosting the application and collecting aggregate page-view and performance data | Standard HTTP request data including IP address, browser type, and page URLs |
| Security and bot protection | Bot detection and CAPTCHA verification to protect the Platform from automated abuse | Security signals and IP address |
| Payment processing | Processing subscription payments securely | Name, email address, and payment method details. Card data is processed directly by our payment processor and is never stored on our servers. |
We do not share your data with advertising networks, behavioral tracking services, or social media platforms.
7. What Is Shared With Other Users
7.1 Public verification links
Watch records are private by default. When you generate a verification link, you choose what is visible. Some information is always shown; the rest is opt-in.
Always shown on collector verification links:
- Watch brand, model, and reference number.
- A partial serial number. The full serial number is opt-in.
- Lost or stolen status — always visible when flagged; cannot be hidden.
- The date the record was last updated and the Atlas Watch Registry verification mark.
Shown only if you enable them: full serial number, purchase price, asking price, photos, ownership documents, your name, country, ownership history, and service history.
Dealer verification links always show the organization name and watch details. Internal notes, acquisition cost, buyer email, and financial data are always hidden on public pages.
7.2 Transfer recipients
When you initiate an ownership transfer, the recipient receives a claim email. We store their email address as part of the transfer record. Once a transfer is accepted, the provenance history carries to the new owner with the buyer’s email address and any other private transaction details removed.
7.3 Dealer organization members
All members of a dealer organization share access to the organization’s full inventory, including pricing and buyer information. Each action is attributed to the team member who performed it.
8. Cookie Policy
This section is our Cookie Policy. It describes what cookies and browser storage we use, why we use them, and how you can manage them.
8.1 What are cookies?
Cookies are small text files stored on your device by your browser. We also use browser-based local storage to save your preferences on your device. We do not use cookies or local storage for advertising or behavioral profiling.
8.2 What we use
| Cookie / Storage | Category | Duration | Purpose |
|---|---|---|---|
| Authentication session | Strictly necessary | Session duration | Keeps you logged in. Set by our authentication system. The Platform cannot function without this cookie while you are logged in. |
| Onboarding state | Functional | Very short (minutes) | Maintains state during account setup while your session updates. Contains no personal data. |
| View preference (browser storage) | Functional preference | Persistent | Remembers your display preference in the dealer interface. Stored in your browser only; never sent to our servers. |
8.3 What we do not use
We do not use advertising cookies, behavioral tracking cookies, session-replay tools, social media pixels, or any cross-site tracking technology.
8.4 Managing cookies
You can manage cookies through your browser settings. Note that blocking authentication cookies will prevent you from logging in. For instructions, visit your browser’s help documentation:
- Chrome: Settings > Privacy and security > Cookies and other site data
- Firefox: Settings > Privacy & Security > Cookies and Site Data
- Safari: Preferences > Privacy > Manage Website Data
- Edge: Settings > Cookies and site permissions
9. Sensitive Data
The following categories receive additional care because of their connection to high-value physical assets:
Serial numbers: a watch’s serial number uniquely identifies a high-value physical object. We show only a partial serial number on public pages by default. The full serial is shared only if you explicitly enable it on a specific link.
Financial data: purchase prices, asking prices, and sale prices are not shown publicly unless you choose to share them. Dealer acquisition costs and internal margins are never shown publicly.
Location and incident data: when a watch is reported lost or stolen, the incident location and date are stored securely and are not shown publicly unless you choose to share them via a lost-alert link.
Ownership documents: purchase receipts, warranty cards, and police reports are stored in a restricted-access file store. They are accessible only via short-lived, time-limited links — never by public URL.
Contact and address data: your personal address and phone number are stored in your account but are never shown on public verification pages unless you are a dealer who has explicitly enabled contact sharing on a specific link.
10. Data Retention
10.1 While your account is active
We keep your data for as long as your account is active. You can edit most of it at any time.
10.2 When you close your account
When you delete your account, we anonymize your profile: your name, email, phone, address, and business name are erased or replaced with “Previous owner.” Your account is then flagged as deleted and your login credentials are removed.
Watch records, service history, and ownership events are not deleted. The provenance chain is the core value of the Platform — deleting events would undermine its integrity for future owners. After deletion, those records remain but are attributed to “Previous owner” rather than to you personally.
10.3 Specific retention rules
- Ownership and service events: retained permanently. Events are append-only by design — no delete path exists.
- Watch provenance records: retained after account deletion, attributed to “Previous owner.”
- Revoked share links: retained with a revoked status so they serve no data but the audit record is preserved.
- Transfer records: retained with a status flag (accepted, expired, or cancelled).
- Watch photos: removed from our database when you delete a watch or your account. Photo files in storage may take a short additional period to be fully purged.
11. Your Rights and Controls
Access and correction: view and edit your profile, watch records, and share-link settings in the Platform at any time.
Share-link control: revoke any verification link at any time. Revoked links immediately stop serving data.
Transfer cancellation: cancel any pending transfer before the recipient claims it.
Account deletion: delete your account from your Settings page. This triggers the anonymization process described in Section 10.2.
Provenance history: event history cannot be deleted (see Section 10.2). After account deletion it remains in the system but is no longer linked to your identity.
For any request you cannot complete through the Platform, submit a request via theatlasregistry.com/contact.
12. California Residents (CCPA)
If you are a California resident, the California Consumer Privacy Act gives you the following rights:
- Right to know: request a summary of the categories of personal information we collect and how we use it.
- Right to deletion: request deletion of your personal information, subject to the provenance-history retention explained in Section 10.2.
- Right to opt out of sale: we do not sell your personal information.
- Right to non-discrimination: we will not discriminate against you for exercising these rights.
To make a request, use the contact form at theatlasregistry.com/contact.
13. Billing and Payments
Atlas Watch Registry offers paid subscription plans. Subscriptions are billed on a recurring basis and renew automatically at the end of each billing period.
Payment processing is handled securely by our payment processor. We do not store your full payment card number, CVV, or bank account details on our servers. We collect your name and email address for billing account purposes.
If you have a billing question or believe you have been charged in error, contact us at theatlasregistry.com/contact within 30 days of the charge.
14. Children
The Platform is not directed at children. We do not knowingly collect personal data from anyone under 13. If you believe a child under 13 has created an account, contact us at theatlasregistry.com/contact so we can remove it.
15. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email and by posting a notice on the Platform at least 30 days before the changes take effect.
16. Contact Us
For privacy questions, rights requests, or complaints:
Lake Road Labs LLC, doing business as The Atlas Register
Contact form: theatlasregistry.com/contact
We aim to acknowledge all requests within five business days and to respond in full within 30 days.
