Privacy Policy
Effective September 6, 2026
This is Digitload's current draft Privacy Policy for Watch-IP. It reflects how the Service actually handles data today, but has not yet been reviewed by outside counsel — treat it as informative rather than final until that review is complete.
This Privacy Policy explains what data Digitload Inc. ("Digitload", "we", "us") collects through Watch-IP (watch-ip.com), why, and for how long. It covers two different groups of people: the visitors and end users of our customers' websites and apps whose requests pass through the Watch-IP API ("Visitors"), and the individuals who hold or use a Watch-IP account ("Customers"). Where we process Visitor data on a Customer's behalf, the Customer — not Digitload — is the controller of that data for most purposes; see our Data Processing Addendum for details on that relationship.
1. Data From API Requests
What we collect depends on which endpoint is called:
- GET /v1/geo — reads Cloudflare's edge request.cf data for the Visitor calling the endpoint (approximate country, region, city, latitude/longitude, timezone, ASN, and connection/threat signals such as VPN, Tor, or datacenter hosting). We do not persist the Visitor's IP address or the response; the request is logged only as an aggregate, non-identifying usage count for rate limiting and billing.
- GET /v1/lookup/{ip} and POST /v1/lookup — compute approximate geolocation (without security or threat fields) for IP addresses the Customer supplies (typically their own end users' IPs, sourced from server logs or account activity). We don't persist the submitted IPs or the computed results beyond the aggregate, per-IP usage count needed for billing (each IP in a bulk request counts as one billable lookup).
- POST /v1/email/validate — checks whether an email address's domain matches a known disposable/temporary provider. The email address is used only to extract and check its domain for the duration of the request; we don't store the email address or domain queried.
- POST /v1/risk/check — compares an IP's resolved location against a userId's last-known location to flag improbable travel speed ("impossible travel"). Unlike the endpoints above, this one is stateful by design: we store the single most recent {latitude, longitude, country, timestamp} observed for each (Customer, userId) pair so the next check has a baseline to compare against. We don't store a history of past locations — each new committed check overwrites the previous baseline. This stored baseline is Visitor/end-user data submitted and controlled by the Customer; we retain it until it's overwritten by a later check, the Customer deletes it, or the Customer's account is closed.
2. Data From Your Account and the Dashboard
When you sign up for Watch-IP, we collect your name, email address, and (through our payment processors, Stripe and PayPal) billing information such as a masked card number or PayPal account identifier and billing address — we don't ourselves store full card numbers. We also store the origins you register, your API keys (hashed, not in plaintext), and your plan and usage history.
If you contact support or submit an enterprise inquiry, we collect what you provide in that form — name, email, company, and your message — and, for the enterprise form, your estimated monthly request volume and use case. Both forms are protected by Cloudflare Turnstile, which processes a small amount of technical signal (not shown to us) to distinguish humans from bots.
4. How We Use Data
We use API request data to provide the Service (compute and return the response), enforce rate limits and plan quotas, detect abuse, and calculate usage for billing. We use account data to operate your subscription, provide support, send service and billing notices, and — if you opt in — product updates. We use contact-form submissions solely to respond to your inquiry.
5. Legal Bases for Processing (EEA/UK Visitors and Customers)
Where GDPR or UK GDPR applies, we process account and billing data to perform our contract with you, API request data under our (or, for /v1/lookup, /v1/email/validate, and /v1/risk/check, the Customer's) legitimate interest in providing and securing the Service, and contact-form data based on your consent to be contacted. We rely on legitimate interest for fraud/abuse detection and rate limiting, balanced against Visitors' and Customers' rights as described in Section 8.
7. International Data Transfers
Digitload is based in Ontario, Canada, and our infrastructure providers operate global networks, so data may be processed in Canada, the United States, and other countries where our subprocessors maintain infrastructure. Where we transfer personal data out of the EEA, UK, or Switzerland, we rely on the subprocessor's Standard Contractual Clauses or an equivalent safeguard.
8. Your Rights
Subject to applicable law (which may include GDPR/UK GDPR, Canada's PIPEDA, and U.S. state privacy laws), you may have the right to access, correct, delete, or export data we hold about you, to object to or restrict certain processing, and to withdraw consent where processing is based on it. Customers can access and correct most account data directly from the dashboard, including deleting a stored /v1/risk/check baseline directly via DELETE /v1/risk/baseline (or by contacting us).
If you're a Visitor or end user and believe a Customer's use of Watch-IP involves your data, please contact that Customer first, since they control how and why your data was submitted to us. You can also reach us directly at the address below and we'll route the request appropriately.
9. Data Retention
We keep account and billing data for as long as your account is active, and for a limited period after closure as needed for tax, accounting, and legal-defense purposes. Aggregate usage totals (used for billing history) are kept indefinitely as low-level financial records. Raw API request bodies and computed geolocation/threat responses are not retained beyond the request itself, except for the /v1/risk/check baseline described in Section 1, which persists until overwritten, deleted, or the account is closed.
10. Security
API keys are stored hashed (SHA-256), never in plaintext. Access to production data is limited to personnel who need it to operate the Service. Traffic to the API and dashboard is encrypted in transit (TLS). No system is perfectly secure, and we can't guarantee absolute security, but we design the Service to minimize what personal data we retain in the first place — see Section 1.
11. Children's Privacy
Watch-IP is a business-to-business developer product, not directed at children, and we don't knowingly collect account data from anyone under 16. If you believe a child has provided us personal data, contact us and we'll delete it.
12. Changes to This Policy
We may update this Policy as the Service evolves. If a change is material, we'll notify Customers by email or an in-dashboard notice before it takes effect. The "Effective" date above reflects the last update.
Questions about this policy or a data subject request can be sent to privacy@watch-ip.com.