Watch-IP

Privacy Policy

Effective September 6, 2026

This is Digitload's current draft Privacy Policy for Watch-IP. It reflects how the Service actually handles data today, but has not yet been reviewed by outside counsel — treat it as informative rather than final until that review is complete.

This Privacy Policy explains what data Digitload Inc. ("Digitload", "we", "us") collects through Watch-IP (watch-ip.com), why, and for how long. It covers two different groups of people: the visitors and end users of our customers' websites and apps whose requests pass through the Watch-IP API ("Visitors"), and the individuals who hold or use a Watch-IP account ("Customers"). Where we process Visitor data on a Customer's behalf, the Customer — not Digitload — is the controller of that data for most purposes; see our Data Processing Addendum for details on that relationship.

1. Data From API Requests

What we collect depends on which endpoint is called:

  • GET /v1/geo — reads Cloudflare's edge request.cf data for the Visitor calling the endpoint (approximate country, region, city, latitude/longitude, timezone, ASN, and connection/threat signals such as VPN, Tor, or datacenter hosting). We do not persist the Visitor's IP address or the response; the request is logged only as an aggregate, non-identifying usage count for rate limiting and billing.
  • GET /v1/lookup/{ip} and POST /v1/lookup — compute approximate geolocation (without security or threat fields) for IP addresses the Customer supplies (typically their own end users' IPs, sourced from server logs or account activity). We don't persist the submitted IPs or the computed results beyond the aggregate, per-IP usage count needed for billing (each IP in a bulk request counts as one billable lookup).
  • POST /v1/email/validate — checks whether an email address's domain matches a known disposable/temporary provider. The email address is used only to extract and check its domain for the duration of the request; we don't store the email address or domain queried.
  • POST /v1/risk/check — compares an IP's resolved location against a userId's last-known location to flag improbable travel speed ("impossible travel"). Unlike the endpoints above, this one is stateful by design: we store the single most recent {latitude, longitude, country, timestamp} observed for each (Customer, userId) pair so the next check has a baseline to compare against. We don't store a history of past locations — each new committed check overwrites the previous baseline. This stored baseline is Visitor/end-user data submitted and controlled by the Customer; we retain it until it's overwritten by a later check, the Customer deletes it, or the Customer's account is closed.

2. Data From Your Account and the Dashboard

When you sign up for Watch-IP, we collect your name, email address, and (through our payment processors, Stripe and PayPal) billing information such as a masked card number or PayPal account identifier and billing address — we don't ourselves store full card numbers. We also store the origins you register, your API keys (hashed, not in plaintext), and your plan and usage history.

If you contact support or submit an enterprise inquiry, we collect what you provide in that form — name, email, company, and your message — and, for the enterprise form, your estimated monthly request volume and use case. Both forms are protected by Cloudflare Turnstile, which processes a small amount of technical signal (not shown to us) to distinguish humans from bots.

3. Cookies and Similar Technologies

The dashboard uses a session cookie strictly necessary to keep you signed in; it isn't used for advertising or cross-site tracking. We don't run third-party advertising trackers on watch-ip.com. Cloudflare, as our infrastructure provider, may set its own operational cookies (e.g. for Turnstile) as described in Cloudflare's own privacy policy.

4. How We Use Data

We use API request data to provide the Service (compute and return the response), enforce rate limits and plan quotas, detect abuse, and calculate usage for billing. We use account data to operate your subscription, provide support, send service and billing notices, and — if you opt in — product updates. We use contact-form submissions solely to respond to your inquiry.

6. Who We Share Data With

We don't sell personal data. We share it only with the service providers needed to run Watch-IP, each acting under contract and only for the purposes described here:

  • Cloudflare, Inc. — hosts the API and dashboard (Workers), and provides the KV, D1, R2, Durable Object, Analytics Engine, email-sending, and Turnstile services the Service is built on. Cloudflare processes all API request and account data as our infrastructure subprocessor.
  • Stripe, Inc. and PayPal, Inc. — process subscription payments and store payment-method and billing details on our behalf.

We may also disclose data if required by law, to enforce these Terms, or to protect the rights, property, or safety of Digitload, our customers, or the public.

7. International Data Transfers

Digitload is based in Ontario, Canada, and our infrastructure providers operate global networks, so data may be processed in Canada, the United States, and other countries where our subprocessors maintain infrastructure. Where we transfer personal data out of the EEA, UK, or Switzerland, we rely on the subprocessor's Standard Contractual Clauses or an equivalent safeguard.

8. Your Rights

Subject to applicable law (which may include GDPR/UK GDPR, Canada's PIPEDA, and U.S. state privacy laws), you may have the right to access, correct, delete, or export data we hold about you, to object to or restrict certain processing, and to withdraw consent where processing is based on it. Customers can access and correct most account data directly from the dashboard, including deleting a stored /v1/risk/check baseline directly via DELETE /v1/risk/baseline (or by contacting us).

If you're a Visitor or end user and believe a Customer's use of Watch-IP involves your data, please contact that Customer first, since they control how and why your data was submitted to us. You can also reach us directly at the address below and we'll route the request appropriately.

9. Data Retention

We keep account and billing data for as long as your account is active, and for a limited period after closure as needed for tax, accounting, and legal-defense purposes. Aggregate usage totals (used for billing history) are kept indefinitely as low-level financial records. Raw API request bodies and computed geolocation/threat responses are not retained beyond the request itself, except for the /v1/risk/check baseline described in Section 1, which persists until overwritten, deleted, or the account is closed.

10. Security

API keys are stored hashed (SHA-256), never in plaintext. Access to production data is limited to personnel who need it to operate the Service. Traffic to the API and dashboard is encrypted in transit (TLS). No system is perfectly secure, and we can't guarantee absolute security, but we design the Service to minimize what personal data we retain in the first place — see Section 1.

11. Children's Privacy

Watch-IP is a business-to-business developer product, not directed at children, and we don't knowingly collect account data from anyone under 16. If you believe a child has provided us personal data, contact us and we'll delete it.

12. Changes to This Policy

We may update this Policy as the Service evolves. If a change is material, we'll notify Customers by email or an in-dashboard notice before it takes effect. The "Effective" date above reflects the last update.

Questions about this policy or a data subject request can be sent to privacy@watch-ip.com.