Privacy Policy
Effective date: 24 August 2026 · Last updated: 24 August 2026
1. Who we are
Aframe Pty Ltd (ABN 91 607 103 695) (“we”, “us”, “our”) operates the Watch Service History application at https://services.chronogeeks.com (the “Service”).
We are the data controller for personal information we hold about you as an account holder. Where you enter information about other people into the Service — for example the contact details of a customer whose watch you are servicing — you are the controller of that information and we act as your processor. Section 11 explains what that means for both of us.
Contact: support@chronogeeks.com
2. Summary
| Question | Short answer |
|---|---|
| Do you track me across the web? | No. The Service contains no analytics, advertising, or third-party tracking scripts. |
| Do you use tracking cookies? | No. Browser storage is used only to remember your theme, layout and view preferences. |
| Do you sell my data? | No. |
| Do you see my card number? | No. Payments run through Stripe’s hosted checkout; card details never reach our servers. |
| Where is my data stored? | Google Cloud in Oregon, USA (us-west1). |
| Can I get my data out? | Yes — you can export it, and you can request a copy at any time. |
| Can I delete my account? | Yes. Deletion is permanent after a 30-day grace period. |
3. Information we collect
3.1 Account information
Collected when you register and maintained in your profile:
- Email address
- Display name (optional)
- Password — handled entirely by Google Firebase Authentication. We never store or see your password.
- If you sign in with Google: the identity information Google returns to Firebase Authentication (your email address and basic profile details)
- Profile photo, if you upload one
- Your preferences: default currency, date format, theme, and interface layout choices
- Account timestamps (when the account was created)
3.2 Content you create
The substance of the Service. All of it is data you choose to enter:
- Watches — brand, model, serial number, movement, lift angle, and free-text notes
- Service records — service dates, titles, Markdown notes, workflow status and the history of status changes
- Timegrapher measurements — rate, amplitude and beat error readings in four positions, before and after service
- Timeline entries — notes, issues, milestones and part-ordered events you log against a service record
- Media — photos and videos you upload, with your comments. We generate thumbnails and extract video frames for preview purposes.
- Service manuals — PDFs and images you upload
- External links — URLs you save against a service record
- Financial information you enter — component costs, sale prices and the resulting profit figures, in your chosen currency
3.3 Information about other people that you enter
The Service lets you record the details of a watch’s owner. Where you use this feature, we process on your behalf:
- Owner name
- Owner phone number
- Owner email address
- Owner shipping address (street, city, postcode, state, country)
We do not contact these people. We send no email, notification or marketing to any address entered in an owner record. This information exists solely so it appears in your own records and in reports you generate. Section 11 sets out your responsibilities when you enter it.
3.4 Billing information
Subscriptions are processed by Stripe. You enter your payment details directly into Stripe’s hosted checkout, and:
- Card numbers, expiry dates and security codes never touch our servers. We cannot see them and do not store them.
- We store the identifiers Stripe gives us so we can manage your subscription: a Stripe customer ID, a subscription ID, your plan (monthly or yearly), subscription status, and the current period end date.
- We store invoice records associated with your account for accounting purposes.
Stripe’s own handling of your payment information is governed by Stripe’s Privacy Policy.
3.5 Technical and operational information
- IP address — processed by our API’s rate limiting to protect the Service from abuse.
- Server logs — our servers log requests and errors to operate and debug the Service. Logs are configured to redact authentication tokens, passwords, secrets and API keys, and to mask email addresses (recording, for example,
a***@example.comrather than the full address). - Storage usage — we record how much file storage your account uses, and a history of upload and deletion events, to enforce storage quotas.
3.6 Browser storage
The Service stores a small number of preferences in your browser’s local storage. These are functional only — they are not identifiers, they are not sent to us for analysis, and they are not used to track you:
| Key | Purpose |
|---|---|
theme | Remembers light or dark mode |
sidebarCollapsed | Remembers whether the sidebar is collapsed |
splitLayoutLeftWidth | Remembers your split-view column width |
dashboardOpenJobsView | Remembers whether you prefer the card or table view |
Firebase Authentication also stores session tokens in your browser so you stay signed in.
3.7 What we do not collect
To be explicit, the Service contains no:
- analytics or product-telemetry SDKs
- advertising or marketing pixels
- third-party session-recording or heatmap tools
- cross-site tracking of any kind
4. How we use your information, and our legal bases
| What we do | Why | Legal basis (GDPR/UK GDPR) |
|---|---|---|
| Create and authenticate your account | You cannot use the Service otherwise | Performance of a contract |
| Store and display the records you create | This is the Service | Performance of a contract |
| Generate reports you request (HTML/PDF) | You asked for them | Performance of a contract |
| Process subscription payments and manage billing | To charge for the Service | Performance of a contract |
| Send service emails about your trial or subscription | To tell you about expiry, renewal and deactivation | Performance of a contract |
| Enforce storage quotas | To operate the Service fairly and sustainably | Legitimate interests |
| Rate-limit requests and keep logs | Security, abuse prevention, debugging | Legitimate interests |
| Retain limited billing records after deletion | Accounting and tax obligations | Legal obligation |
Where we rely on legitimate interests, we have considered the impact on you and limited the processing accordingly — for example, logs mask email addresses and redact credentials.
Emails we send
We send transactional email to account holders only:
- Trial expiry reminders (7 days, 1 day, and on expiry)
- Subscription expiry reminders (30 days, 7 days, 1 day)
- Account deactivation and deletion notices
- Email verification and password reset messages
6. Where your information is stored, and international transfers
Your information is stored in Google Cloud’s us-west1 region (Oregon, United States). Our API also runs in that region.
This means that if you are located outside the United States — including in Australia, the United Kingdom or the European Economic Area — your personal information is transferred to and stored in the United States, a country whose privacy laws differ from your own.
7. How long we keep your information
| Data | Retention |
|---|---|
| Account and all content | Until you delete your account |
| Deleted account — grace period | 30 days from the deletion request, during which you can reactivate |
| Deleted account — after grace period | Permanently deleted: your account record, watches, service records, timeline entries, uploaded files and authentication record |
| Backup and version history | Up to a further 7 days. Anything you delete disappears from the Service immediately, but our cloud provider retains a recoverable copy for a short period before it is destroyed. See the note below this table. |
| Post-deletion billing marker | A minimal record is retained indefinitely: a one-way SHA-256 hash of your user ID, your Stripe customer ID, and the deletion date. This exists to prevent duplicate billing records if you sign up again, and for accounting traceability. It contains no name, email address or content. |
When you request deletion you may choose to delete immediately or at the end of your paid period. Either way the 30-day grace period applies before data is destroyed.
A note on backups
Deleting something — a watch, a service record, an uploaded photo, or your whole account — removes it from the Service straight away. You cannot see it, and neither can we through the application.
For a short period afterwards, however, a copy still exists in our cloud provider’s disaster-recovery systems, which retain recent versions so that data lost to a fault or a mistake can be recovered. Specifically:
- Database records — recoverable for 7 days (Google Cloud Firestore point-in-time recovery).
- Uploaded files — recoverable for 7 days (Google Cloud Storage soft-delete retention).
After those windows pass the data ages out and is destroyed permanently. These are technical safeguards against data loss, not a service we offer: we do not restore individual items you chose to delete, and after the retention window it is not possible to do so even if we wanted to.
This means that if you request erasure of your personal information, it is removed from the Service immediately and disappears from backups within 7 days.
8. How we protect your information
- Authentication is handled by Google Firebase Authentication. We never store passwords.
- Access control: all data access is mediated by our API server, which authorises every request against the signed-in user. Your records are stored under your own user ID and are not readable by other users.
- Encryption in transit: all traffic uses HTTPS.
- Encryption at rest: provided by Google Cloud for Firestore and Cloud Storage.
- Uploaded files are served through short-lived signed URLs rather than public links.
- Credential hygiene in logs: authentication tokens, passwords, secrets and API keys are redacted, and email addresses are masked.
- Rate limiting protects the API against abuse and brute-force attempts.
- Payment isolation: card data is handled entirely by Stripe and never reaches us.
No system is perfectly secure. We cannot guarantee absolute security, and you are responsible for keeping your own login credentials confidential.
9. Your rights
Depending on where you live, you may have the right to:
- Access the personal information we hold about you
- Correct information that is inaccurate or incomplete
- Delete your account and your information
- Export your data in a portable format
- Object to or restrict certain processing
- Withdraw consent, where we rely on it
- Complain to a privacy regulator
You can exercise most of these rights directly in the application: your profile page lets you correct your details, export your data, and delete your account.
For anything else, contact us at support@chronogeeks.com.
If you are in Australia, you may complain to the Office of the Australian Information Commissioner (oaic.gov.au).
If you are in the EEA or UK, you may complain to your local supervisory authority.
10. Children
The Service is not directed at children and is not intended for use by anyone under 18, which is also the minimum age required by our Terms & Conditions. We do not knowingly collect personal information from children. If you believe a child has provided us information, contact us and we will delete it.
11. Information you hold about other people
This section matters if you use the Service professionally — for example as a watchmaker recording the details of customers whose watches you service.
When you enter another person’s name, phone number, email address or shipping address into a watch record:
- You decide what to collect and why. In data-protection terms you are the controller and we are your processor. We store and return that information to you, and we do nothing else with it.
- We never contact them. No email, notification or marketing is sent to any address in an owner record.
- Your obligations are your own. Depending on your jurisdiction and the scale of your business, you may be required to tell those people what you collect and why, keep it accurate and secure, honour their access and deletion requests, and have a lawful basis for holding it. Nothing in this policy discharges those obligations.
- Deleting a watch or your account deletes the owner details it contained, subject to the retention periods in Section 7.
If you need a data processing agreement covering this relationship, contact us at support@chronogeeks.com and we will put one in place. This is the same commitment given in Section 10 of our Terms & Conditions, and it covers the written processor agreement GDPR Article 28 requires for customers in the EU and the UK.
12. Changes to this policy
We may update this policy. When we make material changes we will update the “Last updated” date above, notify account holders by email at the address on their account, and display a notice in the application, at least 30 days before the changes take effect.
Continued use of the Service after a change takes effect means you accept the updated policy.
13. Contact us
Aframe Pty Ltd (ABN 91 607 103 695)
support@chronogeeks.com