Chrono Geeks Chrono Geeks
About Pricing Log In Coming Soon

Privacy Policy

Effective date: 24 August 2026 · Last updated: 3 October 2026

Contents

  1. Who we are
  2. Summary
  3. Information we collect
  4. How we use your information
  5. Who we share it with
  6. Where it is stored
  7. How long we keep it
  8. How we protect it
  9. Your rights
  10. Children
  11. Information about other people
  12. Changes to this policy
  13. Contact us

1. Who we are

Aframe Pty Ltd (ABN 91 607 103 695) (“we”, “us”, “our”) operates the Chrono Geeks application at https://services.chronogeeks.com (the “Service”) and the public website at https://chronogeeks.com (the “Website”).

The two are treated differently in this policy. The Service is the signed-in application where your records live; it contains no analytics of any kind. The Website is the marketing site you are reading now, which uses Google Analytics to measure traffic. Section 3.7 sets out exactly what that collects and how to opt out.

We are the data controller for personal information we hold about you as an account holder. Where you enter information about other people into the Service — for example the contact details of a customer whose watch you are servicing — you are the controller of that information and we act as your processor. Section 11 explains what that means for both of us.

Contact: support@chronogeeks.com

2. Summary

QuestionShort answer
Do you track me across the web?No. No advertising, no marketing pixels, and no cross-site tracking anywhere.
Is the application tracked?No. The signed-in Service contains no analytics or telemetry SDKs at all.
Does the website use analytics?Yes. The public marketing website uses Google Analytics to count visits and see which pages are read. The signed-in application does not.
Do you use tracking cookies?Two, on the website. Google Analytics sets them to count visits. They are not used for advertising, and Section 3.7 explains how to block them. Everything else is functional storage for your theme, layout and view preferences.
Do you sell my data?No.
Do you see my card number?No. Payments run through Stripe’s hosted checkout; card details never reach our servers.
Where is my data stored?Google Cloud in Oregon, USA (us-west1).
Can I get my data out?Yes — you can export it, and you can request a copy at any time.
Can I delete my account?Yes. Deletion is permanent after a 30-day grace period.

3. Information we collect

3.1 Account information

Collected when you register and maintained in your profile:

  • Email address
  • Display name (optional)
  • Password — handled entirely by Google Firebase Authentication. We never store or see your password.
  • If you sign in with Google: the identity information Google returns to Firebase Authentication (your email address and basic profile details)
  • Profile photo, if you upload one
  • Your preferences: default currency, date format, theme, and interface layout choices
  • Account timestamps (when the account was created)

3.2 Content you create

The substance of the Service. All of it is data you choose to enter:

  • Watches — brand, model, serial number, movement, lift angle, and free-text notes
  • Service records — service dates, titles, Markdown notes, workflow status and the history of status changes
  • Timegrapher measurements — rate, amplitude and beat error readings in four positions, before and after service
  • Timeline entries — notes, issues, milestones and part-ordered events you log against a service record
  • Media — photos and videos you upload, with your comments. We generate thumbnails and extract video frames for preview purposes.
  • Service manuals — PDFs and images you upload
  • External links — URLs you save against a service record
  • Financial information you enter — component costs, sale prices and the resulting profit figures, in your chosen currency
  • Insurance details — for each policy you record: the insurer, policy number, type of cover, currency, excess, renewal date, notes and any policy documents you upload; and for each watch a policy covers, its insured value and valuation history

3.3 Information about other people that you enter

The Service lets you record the details of a watch’s owner. Where you use this feature, we process on your behalf:

  • Owner name
  • Owner phone number
  • Owner email address
  • Owner shipping address (street, city, postcode, state, country)

We do not contact these people. We send no email, notification or marketing to any address entered in an owner record. This information exists solely so it appears in your own records and in reports you generate. Section 11 sets out your responsibilities when you enter it.

3.4 Billing information

Subscriptions are processed by Stripe. You enter your payment details directly into Stripe’s hosted checkout, and:

  • Card numbers, expiry dates and security codes never touch our servers. We cannot see them and do not store them.
  • We store the identifiers Stripe gives us so we can manage your subscription: a Stripe customer ID, a subscription ID, your plan (monthly or yearly), subscription status, and the current period end date.
  • We store invoice records associated with your account for accounting purposes.

Stripe’s own handling of your payment information is governed by Stripe’s Privacy Policy.

3.5 Technical and operational information

  • IP address — processed by our API’s rate limiting to protect the Service from abuse.
  • Server logs — our servers log requests and errors to operate and debug the Service. Logs are configured to redact authentication tokens, passwords, secrets and API keys, and to mask email addresses (recording, for example, a***@example.com rather than the full address).
  • Storage usage — we record how much file storage your account uses, and a history of upload and deletion events, to enforce storage quotas.

3.6 Browser storage

The Service stores a small number of preferences in your browser’s local storage. These are functional only — they are not identifiers, they are not sent to us for analysis, and they are not used to track you:

KeyPurpose
themeRemembers light or dark mode
sidebarCollapsedRemembers whether the sidebar is collapsed
splitLayoutLeftWidthRemembers your split-view column width
dashboardOpenJobsViewRemembers whether you prefer the card or table view
cookieConsentWebsite only — records that you accepted or opted out of analytics
cookieConsentDateWebsite only — records when you made that choice
cookieNoticeSeenWebsite only — stops the cookie notice reappearing on every page

Firebase Authentication also stores session tokens in your browser so you stay signed in.

The three website keys are what let us respect your choice without asking again on every page. They are stored on your device and never sent to us.

3.7 Cookies and analytics on the website

The public website at chronogeeks.com uses Google Analytics 4 to measure traffic — which pages are visited, roughly where visitors come from, and which links bring people to us. We use it to decide what to write and build next. The signed-in application does not use it at all.

When you first arrive we show a notice saying so. What that notice does depends on where you are:

Where you areWhat happens
European Economic Area or United KingdomWe ask first. No analytics script loads and no cookie is set until you press Accept. Declining is a single click and the site works identically.
Everywhere elseAnalytics runs when the page loads, and the notice tells you so. You can opt out at any time using the link in the footer, or by any of the methods below.

We determine this from your browser’s time-zone setting. That is a reading of a value your browser already holds — we do not look your IP address up against a location database to decide, because doing so would disclose your visit to a third party before you had said anything.

Google Analytics sets the following cookies:

CookiePurposeExpires
_gaDistinguishes one visitor from another2 years
_ga_43J0JTLZMRMaintains the analytics session state2 years

Through these cookies Google receives your IP address, the pages you view, and general device and browser information. Google Analytics 4 derives an approximate location from your IP address and then discards it — the IP address is not retained in the reports we see, and we never see individual visitors. We use the results only in aggregate.

We do not run advertising, and we do not upload this data to any advertising product. Google Signals — the setting that would let Google link your visit across devices for advertising purposes — is not enabled on our property.

Google processes this information on servers in the United States. See Sections 5 and 6, and Google’s own privacy policy.

How to opt out, wherever you are.

  • Use the Cookie settings link in the footer of any page. It offers Accept or Decline in every region, whatever you chose before. Declining stops collection immediately and deletes the analytics cookies already on your device.
  • Install Google’s official Analytics opt-out browser add-on, which blocks Google Analytics on every site you visit.
  • Block or delete cookies for this site in your browser settings, or use an extension that blocks analytics scripts. We do not attempt to detect or work around these.

An opt-out recorded through the footer link is honoured in every region and on every page, and the website works normally with analytics blocked.

3.8 What we do not collect

To be explicit, the signed-in Service contains no:

  • analytics or product-telemetry SDKs
  • advertising or marketing pixels
  • third-party session-recording or heatmap tools
  • cross-site tracking of any kind

Nothing you enter into the application — your watches, your records, your insurance details, your customers’ details — is ever sent to Google Analytics or any other analytics provider. The measurement described in Section 3.7 applies to the public marketing pages only.

Across both the Website and the Service we run no advertising, no marketing pixels, no session recording or heatmaps, and no cross-site tracking.

4. How we use your information, and our legal bases

What we doWhyLegal basis (GDPR/UK GDPR)
Create and authenticate your accountYou cannot use the Service otherwisePerformance of a contract
Store and display the records you createThis is the ServicePerformance of a contract
Generate reports you request (HTML/PDF)You asked for themPerformance of a contract
Process subscription payments and manage billingTo charge for the ServicePerformance of a contract
Send service emails about your trial or subscriptionTo tell you about expiry, renewal and deactivationPerformance of a contract
Enforce storage quotasTo operate the Service fairly and sustainablyLegitimate interests
Rate-limit requests and keep logsSecurity, abuse prevention, debuggingLegitimate interests
Retain limited billing records after deletionAccounting and tax obligationsLegal obligation
Measure traffic to the public website with Google AnalyticsTo understand which pages are useful and where visitors come fromConsent in the EEA and UK; legitimate interests elsewhere

Where we rely on legitimate interests, we have considered the impact on you and limited the processing accordingly — for example, logs mask email addresses and redact credentials.

Website analytics is the one place where our basis depends on where you are. In the EEA and the UK we rely on your consent, asked for before anything loads and withdrawable at any time. Elsewhere we rely on our legitimate interest in understanding how the site is used, and we have limited the processing to match: measurement is aggregate, it covers the public marketing pages only, it is never joined to your account or to anything you store in the application, and it is not used for advertising. Section 3.7 sets out how to opt out in either case.

Emails we send

We send transactional email to account holders only:

  • Trial expiry reminders (7 days, 1 day, and on expiry)
  • Subscription expiry reminders (30 days, 7 days, 1 day)
  • Insurance renewal reminders (30 days and 7 days before a renewal date you have recorded)
  • Account deactivation and deletion notices
  • Email verification and password reset messages

5. Who we share your information with

We do not sell your personal information. We share it only with the service providers below, each of which processes it on our behalf to run the Service.

Every provider except Google Analytics is used to run the application itself. Google Analytics applies to the public marketing website only — it receives nothing you enter into the application.

ProviderWhat they handleTheir policy
Google Cloud Platform (Firestore, Cloud Storage, Cloud Run) All account data, records and uploaded files Policy
Google Firebase (Authentication, Hosting) Credentials, sessions, front-end delivery Policy
Stripe Payment processing, billing Policy
Resend Sending transactional email Policy
Google Analytics (public website only) Traffic measurement: pages viewed, approximate location, device and browser Policy

We may also disclose information where we are legally required to — for example in response to a valid court order or lawful request from a regulator — or where necessary to establish, exercise or defend legal claims.

If we are ever involved in a merger, acquisition or sale of assets, we will give you notice before your information becomes subject to a different privacy policy.

6. Where your information is stored, and international transfers

Your information is stored in Google Cloud’s us-west1 region (Oregon, United States). Our API also runs in that region.

This means that if you are located outside the United States — including in Australia, the United Kingdom or the European Economic Area — your personal information is transferred to and stored in the United States, a country whose privacy laws differ from your own.

Website analytics data is also processed by Google in the United States. Google relies on the EU–US Data Privacy Framework and on standard contractual clauses for these transfers. If you are in the EEA or the UK, no such transfer happens unless you accept analytics; elsewhere, the opt-out routes in Section 3.7 prevent it.

7. How long we keep your information

DataRetention
Account and all contentUntil you delete your account
Deleted account — grace period30 days from the deletion request, during which you can reactivate
Deleted account — after grace periodPermanently deleted: your account record, watches, insurance policies, service records, timeline entries, uploaded files and authentication record
Backup and version historyUp to a further 7 days. Anything you delete disappears from the Service immediately, but our cloud provider retains a recoverable copy for a short period before it is destroyed. See the note below this table.
Post-deletion billing markerA minimal record is retained indefinitely: a one-way SHA-256 hash of your user ID, your Stripe customer ID, and the deletion date. This exists to prevent duplicate billing records if you sign up again, and for accounting traceability. It contains no name, email address or content.

When you request deletion you may choose to delete immediately or at the end of your paid period. Either way the 30-day grace period applies before data is destroyed.

A note on backups

Deleting something — a watch, a service record, an uploaded photo, or your whole account — removes it from the Service straight away. You cannot see it, and neither can we through the application.

For a short period afterwards, however, a copy still exists in our cloud provider’s disaster-recovery systems, which retain recent versions so that data lost to a fault or a mistake can be recovered. Specifically:

  • Database records — recoverable for 7 days (Google Cloud Firestore point-in-time recovery).
  • Uploaded files — recoverable for 7 days (Google Cloud Storage soft-delete retention).

After those windows pass the data ages out and is destroyed permanently. These are technical safeguards against data loss, not a service we offer: we do not restore individual items you chose to delete, and after the retention window it is not possible to do so even if we wanted to.

This means that if you request erasure of your personal information, it is removed from the Service immediately and disappears from backups within 7 days.

8. How we protect your information

  • Authentication is handled by Google Firebase Authentication. We never store passwords.
  • Access control: all data access is mediated by our API server, which authorises every request against the signed-in user. Your records are stored under your own user ID and are not readable by other users.
  • Encryption in transit: all traffic uses HTTPS.
  • Encryption at rest: provided by Google Cloud for Firestore and Cloud Storage.
  • Uploaded files are served through short-lived signed URLs rather than public links.
  • Credential hygiene in logs: authentication tokens, passwords, secrets and API keys are redacted, and email addresses are masked.
  • Rate limiting protects the API against abuse and brute-force attempts.
  • Payment isolation: card data is handled entirely by Stripe and never reaches us.

No system is perfectly secure. We cannot guarantee absolute security, and you are responsible for keeping your own login credentials confidential.

9. Your rights

Depending on where you live, you may have the right to:

  • Access the personal information we hold about you
  • Correct information that is inaccurate or incomplete
  • Delete your account and your information
  • Export your data in a portable format
  • Object to or restrict certain processing
  • Withdraw consent, where we rely on it
  • Complain to a privacy regulator

You can exercise most of these rights directly in the application: your profile page lets you correct your details, export your data, and delete your account.

To withdraw consent for website analytics, or to object to it, use the Cookie settings link in the footer of any page. It takes effect immediately and deletes the analytics cookies already on your device. Because that measurement is aggregate and is never linked to your account, we generally cannot single out an individual visitor’s past analytics data in order to extract or delete it — stopping the collection is the effective remedy.

For anything else, contact us at support@chronogeeks.com.

If you are in Australia, you may complain to the Office of the Australian Information Commissioner (oaic.gov.au).
If you are in the EEA or UK, you may complain to your local supervisory authority.

10. Children

The Service is not directed at children and is not intended for use by anyone under 18, which is also the minimum age required by our Terms & Conditions. We do not knowingly collect personal information from children. If you believe a child has provided us information, contact us and we will delete it.

11. Information you hold about other people

This section matters if you use the Service professionally — for example as a watchmaker recording the details of customers whose watches you service.

When you enter another person’s name, phone number, email address or shipping address into a watch record, or the insurance details of a watch they own:

  • You decide what to collect and why. In data-protection terms you are the controller and we are your processor. We store and return that information to you, and we do nothing else with it.
  • We never contact them. No email, notification or marketing is sent to any address in an owner record.
  • Your obligations are your own. Depending on your jurisdiction and the scale of your business, you may be required to tell those people what you collect and why, keep it accurate and secure, honour their access and deletion requests, and have a lawful basis for holding it. Nothing in this policy discharges those obligations.
  • Deleting a watch deletes the owner details, insured value and valuations it contained, and deleting an insurance policy deletes its details and documents. Deleting your account deletes all of them. Each is subject to the retention periods in Section 7.

If you need a data processing agreement covering this relationship, contact us at support@chronogeeks.com and we will put one in place. This is the same commitment given in Section 10 of our Terms & Conditions, and it covers the written processor agreement GDPR Article 28 requires for customers in the EU and the UK.

12. Changes to this policy

We may update this policy. When we make material changes we will update the “Last updated” date above, notify account holders by email at the address on their account, and display a notice in the application.

Continued use of the Service after a change takes effect means you accept the updated policy.

13. Contact us

Aframe Pty Ltd (ABN 91 607 103 695)
support@chronogeeks.com

Chrono Geeks

Watch service tracking for the obsessed.

About Pricing Log In Coming Soon Contact Terms & Conditions Privacy Cookie settings

© 2026 Chrono Geeks. All rights reserved.