Privacy policy
Last updated 15 September 2026
Who we are
Holder's Watch (“we”, “us”) is the controller of the personal data described here. For anything about your data, email privacy@holderswatch.com.
What we collect
Account information
- Your email address, and your name if you choose to give it.
- Your password, stored only as a one-way hash. We can't read it.
- Whether you've confirmed your email address, and your email alert preference.
Wallet information
- The public wallet addresses you add, which chain each is on, and the names you give your wallets.
- The tokens and balances we detect at those addresses, and the alerts and case files we create about them.
- Any notes you add to a case file.
Public addresses and balances are visible to anyone on the blockchain. Once linked to your email address, though, they can identify you, so we treat them as personal data.
Technical and security information
- For each signed-in session: your IP address, browser user agent, and when the session was created and last used. You can see and end your sessions in settings.
- Failed sign-in attempts, recorded against the email address and IP address used, to rate-limit guessing.
- Standard server logs of requests, kept for operating and securing the service.
Why we use it, and our lawful basis
- To provide the service (creating your account, monitoring your addresses, showing and emailing alerts): necessary to perform our contract with you.
- To keep accounts and the service secure (rate limiting, session records, breached-password checks, logs): our legitimate interest in protecting users and the service.
- To send service emails such as email confirmation, password resets and security notices: necessary to perform our contract with you.
We don't sell your data, use it for advertising, or make decisions about you based solely on automated processing.
Who processes it for us
We use these providers to run the service. They process data on our instructions:
- Vercel: hosting and running the website and API.
- Neon: our database.
- Resend: sending email. It receives your email address and the content of emails we send you.
- Alchemy: looking up the tokens held at the public addresses you add. It receives those addresses, not your email address.
- CoinGecko: token listings, contracts, prices and project activity. It receives token identifiers, not your addresses or email.
- Have I Been Pwned: checking whether a new password appears in a known breach. It receives only the first five characters of a hash of the password, never the password or your email.
Some of these providers process data outside the UK, including in the United States. Where they do, we rely on appropriate safeguards for international transfers, such as the UK International Data Transfer Agreement or Addendum.
How long we keep it
- Account, wallet and alert data: until you delete your account.
- Session records: until the session ends or expires, which is at most 30 days.
- Failed sign-in records: deleted after a short rate-limiting window.
- Password reset links expire after one hour, and email confirmation links after 24 hours.
When you delete your account, we delete your account, wallets, holdings, alerts, case files and sessions.
Cookies
We use one strictly necessary cookie to keep you signed in. It's set only when you sign in, can't be read by page scripts, and isn't used for tracking. We don't use advertising cookies.
Your rights
Under UK data protection law you can ask us to:
- give you a copy of your personal data;
- correct data that is wrong;
- delete your data;
- restrict or object to how we use it;
- give your data to you, or another organisation, in a portable format.
You can delete your account yourself in Settings. For anything else, email privacy@holderswatch.com. If you're unhappy with how we handle your data, you can complain to the Information Commissioner's Office at ico.org.uk.
Changes
If we make a significant change to this policy, we'll tell you by email or in the app before it takes effect. See also our terms of service.