Privacy
What this site stores, what it does not, and who else sees a request you make to it.
Last updated
The short version: there is no analytics on this site, no advertising, no tracking pixels and no third-party scripts. Nothing you do here is profiled, and nothing about you is sold or shared for marketing. What follows is the long version, which exists so you can check that claim rather than take it.
Browsing without an account
You do not need an account to read anything. The catalogue, the journal, the search and the listings are all open to a signed-out visitor, and a signed-out visitor is stored nowhere.
Two cookies may be set as you browse, both first-party, both holding a single value you chose yourself:
ui-theme: light or dark. Set when you use the theme toggle.ui-currency: the currency prices are displayed in. Set when you change it.
They exist so a preference survives a reload without a flash of the wrong theme. They contain no identifier, are not read by anyone else, and expire after a year. Refusing them costs you nothing except that the site forgets the preference.
The site also installs a service worker, which caches pages and images you have already visited in your own browser so the site opens instantly and works offline. That cache lives on your device, is never uploaded, and is cleared when you clear site data.
Accounts
An account is optional and exists only to hold your preferences and give the back office something to check a role against.
Signing in is passwordless; there is no password anywhere in this system, so there is nothing to leak. You either receive a magic link by email or sign in with Google. Either way we end up storing your email address, a display name and username if you set one, and the sessions that keep you signed in. Google sign-in tells us your email address and name; it does not give us access to anything else in your Google account.
Session cookies are first-party, SameSite=Lax, and expire. Signing out ends them. Ask at hello@dials.co and your account and everything attached to it will be deleted.
Search
Search runs against a Meilisearch index and is queried directly from your browser with a read-only key. Your query goes to our search host and nowhere else; it is not logged against you, and there is no per-user search history.
Who else sees a request
Three parties necessarily see traffic, because they carry it:
- Cloudflare serves this site and its API from its edge network, and hosts the images. It sees the requests it routes, including IP addresses, as any CDN does.
- Our own workers and database, running on that network.
- Google, if and only if you choose Google sign-in.
Server logs are operational: they exist to find faults and to enforce the API's published rate limits, and they are not used to build a profile of anyone.
Listings link out to the dealers and platforms that published them. Following one of those links takes you to a third party with its own privacy practices, which are theirs and not ours.
Automated clients
Machine access is expected here and treated the same as human access. The public API needs no key and therefore identifies nobody; the rate limits are counted against an IP address for the length of a one-minute window and are not retained beyond it.
Children
This is a reference site about wristwatches and is not directed at children. We do not knowingly hold data about anyone under 13.
Changes, and how to ask
If this policy changes materially, the date at the top of this page changes with it and the change is described here rather than quietly folded in.
Questions, corrections, or a request to see or delete what is held about you: hello@dials.co.