Privacy Policy
Last updated 5 August 2026
1. Who we are
This policy is issued by Offwatch Social Ltd ("OffWatch", "we", "us", or "our"), the company developing the OffWatch mobile application. Offwatch Social Ltd is registered in England and Wales under company number 17242018, with its registered office at 71–75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom.
2. Scope of this policy
This policy covers this website (off-watch.com) and, once launched, the OffWatch mobile application. It does not cover third-party websites or services we link to.
3. Data we collect
The categories of personal data OffWatch is currently designed to process are:
- Account and profile data — information you provide to create and maintain a profile, such as a display name, profile details, and profile photo.
- Verification status metadata — a record of whether identity/age verification has been completed via our third-party verification provider. We do not receive or store the identity documents themselves; those are processed directly by the verification provider.
- Communications data — messages and related content sent through the app, and reports submitted for moderation purposes.
- Presence and activity data — limited technical data used to support in-app functionality, such as connection state between users.
- Device and push notification data — a device token used to deliver notifications, and basic device/platform information.
- Subscription data — entitlement and subscription status, handled via our subscription management provider and the relevant app store, not raw payment card data.
- Android beta testers. If you take part in the OffWatch beta on an Android device, we will ask you for the email address of the Google account you use on that device. We use it only to give that account access to the OffWatch beta on Google Play, and to manage that access. It may be different from the email address you use to sign in to OffWatch, and we do not use it as your OffWatch account or add it to your profile. Google processes it as part of providing Google Play.
- Waiting-list data — if you join the OffWatch launch waiting list on this website, we collect the email address you enter; where you arrived through a specific link, a short campaign tag identifying that link; and, only if you choose to answer the optional question, whether you expect to use OffWatch on an iPhone, on Android, or on both. That answer is used solely to send you the right app when a place opens up, and leaving it blank makes no difference to your place. Nothing else is collected: there is no name, no account, no profile, and we do not detect or record what device you are browsing from. Joining the waiting list does not create an OffWatch account and does not give access to the app.
- Website usage data — this website does not currently use analytics or tracking cookies. If that changes, this policy and an appropriate consent mechanism will be updated first.
4. How we use your data
- To create and operate your account and provide the core functionality of the app.
- To verify identity/age where required, via our verification provider.
- To enable communication between users and to act on reports for trust and safety purposes.
- To deliver push notifications you have enabled.
- To manage subscriptions and entitlements.
- To maintain the security and integrity of the service.
5. Legal basis for processing
We rely on the following legal bases under UK GDPR for the processing described above:
- Performance of a contract — for account creation, core app functionality, communications between users, and subscription management.
- Legal obligation — for identity/age verification, where required by law or app store policy.
- Legitimate interests — for security, fraud prevention, and acting on reports for trust and safety purposes, balanced against your rights and freedoms.
- Consent — for the launch waiting list. We ask you to confirm your address by clicking a link in an email before we treat you as having joined, and you can withdraw that consent at any time using the removal link in any email we send you. Withdrawing it is as easy as giving it.
6. Who we share data with
We use a small number of third-party service providers to operate OffWatch. Most act as data processors under contract — they handle data on our instructions and for our purposes only. Stripe is different, and we explain that below: for identity verification it acts partly on our instructions and partly for its own fraud-prevention and security purposes, where it is an independent controller in its own right.
- Supabase — our backend/database hosting provider, for storing application data.
- Stripe Identity — our identity/age verification provider, and the one
provider whose role is genuinely split. It is worth reading this entry in full.
- What we ask Stripe to do. We ask only for a document check. We do not ask Stripe to take a selfie, to run a face-matching check, to collect an ID number, or to force live camera capture. We send Stripe no personal data about you at all — only an internal reference for your account and the address to return you to afterwards.
- What we get back. Whether the check passed or failed, and if it failed, Stripe's reason code. Our app never receives, and never stores, your document images, your name, your date of birth or your document number. What we keep is a yes/no and a reference to the Stripe session.
- What we can nonetheless see. To be straight with you: because the Stripe account is ours, the captured images and the details extracted from them are visible to us in Stripe's own dashboard, even though our app never requests or keeps them. Access there is restricted to us.
- What Stripe does for its own purposes. Stripe also uses verification data for fraud prevention and security. For that, Stripe is an independent controller, not our processor — it decides those purposes itself and we do not control them. Stripe's documentation states that its verification technology can create biometric identifiers from a face photo, and that it removes them within one year. That face-matching is not something we ask for; Stripe's own processing for fraud and security is nevertheless its own.
- Deleting it. If you delete your OffWatch account, we now automatically ask Stripe to redact the verification session — and your account deletion never waits on Stripe to succeed. Stripe states it keeps submitted documents for around three years unless deleted sooner. Because part of Stripe's processing is its own, our request may not reach everything Stripe is entitled or required to keep, so you can also contact Stripe directly about your data and your rights through Stripe's Privacy Center. We would rather tell you that than imply our deletion covers more than it does.
- Firebase Cloud Messaging (Google) — our push notification delivery provider.
- RevenueCat, alongside the Apple App Store / Google Play — for subscription and in-app-purchase management and billing.
- Resend — our transactional email provider, used to send waiting-list confirmation emails and, in the app, invitation and notification emails.
- Cloudflare — our website hosting and DNS provider. Requests to this website, including a waiting-list submission, pass through Cloudflare's network.
- Sentry — our crash and error reporting provider. When the app hits an error we send diagnostic information: the technical details of the fault, your device model, operating system version and app version, and an anonymous account identifier. We have configured Sentry so that it does not collect your email address, username or IP address, and we never send the contents of your profile or messages. Our Sentry data is stored in the European Union.
- PostHog — our product analytics provider, used to understand which parts of the app people use. We send a fixed, limited list of event names — for example that a screen was opened or that onboarding was completed — together with an anonymous account identifier, the platform you are on, and whether the app is a test or live build. We do not send your name, email address, messages, location, or any payment or price information, and we have switched off session recording and location lookup. Our PostHog data is stored in the European Union.
- Mapbox — our map provider. To draw the map, your device requests map imagery from Mapbox, which necessarily tells Mapbox roughly which part of the world you are looking at and your IP address. We do not send Mapbox your account details. Other people's positions are never shown to you precisely: before any position leaves our servers it is reduced to an approximate area of roughly a kilometre, so neither you nor Mapbox receives anyone's exact location.
We do not sell personal data to third parties.
7. International data transfers
Some of the providers listed above may process data outside the UK/EEA, including in the United States. Where this occurs, we rely on the safeguards those providers offer under UK GDPR — such as Standard Contractual Clauses or an equivalent adequacy mechanism — as part of our agreement with them.
8. Data retention
We retain account and profile data for as long as your account remains active, and generally delete it within 30 days of account deletion. Messages and reports may be retained for a limited period after that for trust and safety purposes. We may retain certain records for longer where required to comply with a legal obligation, resolve a dispute, or enforce our agreements.
Waiting-list addresses are handled separately. If you remove your address using the link in any waiting-list email, we delete the entry outright rather than keeping a record that you were once on the list. If you join and never confirm your address, we delete the entry within 30 days of the last confirmation email we sent you, and we will not email you about the launch in the meantime. Otherwise we keep your address until OffWatch launches and we have contacted you about it, after which we delete it. If you are later given a place in the OffWatch beta, that place is recorded separately and removing yourself from the launch waiting list does not cancel it.
9. Your rights
Subject to applicable law, you generally have the right to access, correct, delete, restrict, or export your personal data, and to object to certain processing. Once the app has launched, this section will describe exactly how to exercise these rights in-app and via our support contact.
For the launch waiting list specifically, the removal link in any email we send you deletes your address immediately and without needing to contact us. You can also email enquiries@off-watch.com to ask what we hold about you or to have it deleted.
10. Children's privacy
OffWatch is intended for adults working in maritime and offshore industries. It is not directed at children, and we do not knowingly collect personal data from children.
11. Security
We intend to apply industry-standard technical and organisational measures — including access controls and encryption in transit — to protect the data described above. No system can be guaranteed 100% secure.
12. Changes to this policy
As OffWatch moves from development towards public launch, this policy will be revised — most significantly once legal review is complete. Material changes will be dated and, once the app has launched, notified to users through the app.
13. Contact us
Questions about this policy, and any request to access, correct or delete your personal data, can be sent to enquiries@off-watch.com. Our full details are on the Contact page.