Draft — needs legal review before launch. This document was written by the people who built the product, to describe accurately what it does. It has not been reviewed by a qualified lawyer and must be before this site takes real customers.
Privacy
WatchMyCover holds insurance documents belonging to companies who never signed up for it. This page says what we collect, why, who else sees it and how to get it back — in the words we would use out loud.
What we collect from you
Your name, your work email address, and the name of your company, because we need to know who owns the workspace and where to send things.
Whatever you type into the product: vendors, their trade, their contact email addresses, insurers, policy numbers, coverage limits, effective and expiry dates, requirement templates, projects, notes and the verdicts produced from all of it.
Certificate documents. Files you upload, and files your subcontractors send through an upload link, are stored. They are held in a private bucket with no public addresses, and every download is authorised against your organisation at the moment it happens.
Ordinary operational records: sign-in times, session records, an audit row for every change made in the product, and server logs. Logs redact credentials, cookies and passwords.
Information about people who are not our customers
Most of what is in a WatchMyCover workspace is about somebody else — your subcontractors, their brokers, their insurers. You are the one who decides to put it there, and in data-protection terms you control it; we hold and process it on your behalf under your instructions.
We use it to do the job you asked for: comparing certificates against your requirements, emailing vendors to ask for renewals, and producing the reports you choose to share. We do not use it to market to your subcontractors, and we do not build a profile of them across customers.
What we do not do
We do not sell your data, or anyone else’s in your workspace. We do not share it with advertisers, and there are no advertising trackers on the website or in the product. The product analytics we do use are described in their own section below, and never carry the contents of your workspace.
We do not read your workspace for our own purposes. Staff access to customer data happens only when you ask us for support or when we are investigating a fault, and it is logged.
Product analytics and error reports
The website and the app use PostHog, hosted in the US, to count how they are used and to report errors. PostHog processes this for us and for nothing else.
It sets no cookie and uses no browser storage: the identifier it works with is kept in memory for the open tab only, and is gone when you close it. There is no session recording, and nothing is captured automatically from your clicks or from what you type.
What is recorded: page views; clicks on the sign-up, contact and pricing links; and named actions in the product — for example a vendor added, a certificate recorded, a verdict changing, a reminder sent. These carry identifiers, counts and statuses only. They never carry names, email addresses, certificate values or the contents of any document.
When you are signed in, events are linked to your internal account id, not to your email address.
Upload-link, report-link, invitation and password-reset tokens are removed from page addresses before anything is sent, and a page whose address contains one of those tokens sends nothing at all.
An error report contains the technical error and the page route it happened on.
Who else touches it
The companies that run the infrastructure this product sits on, named rather than described: Vercel (the website and app front end), Render (the API and the background worker), Neon (the Postgres database and the document storage), Resend (renewal chases and account email), PostHog (product analytics and error reports, US-hosted) and Stripe (subscription billing; card details go to Stripe and never reach us). They process data to provide those services and for nothing else. If we add or change one, this list changes with it.
Anyone you deliberately send a share link to. A shared compliance report is readable by whoever holds the link until its expiry date, or until you withdraw it. Choose the scope and the expiry accordingly.
We will disclose data if the law requires it. If we can lawfully tell you first, we will.
How long it is kept
Superseded certificates are retained rather than deleted, because the history is what a claim or an audit asks to see. That is a deliberate product decision and you should know about it.
If you close your account, ask us to delete the workspace and we will remove it, including stored documents, within 30 days — except anything we are legally required to keep. Export first: the register exports as CSV on every plan.
Your rights, and how to use them
You can get a copy of what we hold, correct it, or ask us to delete it. Much of this you can do yourself inside the product; for the rest, write to us and we will do it.
Depending on where you live you may have additional statutory rights, including under US state privacy laws and, if you are in the UK or the EU, under the UK GDPR and GDPR. We will honour them regardless of which of those applies to you, because operating one standard is simpler than operating five.
Cookies
A session cookie so you stay signed in. The marketing site also keeps one value in your browser session storage: where you arrived from, so we know which pages bring people here. It is cleared when you close the tab, it never leaves your browser as an identifier, and nothing about it identifies you. The product analytics described above use no cookie and no browser storage at all. There is no advertising cookie and no analytics cookie, and because nothing is stored on your device for analytics, there is still no consent banner to click through.
Changes
If this policy changes materially we will say so in the product and by email rather than quietly reposting the page.
Asking us something
Write to info@watchmycover.com. The technical measures behind all of this are set out on the security page, including the gaps.