Legal
Privacy Policy.
What we collect, why, who else sees it, and how long it stays. No advertising, no analytics product, and three cookies — all of which exist to sign you in.
Last updated 3 September 2026
In short
- We collect what an account needs and what a server log records. Nothing else.
- No advertising, no tracking pixels, no analytics product, no data broker.
- We have never sold personal data and will not.
- Cookies here are strictly necessary — three of them, all for signing you in.
- Data is processed on AWS in the United States. You can ask for a copy, or for deletion.
This summary is for orientation only. The numbered sections below are the ones that apply.
Who is responsible for your data
www.spacwatch.com is operated by Sergey Monin, an individual, who is the controller of the personal data described here. “We”, “us” and “our” refer to that operator.
This policy covers the website and the account features behind it. It does not cover the SEC’s EDGAR system or any other site we link to. For questions, or to exercise any of the rights in section 9, write to info@spacwatch.com.
What we collect
- Account details
- When you register: a username, an email address, and a password (which is held by our identity provider as a hash — we never see it). If you choose to complete your profile: first and last name, phone number, date of birth, country, language preference, and a profile picture you upload. Everything beyond the username, email and password is optional and can be removed at any time.
- What you do in the product
- The SPACs on your watchlist, your notification preferences, and — if you turn on browser notifications — the push subscription your browser issues, which is an endpoint address and two keys belonging to your browser’s push service.
- Messages you send us
- If you use the contact form: your name, email address, and optionally a company name and firm type, plus the message itself. These are delivered to us as an email and kept in that mailbox.
- Technical records
- Our content delivery network writes an access log for each request: the IP address it came from, the date and time, the URL, the response status, the referring page and the browser’s user-agent string. Our servers write application logs and error reports, which may incidentally contain the same request details.
- Sign-in security signals
- Our identity provider records sign-in attempts, including your IP address, to detect credential stuffing and unusual access. We pass on the address the request actually arrived from so that this works.
We do not ask for and do not want payment details, government identifiers, or any special category data — health, biometrics, political opinions, and so on. Please do not send them through the contact form.
What we deliberately do not do
- We do not run advertising, and there are no advertising or social media tracking pixels on this site.
- We do not use a third-party analytics product. There is no Google Analytics tag, no session recorder, and no heatmap tool.
- We do not build advertising or behavioural profiles, and we do not do any automated decision-making that produces legal or similarly significant effects.
- We have never sold or “shared” personal data as those terms are defined under U.S. state privacy laws, and we do not intend to.
- We do not buy personal data or enrich your record from data brokers.
Why we use it, and on what legal basis
For readers in the UK and the EEA, the legal bases under the UK GDPR and the GDPR are as follows.
- To run your account and the features in it
- Registering you, signing you in, showing your profile, keeping your watchlist, sending the alerts you asked for. Basis: performance of a contract with you (Article 6(1)(b)).
- To answer your messages
- Replying to what you send through the contact form. Basis: legitimate interests in responding to correspondence, or performance of a contract where the message concerns your account (Article 6(1)(b) and (f)).
- To keep the service secure and working
- Access and application logs, rate limiting, abuse and fraud detection, debugging, and reconstructing what happened during an incident. Basis: legitimate interests in the security and integrity of the service (Article 6(1)(f)).
- To send browser or email notifications
- Only the ones you switched on, and only until you switch them off. Basis: consent (Article 6(1)(a)), withdrawable at any time in settings.
- To comply with the law
- Where we are required to retain or disclose something. Basis: legal obligation (Article 6(1)(c)).
Where it is processed
Our infrastructure runs in Amazon Web Services regions in the United States, and the content delivery network serves the site from edge locations around the world. If you are in the UK or the EEA, that means your data is transferred outside your home jurisdiction.
Those transfers are made under the European Commission’s Standard Contractual Clauses and the UK Addendum, incorporated into our agreement with AWS, together with the technical measures described in section 10. You can ask us for more detail about the safeguards that apply.
How long it is kept
- Account data
- For as long as your account exists. When you delete your account, the account record and its profile fields, watchlist and notification subscriptions are deleted with it.
- Access logs
- Ninety days, then deleted automatically. They are kept that long so that an incident noticed weeks after the fact still has the traffic that explains it, and no longer, because they carry IP addresses.
- Contact form messages
- Kept in our mailbox for as long as the correspondence is useful, and reviewed periodically.
- Backups
- Deleted data may persist in routine backups for a short period after deletion before being overwritten in the normal cycle.
Your rights
Wherever you are, you can ask us for a copy of the personal data we hold about you, ask us to correct it, or ask us to delete it — and you can do a good deal of it yourself from the profile and settings screens.
If you are in the UK or the EEA, you also have the right to object to processing carried out on the basis of legitimate interests, to ask us to restrict processing, to receive your data in a portable format, and to withdraw consent at any time without affecting what was done before you withdrew it. You have the right to complain to your data protection authority — in the UK, the Information Commissioner’s Office.
If you are in California or another U.S. state with a comprehensive privacy law, you have rights to know, delete, correct and obtain a portable copy, and a right not to be discriminated against for exercising them. We do not sell or share personal data for cross-context behavioural advertising, so there is no opt-out to offer; we honour Global Privacy Control signals regardless.
To exercise any of these, write to info@spacwatch.com from the address on your account, or use the contact form. We will respond within one month, and will tell you if we need longer. There is no charge, and we may need to verify who you are before acting on a request.
How it is protected
The site is served over HTTPS only, with strict transport security. Passwords are held by our identity provider and are never visible to us. Session cookies are HttpOnly, signed, and restricted to secure connections. Data at rest is encrypted, storage is private and reachable only through the site, and internal access is limited to the accounts that need it.
No system is perfectly secure, and we cannot guarantee the security of anything you send over the internet. If a breach affecting your data occurs and the law requires us to tell you, we will.
Children
The service is not intended for anyone under 18, and we do not knowingly collect data from children. If you believe a child has given us personal data, tell us and we will delete it.
Changes to this policy
We may update this policy. The date at the top of the page shows when it last changed. Where a change materially affects how we use your data we will give notice through the service or by email before it takes effect.
Want a copy of your data?
Ask, and we will send it. The same address handles corrections, deletion requests and anything else in this policy.