Skip to content

Legal

Privacy Policy.

What we collect, why, who else sees it, and how long it stays. No advertising, no analytics product, and three cookies — all of which exist to sign you in.

Last updated 3 September 2026

In short

  • We collect what an account needs and what a server log records. Nothing else.
  • No advertising, no tracking pixels, no analytics product, no data broker.
  • We have never sold personal data and will not.
  • Cookies here are strictly necessary — three of them, all for signing you in.
  • Data is processed on AWS in the United States. You can ask for a copy, or for deletion.

This summary is for orientation only. The numbered sections below are the ones that apply.

Who is responsible for your data

www.spacwatch.com is operated by Sergey Monin, an individual, who is the controller of the personal data described here. “We”, “us” and “our” refer to that operator.

This policy covers the website and the account features behind it. It does not cover the SEC’s EDGAR system or any other site we link to. For questions, or to exercise any of the rights in section 9, write to info@spacwatch.com.

What we collect

Account details
When you register: a username, an email address, and a password (which is held by our identity provider as a hash — we never see it). If you choose to complete your profile: first and last name, phone number, date of birth, country, language preference, and a profile picture you upload. Everything beyond the username, email and password is optional and can be removed at any time.
What you do in the product
The SPACs on your watchlist, your notification preferences, and — if you turn on browser notifications — the push subscription your browser issues, which is an endpoint address and two keys belonging to your browser’s push service.
Messages you send us
If you use the contact form: your name, email address, and optionally a company name and firm type, plus the message itself. These are delivered to us as an email and kept in that mailbox.
Technical records
Our content delivery network writes an access log for each request: the IP address it came from, the date and time, the URL, the response status, the referring page and the browser’s user-agent string. Our servers write application logs and error reports, which may incidentally contain the same request details.
Sign-in security signals
Our identity provider records sign-in attempts, including your IP address, to detect credential stuffing and unusual access. We pass on the address the request actually arrived from so that this works.

We do not ask for and do not want payment details, government identifiers, or any special category data — health, biometrics, political opinions, and so on. Please do not send them through the contact form.

What we deliberately do not do

  • We do not run advertising, and there are no advertising or social media tracking pixels on this site.
  • We do not use a third-party analytics product. There is no Google Analytics tag, no session recorder, and no heatmap tool.
  • We do not build advertising or behavioural profiles, and we do not do any automated decision-making that produces legal or similarly significant effects.
  • We have never sold or “shared” personal data as those terms are defined under U.S. state privacy laws, and we do not intend to.
  • We do not buy personal data or enrich your record from data brokers.

Cookies

This site sets three cookies, all of them strictly necessary to sign you in and keep you signed in. There are no analytics, advertising or preference cookies, which is why you are not asked to consent to any.

accessToken, idToken, refreshToken
The three halves of your session — one authorises API calls, one carries your profile details for display, and one obtains fresh copies of the other two. All three are HttpOnly, so no script on the page can read them; all three are sent only over HTTPS; and all three are signed by us so they cannot be tampered with. They expire after thirty days, and signing out deletes them immediately.

A signed-out visitor is sent no cookies at all. Blocking these cookies will not stop you reading the public pages, but you will not be able to sign in.

Your browser may also store data locally for the site — for example a push notification subscription, or interface preferences. That is held on your device, not on our servers, and clearing your browser’s site data removes it.

Why we use it, and on what legal basis

For readers in the UK and the EEA, the legal bases under the UK GDPR and the GDPR are as follows.

To run your account and the features in it
Registering you, signing you in, showing your profile, keeping your watchlist, sending the alerts you asked for. Basis: performance of a contract with you (Article 6(1)(b)).
To answer your messages
Replying to what you send through the contact form. Basis: legitimate interests in responding to correspondence, or performance of a contract where the message concerns your account (Article 6(1)(b) and (f)).
To keep the service secure and working
Access and application logs, rate limiting, abuse and fraud detection, debugging, and reconstructing what happened during an incident. Basis: legitimate interests in the security and integrity of the service (Article 6(1)(f)).
To send browser or email notifications
Only the ones you switched on, and only until you switch them off. Basis: consent (Article 6(1)(a)), withdrawable at any time in settings.
To comply with the law
Where we are required to retain or disclose something. Basis: legal obligation (Article 6(1)(c)).

Who else sees it

We do not sell personal data and we do not disclose it to third parties for their own purposes. We do rely on service providers who process it strictly on our instructions:

Amazon Web Services
Hosting, storage, the identity provider that holds your account, the content delivery network that serves the site, and the service that sends our email. Substantially all of the data described in this policy is held on AWS infrastructure.
Your browser’s push service
If you enable browser notifications, the message is delivered through the push service your own browser nominates — for example Google, Mozilla or Apple, depending on your browser. Notification content passes through them; we sign each message so its origin can be verified.
Our market data provider
Supplies market prices to us. It receives no information about you: we request prices for securities, not for people.

We may also disclose data where we are legally required to, or where it is necessary to establish, exercise or defend a legal claim, or to protect the rights and safety of users. If the service is ever transferred to another operator, account data would transfer with it, and we would tell you before that happened.

Where it is processed

Our infrastructure runs in Amazon Web Services regions in the United States, and the content delivery network serves the site from edge locations around the world. If you are in the UK or the EEA, that means your data is transferred outside your home jurisdiction.

Those transfers are made under the European Commission’s Standard Contractual Clauses and the UK Addendum, incorporated into our agreement with AWS, together with the technical measures described in section 10. You can ask us for more detail about the safeguards that apply.

How long it is kept

Account data
For as long as your account exists. When you delete your account, the account record and its profile fields, watchlist and notification subscriptions are deleted with it.
Access logs
Ninety days, then deleted automatically. They are kept that long so that an incident noticed weeks after the fact still has the traffic that explains it, and no longer, because they carry IP addresses.
Contact form messages
Kept in our mailbox for as long as the correspondence is useful, and reviewed periodically.
Backups
Deleted data may persist in routine backups for a short period after deletion before being overwritten in the normal cycle.

Your rights

Wherever you are, you can ask us for a copy of the personal data we hold about you, ask us to correct it, or ask us to delete it — and you can do a good deal of it yourself from the profile and settings screens.

If you are in the UK or the EEA, you also have the right to object to processing carried out on the basis of legitimate interests, to ask us to restrict processing, to receive your data in a portable format, and to withdraw consent at any time without affecting what was done before you withdrew it. You have the right to complain to your data protection authority — in the UK, the Information Commissioner’s Office.

If you are in California or another U.S. state with a comprehensive privacy law, you have rights to know, delete, correct and obtain a portable copy, and a right not to be discriminated against for exercising them. We do not sell or share personal data for cross-context behavioural advertising, so there is no opt-out to offer; we honour Global Privacy Control signals regardless.

To exercise any of these, write to info@spacwatch.com from the address on your account, or use the contact form. We will respond within one month, and will tell you if we need longer. There is no charge, and we may need to verify who you are before acting on a request.

How it is protected

The site is served over HTTPS only, with strict transport security. Passwords are held by our identity provider and are never visible to us. Session cookies are HttpOnly, signed, and restricted to secure connections. Data at rest is encrypted, storage is private and reachable only through the site, and internal access is limited to the accounts that need it.

No system is perfectly secure, and we cannot guarantee the security of anything you send over the internet. If a breach affecting your data occurs and the law requires us to tell you, we will.

Children

The service is not intended for anyone under 18, and we do not knowingly collect data from children. If you believe a child has given us personal data, tell us and we will delete it.

Changes to this policy

We may update this policy. The date at the top of the page shows when it last changed. Where a change materially affects how we use your data we will give notice through the service or by email before it takes effect.

Want a copy of your data?

Ask, and we will send it. The same address handles corrections, deletion requests and anything else in this policy.