1. Who is responsible
TIE Watch, trading as TIE Watch, is the controller for account, subscription and direct customer data. Registered/contact address: Spain. Email: privacy@tiewatch.com.
If a Pro user enters another person’s information, that user must have the applicant’s authority and may have separate responsibilities as a controller. TIE Watch processes those details only to provide the requested monitoring service.
2. Data we collect
| Category | Examples | Why it is needed |
|---|---|---|
| Account | Name, verified email, internal user ID, authentication and account timestamps. | Create and secure your account, communicate with you and associate your requests with you. |
| Applicant identity | Full legal name, NIE/TIE, nationality, mobile number and notification email. | Complete the fields required by the official appointment website. These fields are encrypted before database storage. |
| Appointment preferences and authority | Province, office scope, procedure, next-available instruction, authorization version and time. | Run only the search you requested and record the scope you authorized. We never ask for or store Cl@ve credentials. |
| Checks and bookings | Check times, outcome, office, detected dates/times, errors, latency, support IDs, confirmation text/reference and, where captured, a confirmation screenshot. | Operate the service, stop after a booking, show status, diagnose failures and keep booking evidence available to you. |
| Extension and security | Device name, a one-way hash of the pairing token, issue/revocation/last-seen times, IP address, browser/request information and ordinary hosting/security logs. | Pair and revoke Chrome installations, prevent abuse and investigate incidents. We do not store the raw pairing token after it is issued. |
| Billing | Plan, Stripe customer/subscription identifiers, subscription status and renewal/cancellation state. | Take payment and provide the correct plan. TIE Watch does not store full card numbers, card security codes or online-banking credentials. |
| Free-trial abuse prevention | Keyed, one-way HMAC fingerprints derived separately from the normalized NIE/TIE and account ID; first/last-attempt and expiry times. | Prevent the same applicant from repeatedly claiming Free trials through different emails or replacement accounts. The ledger contains neither the NIE/TIE nor email and cannot be used to reconstruct them. |
The Chrome extension also stores its pairing token, service address and operational state locally in your Chrome profile. Government cookies and page sessions remain in your browser and are not copied into our account database.
3. How we use it and our legal bases
- Contract: account access, appointment monitoring, alerts, extension pairing, subscription administration and customer support are necessary to provide the service you request (GDPR Article 6(1)(b)).
- Explicit instruction/consent: we use applicant details supplied for a friend, family member or client only after the account holder confirms authority and the appointment scope. Consent can be withdrawn, although processing already carried out remains lawful.
- Legal obligations: billing, accounting, tax, consumer-rights and regulatory records may be kept where required (Article 6(1)(c)).
- Legitimate interests: proportionate security logging, fraud/abuse prevention, debugging and service reliability (Article 6(1)(f)). You may object, but some security processing is necessary to operate safely.
We do not sell personal data, use applicant identity data for advertising, or make legal or immigration eligibility decisions. The service automatically schedules checks and may identify a matching slot, but a person remains responsible for the official CAPTCHA and final confirmation.
4. Who receives data
We use specialist service providers under contractual and security controls:
- Supabase: authentication, database and private confirmation-image storage.
- Vercel: application hosting, delivery and operational/security logs.
- Stripe: checkout, recurring billing, invoices and the customer billing portal. Stripe receives payment and billing information under its own privacy terms.
- Resend: transactional account and appointment email delivery.
- Google Chrome: the extension and its local storage run in the browser installation you control.
- Browserless: only if a legacy or administrator-enabled server-side browser workflow is used; it then receives the fields necessary to run that specific check.
- Spanish public administration: the identity and contact fields required by the official appointment form are submitted to its website at your instruction.
Providers may process data outside the EEA. Where this occurs, we rely on applicable adequacy decisions or contractual safeguards such as the European Commission’s Standard Contractual Clauses. We do not give applicant data to unrelated data brokers or advertisers.
5. Security
- AES-256-GCM application-level encryption for stored applicant, contact and booking-confirmation payloads.
- TLS/HTTPS in transit; private database and storage access; row-level policies separating customer accounts.
- Pairing tokens are random, revocable and stored by us only as SHA-256 hashes.
- Payment card handling is delegated to Stripe; secret service credentials remain server-side.
- Access is limited to what is required for operation, support and incident response.
No internet service can promise absolute security. If a breach is likely to create a high risk to affected people, we will notify them and the relevant authority where the GDPR requires it.
6. Retention and deletion
- Active account: account, monitor, device, check, slot and booking evidence is kept while your account exists and as needed to provide the service.
- Account deletion: the self-service control permanently cancels an active TIE Watch subscription, invalidates paired devices, removes applicant monitors and related checks/bookings/screenshots, and deletes the Supabase authentication account.
- Free-trial ledger: the non-reversible applicant and account fingerprints are retained for 24 months from the trial claim to enforce one Free trial per applicant. This limited fraud-prevention record intentionally survives account deletion, but contains no readable NIE/TIE, name or email.
- Provider backups and logs: residual encrypted backups and security logs may remain for a limited provider-controlled cycle before automatic overwrite.
- Billing/legal records: Stripe and TIE Watch may retain invoice, transaction and legally required accounting information for statutory periods even after account deletion. This exception does not permit continued appointment monitoring.
Removing your account does not remove data already submitted to the Spanish administration or local data held in your Chrome profile. Remove the extension or clear its storage separately.
Open Account & deletion to delete your account now.
7. Your rights
Subject to applicable law, you may request access, correction, deletion, restriction, portability or object to processing; withdraw consent; and complain to the Spanish Data Protection Agency (AEPD). Requests are free in ordinary cases and are normally answered within one month. Email privacy@tiewatch.com. We may need to verify identity before disclosing or changing data.
8. Cookies and local storage
TIE Watch uses essential authentication cookies and local storage needed to keep you signed in, preserve a form draft and operate the paired extension. These are not used for behavioural advertising. If optional analytics or marketing technologies are added later, we will update this policy and obtain consent where required.
9. Changes
Material changes will be dated here and, where appropriate, announced in the service or by email. Earlier processing remains governed by the policy in effect at that time.
For official guidance, see the AEPD’s information on the right to information and data-protection rights.