Privacy Policy
This policy explains how Time Exchange collects, uses, shares and protects personal information relating to customers, sellers, sourcing customers, retailers and website visitors.
Version 1.2 · Last updated: 16 August 2026
1. Who we are
Time Exchange is a UK business and is not a limited company. In this policy, “Time Exchange”, “we”, “us” and “our” mean the business operating the Time Exchange website and Platform. We are the controller of personal information processed for the purposes described in this policy.
Time Exchange6 Valley View Drive
Bradford
BD10 0FF
Email: info@timeexchange.co.uk
2. Scope of this policy
This policy applies when you visit our website, submit a Watch for sale, ask us to source a Watch, apply for or use a Retailer account, submit or review an Offer or sourcing response, communicate with us, receive an introduction or otherwise use our Services.
Time Exchange connects Customers with independent Retailers. Once an introduction is made, the selected Retailer will normally be a separate controller for information it uses to inspect, buy, sell, deliver, authenticate, insure, take payment for or provide after-sales service relating to a Watch. You should also read that Retailer’s privacy information.
3. Information we collect
Depending on how you use Time Exchange, we may collect:
- Identity and contact information: name, email address, telephone number, postal or delivery address and business contact details.
- Account information: login and authentication records, account role, notification preferences, membership status and account history.
- Watch and Submission information: brand, model, reference and serial details, ownership history, condition, faults, service, repair or modification history, box, papers, accessories, photographs, provenance and information about finance, insurance claims, liens or other third-party interests.
- Sourcing information: the Watch sought, specifications, condition, timeframe, indicative budget, preferences and related messages.
- Offer and transaction information: Offers, sourcing responses, prices, selection and introduction records, any transaction status later reported to us, fulfilment updates, correspondence, complaints and evidence relating to a proposed or completed transaction.
- Retailer and verification information: business and trading details, the identity and authority of representatives, proof of identity and address, bank statements or evidence of account ownership, business records, references, source-of-funds information and the outcome of internal KYC, anti-money-laundering, sanctions or fraud checks where reasonably required.
- Membership and payment information: subscription status, invoices, payment references and limited payment metadata. Stripe processes retailer card payments; Time Exchange does not normally receive or store full card details.
- Communications: emails, telephone calls, SMS and WhatsApp messages, support requests, form responses, notes, complaints, message delivery information made available by the relevant provider and your communication and marketing choices.
- Technical and usage information: IP address, device and browser information, pages and features used, timestamps, security and audit logs, approximate location derived from an IP address, cookie identifiers and consent choices.
We do not ask for special-category information unless it is genuinely necessary. Identification or bank documents can contain more information than we need, so we may ask you to redact unrelated information where doing so does not prevent the relevant check. We do not use facial recognition or other biometric identification.
4. Where information comes from
We collect most information directly from you. We may also receive information from another Customer or Retailer involved in a Submission, our payment and technical service providers, professional advisers, fraud-prevention sources, public registers or websites, and public authorities. Where required, we will tell you about information obtained from another source.
5. Why we use information and our lawful bases
We use personal information only where we have a lawful basis. Depending on the activity, we rely on:
- Contract or steps at your request: to receive and review Submissions, provide accounts and membership, contact you by appropriate service channels, communicate Offers and sourcing responses, record selections, make introductions and administer the Services and Retailer membership.
- Legitimate interests: to operate a private watch-introduction platform, follow up and clarify active or recent requests, negotiate and communicate Offers, provide support, assess Retailer applications manually, improve and protect the Platform, keep appropriate records, prevent misuse and fraud, enforce our terms and establish, exercise or defend legal claims. We consider the necessity and effect on the people concerned before relying on this basis.
- Legal obligations: to keep tax and accounting records, respond to binding requests from authorities, comply with applicable reporting duties, and meet fraud-prevention, sanctions or other legal requirements that apply to us.
- Consent: for promotional electronic marketing to individuals and for non-essential analytics or advertising technologies. You may withdraw consent at any time without affecting processing that took place before withdrawal.
Required fields on our forms are needed to assess and administer the relevant request. If you do not provide them, we may be unable to process the Submission, open an account, verify a Retailer or provide the requested Service. Optional fields are marked or can be left blank.
6. How the private introduction process works
Retailers may see the relevant Watch listing or sourcing brief while Customer contact details remain hidden. Information displayed at this stage is limited to what is reasonably needed for Retailers to consider an Offer or sourcing response.
When a Seller or sourcing customer selects an Offer and requests an introduction, we may give the selected Retailer the Customer’s name, email address and telephone number, together with the information needed to discuss that specific arrangement. Selection on Time Exchange does not form a Watch contract. Other Retailers do not receive those contact details. The selected Retailer must use the information only for the introduction, any transaction later agreed directly, and related after-sales responsibilities unless it has another lawful basis and provides its own privacy information.
7. Transactional and marketing messages
We may send service messages needed to operate the Platform, including confirmations, requests for information, Retailer application and verification updates, Watch Submission or sourcing-request updates, Offers, sourcing responses, account and membership messages, security notices, changes to our terms, and transaction, fulfilment or support updates. These are not promotional messages and may be sent where necessary to take steps at your request, perform a contract or pursue our legitimate interests.
If you give us a telephone number in connection with a Customer request, Watch Submission, sourcing request, Retailer application, account or transaction, we may use that number to contact you by telephone, SMS or WhatsApp about that specific matter or your related relationship with Time Exchange. WhatsApp communications may include requests to clarify information, progress or decision updates, Offers and responses, introduction or fulfilment arrangements, and account or support messages. You may ask us at any time to stop using WhatsApp and use another available channel by replying to the message or emailing info@timeexchange.co.uk. We may still contact you through another channel where reasonably necessary to administer your request, account or transaction or to comply with law.
Our selling, sourcing and Retailer application forms may include a separate, optional and initially unticked checkbox for occasional promotional emails. Where you opt in, we record the choice, the consent wording or version and the server time as evidence. Marketing consent is separate from acceptance of our Terms and is not a condition of using the Services. Every marketing message will provide a simple way to unsubscribe. Retailer notification preferences can also be changed through the Retailer account where available or by contacting us.
We do not treat a telephone number supplied for an application, Watch request or transaction as permission to send promotional WhatsApp messages. We will only use WhatsApp for direct marketing where we have a valid consent or another permission allowed by law, and each such message will identify Time Exchange and provide a simple way to opt out.
We may contact a corporate Retailer about relevant business services on the basis of our legitimate interests where permitted by law. Any person may object to direct marketing at any time by using the unsubscribe method in the message or emailing info@timeexchange.co.uk.
For authorised Retailer campaign emails, we record whether a message was delivered, delayed, bounced, rejected or reported as spam, together with unsubscribe requests and demonstration responses. We use this information to honour preferences, maintain an accurate list and protect email-sending reputation. We do not use tracking pixels to record whether a recipient opens these launch emails.
8. Who we share information with
We may share personal information, only as reasonably necessary, with:
- the selected Retailer after a Customer agrees to an introduction;
- Netlify for website hosting and delivery;
- Supabase for database hosting, authentication, storage and server-side functions;
- Resend for delivery of transactional and authorised marketing emails;
- WhatsApp and its parent company Meta, where we use WhatsApp to communicate with you about an application, Watch request, account, introduction, transaction or support matter;
- Stripe for Retailer membership checkout, recurring billing and payment administration;
- Google Analytics and Meta Pixel if those technologies are enabled and the visitor has consented;
- professional advisers, insurers, auditors and other suppliers that support our business;
- HMRC, courts, regulators, law-enforcement bodies, banks or other competent authorities where disclosure is required by law or reasonably necessary to report or address suspected fraud, crime, security risk or unlawful activity; and
- a purchaser, successor or adviser in connection with a genuine sale, restructuring or transfer of the business, subject to appropriate confidentiality and data-protection safeguards.
When we communicate through WhatsApp, WhatsApp and Meta receive information needed to operate the service, which may include your telephone number, WhatsApp profile information, message content and associated delivery, device and usage information. Their handling of that information is also governed by their own terms and privacy information. WhatsApp messages are protected in transit by end-to-end encryption, but recipients and businesses can retain or otherwise use messages after delivery.
We do not sell personal information. Internal identity checks are carried out by authorised Time Exchange personnel. We do not currently use a separate third-party identity-verification service, although our database and storage providers process the documents on our behalf.
9. International transfers
Our main database is configured in the United Kingdom, but some suppliers may process or support personal information from other countries. Where personal information is transferred outside the United Kingdom, we use a lawful transfer mechanism where required, such as UK adequacy regulations, the UK International Data Transfer Agreement or the UK Addendum to approved contractual clauses, together with appropriate risk and security measures. You may contact us for further information about the safeguards relevant to your information.
10. Retention
We keep identifiable information only for as long as reasonably needed for the purpose for which it was collected, including legal, accounting, fraud-prevention and dispute requirements. Our normal retention periods are:
- an inactive selling Submission or sourcing request that did not lead to an introduction: up to 24 months after the last activity;
- selected Offers, introductions, completed arrangements and associated records: up to six years after completion or the last material activity;
- an unsuccessful or withdrawn Retailer application: normally six months after the decision or withdrawal;
- Retailer account, membership and operational information: for the membership and normally six months after it ends, except for the records described below;
- identity, bank and other internal verification documents: while the check or relationship is active and normally no longer than six months after an application is rejected, withdrawn or the membership ends, unless a legal, fraud or dispute reason requires longer retention;
- billing, tax, accounting, transaction and material compliance records: normally six years after the relevant relationship, transaction or accounting period;
- general enquiries, service correspondence (including WhatsApp messages) and resolved complaints: normally three years after the last response, or up to six years where the matter may relate to a transaction or legal claim;
- routine technical, email-delivery, audit and security logs: normally up to 12 months, unless needed for an active investigation; and
- marketing consent and preference records: while marketing continues. We may retain the minimum information needed to honour an unsubscribe or objection for as long as necessary to prevent further marketing.
We may retain information longer where required by law, a regulator, litigation, an unresolved complaint, fraud prevention or another documented necessity. When retention is no longer justified, information is deleted or anonymised. Residual copies may remain temporarily in protected backups until they are overwritten through the normal backup cycle.
11. Security
We use proportionate technical and organisational measures intended to protect personal information, including access controls, authentication, restricted document access, encrypted connections, activity logging and limited administrative access. No online system can be guaranteed completely secure. You are responsible for keeping account credentials and secure response links confidential and for notifying us promptly if you suspect misuse.
12. Cookies, analytics and advertising technologies
Our website may use cookies, browser storage and similar technologies. Strictly necessary technologies support functions such as security, authentication, session continuity, routing, consent records and account access. Where they are necessary to provide a service you request, they do not require consent, but we still explain their use.
During the founding launch, session storage records the first campaign source, medium, campaign, partner and landing page for the current browser session so that a submitted selling brief, sourcing request or launch-list registration can be attributed to the activity that generated it. The selling form may also keep an unfinished draft in session storage on that browser. Draft data and attribution are cleared by the browser when the session ends; consent preferences are kept in local storage so the site can remember your choice. Sensitive documents and image files are not stored as part of the draft.
We intend to use Google Analytics to understand website usage and Meta Pixel to measure advertising and create or measure audiences. These services can receive information such as cookie or device identifiers, IP address, browser details, pages viewed, interactions and referral information. Google and Meta may act as separate controllers for some processing under their own privacy terms.
Google Analytics and Meta Pixel are non-essential and are not activated unless the relevant service is configured and you choose to accept its category through the site’s privacy preference control. Refusing or withdrawing consent does not prevent use of the core website. You can reopen the preference control at any time using the Cookie preferences link in the site footer.
13. Your data-protection rights
Depending on the circumstances and lawful basis, you may have the right to:
- ask for access to your personal information and a copy of it;
- ask us to correct inaccurate or incomplete information;
- ask us to erase information;
- ask us to restrict how information is used;
- receive certain information in a portable format;
- withdraw consent at any time where processing is based on consent; and
- object to processing based on legitimate interests.
You have an absolute right to object to the use of your personal information for direct marketing.
These rights are not absolute and exemptions may apply. We may ask for reasonable proof of identity before acting on a request. We do not charge a fee in ordinary cases and normally respond within one month. To exercise a right, email info@timeexchange.co.uk.
14. Automated decisions
Time Exchange does not make decisions about Customers or Retailers based solely on automated processing where the decision has legal or similarly significant effects. Retailer approval, verification concerns, platform restrictions and relevant disputes are considered by a person.
15. Children
The Services are for people aged 18 or over. We do not knowingly collect personal information from a child for a Submission, sourcing request or Retailer account. If you believe a child has provided information to us, please contact us so that we can investigate and take appropriate action.
16. Complaints
Please raise a privacy concern with us first by emailing info@timeexchange.co.uk or writing to the address above. Include your name, contact details and a clear explanation of the concern. We aim to acknowledge complaints within 48 hours and provide a substantive response within three weeks, although a complex matter may take longer.
You also have the right to complain to the Information Commissioner’s Office (ICO), the UK supervisory authority. Visit ico.org.uk/make-a-complaint, call 0303 123 1113 or write to the Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF.
17. Changes to this policy
We may update this policy to reflect changes to the Platform, our suppliers or the law. The latest version and effective date will appear on this page. If a change materially affects registered Retailers or an active Customer and we hold their email address, we will take reasonable steps to bring it to their attention before or when the change takes effect.
18. Contact us
For privacy questions, rights requests or complaints, email info@timeexchange.co.uk or write to Time Exchange, 6 Valley View Drive, Bradford, BD10 0FF.