Skip to content
First DialsBrought to you byWatchgauge HQ
Live feedLatest DealsAlertsDealersFor dealersPrivacy

Trust

Security & data protection

Last updated October 2026. Please also read our Privacy Policy and Listing Data & Sources Notice.

1. Scope of this page

This page describes the security controls we currently operate for First Dials (the Service). It is a statement of our practices, not a certification. We are not currently certified against ISO/IEC 27001 or audited under SOC 2, and we do not claim either. Where we align our controls with those frameworks we say so plainly below.

The Service does not collect, store or process protected health information, so HIPAA does not apply to it. If that ever changes we will say so here before it does.

2. Data we hold

Account data (email address, plan and role), alert preferences and saved searches, subscription status, listing and benchmark data sourced from publicly available dealer websites and dealer feeds, and technical logs. Passwords are never stored by us in readable form — authentication is handled by our identity provider and passwords are stored only as salted hashes.

Card numbers are never stored on our systems; payments are handled by our payment provider.

3. Access control

Every table holding account or dealer data enforces row-level security in the database itself, not only in the application. A signed-in user's requests carry their own identity to the database, so they can read and write only their own rows.

Paid features are enforced in the database as well as the interface. Non-members receive listing data with dealer identity, dealer websites and outbound links removed at the query layer, so restricted fields are never transmitted to the browser.

Dealer licence numbers, dealer owner identities and feed configuration are excluded from all public reads. The public dealer directory is served by a restricted view that exposes only business name, location, verified status and whether a licence has been verified.

Administrative access is limited to named individuals, granted through a dedicated roles table rather than a flag on the user record, and checked server-side on every privileged request. Privileged database credentials are held only in the server environment and are never present in browser code.

4. Encryption

All traffic to and from the Service is served over HTTPS with TLS. Data at rest in our managed database and object storage is encrypted by the platform provider. Secrets and API keys are stored in a managed secret store and injected into the server runtime at execution time.

5. Logging and audit trail

Sensitive administrative actions — manual dealer crawls, market-value refreshes, notification dispatch runs and changes to notification preferences — are written to an append-only audit log recording the actor, action, target, timestamp, source IP and user agent. Audit entries are written with elevated server credentials so an actor cannot suppress their own entry, and are readable only by administrators.

Application and platform logs are retained for operational troubleshooting and are not used for advertising or profiling.

6. Scheduled jobs and public endpoints

Endpoints that trigger paid or privileged background work require a server-only scheduler secret presented in a request header and compared in constant time. Public API keys are never accepted as authorisation for those endpoints.

7. Retention and deletion

Account data is retained while the account is open, then deleted or de-identified once we no longer need it for accounting, dispute-resolution or legal-compliance purposes. You may request deletion of your account and associated data at any time by emailing support@watchgaugehq.com; see our Privacy Policy for access and correction rights.

Dealers may request removal of their listings at any time and we action verified requests within two business days — see the Listing Data & Sources Notice.

8. Subprocessors

We rely on third-party providers for cloud hosting and application delivery, managed database and authentication, email delivery, payment processing, and error and performance monitoring. Providers are selected on the basis of their own published security posture, are contractually restricted to processing data on our instructions, and some process data outside Australia (including the United States and the European Union).

A current list of subprocessors is available on request to support@watchgaugehq.com.

9. Incident response and breach notification

Suspected incidents are triaged on detection, contained, and assessed for impact on personal information. Where an eligible data breach occurs we notify affected individuals and the Office of the Australian Information Commissioner as required by the Notifiable Data Breaches scheme.

10. Responsible disclosure

If you believe you have found a security vulnerability, email support@watchgaugehq.com with the subject line “Security” and enough detail to reproduce the issue. Please do not access or modify other users' data, degrade the Service, or publicly disclose the issue before we have had a reasonable opportunity to remediate. We will acknowledge reports within one business day and will not pursue action against good-faith researchers who follow this process.

11. Framework alignment

Our controls are designed with reference to ISO/IEC 27001 Annex A and the SOC 2 security and confidentiality criteria: access control on a least-privilege basis, encryption in transit and at rest, audit logging of privileged actions, change management through reviewed deployments, vendor review, retention limits and documented incident response.

Formal certification requires an independent audit over an observation period, together with an information security management system, risk register, staff security training and evidence collection. We will publish audit status on this page if and when we complete one, and we will not describe the Service as certified before then.

First Dials

See it first. Own it first.

Brought to you by

Watch Gauge

Australia's pre-owned watch price intelligence and deal-alert platform.

Buyers

  • Live deal feed
  • Latest Deals
  • Saved searches

Dealers

  • Why dealers join
  • Dealer directory
  • Dealer dashboard

Legal

  • Pricing
  • Terms & Conditions
  • Privacy Policy
  • Refund Policy
  • Listing Data & Sources
  • Security & data protection

Value scores and market values are our opinion only, built from market and sold price data — they are not valuations or advice. Dealer licence numbers are shown only where the licence has been verified against a state secondhand dealer register.

© 2026 Watchgauge HQ. All rights reserved. First Dials is an information and alert service only. We are not the seller, agent or broker of any watch listed, we are not a party to any transaction between you and a dealer, and we do not provide valuations, authentication, financial or investment advice. Value scores, market values and discount indicators are opinion-only estimates generated from third-party market data and may be incomplete or out of date — it is unreasonable to rely on them when buying or selling; always verify price, condition, authenticity and availability directly with the dealer. Prices are in AUD and include GST where applicable. Subscriptions renew automatically until cancelled and free trials convert to paid plans unless cancelled before the trial ends. Alerts depend on dealer data and carrier delivery and cannot be guaranteed. Listings are aggregated from the publicly available websites of Australian dealers on an opt-out basis — dealers may request correction or removal at any time via our Listing Data & Sources Notice. Your use of this site is governed by our Terms & Conditions and Privacy Policy. Nothing here excludes rights you have under the Australian Consumer Law.

Edit with