Inventory monitoring pilot
Inventory Data & Monitoring Policy
Effective August 3, 2026 · Updated August 3, 2026
This policy explains the data practices and operating limits that apply when a business uses WatchRecall inventory monitoring.
Pilot interest form
The pilot interest form includes business and contact names, work email, optional inventory system and optional message. WatchRecall sends those details privately to the operator; it does not send an applicant confirmation, expose the operator's personal email address or add the interest to the inventory database. Do not submit inventory files, customer records or order history through the form.
What WatchRecall receives
A monitor contains the business contact email and monitor name, normalized product fields such as SKU, title, brand, model, UPC/GTIN, quantity and location, plus source and import metadata. WatchRecall does not need prices, customer records, order history or payment information; do not include them in an inventory export.
How files and credentials are handled
Initial CSV, TSV and XLSX uploads are parsed in the browser before normalized rows are submitted. Dashboard replacements, API uploads and emailed attachments pass through WatchRecall or its receiving provider only long enough to validate and normalize them. WatchRecall does not intentionally retain original file bytes. API keys and private receiving addresses are shown once and stored only as SHA-256 hashes.
Retention and deletion
Normalized active and removed inventory rows, contact details, source metadata, matches and import history remain until the monitor is deleted. Queued normalized payloads are erased after a job completes or fails. Delete monitor and data removes the monitor and its related rows from the primary database. Limited records may remain temporarily in infrastructure logs or backups under provider retention schedules.
Service providers
WatchRecall uses Vercel to run the web application, Railway to host PostgreSQL and scheduled workers, and Resend to send email and receive automated inventory attachments. These providers process only the data needed to deliver their part of the service and apply their own security and retention practices.
Security controls
Data is transmitted over HTTPS. Private dashboard credentials are exchanged for secure, SameSite, HTTP-only browser sessions and are kept out of request URLs and analytics. Source credentials are hashed, imports are rate-limited and idempotent, and signed Resend webhooks are required for inbound email.
Monitoring limitations
WatchRecall is a screening and notification tool, not a legal compliance certification. Results depend on the identifiers in the inventory export and on the completeness and timing of official CPSC, FDA and NHTSA records. A no-match result does not prove a product is safe or unrecalled. Businesses should review linked official notices and follow their own recall, stop-sale and recordkeeping obligations.
Questions or data requests
Use the interest form for pilot questions. Existing monitor owners can delete the monitor and its retained data directly from the private dashboard.