Privacy Policy

Last updated: June 2026

Who we are

PageWatch is a webpage change monitoring service built and operated by CoffeeHaus Labs. We make a Chrome extension and web dashboard that let you watch any element on any page and get notified when it changes. This policy explains what data we collect, why we collect it, and what we do — and don't do — with it.

What we collect and why

Account information

When you create an account we store your email address and a bcrypt hash of your password — we never store your password in plain text. We use your email to identify your account and, if you opt in, to send you change notifications.

Watch data

For each watch you create we store the page URL, the CSS selector you chose, your label, check interval, and the content snapshots captured during monitoring. These snapshots are the only way we can detect changes and show you before/after history. We store only the specific element you selected — not the full page, not your other open tabs, not your browsing history.

Change history

When a change is detected we record the previous and new content, the timestamp, and any acknowledgment notes you add when reviewing the change. This history is visible only to you (and your team, if you are on the Team plan).

Visual screenshots (Pro/Team)

If you enable the optional Visual snapshot feature on a watch, the extension captures a screenshot of the watched page whenever a change is detected and the page is open in your browser. The screenshot, a highlighted diff image, and a changed-pixel ratio are uploaded to and stored on our server. Screenshots are tied to your change history and are deleted when you delete the watch or its history. This feature is opt-in, off by default, and available on Pro and Team plans only.

Profile avatar

If you upload a profile photo it is stored on our server and displayed in the extension and dashboard. Uploading a photo is entirely optional.

Session tokens

We issue short-lived JWT access tokens (15-minute expiry) and longer-lived refresh tokens (30 days, stored as a bcrypt hash on our server). These tokens keep you signed in without requiring your password on every request.

Team data

If you create or join a team we store the team name, member email addresses, and member roles. Team members can see watches that have been explicitly shared with the team — personal watches remain private.

Notification settings

If you configure email notifications, Slack, Discord, or generic webhook delivery, we store those endpoint URLs or preferences so we can send you alerts. We do not sell or share these addresses with third parties.

Usage analytics

The extension sends a small number of anonymised usage events to help us understand how the product is used and where users hit limits. The full list of events we record is:

  • sidepanel.opened — the extension panel was opened (no properties)
  • watch.created — a watch was created (monitor mode, account tier)
  • check.completed — a watch check ran (monitor mode, result, error type if any)
  • watch.create_blocked — a watch could not be created due to the plan limit (tier, limit)
  • upgrade.prompt_viewed — the upgrade screen was shown (context, trigger)

No page content, URLs, or personally identifying information is included in these events. Events are linked to your user ID if you are signed in, or recorded anonymously if you are not.

Billing information

Payments are processed by Stripe. We never see or store your credit card number, CVV, or full card details. We store only your Stripe customer ID and subscription status so we know which plan your account is on.

What we do not collect

  • Your browsing history or any pages you visit other than the ones you explicitly watch
  • Content from outside the specific element you selected on a watched page
  • Passwords in plain text
  • Payment card details (handled entirely by Stripe)
  • Data from other browser tabs or extensions
  • Advertising identifiers or third-party tracking data

Local storage (Free plan)

Free plan users who are not signed in store all watch data locally inchrome.storage.local on their own device. This data never leaves the browser. If you uninstall the extension or clear browser data, it is gone — we have no copy of it.

Data storage and security

Account and watch data for signed-in users is stored on a private server running PostgreSQL. Passwords are hashed with bcrypt before storage and never stored in recoverable form. All communication between the extension, the dashboard, and our server is encrypted over HTTPS.

Third-party services

We use Stripeto process subscription payments. Stripe's privacy policy governs any data you share with them during checkout. We do not use any advertising networks, data brokers, or third-party analytics platforms. The only analytics data collected is our own, as described above.

Your rights

You can request any of the following at any time by emailing us:

  • A full export of your data (watches, history, account details)
  • Deletion of your account and all associated data
  • Correction of inaccurate data

Signed-in users can also export their watch data directly from the extension (Settings → Export watches) without contacting us.

Data retention

We retain your data for as long as your account is active. If you delete your account we delete your personal data within 30 days. Anonymised analytics events do not contain personal data and are retained indefinitely for product improvement purposes.

Changes to this policy

If we make material changes to what we collect or how we use it, we will update the "Last updated" date at the top of this page and notify signed-in users by email.

Contact

Questions, data requests, or concerns — email us at support@coffeehauslabs.com