This Privacy Policy explains how DotClock processes personal data when you visit dotclock.it, buy or use a DotClock, create an account, join the waitlist, contact us, use the public roadmap, publish community content, or enable cloud/device features.
For GDPR purposes, the data controller is Andrea Teofilo, operating as DotClock. You can contact the controller at privacy [at] dotclock [dot] it .
Data We Collect
- Account data — name, email address, password hash, role/admin flags, profile/avatar display values, assigned devices, verification and password-reset tokens, login/session metadata, and smart-home account-linking tokens where you connect DotClock to Amazon Alexa or Google Home.
- Order and checkout data — cart contents, products, invoice details, billing and shipping addresses, phone number where needed for delivery, order status, payment status, refund/return information, and shipment/tracking information.
- Payment data — payment identifiers, status, amounts, currency, and fraud/payment confirmation data from payment providers. We do not store full card numbers or card security codes.
- Waitlist and restock data — email address, signup source, browser language, IP address, user agent, and signup time.
- Support and warranty data — messages you send us, order numbers, photos/videos you choose to provide for support, return labels, repair notes, and related correspondence.
- Public/community content — roadmap votes, product reviews, gallery/watchface submissions, author/display name, likes, replies, and moderation actions.
- Device data — device MAC address or similar device identifier, hostname, firmware/build version, hardware model, local IP reported by the device, online/offline status, configuration, selected language/time zone, brightness/display settings, enabled cloud features, custom messages, color themes, and stock ticker preferences.
- Smart-home integration data — device names, device identifiers, supported traits/capabilities, on/off or brightness state, command requests, command results, account-linking status, and the minimum data needed to let Amazon Alexa or Google Home discover and control your DotClock.
- Location-related device data — latitude/longitude used for weather, sunrise/sunset, weather alerts, and local information. When supported, the device may send nearby WiFi access point data so our server can estimate location through a geolocation provider; we cache the resulting location so the clock does not need to repeat the lookup every time.
- Sensor and diagnostic data — ambient temperature, humidity, light, air-quality readings, optional bitmap/display diagnostics if enabled, crash/panic/coredump data, logs, and timestamps.
- Technical website data — IP address, user agent, URL, timestamp, security/rate-limit events, and client-side error reports posted to our own error log endpoint.
How We Use Data
- To provide the website, accounts, login sessions, admin tools, carts, wishlists, invoices, and order history.
- To process purchases, payments, fraud checks, refunds, shipping, returns, warranties, and customer support.
- To send transactional emails such as account, waitlist, order, invoice, support, and device-related messages.
- To provide optional DotClock cloud features: weather, forecasts, weather alerts, news, stock data, public holidays, earthquake notices, device state sync, remote configuration, sensor history, custom messages, and display previews.
- To provide optional Amazon Alexa and Google Home integrations, including account linking, device discovery, command handling, state reporting, and unlinking.
- To estimate the clock's location when needed for weather and alerts, including by using nearby WiFi access point data where the feature is enabled.
- To publish and moderate reviews, roadmap votes, gallery/watchface content, and other community features.
- To secure the site and services, prevent abuse, rate-limit requests, debug errors, maintain backups, and comply with legal/tax obligations.
Legal Bases
Under the GDPR, we rely on these legal bases:
- Contract — to create and manage accounts, sell products, process orders, provide device/cloud features you request, and provide support or warranty service.
- Legal obligation — to keep invoices, accounting records, tax records, and records needed for consumer-law compliance.
- Legitimate interests — to secure and improve the website and device service, prevent fraud and abuse, maintain logs, run the roadmap, handle non-marketing communications, and understand product demand.
- Consent — for optional marketing/waitlist messages, optional community publishing, and any optional cookies or integrations that require consent. You can withdraw consent at any time.
Device Cloud Features
DotClock can work on your local network through its built-in web interface. Some features use DotClock servers, MQTT/WebSocket transport, and external data sources so the device can receive weather, alerts, news, stock data, updates, and configuration changes.
Device messages are addressed by the device identifier, such as its MAC address. Accounts may be linked to assigned devices so only authorised users can see or control their own device data. Administrators may access device data when needed for support, security, or maintenance.
If you enable diagnostic bitmap sending, sensor history, crash reporting, or similar troubleshooting features, the device may send additional technical data to DotClock servers. You should not put sensitive personal information in custom messages, hostnames, gallery content, or display diagnostics.
Amazon Alexa And Google Home
If you choose to connect DotClock to Amazon Alexa or Google Home, those platforms may send DotClock account-linking tokens, device discovery requests, device-control commands, and state-reporting requests. We use that information only to link your DotClock account, identify the DotClock devices assigned to you, send commands to those devices, and report their current state back to the platform.
DotClock does not receive or store your Alexa or Google Assistant voice recordings. Voice recognition, transcripts, and assistant account data are handled by Amazon or Google under their own privacy terms. DotClock receives only the integration messages needed to perform the requested smart-home action, such as turning the display on or off, changing brightness, or reading device state.
You can disconnect the integration from the Alexa app, Google Home app, or DotClock account controls where available. After unlinking, DotClock stops accepting new commands from that platform, although we may retain limited logs or account-linking records for security, debugging, fraud prevention, or legal compliance as described in this policy.
Firmware And Web Serial
Firmware downloads and the browser-based flashing flow may use your browser's Web Serial capability to talk directly to a connected device. Serial access requires your explicit browser permission. We use it to install firmware or read/write device setup information needed for that action; your browser and operating system control the permission prompt.
Cookies And Local Storage
We use cookies and browser storage for login sessions, language preference, storefront unlocks, carts, wishlist UI, roadmap voting, and remembering choices such as cookie consent. Our current cookie policy explains the main cookies in more detail: Cookie Policy.
We do not sell advertising profiles. Where third-party payment, security, or anti-abuse tools set their own cookies or identifiers, their own policies also apply.
Processors And Third Parties
We share personal data only where needed to run DotClock:
- Hosting and infrastructure providers for website, database, server, logs, backups, and network security.
- Payment providers such as Stripe and PayPal for checkout, fraud prevention, payment processing, refunds, and disputes.
- Shipping and fulfilment providers for delivery, tracking, returns, and customs paperwork where applicable.
- Email providers for transactional, waitlist, support, and notification email.
- Security and anti-abuse providers, including Cloudflare Turnstile where enabled, to protect forms and accounts from spam or abuse.
- Smart-home platforms, including Amazon Alexa and Google Home, when you choose to link DotClock to those services.
- Location and content providers, including weather, geolocation, mapping/reverse-geocoding, news, stock, earthquake, and public alert sources, to deliver optional device features.
We do not sell your personal data. We do not allow third parties to use DotClock customer or device data for their own advertising.
International Transfers
Some providers may process data outside the European Economic Area. When that happens, we rely on appropriate safeguards such as adequacy decisions, Standard Contractual Clauses, provider data-processing terms, and technical measures such as encryption in transit where appropriate.
Retention
- Account data is kept while your account is active, then deleted or anonymised unless we need it for legal, security, or dispute reasons.
- Order, invoice, tax, and payment records are kept for the period required by accounting, tax, consumer, and legal obligations.
- Waitlist and marketing data is kept until you unsubscribe or ask us to delete it, subject to suppression records needed to honour opt-outs.
- Support and warranty records are kept as long as needed to resolve the issue and meet warranty/legal obligations.
- Device configuration, assignment, and smart-home linking data is kept while the device uses DotClock cloud services or remains linked to an account or smart-home platform.
- Sensor history, diagnostics, crash reports, and technical logs are kept only as long as useful for the feature, support, reliability, security, or abuse prevention, then deleted or aggregated where practical.
- Roadmap votes and public/community content remain until removed, anonymised, or no longer needed for the feature.
Security
We use technical and organisational measures appropriate to the risk, including HTTPS, hashed passwords, HttpOnly session cookies where applicable, role-based access controls, rate limiting, database indexes and access controls, server-side validation, and limited administrative access. No internet service is perfectly secure, but we work to keep the amount of data small and access tightly scoped.
Your GDPR Rights
If you are in the EU, EEA, UK, or another region with similar rights, you can ask us to:
- access a copy of your personal data;
- correct inaccurate or incomplete data;
- delete data where the law allows;
- restrict or object to certain processing;
- receive portable data you provided to us;
- withdraw consent for processing based on consent;
- object to direct marketing at any time.
To exercise your rights, email privacy [at] dotclock [dot] it . We may need to verify your identity before acting. We normally respond within one month, unless the request is complex or we are legally allowed more time.
You also have the right to complain to your local data protection authority. If you are in Italy, that is the Garante per la protezione dei dati personali.
Children
DotClock is not directed to children and we do not knowingly collect personal data from children. If you believe a child has provided us personal data, contact us and we will take appropriate action.
Changes
We may update this policy when the product, website, providers, or legal requirements change. The date at the top shows when it was last updated.
Contact
Privacy requests: privacy [at] dotclock [dot] it
General support: support [at] dotclock [dot] it