What happens when someone buys a watch, when one comes back, when one goes missing, and who touches the record at each point. Written for the people who will run it, not for the people who built it.
Start here
The idea in one minute
Every CZARD collection is recorded in chapters, and a chapter carries a full run of each reference in that collection — 500 apiece on the Compass, 100 apiece on Genève 1541. When every reference in a chapter has finished its run the next chapter begins, and a finished chapter is never reopened.
The whole system rests on four separate things that are easy to confuse for one another. Most mistakes in this domain are one of them being mistaken for another.
Layer
Example
What it is
Shown to the customer?
Collection
Genève 1541
Each collection runs its own chapter sequence, independently.
Yes
Chapter
Founding, A, B … Z, AA
A run of numbers per reference — 500 Compass, 100 Genève. Once every one is full, sealed for good.
Yes
Number
127 / 500
Where this watch sits in its reference’s order within that chapter.
Yes
Full serial
CZD-G1541-F-EC-0127
The only thing that identifies a watch without ambiguity.
On the certificate and the registry
The watch itself
internal id
The physical object that was assembled and sold.
Never
Why the long serial exists
The Compass and Genève 1541 each have their own chapters, so both can contain an “A-150”. A customer saying “I’ve got A-150” is fine. A system storing only “A-150” is not — that is two different watches with one identity. The full serial carries the collection, which is what makes it unique across the whole company.
The two rules that never bend
A number is used up when the parcel is handed to the courier. Not at checkout, not when it is packed. Before that moment a number can be freed up; after it, never.
A number that has been out in the world is never given to another watch. Lost, stolen, returned, destroyed — the record stays, and the number stays with it.
The life of one watch
Seven normal states, and one line that everything turns on.
Everything that can go wrong sits to the right of the line, which is why none of it ever frees a number up again. The system refuses the move rather than trusting anyone to remember.
The two codes, and why there are two
One is printed on the outside and anyone may use it. One is hidden inside the box and works exactly once. Confusing them is the difference between a registry and a giveaway.
A QR code can be photographed and copied, so it only ever opens a page anyone was allowed to see. Proving you actually hold the watch takes the concealed card — which is why it is separate, hidden, and dies the moment it is used.
Customer flows
CustomerShopifyWarehouseEnds with a number
Buying a watch, and getting a number
The most important thing here is what does not happen: nobody is promised a number at checkout.
The customer buys as normal. No number is mentioned, and none is set aside.
We record nothing yet. There is no chapter record for an order that has not been packed.
Payment and fraud checks clear. Shopify tags the order as ready to pack.
The warehouse starts packing. Shopify asks us for a number, and gets the lowest free one in the open chapter.
We record the number as reserved against that one order line, with the time and who asked.
The engraver takes a caseback and a coin, engraves the same identity on both, photographs them, and seals the pair in one pouch.
We record both engraved parts and the pouch they went into.
A different person checks the two engravings match, then the watch is boxed with its certificate and a sealed card carrying the claim code.
We record who checked it, the photographs, and that a claim code was issued. We keep only a scrambled copy of the code itself.
The parcel is handed to the courier and Shopify creates the shipment.
We record the number as permanently used. The watch becomes visible on the public registry for the first time.
The customer gets an email with their collection, chapter, number, full serial and a link to their record.
The question this always raises
“My friend ordered after me and got a lower number.” That is correct behaviour. Numbers follow the order things are shipped, not the order they were bought — a payment hold, an address correction or a dial being out of stock all move a parcel back in the queue. Check the dispatch times, not the order times.
AnyoneNo login
Checking a watch is real
Works for owners, for someone buying second-hand, and for a service centre. It never reveals who owns the watch.
They scan the QR on the coin, or type the serial from the certificate into the registry page.
They see the collection, the model, the chapter and number, the month it shipped, and its current status.
We record nothing about them. They never see a name, an address, an order number or a price — and the page source does not contain them either.
If the watch has been reported lost or stolen, the page says only: contact CZARD before any transaction involving this watch. It does not publish the incident.
If nothing matches, they get one message — the same one for a typo, a fake serial, and a real watch that has not shipped yet.
We record nothing. Different answers would tell a counterfeiter which serials are real and which are still to come.
OwnerUses up the card
Claiming your watch
Optional for the customer, and the only thing that creates an owner record.
The owner opens the claim page and enters the serial plus the code from the sealed card in the box.
They add an email or a phone number, so a future sale can be verified.
We record a private owner record. Nothing about it appears on the public page.
The code stops working the moment it is used. There is no way to reissue it to someone else.
Given as a gift, or bought second-hand? The card belongs to whoever received it first. The right route is a transfer, not the card.
SellerBuyerSupport (if needed)
Selling it on
The watch does not change. Only the relationship does.
The current owner starts a transfer and receives a one-time code to hand to the buyer.
We record the refusal, if there is one. A transfer is blocked while the watch is flagged lost or stolen, or has an open service case.
The buyer enters the code and their own contact details.
The old owner record is closed and a new one opens. The serial, the chapter and the number are untouched.
We record the new owner, and we kill the original claim card in case it is still in the box.
If the seller cannot get into their account, support handles it by hand: photographs of the watch, ID checked privately, proof of purchase where it exists, and a waiting period.
CustomerQCOperations
Sending one back
What happens next depends entirely on the physical condition, and nobody decides until QC has looked.
What came back
The number
The stock
The customer is told
Cancelled before engraving
Freed up
Normal stock
Standard cancellation
Cancelled after engraving, before shipping
Freed only once both engraved parts are back and a supervisor signs off
Parts quarantined
Standard cancellation, no number promised
Refused, still sealed
Stays with this watch
Can be sold again as new after inspection
Nothing published
Opened but unworn
Stays with this watch
Open-box, or new stock only under written policy
Refund per policy
Worn, or the claim code was used
Stays for good
Certified open-box, service stock or archive
Refund or repair per condition
Never
A worn or claimed watch is never renumbered and put back on the shelf as new. It keeps its number and its history, and if it is sold again the condition is stated up front.
The console has a checklist for this: tick what is true of the parcel in front of you and it gives you the row — the same row support reads to the customer, so the two can never disagree.
ServiceChapter custodian signs off
Warranty replacement
The customer keeps their place in the chapter. Which of two routes applies is decided by a physical fact, not by what is nicer to say.
If the original engraved parts come back to us and are destroyed under witness, the replacement carries the exact same serial.
We record the destruction, the technical report and who approved it.
If they cannot be recovered, the replacement is engraved 127 / 500 · R1 and the original is blocked.
We record the link between the two. The registry shows that an authorised replacement exists.
Why the suffix
It is not a black mark. It is the proof that CZARD refuses to have two watches walking around presented as the same untouched original.
SupportOperationsBlocks the number
Lost in delivery, or reported stolen
A carrier investigation opens and the number is flagged straight away. It does not go back into stock while the outcome is unknown.
Once loss is confirmed, the number is blocked permanently and a replacement is issued under the warranty rules above.
We record a critical problem against whoever asks, if anyone later tries to reuse it. The system refuses the move.
If the original later turns up, it goes to authentication — never quietly back onto the shelf.
For as long as it is flagged, nobody can transfer it to a new owner without a person reviewing it.
Warehouse flows
Warehouse leadEngraverSecond checker
Engraving the day’s batch
We deliberately do not engrave a reference's whole 500 up front. Doing so creates a mountain of parts to reconcile and makes every mistake expensive.
The warehouse lead releases the next 25 numbers into the engraving queue and prints the pouch labels.
We record which numbers went out. On the label: the serial, the chapter, the number and a checklist. Nothing about the customer.
The engraver puts the same identity on the caseback and the coin, and photographs both at a fixed station.
A second person checks the text, the sequence, the collection, the orientation and the finish.
The matched pair goes into one sealed pouch, marked ready.
Working ahead
25 sets during launch week. You may go to 50, but only after two days in a row where the end-of-day count matched exactly. The console will refuse a bigger batch until then.
PackerQC
Packing an order
The watch is not tied to a number until this moment — which is why a dial being out of stock never holds up the next number in line.
The packer scans the order, and the system reserves the lowest ready number for it.
They scan the watch, the pouch, the coin and the certificate.
We record every scan. The system blocks completion unless all four carry the same identity.
The caseback is fitted and any water-resistance check is done.
QC does the final look, the serial match, and the photograph of the whole set.
The box is sealed with the claim card inside. The shipping label stays locked until QC has passed it.
Hard stop
A coin and caseback that disagree is not a note to pass along. It stops the order, the pair is red-tagged, and everything engraved on that shift gets checked.
Dispatch supervisorThe number is spent here
Handing it to the courier
The supervisor scans the sealed parcel against the courier manifest.
Shopify creates the shipment with tracking.
The number becomes permanently used, and the public record goes live at that instant.
We record the handover. A watch still in the building has no public record at all, so the registry can never be used to see tomorrow’s numbers.
The customer’s email goes out with the chapter, the number and the registry link.
At end of day, check that no packed parcel is missing a shipment and no shipment is missing a number.
WarehouseQCSupervisor signs off
A parcel comes back
Scan the parcel before opening it, and film the opening for anything high-value.
Scan the caseback, the coin, the certificate and the watch.
Check the registry for the claim status, any service history, and any lost or stolen flag.
Classify it: sealed and perfect, opened but unworn, worn or claimed, damaged, mismatched, or suspected fake.
We record the classification, once it is made. Do not change the status or decide how it will be resold until QC is finished.
Putting it back into stock needs a supervisor, and the number stays with this watch.
Warehouse leadOperations
Counting up at the end of the day
Six things that should all match. The target for every gap is zero.
What we say
What it should equal
Where the other figure comes from
Numbers used up today
Orders Shopify shipped today
Shopify
Numbers used up today
Watches Zoho sent out
Zoho Inventory
Boxes we think are packed
Sealed boxes on the shelf
Counted by hand
Engraved pouches we think we have
Pouches in the tray
Counted by hand
Free numbers left
This reference’s 500 minus everything spoken for
Us
Watches on the public registry
Watches that have shipped
Us
Two things that matter more than the count itself
Leave one of the outside figures blank and that line says waiting, not passed. A page of green ticks that only ever compared the system to itself is worse than no page at all.
If a figure is wrong, fix the thing causing it. Never adjust the number to make the page look right.
Office flows
Support
Answering customers
Six questions cover almost everything. The answers live in the console so nobody has to invent one under pressure.
They ask
You say
Can I have number 001?
Numbers are given out in shipping order. We do not reserve or sell preferred numbers, so everyone enters the chapter under the same rule.
My friend ordered later and got a lower number.
Check the shipping times, not the order times. If the sequence really is wrong, raise it as a problem — never renumber a watch that has shipped.
My coin and my watch don’t match.
Ask them not to post it yet. Get photographs, block both records, arrange an insured collection, and check everything engraved on that shift.
My watch was lost in delivery.
The number is blocked and a traceable replacement is issued. The original is never given to another watch, even if it never turns up.
I sold my watch — how does the buyer claim it?
Start a transfer. The public record does not change at all; only the private owner record does.
Will this number go up in value?
CZARD does not promise or predict resale value. The chapter records when the watch entered its collection’s history; the market decides the rest.
Anyone who spots itNamed owner per type
Reporting a problem
Problems are reported by type, not described in your own words — otherwise the same thing gets called ten different names within a week and nothing can be counted.
Pick the type from the list, name the watch if it is about one, and say what happened.
The console shows the immediate action for that type and who owns it.
A critical one stops the line. Duplicate serials, a coin and caseback that disagree, a watch shipped with no number, an attempt to reuse a lost number, a customer reporting a duplicate, or personal data appearing on the public page.
Closing it needs a written note.
We record what was actually done. At end of day, read the closed ones too, not just the open ones.
OperationsUses real numbers
Practising before launch
Run each scenario from the console: everything goes right, cancelled before engraving, coin and caseback disagree, came back unopened, lost by the courier.
Each run drives a real order through the real system.
We record all of it, exactly as if it were a customer order. A practice run against a pretend system only tells you the pretend system works.
Do not open sales until twenty in a row finish with nothing unexplained.
Everyone
Launch morning
Before you open. Check the five safety conditions on the control room screen. If any one has failed, do not open sales.
Confirm 25 matched sets are ready and that the physical count agrees with the screen.
Push one live zero-value order all the way through, then cancel it.
First four hours. Count up every thirty minutes. Stop shipping the moment a duplicate, a mismatch or a missing record appears.
Keep what the customer is told conservative: the chapter is open, and that is all.
End of day. Export the snapshots, count what is left, review every problem including the closed ones, and publish nothing celebratory until the figures agree.
Behind the scenes
How Shopify talks to us
Two moments, and only two. Shopify never invents a number, and we never invent an order.
Shopify’s shipment trigger can fire more than once for a split delivery, so the second message is written to be harmless on a repeat — it returns the same answer instead of spending another number.
If the first exchange fails
The order is tagged as a problem and its shipment is held. Nobody dispatches by hand and nobody writes a number in a note — a watch out of the door with no record is one of the six things that stop the line.
When a chapter fills up
The sequence runs Founding, then A to Z, then AA, AB and onward. Letters are never skipped because a particular one sounds better.
On the shop
The product page shows the open chapter and the highest number that has actually been shipped — never a live counter of what has been reserved. A reservation is not a shipment, and the two drift apart the moment somebody cancels.
Who can do what
The console shows fewer buttons to some people, but that is only a courtesy — the refusal happens on the server, so pointing a different tool at it changes nothing.
Role
Can
Cannot
Chapter custodian
Open and seal chapters, approve replacements, override with a reason, see owner details
Release the engraving batch — that is the warehouse’s call
Warehouse lead
Release the engraving batch, move watches along, count up
See owner or order details
Engraver
Move a watch to engraved
Pass its own work — a second person has to
QC
Pass, fail and classify returns
Sign off work they did themselves
Dispatch supervisor
Hand to the courier, pull a parcel back before it leaves
Do anything after it has left
Service manager
Authorise replacements, record service
Approve their own replacement — the custodian does
Support
Look up any watch, help with a transfer
See the owner’s name, contact details or order — the answer is about the watch
Legal / privacy
Read everything, check the history is unedited
Change anything
Shopify (the machine)
Ask for a number, report a shipment
Read anything at all
Public and private
Two separate sets of data with separate permissions. The public side describes an object; the private side describes a relationship, and relationships change.
Anyone can see
The full serial · the collection, model and variant · the chapter and number · the month it shipped · its current status · whether an authorised replacement exists · a summary of any authorised service.
Nobody outside CZARD ever sees
The owner’s name, phone, email or address · the order number or what was paid · payment details · support conversations · who owned it before · the claim code.
Two details are deliberate rather than incidental. The shipping date is published as a month, never a day — the month gives provenance, the day gives a stranger a way to profile a customer. And the public record is built by naming the handful of fields that go on it, not by hiding the rest, so a field added to the system next year is private unless somebody decides otherwise.
Tags, and what they are not
The owners’ register carries tags. They sit next to the Chapter System without being part of it, and the difference is worth being clear about — one is a record, the other is a description.
Kind
Example
What it says
Chapter
Founder
This owner holds a piece from that chapter
Serial
№1, Mirror, Milestone
Something about the number itself — it is one, it reads the same both ways
Set
Genève 1541 complete
This owner holds every reference in that line at once
What a tag is not
A tag is not a score, a rank or a level. Nothing adds them up, nothing sorts by them, and there is no “more” of one. The register is alphabetical and stays that way.
A tag is also not a promise about value. It says a watch is number one in its chapter; it says nothing about what number one is worth, and CZARD does not predict that.
Tags follow the watch, not the person. Sell a piece and its serial tag goes with it — the tag describes the object, so it would be odd for it to stay behind. A chapter or set tag can therefore disappear from a seller’s row after a sale, which is correct: they no longer hold the thing it described.
Where they come from
Chapter tags are the badgeName on a chapter. Serial tags are patterns in the CMS, matched against the numeral in priority order, and editable — which means changing one silently relabels watches people already own. Set tags are computed, not stored.
The console is a client of the same interface everything else uses. Anything it can do can be done with the same key from a scanner, a script or a spreadsheet — and anything it cannot do, it cannot do by showing a different button.