Back to Gate97

Privacy Policy

Last updated: July 26, 2026. This is a template starting point — have it reviewed by a lawyer before relying on it.

This policy describes what data Gate97 ("we", "us") collects, why, and how it's handled, reflecting how the Service actually works.

1. What we collect

  • Account data: your email address, a salted hash of your password (never the password itself), your name if provided, and your organization name.
  • Connected-app credentials: OAuth tokens or API keys for third-party services you connect (e.g., Google Sheets, Slack, Stripe). These are encrypted at rest (AES-256-GCM) and only decrypted in memory when needed to run your workflows.
  • Workflow configuration and run history: the steps you build, the field mappings between them, and a log of each run (status, timing, and the data that passed through each step) so you can debug and audit your automations.
  • Billing data: handled by our payment processor, PayPal. We store your PayPal subscription ID and plan status, not your card or PayPal account details.
  • Technical data: standard request logs (IP address, timestamps) for security and rate-limiting purposes, and error reports (via Sentry, if configured) which may include stack traces.

2. How we use it

Solely to provide the Service: authenticating you, executing the workflows you configure against the third-party accounts you connect, enforcing your plan's usage limits, sending you account and billing-related notifications (e.g., approaching a usage limit, or a connection needing reauthorization), and diagnosing errors.

3. Third parties we share data with

We only share data with services necessary to operate Gate97:

  • The third-party apps you connect (e.g., Slack, Google, Stripe) — only the data your workflows are configured to send them, only when a workflow runs.
  • PayPal , for billing our own subscription plans.
  • Our email delivery provider , to send transactional notifications (threshold warnings, reauthorization alerts).
  • Sentry (if configured), for error monitoring.

We do not sell your data.

4. Cookies and sessions

We use a single, strictly necessary session cookie to keep you logged in. With your consent — asked for via the cookie banner, never assumed — we also use Google Analytics to understand aggregate site usage; it is not loaded until you accept it, and you can withdraw that consent at any time. See our Cookie Policy for the full list of cookies and their durations.

5. Data retention

We retain your data for as long as your account is active. If you delete your account or organization, we delete your data (including connected credentials and run history) within a reasonable period, except where retention is required for legal or billing-record purposes.

6. Your rights

You can access, export, or request deletion of your data at any time by contacting us, or by deleting connections/workflows directly from the dashboard.

7. Security

Connected-app credentials are encrypted at rest. Access to your organization's data is enforced at the database level (row-level security), and all traffic is served over HTTPS in production.

8. Changes to this policy

We may update this policy from time to time. We will post the updated policy with a new "Last updated" date.

9. Contact

Questions about this policy can be sent to the contact address listed on our website.