SmartGate

Privacy Policy

How SmartGate collects, uses, stores, and protects your information when you use smartgate.network, MCP tools, dashboards, billing, and team features — including retention and your rights.


Effective date: June 5, 2026 · Last updated: July 9, 2026

This Privacy Policy explains how SmartGate ("we", "us", "our") collects and uses information when you use smartgate.network and related services.

Contact: support@smartgate.network

1. Data controller

The data controller for personal data described here is SmartGate.

2. Information we collect

Account information

When you register or sign in, we may collect:

  • Email address and display name
  • Authentication metadata (e.g., OAuth provider, sign-in timestamps)
  • Team and membership relationships

Sign-in methods include email magic link (via Resend) and Google OAuth.

Usage and service data

When you use SmartGate tools or the Dashboard, we may collect:

  • Request timestamps, tool names, and routing metadata
  • Approximate token counts and estimated cost savings (for analytics and ROI reporting)
  • Optional audit fields such as correlation IDs, agent platform, and route (mcp, rest, playground)
  • For fetch-related tools, the requested URL may be stored as a task source for audit and reporting

Billing data

Paid subscriptions are processed by Paddle (Merchant of Record). Paddle collects payment and billing details according to its own privacy policy. We receive subscription status, plan identifiers, and limited billing metadata needed to provision your account — not full payment card numbers.

API keys

We do not store raw API keys. We store only a hashed representation for authentication.

Cookies and similar technologies

We use cookies and local storage for session management, authentication, and preferences. See Section 8.

3. How we use information

We use information to:

  • Provide, maintain, and secure the service
  • Authenticate users and enforce team isolation
  • Operate billing and subscription features
  • Compute usage analytics and estimated savings
  • Debug reliability issues and prevent abuse
  • Communicate service updates and respond to support requests

Where GDPR applies, we rely on:

  • Contract — to provide the service you signed up for
  • Legitimate interests — security, fraud prevention, product improvement, and aggregated analytics
  • Consent — where required (e.g., non-essential cookies if enabled in the future)
  • Legal obligation — where we must retain or disclose data by law

5. Sub-processors

We use trusted providers to operate SmartGate:

ProviderPurposeLocation
Paddle.com Market LtdSubscription billing (Merchant of Record)Per Paddle policies
Google LLCOAuth sign-inPer Google policies
ResendTransactional email (magic links)Per Resend policies
UpstashRate limiting and session cachePer Upstash policies
Cloud hosting providerApplication and database hostingSee Section 9

We require appropriate safeguards where providers process personal data on our behalf.

6. Data retention

Retention depends on your plan and operational needs:

PlanActivity log retention (typical)
Free7 days
Pro30 days
Teams90 days
Enterprise180 days

Account data is retained while your account is active. You may request account deletion by contacting us; we will delete or anonymize personal data subject to legal and billing retention requirements.

7. Your rights

Depending on your location, you may have the right to:

  • Access, correct, or delete your personal data
  • Export your data in a portable format
  • Object to or restrict certain processing
  • Withdraw consent where processing is consent-based
  • Lodge a complaint with a supervisory authority (EEA/UK)

California (CCPA/CPRA): You may request disclosure of categories collected and deletion of personal information, subject to exceptions. We do not sell personal information as defined by the CCPA.

To exercise rights, email support@smartgate.network. We may verify your identity before responding.

8. Cookies

We use:

  • Essential cookies — authentication sessions and security
  • Preference cookies — locale and UI settings where applicable

We do not use third-party advertising cookies on the core product. If we add analytics or marketing cookies in the future, we will update this policy and, where required, obtain consent.

You can control cookies through your browser settings; disabling essential cookies may prevent sign-in.

9. International transfers and storage

Your data may be processed in countries where we or our sub-processors operate. Application and database hosting may occur in regions selected for our cloud infrastructure (e.g., United States or European Union data centers, depending on deployment). We use appropriate safeguards for cross-border transfers where required by law.

We do not use your VPS or server IP address as our legal contact address. Operational hosting locations are separate from our registered business contact.

10. Security

We implement measures including HTTPS encryption in transit, hashed API keys, team-scoped access controls, and rate limiting. No method of transmission or storage is 100% secure; please protect your credentials.

11. Children

SmartGate is not directed to children under 16 (or 13 in the US). We do not knowingly collect personal data from children. Contact us if you believe we have collected such data.

12. Changes

We may update this Privacy Policy. We will post the revised policy with a new effective date and notify you of material changes when appropriate.

13. Contact

SmartGate
Email: support@smartgate.network

See also our Terms of Service.