Privacy Policy
How SmartGate collects, uses, stores, and protects your information when you use smartgate.network, MCP tools, dashboards, billing, and team features — including retention and your rights.
Effective date: June 5, 2026 · Last updated: July 9, 2026
This Privacy Policy explains how SmartGate ("we", "us", "our") collects and uses information when you use smartgate.network and related services.
Contact: support@smartgate.network
1. Data controller
The data controller for personal data described here is SmartGate.
2. Information we collect
Account information
When you register or sign in, we may collect:
- Email address and display name
- Authentication metadata (e.g., OAuth provider, sign-in timestamps)
- Team and membership relationships
Sign-in methods include email magic link (via Resend) and Google OAuth.
Usage and service data
When you use SmartGate tools or the Dashboard, we may collect:
- Request timestamps, tool names, and routing metadata
- Approximate token counts and estimated cost savings (for analytics and ROI reporting)
- Optional audit fields such as correlation IDs, agent platform, and route (
mcp,rest,playground) - For fetch-related tools, the requested URL may be stored as a task source for audit and reporting
Billing data
Paid subscriptions are processed by Paddle (Merchant of Record). Paddle collects payment and billing details according to its own privacy policy. We receive subscription status, plan identifiers, and limited billing metadata needed to provision your account — not full payment card numbers.
API keys
We do not store raw API keys. We store only a hashed representation for authentication.
Cookies and similar technologies
We use cookies and local storage for session management, authentication, and preferences. See Section 8.
3. How we use information
We use information to:
- Provide, maintain, and secure the service
- Authenticate users and enforce team isolation
- Operate billing and subscription features
- Compute usage analytics and estimated savings
- Debug reliability issues and prevent abuse
- Communicate service updates and respond to support requests
4. Legal bases (EEA/UK users)
Where GDPR applies, we rely on:
- Contract — to provide the service you signed up for
- Legitimate interests — security, fraud prevention, product improvement, and aggregated analytics
- Consent — where required (e.g., non-essential cookies if enabled in the future)
- Legal obligation — where we must retain or disclose data by law
5. Sub-processors
We use trusted providers to operate SmartGate:
| Provider | Purpose | Location |
|---|---|---|
| Paddle.com Market Ltd | Subscription billing (Merchant of Record) | Per Paddle policies |
| Google LLC | OAuth sign-in | Per Google policies |
| Resend | Transactional email (magic links) | Per Resend policies |
| Upstash | Rate limiting and session cache | Per Upstash policies |
| Cloud hosting provider | Application and database hosting | See Section 9 |
We require appropriate safeguards where providers process personal data on our behalf.
6. Data retention
Retention depends on your plan and operational needs:
| Plan | Activity log retention (typical) |
|---|---|
| Free | 7 days |
| Pro | 30 days |
| Teams | 90 days |
| Enterprise | 180 days |
Account data is retained while your account is active. You may request account deletion by contacting us; we will delete or anonymize personal data subject to legal and billing retention requirements.
7. Your rights
Depending on your location, you may have the right to:
- Access, correct, or delete your personal data
- Export your data in a portable format
- Object to or restrict certain processing
- Withdraw consent where processing is consent-based
- Lodge a complaint with a supervisory authority (EEA/UK)
California (CCPA/CPRA): You may request disclosure of categories collected and deletion of personal information, subject to exceptions. We do not sell personal information as defined by the CCPA.
To exercise rights, email support@smartgate.network. We may verify your identity before responding.
8. Cookies
We use:
- Essential cookies — authentication sessions and security
- Preference cookies — locale and UI settings where applicable
We do not use third-party advertising cookies on the core product. If we add analytics or marketing cookies in the future, we will update this policy and, where required, obtain consent.
You can control cookies through your browser settings; disabling essential cookies may prevent sign-in.
9. International transfers and storage
Your data may be processed in countries where we or our sub-processors operate. Application and database hosting may occur in regions selected for our cloud infrastructure (e.g., United States or European Union data centers, depending on deployment). We use appropriate safeguards for cross-border transfers where required by law.
We do not use your VPS or server IP address as our legal contact address. Operational hosting locations are separate from our registered business contact.
10. Security
We implement measures including HTTPS encryption in transit, hashed API keys, team-scoped access controls, and rate limiting. No method of transmission or storage is 100% secure; please protect your credentials.
11. Children
SmartGate is not directed to children under 16 (or 13 in the US). We do not knowingly collect personal data from children. Contact us if you believe we have collected such data.
12. Changes
We may update this Privacy Policy. We will post the revised policy with a new effective date and notify you of material changes when appropriate.
13. Contact
SmartGate
Email: support@smartgate.network
See also our Terms of Service.