Privacy policy
Version 2026-09-27 · How GateClash ("we") collects, uses and protects personal data, following Singapore's Personal Data Protection Act 2012 (PDPA).
1. Contact and Data Protection Officer
Our Data Protection Officer can be reached at privacy@gateclash.com or by post at Singapore.
2. What we collect
- Account details: name, work email, password (stored only as a secure one-way scramble), two-step sign-in settings, language.
- Company details: company name, industry, team members and their roles, billing name, UEN, address and billing email.
- What you ask us to check: website addresses, ownership proof, check results, issue history and comments, readiness quiz answers, and your company logo if you add one.
- Phone app files you upload. They are only used during the check and are deleted as soon as the check ends; only the results are kept.
- Test sign-in accounts for behind-the-login checks. The password is stored encrypted and used only to run your checks.
- Payments: invoices, amounts, and a label such as "Visa ending 4242". Card numbers are handled by our payment provider; we never see or store them.
- Security records: sign-in times, IP addresses, browser type and an activity log of important actions, used to keep accounts safe and to investigate misuse.
Check results can sometimes include personal data that happens to be visible on your website (for example a file that is exposed by mistake). We store only a short description of what we found, never a copy of such files.
3. Why we use it
To run the service you signed up for (checks, reports, alerts, team access and billing), to keep GateClash and your account secure, to prevent misuse such as checking systems without permission, to send service emails you need (sign-in links, results, receipts, renewal reminders), to meet legal and tax duties, and to improve GateClash using summarised figures that don't identify anyone. We do not sell personal data and do not use it for advertising. We send marketing emails only if you ask for them, and you can stop them at any time.
4. Who we share it with
- Service providers who help us run GateClash, under contracts that require them to protect the data: our hosting provider, our email delivery provider and our payment provider.
- Services used during checks. To check your website we send its domain name (not your personal details) to public security services: Spamhaus and Google Safe Browsing (blacklists), domain registry lookup services (expiry dates) and, if switched on for your plan, Have I Been Pwned (email addresses on your domain found in data leaks).
- People you choose: team members you invite, and anyone you send a share-report link to.
- Authorities or others where the law requires it, or where needed to stop GateClash being used to check systems without permission.
5. Data stored outside Singapore
Some providers may store or process data outside Singapore. When that happens we make sure the data is protected to a standard comparable to the PDPA, as the PDPA's transfer rules require.
6. How long we keep it
- Check history: as long as your plan includes (from 1 month on Free to 2 years on Business), and at least 12 months after you move to a smaller plan.
- Uploaded phone app files: deleted when the check ends (and in any case within one day).
- Invoices and payment records: 5 years, as Singapore tax rules require.
- Security and activity records: kept while your company uses GateClash, so you have a full history of who did what.
- When you delete your account or company, it is removed after a 14-day grace period (so you can change your mind), except for records we must keep by law.
7. How we protect it
Encrypted connections (HTTPS), one-way scrambled passwords, optional and enforceable two-step sign-in, encrypted storage of test sign-in passwords, strict separation between companies, limits on sign-in attempts, and an activity log. Access by GateClash staff is limited to support and security needs and is itself logged.
8. Your choices and rights
You can see and correct most of your data yourself in My account and Company settings, download your company's data, and delete your account. You may also ask us for access to or correction of your personal data, or withdraw consent for a purpose, by emailing our Data Protection Officer. We'll reply within 30 days. Withdrawing consent may mean we can no longer provide some or all of GateClash.
9. Cookies
GateClash uses only cookies it needs to work: keeping you signed in, protecting forms against forgery, showing one-time messages, remembering your chosen colour theme, and remembering a plan you picked before signing up. There are no advertising or tracking cookies.
10. If something goes wrong
If we have a data breach that is likely to cause significant harm, or that affects a large number of people, we will notify the Personal Data Protection Commission and the people affected as the PDPA requires.
11. Changes
If we change this policy we'll update the version above and ask you to accept it the next time you sign in; important changes will also be emailed.