GateList

GateList Privacy Policy

Policy version: 2026-06-20

Service: GateList

Website: https://gatelist.ru

Mobile application: GateList

Integrations: GateList mobile application

1. General Information

This Privacy Policy explains how personal data is collected, used, stored and protected when using GateList.

GateList is a service for organizations that helps manage vehicle lists, guest lists, passes, entry and exit logs, arrival and departure events, organization users and service notifications.

The personal data operator is an individual: Менякин Дмитрий Николаевич.

Privacy contact email: privacy@gatelist.ru.

The operator does not publish passport details or other excessive personal information on the website. Privacy-related communication is handled through the email address listed above.

2. Products Covered by This Policy

This Privacy Policy applies to:

  • the website https://gatelist.ru;
  • the GateList web account;
  • the GateList API;
  • the GateList mobile application for iOS;
  • public registration, login and support pages of GateList.

3. Roles of GateList and Organizations

For data provided by a user during organization registration, account creation, authentication and use of the service, the personal data operator is Менякин Дмитрий Николаевич.

For guest data, vehicle data, pass data, comments and log entries entered into GateList by an organization, the organization independently determines the purposes and legal grounds for processing such data.

GateList provides a technical service for storing and processing such data within the product functionality, but it is not an independent legal basis for processing third-party data entered by an organization.

The organization is responsible for ensuring that it has a lawful basis for entering and processing such data, including obtaining consents, notifying data subjects or relying on another lawful basis under applicable law.

4. Data GateList May Process

4.1. Organization Administrator Data

  • name;
  • phone number;
  • email address;
  • organization name;
  • organization identifier;
  • password stored as a secure hash;
  • user role and status;
  • registration date and last login date;
  • IP address, User-Agent, session data and cookies;
  • technical activity logs;
  • records of accepted consents and confirmations during registration.

4.2. Organization User Data

  • name;
  • phone number;
  • email address, if used;
  • user role and status;
  • account creation date and last login date;
  • technical activity logs.

4.3. Guest, Vehicle, Pass and Log Data

  • guest name;
  • vehicle plate number;
  • vehicle model;
  • comment or note;
  • pass type: permanent or temporary;
  • temporary pass validity period;
  • log events: entry, exit, arrival, departure;
  • information about who added, changed or deleted a record;
  • information about notification recipients within the organization.

4.4. Technical Data

  • IP address;
  • request date and time;
  • browser, device and operating system information;
  • cookies and session identifiers;
  • selected interface language;
  • error logs and security logs;
  • technical data required to protect the service from unauthorized access.

5. Data the Mobile Application May Process

The GateList mobile application may process data required for authentication and service functionality:

  • phone number;
  • password or one-time authentication code;
  • access and refresh tokens;
  • organization information;
  • user profile and role;
  • local cache of vehicle, guest, pass and log data;
  • technical API request data;
  • diagnostics and error data, if such diagnostics are used.

The GateList mobile application is not intended to collect:

  • precise location;
  • device contacts;
  • photos or videos from the gallery;
  • camera data;
  • microphone data;
  • health data;
  • payment data;
  • bank card data;
  • advertising identifiers for tracking;
  • data for advertising profiling.

If the application functionality changes in the future, this Privacy Policy must be updated before publishing the updated application.

6. Purposes of Processing

  • registering an organization in GateList;
  • creating an administrator account;
  • authenticating the user;
  • providing access to the web account, API, mobile application ;
  • restoring access;
  • sending service notifications;
  • managing organization users;
  • maintaining vehicle, guest and pass lists;
  • maintaining event logs;
  • managing temporary and permanent passes;
  • sending internal organization notifications;
  • ensuring service security;
  • preventing unauthorized access;
  • providing technical support;
  • maintaining technical logs;
  • complying with legal requirements;
  • improving service stability and quality.

7. Separate Consents During Registration

During organization registration, GateList uses separate checkboxes for different purposes. The following are required for registration:

  1. Consent to personal data processing for registration and use of GateList.
  2. Consent to transfer personal data to technical providers where necessary for service operation.
  3. Confirmation of authority to register the organization and of the organization’s responsibility for the data it enters into GateList.

A separate optional consent may be offered for receiving informational emails from GateList. This consent is not required for registration or use of the service, and refusal does not block organization registration.

8. Informational and Service Emails

GateList may send service messages required for account operation and security, including registration emails, access recovery emails, security notifications, technical notifications and messages related to the user account or organization.

Informational emails, including service news, feature updates, useful materials and important product changes, are sent only if the user has provided separate consent.

The user may unsubscribe from informational emails by sending a request to privacy@gatelist.ru. If an unsubscribe link is implemented in the interface or emails, the user may also use it.

9. Mobile Notifications

GateList sends personal notifications through mobile push providers APNs and FCM. Push text contains no personal data; details are available only after authentication in the app.

10. Cookies

GateList may use cookies and similar technologies to maintain user sessions, provide authentication, protect against unauthorized access, remember the selected interface language, ensure correct operation of the web account and perform technical diagnostics.

The user may restrict cookies in their browser settings. However, this may prevent login or cause some functions to work incorrectly.

11. Transfer of Data to Technical Providers

GateList may transfer personal data to technical providers only to the extent necessary for service operation.

  • hosting and server infrastructure providers;
  • email service providers;
  • notification delivery services;
  • technical support services;
  • other infrastructure providers required for stable and secure operation of GateList;
  • Apple, if the user uses the mobile application through the App Store.

Data may be transferred for registration and authentication, service message delivery, access recovery, technical support, security, stable operation of the website, API, mobile application , and distribution and updates of the mobile application.

GateList does not sell personal data, does not transfer personal data to data brokers and does not use personal data for advertising tracking.

12. Tracking, Advertising and Sale of Data

GateList does not use personal data for advertising tracking.

GateList does not sell personal data.

GateList does not transfer personal data to data brokers.

GateList does not combine user data with data from third-party apps or websites for advertising profiling.

GateList does not use advertising SDKs to track users across apps and websites.

13. Data That Should Not Be Entered into GateList

GateList is not intended for processing special categories of personal data. Users and organizations should not enter health data, political opinions, religious beliefs, biometric data, intimate life information, national or racial origin or other sensitive information into comments, notes or other free-text fields.

If an organization enters such information, it is responsible for having a lawful basis for such processing.

14. Data Retention

Personal data is stored only for as long as necessary for the purposes of processing.

  • account data — while the account is active;
  • organization data — while the organization uses GateList;
  • vehicle, guest, pass and log data — while such data is stored by the organization in the service or until deleted by the organization;
  • technical security logs — for the period necessary to protect the service and investigate incidents;
  • support request data — for the period necessary to process the request and protect the operator’s rights;
  • backup copies — for the technically necessary backup retention period.

After deletion from the active database, data may remain temporarily in backup copies until scheduled backup overwriting.

15. Data Security

GateList takes organizational and technical measures to protect personal data, including role-based access control, organization-level data isolation, secure connection, storing passwords as secure hashes, security logging, backups, limiting access to data, technical maintenance and service updates.

The user and the organization must use strong passwords, avoid sharing access with third parties, promptly remove users who no longer need access and avoid placing excessive or unlawfully obtained data in the service.

16. Recording Consents

During organization registration, GateList may record accepted consents and confirmations, including date and time, IP address, User-Agent, interface language, consent version, policy version, policy URL and the text of the consent or confirmation shown to the user at the time of acceptance.

This is necessary to confirm that the consent was given knowingly and in relation to a specific text.

17. User Rights

The user may have the right to receive information about processing, request correction, restriction or deletion of personal data, withdraw consent, unsubscribe from informational emails, request account deletion, contact the operator regarding personal data processing or contact the competent data protection authority.

Requests should be sent to: privacy@gatelist.ru.

If the request concerns data entered by a specific organization, GateList may request confirmation from that organization or suggest that the data subject contact the administrator of the relevant organization.

18. Account and Data Deletion

A user may contact their organization administrator or the operator to request account deletion.

An organization administrator may delete users, vehicles, guests, passes and other records within the permissions granted to them.

Deletion of an organization and all related data may be carried out upon request of an authorized representative of that organization, unless otherwise required by law or necessary to protect the operator’s rights.

To request data deletion, contact: privacy@gatelist.ru.

19. Withdrawal of Consent

The user may withdraw consent to personal data processing by sending a request to privacy@gatelist.ru.

Withdrawal of consent may make further use of the service impossible if the relevant data processing is necessary for account operation, authentication, security or access to GateList.

Unsubscribing from informational emails does not affect the ability to use GateList.

20. Children’s Data

GateList is intended for use by organizations and their authorized users. The service is not intended for independent use by children.

If an organization enters data relating to minors, the organization is responsible for ensuring that it has a valid legal basis for such processing.

21. Automated Decision-Making

GateList does not make decisions based solely on automated processing that produce legal effects concerning a data subject or similarly significantly affect them.

22. Changes to This Policy

The operator may update this Privacy Policy from time to time. The current version is published at: https://gatelist.ru/en/privacy.

The updated version becomes effective upon publication, unless another effective date is specified.

23. Contacts

Personal data operator: Менякин Дмитрий Николаевич.

Privacy contact email: privacy@gatelist.ru.

Website: https://gatelist.ru.