Verifying secure connection...

This will only take a moment

Data Protection & Privacy

Privacy Policy

Effective Date: January 1, 2025 | Last Updated: November 4, 2025

What This Means for You at a Glance

We only collect what's needed to deliver and manage shipments
We never sell your data
You control your privacy choices
Your data is encrypted and stored securely in SOC 2 certified data centers

1. Introduction

Gateway ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our services or visit our website. Please read this privacy policy carefully. If you do not agree with the terms of this privacy policy, please do not access our services.

2. Information We Collect

2.1 Personal Information

We collect information that identifies you, including:

  • Name and company name
  • Email address and phone number
  • Billing and shipping addresses
  • Federal Tax ID and business registration details
  • Payment information (processed securely)
  • Shipping and cargo details

2.2 Automatically Collected Information

When you visit our website, we automatically collect:

  • IP address and browser type
  • Device information and operating system
  • Pages visited and time spent
  • Referring website addresses
  • Cookie and tracking data

3. How We Use Your Information

We use collected information for various purposes:

Service Delivery

Process shipments and provide logistics services

Communication

Send updates about your shipments and services

Billing

Process payments and manage credit accounts

Compliance

Meet regulatory and legal requirements

Improvement

Enhance our services and user experience

Marketing

Send promotional materials (with consent)

4. Information Sharing and Disclosure

We may share your information in the following situations:

  • Service Providers: With carriers, customs brokers, and logistics partners to fulfill services
  • Legal Requirements: When required by law or to protect our rights
  • Business Transfers: In connection with mergers or acquisitions
  • With Consent: With your explicit permission

We do not sell, trade, or rent your personal information to third parties for marketing purposes.

5. Data Security

We implement appropriate technical and organizational security measures to protect your information:

Encryption

256-bit SSL encryption for data transmission

Access Control

Restricted access on need-to-know basis

Regular Audits

Security assessments and penetration testing

Secure Storage

SOC 2 Type II compliant data centers

6. Cookies and Tracking Technologies

We use cookies and similar tracking technologies to enhance your experience:

  • Essential cookies for website functionality
  • Analytics cookies to understand usage patterns
  • Preference cookies to remember your settings
  • Marketing cookies (with your consent)

You can control cookies through your browser settings. Disabling cookies may affect website functionality.

Security & Bot Protection

We use the following services to protect our platform and ensure security:

  • Cloudflare Turnstile: Bot protection and human verification without intrusive CAPTCHAs
  • Cloudflare Security: DDoS protection, web application firewall, and threat detection
  • Vercel Analytics: Privacy-focused web analytics to improve user experience
  • Microsoft Clarity: Session recordings and heatmaps to understand how users interact with our platform
  • Google Analytics: Website traffic analysis and user behavior insights
  • IP & Bot Detection: Fraud prevention and security monitoring to protect against malicious activity
  • Sentry: Error tracking and performance monitoring to identify and fix issues

Do Not Track Signals

Our services do not currently respond to browser-based "Do Not Track" signals. However, you can control cookies through your browser settings and opt out of marketing communications at any time.

7. Your Privacy Rights

You have the following rights regarding your personal information:

Access: Request copies of your personal data
Correction: Request correction of inaccurate data
Deletion: Request deletion of your data
Portability: Request data transfer to another service
Opt-Out: Unsubscribe from marketing communications
Restriction: Request limited processing of your data

To exercise these rights, contact us at privacy@gatewaylines.com

8. International Data Transfers

As an international logistics provider, we may transfer your information to countries outside your residence. We ensure appropriate safeguards are in place, including standard contractual clauses and adequacy decisions, to protect your information in accordance with this policy.

Data Privacy Framework Compliance

Gateway complies with the EU-U.S. Data Privacy Framework (EU-U.S. DPF), the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. Data Privacy Framework (Swiss-U.S. DPF) as set forth by the U.S. Department of Commerce.

International Data Protection Officer

For privacy inquiries from the following regions, please contact our designated Data Protection Officer:

Shapet Khan - Data Protection Officer

Email: khans@grcilaw.com

Serving: China, Shanghai, Singapore, Germany, France, Italy, and Canada

View DPO Service Description

9. Children's Privacy

Our services are not intended for individuals under 18 years of age. We do not knowingly collect personal information from children. If we learn we have collected information from a child under 18, we will delete that information promptly.

10. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last Updated" date. You are advised to review this Privacy Policy periodically for any changes.

11. Contact Us

If you have questions or concerns about this Privacy Policy, please contact us:

Privacy Inquiries: privacy@gatewaylines.com

General Inquiries: info@gatewaylines.com

Sales Inquiries: sales@gatewaylines.com

GDPR Compliance

For EU residents: We comply with the General Data Protection Regulation (GDPR). You have additional rights including the right to lodge a complaint with your local supervisory authority.

California Privacy Rights (CCPA/CPRA)

California residents have additional rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA), including:

  • • The right to know what personal information is collected
  • • The right to opt-out of the sale of personal information (which we do not sell)
  • • The right to correct inaccurate information
  • • The right to limit the use of sensitive personal information

12. API and Third-Party Integrations

If you access Gateway services through our API or connect with third-party systems (e.g., Shopify, SAP, NetSuite, QuickBooks), we may process and transfer the data exchanged through these integrations.

  • You are responsible for ensuring that any data transmitted through integrations complies with applicable privacy laws
  • We do not control data sent to us from third-party apps you connect to Gateway
  • API keys must be kept secure and not shared with unauthorized parties

13. Data Retention

We retain your data only as long as necessary to provide services, comply with legal obligations, resolve disputes, and enforce agreements.

Account & Shipping Data

Retained for 7 years (for compliance with U.S. customs and maritime regulations)

Operational Data

Customer support and operational data retained for 3 years

Marketing Data

Retained until you unsubscribe or request deletion

14. Automated Decision-Making

We use algorithms and automated systems to process shipment data and make decisions such as:

  • Risk scoring and delay prediction
  • Route optimization and carrier selection
  • Auto-filing of customs paperwork
  • Pricing calculations and rate quotes
  • ETA predictions and shipment monitoring

Your Rights: You have the right to request human review of decisions made solely through automated processing. Contact us at privacy@gatewaylines.com to request a review.

15. Security Incident Notification

In the event of a data breach affecting your personal information, we will notify you in accordance with applicable law. Notifications will be made without undue delay and will include:

  • The nature of the breach and affected data
  • Steps we are taking to address the breach
  • Actions you can take to protect your information
  • Contact information for further assistance