Privacy Policy
This document explains what personal data Mistgate collects, why we collect it, and the choices and rights you have over it.
- Effective
- Updated
0Summary
We collect the minimum personal data needed to provide the service, bill paid plans, and keep the platform secure and reliable. We do not sell personal data, we do not run advertising, and we do not host user-uploaded files or photos.
This policy applies to the Mistgate website and any related services that link to it.
1Who we are
Mistgate is operated by Mistgate, the data controller responsible for the personal data described in this policy.
For privacy questions, data subject requests, deletion or export, contact [email protected].
2Data we collect
We collect personal data in a small number of high-level categories. Anything outside the categories below is not intentionally collected.
| Account data | Information you provide when creating or maintaining an account, such as email address and display name. Authentication credentials are stored in protected form; we never see them in plain text. |
|---|---|
| Profile data (optional) | Optional profile fields you choose to provide, including any data supplied by a third-party identity provider when you opt to sign in with one. |
| Connection metadata | Technical metadata generated when you use the service, such as IP address, user-agent string, and approximate timing of requests. Used to keep accounts secure and to operate the service. |
| Billing data | If you subscribe to a paid plan, we record the existence of your subscription and its status. Payment instruments (card numbers, billing addresses, tax information) are handled by a third-party payment processor and never reach our servers. |
| Service data | Data you submit through the product to enable features you have requested. You can review and remove this data through the product interface or by contacting us. |
| Diagnostic data | Anonymous or pseudonymous information about errors and usage of the product, used to keep the service reliable and to improve it. |
We do not collect: precise device fingerprints, advertising identifiers, contact lists, microphone or camera input, location beyond IP-derived geolocation, or biometric data.
3How we use your data
- To provide, maintain, and improve the service.
- To create and manage your account, including authentication and account security.
- To process payments and manage subscriptions.
- To prevent fraud, abuse, and unauthorized access, and to comply with our legal obligations.
- To respond to support, security, and privacy requests you send us. We do not currently send marketing email.
We do not use your personal data to make solely automated decisions that produce legal or similarly significant effects on you.
4Legal basis
Where the EU/UK General Data Protection Regulation or a similar law applies, we rely on the following legal bases:
- Contract: to provide the service you signed up for and to bill paid plans.
- Legitimate interests: to keep the service secure, prevent abuse, and improve product quality.
- Legal obligation: to comply with applicable laws (for example, accounting and tax record-keeping).
- Consent: where required, for any non-essential cookies or communications. You can withdraw consent at any time.
7Data retention
We keep personal data only for as long as we need it for the purposes set out in this policy or as required by law.
- Account data: kept while your account is active. On account deletion, we delete or anonymize personal data associated with the account within a reasonable period, except where retention is required by law.
- Sign-in sessions: kept only for the duration of a session and deleted at expiry or sign-out.
- Billing records: retained for the period required by tax, accounting, and other legal obligations.
- Logs and diagnostics: retained for a short rolling window sufficient for operational debugging.
8Your rights
Depending on where you live, you may have some or all of the following rights in relation to your personal data:
- access the personal data we hold about you;
- request a portable copy of that data;
- correct inaccurate data;
- delete your data (right to erasure);
- restrict or object to certain processing;
- withdraw consent where consent is the legal basis;
- lodge a complaint with your local data-protection authority.
Many of these are self-service from your account settings. For other requests, email [email protected] and we will respond within the time required by applicable law (and in any case within 30 days). We may need to verify your identity before acting on a request.
9Security
We use a combination of technical and organizational measures appropriate to the nature of the data we process. These include access controls, encryption in transit and at rest where appropriate, monitoring for suspicious activity, and regular review of our practices.
No system is perfectly secure. If you believe you have found a vulnerability, email [email protected] and we will respond promptly.
10Children
Mistgate is not directed to and is not intended for children under 13 (or the minimum age required by law in your jurisdiction). We do not knowingly collect personal data from children. If you believe a child has given us personal data, contact us and we will delete it.
11International transfers
Your personal data may be processed in countries other than the one in which you reside. Where required by law, transfers from the European Economic Area, United Kingdom, or Switzerland rely on Standard Contractual Clauses or other recognized safeguards.
12Changes to this policy
We may update this policy from time to time. When we change a substantive item — what we collect, why, or with whom we share it — we update the "Last updated" date at the top of this page and, for material changes, surface an in-app notice or contact signed-in users.
13Contact
Mistgate is the data controller for Mistgate. For privacy questions, data subject requests, or security reports, email [email protected].