GateAway

Privacy notice

Last updated: 16 July 2026

This is an English translation provided for convenience. In case of any discrepancy, the Italian version prevails.

This notice explains how GateAway processes personal data, pursuant to Articles 13-14 of Regulation (EU) 2016/679 (GDPR). GateAway is used to create and share travel itineraries and is used both by travel professionals (advisors, agencies) and by private travelers. Whoever registers creates itineraries for themselves or for their clients (the travelers) and shares them via a link.

1. Data Controller

Adelchi Brignoli — Tax code BRGDCH89M13F119Y, Via Mozart 18, 20050 Liscate (MI), Italy. For any request about your data: amministrazione@gateaway.world.

2. What data we process

Advisors’ data (registered users; GateAway is an independent Controller): email and sign-in credentials (also via Google, if you use Google sign-in); name and agency details (phone, website, socials, logo); usage data and technical logs; proof of the consents given (date, time, IP address, user agent). Subscription payment data is handled directly by Lemon Squeezy (Merchant of Record), which does not transmit card data to us.

Travelers’ data (entered by the advisor; GateAway is a Processor on the advisor’s behalf — detailed terms in the DPA, Art. 28): name, group composition, trip details and any uploaded documents, which may contain personal data — including identity documents or other special-category data. In respect of this data GateAway acts as a Processor on behalf of the advisor, who is the Controller. GateAway provides the upload space but does not review, classify or filter the content of the documents: it is up to the advisor to assess their nature, legal basis and adequacy, including where they contain special-category data (Art. 9 GDPR). GateAway treats uploaded content as potentially special category and applies adequate security measures to it; it is up to whoever uploads to have a valid condition under Art. 9(2) GDPR (e.g. the data subject’s explicit consent) and to avoid uploading unnecessary special-category data.

If you use GateAway as a private individual — to organize your own trips and share them with your companions — processing your data for purely personal purposes may fall under the household exemption (Art. 2(2)(c) GDPR). However, it remains your responsibility to have a legal basis and to inform the data subjects when you upload or share third-party data (e.g. your companions’ documents), because that may go beyond the household scope. In any case GateAway is an independent Controller for your account data, security and the infrastructure.

3. Why we process it (purposes and legal bases)

To provide the service and perform the contract (Art. 6(1)(b)); for security and abuse prevention and aggregate traffic statistics (legitimate interest, Art. 6(1)(f)); to comply with legal obligations (Art. 6(1)(c)); to manage subscriptions and related payments (contract). We also send service messages and product onboarding emails (welcome, reminders, notices) on the basis of legitimate interest (Art. 6(1)(f)): you can object to these communications at any time via the unsubscribe link at the bottom of those emails or by writing to amministrazione@gateaway.world. For travelers’ data, the legal basis is identified by the advisor as Controller.

4. Artificial intelligence (itinerary generation)

If the advisor uses the automatic generation feature, the text or PDF provided — which may contain travelers’ personal data — is sent to Google (Gemini API) to produce the itinerary, for this purpose only. On the paid tier of the Gemini API, Google does not use this data to train or improve its models (see the Gemini API terms). The processing may involve a transfer to the United States, governed by adequate safeguards (Standard Contractual Clauses and, where applicable, the EU-US Data Privacy Framework adequacy; you can request a copy). The feature is optional: if you do not use it, no data is sent to Google.

5. Sharing via link

Itineraries are shared via a private link with a unique, unguessable code, not indexed by search engines. Anyone who has the link can view the itinerary without authentication: it is up to the advisor to share it only with the intended recipients. The link has an expiry and is revocable at any time. Documents attached to the trip travel with the link and are accessible only to whoever holds it, after the token is verified.

Unlike the private link, the public showcase (optional, enabled by the user) makes the itinerary visible to anyone and indexable by search engines. On publication the system automatically removes the identifying fields (client name, real dates, documents, private notes), exposing only the trip structure and the creator’s public data (name/brand, logo, contacts, socials) that the user chooses to show for their own promotion. The system also checks free-text fields (titles, descriptions, tips) and warns the creator if it detects possible booking data (codes, PINs, phone numbers) before publishing; removing such data and the final check remain the creator’s responsibility. The ratings (stars) from those who import an itinerary are processed to compute the average shown in the showcase; the identity of who rates is not made public. The user can withdraw the itinerary from the showcase at any time.

6. Who we share data with

We rely on providers acting as processors (or sub-processors): Vercel (application hosting and compute — request handling, page rendering, document delivery — and aggregate, cookieless traffic statistics via Vercel Web Analytics and Speed Insights); Supabase (database and files, servers in the European Union); Google (Gemini, only if you use the AI, and Google Maps/Places, only in the editor when you search a stop’s exact place); Open-Meteo (daily weather from the given city: receives only the location, not the traveler’s data); Resend (sending service and lifecycle emails: welcome, password reset, onboarding and inactivity notices); Sentry (monitoring of the platform’s technical errors, servers in the European Union): it receives only technical error data and any internal identifiers (e.g. user/trip ID), by configuration it does not receive IP addresses, cookies or the itinerary content, and it serves solely to keep the app stable and secure (our legitimate interest). Subscription payments are handled by Lemon Squeezy (Merchant of Record), which acts as an independent Controller for billing and payments and has no access to travelers’ data. We do not sell data to third parties.

7. Where it is stored and transfers

Database and documents are stored at rest on Supabase in the European Union. Some providers may however process data in the United States Vercel (hosting/compute and statistics), Google (Gemini and Maps), Resend (email) — subject to adequate safeguards (Standard Contractual Clauses and, where applicable, EU-US Data Privacy Framework adequacy); you can request a copy. Open-Meteo processes data within the European Union.

8. How long we keep it

Advisor account and data: for the entire duration of the account; on deletion, data is removed within 30 days. Travelers’ itineraries and documents: until the trip or the account is deleted by the advisor. In the case of an inactive account (no sign-in) for more than 24 months, we send an email warning and, after a further 30 days without sign-in, the account and related data are permanently deleted, except data needed for legal obligations. Technical and security logs: 6-12 months. Proof of consents: for the duration of the account and for the time needed to defend legal claims. Billing data: for the terms set by tax and accounting obligations.

9. Your rights

You can exercise at any time the rights of access, rectification, erasure, restriction, portability and objection, and withdraw the consents given. You also have the right to lodge a complaint with the Italian Data Protection Authority (Garante, www.garanteprivacy.it). To exercise your rights write to amministrazione@gateaway.world.

Right to object: when we process your data on the basis of legitimate interest (Art. 6(1)(f), e.g. security and abuse prevention), you have the right to object at any time on grounds relating to your particular situation, by writing to amministrazione@gateaway.world (Art. 21 GDPR).

No automated decision-making: GateAway does not make decisions based solely on automated processing, nor does it carry out user profiling (Arts. 13(2)(f) and 22 GDPR).

10. Changes to this notice

We may update this notice; significant changes will be communicated through the service or by email.