1. Who is responsible for what
For this website and for the accounts of the people who use our dashboard, GatewayChanger is the controller.
For the routing and ledger data your shops send us about your customers' orders, GatewayChanger is a processor: you are the controller, and we act on your instructions under the data processing addendum.
To be confirmed The controller entity, its address and the contact point for data protection questions will be named here before this notice takes effect.
2. When you visit this website
Our web server writes a standard access log containing the request, the time, the response status, the user agent and a truncated IP address, kept for a short retention period to keep the service secure and working. The legal basis is our legitimate interest in operating and protecting the site.
This site has no analytics, no advertising pixels, no session recording and no third-party trackers. Web fonts are requested from fonts.bunny.net, which means your IP address is visible to that provider while the font files are fetched; everything else on the page is served from gatewaychanger.com.
3. Cookies
We set two strictly necessary cookies, both first-party:
gatewaychanger_session— keeps your session while you are signed in to the dashboard and protects form submissions.XSRF-TOKEN— a cross-site request forgery token that pairs with it.
Both expire after a couple of hours of inactivity. Because they are strictly necessary for a service you asked for, we do not show a consent banner — and because we run no analytics or advertising cookies, there is nothing else to consent to.
4. When you create an account
We process your name, email address, hashed password, organization details and the actions you take in the dashboard (which rule you changed, which shop you added, which key you rotated), so that we can provide the Service, keep it secure, bill you and support you. The legal basis is the performance of our contract with you, and our legitimate interest in security and audit.
We send you service email: verification, security alerts, incident notices, billing and — if you opt in — product updates. You can turn product updates off at any time without losing the operational ones.
5. The data your shops send us
This is the data your plugins report for each routed order. We process it on your behalf:
- amount, currency, billing and shipping country, and item categories used by your rules;
- an optional SHA-256 hash of the customer email — never the address itself, unless you choose to send it;
- card brand and the last four digits, the processor name and its reference, and the status of the payment;
- order references at both shops, the matched rule, and the full decision trace;
- consent evidence: the accepted text, its hash, the timestamp, the IP address and the user agent.
We never receive a card number, a CVV, an expiry date or a cardholder name. There is no field for them in our API and no column for them in our database.
6. Who we share data with
- Your own shops. A routing decision necessarily tells the seller shop which charger shop was chosen, and tells the charger shop the order details it needs to charge and to handle refunds.
- Sub-processors — hosting, email delivery and error monitoring — listed in the data processing addendum, each under a written contract.
- Authorities, where we are legally required to, and where we are permitted to tell you, we will.
We do not sell personal data, we do not share it for advertising, and we do not use your transaction data to train machine-learning models.
7. How long we keep it
- Account and billing records: for the life of the account and then as long as tax and accounting law requires.
- Decisions, transactions and consent evidence: for the life of the account plus the retention period agreed in the addendum, because they are financial and dispute records.
- Server logs: a short rolling window.
To be confirmed The exact retention periods will be stated here in days and months.
8. International transfers
To be confirmed The hosting region and the transfer mechanism for any sub-processor outside it — standard contractual clauses plus a transfer assessment where required — will be listed in the data processing addendum and repeated here.
9. Your rights
Where the GDPR or a comparable law applies to you, you can ask for access to your data, correction, deletion, restriction, portability, and you can object to processing based on legitimate interests. You can also complain to your supervisory authority.
If your request concerns data we process for one of our customers — for example an order you placed in their shop — we will refer you to that shop, which is the controller, and help them answer you.
10. Security
TLS on every connection, credentials hashed with a modern algorithm, API keys scoped per shop and per environment, signed grants and signed shop-to-shop requests, replay protection, least-privilege access to production, and an audit trail of administrative actions. Report a vulnerability to [email protected] and we will answer.
11. Changes and contact
We will update this notice as the Service grows and will note material changes in the changelog. Questions go to [email protected].
Questions about this draft go to [email protected]. See also the compliance page for the plain-language version of how the service is built.