How Gatepass handles account data, workspace records, submissions, uploads, Google Drive/Form data, WhatsApp messages, PayGo usage and support requests.
Last reviewed
June 19, 2026
Customers control project contentGoogle data is used only for connected featuresWe do not sell Google user dataData requests and disconnect options are supported
Plain-language privacy summary
Gatepass is used to create forms, ID capture workflows, event tickets and verification records. Customers control what they collect. When Google Drive or Google Forms are connected, Gatepass uses Google data only to provide the connected feature and follows the Google API Services User Data Policy, including Limited Use requirements.
01
Data we collect
Gatepass collects the information needed to provide accounts, workspaces, published projects, submissions, files, verification, exports, support and billing. The exact data depends on how a customer configures their forms, ID capture projects, event registrations and connected integrations.
Account and workspace data such as name, email, role, organization details and login activity.
Project data such as forms, fields, templates, design settings, statuses, public links and review configuration.
Submission data such as answers, uploaded files, photos, signatures, event attendee records, ID records and verification references.
Google account data when Google sign-in or Google integrations are used, such as basic profile information, email address, Google account identifier and OAuth connection status.
WhatsApp data such as phone number, message content, media uploads, session status, link codes and support conversations where WhatsApp is used.
Billing and support data such as PayGo purchases, usage records, receipts, contact requests and issue details.
02
Google APIs, Google Drive and Google Forms data
When you choose to connect Google, Gatepass requests Google permissions only for the features you activate, such as Google sign-in, importing Google Forms and storing Gatepass-related files in Google Drive.
Google sign-in is used to authenticate your account and confirm your name, email address and basic profile information.
Google Forms access is used to read the structure of forms you own or can access, such as titles, descriptions, questions, options and form metadata, so you can import or recreate them in Gatepass.
Google Drive metadata access is used to locate supported Forms or Drive items, confirm file names, file types, IDs and access status, and help you choose the correct item to import or connect.
Google Drive file access is used to create, upload, read, update or manage files and folders that are created by Gatepass or intentionally selected for use with Gatepass, such as uploads, exports, generated tickets, badges, cards and reports.
Gatepass does not request access to your entire Drive unless you explicitly authorize a feature that requires broader access. We aim to use the narrowest Google scopes that support the feature.
You can disconnect Google from your Gatepass profile or revoke access from your Google Account permissions page. Disconnecting stops future use of that Google connection, but files already saved in your Google Drive may remain there unless you delete them from Google Drive.
03
Google API Limited Use disclosure
Gatepass's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
We do not sell Google user data.
We do not use Google user data for advertising or ad targeting.
We do not use Google Drive, Google Forms or Google profile data to train generalized AI models.
We do not transfer Google user data except as needed to provide or improve user-facing Gatepass features, comply with law, prevent abuse, maintain security or use trusted service providers under appropriate confidentiality and security obligations.
Human access to Google user data is limited to cases such as support requested by you, security investigation, abuse prevention, legal compliance or internal operations necessary to provide the service.
OAuth tokens and connection details are stored securely and are used only to operate the Google features you connect.
04
How we use data
We use data to run Gatepass, secure accounts, publish projects, collect and review records, generate ID cards, event tickets and badges, provide support, process billing and improve platform reliability.
Create and manage accounts, workspaces, team roles and sessions.
Publish and operate standard forms, ID capture projects and event registration pages.
Store, display, review, verify, export and archive submitted records.
Import supported Google Forms, store Gatepass-related files in connected Google Drive and generate exports where those features are enabled.
Send operational messages such as email, WhatsApp replies, login notices and support responses.
Monitor security, prevent misuse, troubleshoot errors and keep audit records.
05
Customer-controlled content
Customers decide what their forms ask for, which files they collect, who can submit, who can review, and how records are exported, stored or used. Gatepass provides the platform; customers remain responsible for collecting only data they are allowed to collect.
Use clear instructions and consent wording where needed.
Avoid collecting sensitive information unless it is necessary and authorized.
Limit workspace access to people who need the records.
Review exports and downloaded files carefully before sharing them outside Gatepass.
If using Google Drive storage, confirm that the connected Google account is authorized to store the project files.
06
Sharing and service providers
Gatepass may use trusted providers for hosting, storage, email, payments, WhatsApp messaging, analytics, monitoring and support. We do not sell customer submission data or Google user data to advertisers.
Providers process data only to help operate, support or secure the service.
Payment providers process checkout, receipts and payment references.
Messaging providers may process operational email or WhatsApp messages.
Cloud infrastructure providers may process files, generated records, exports, logs and database records needed to run Gatepass.
Public submitter data is mainly controlled by the customer organization that created the project.
Google user data is shared only as described in this policy and in line with the Google API Services User Data Policy, including Limited Use requirements.
07
Retention and deletion
Gatepass keeps information for as long as needed to provide the service, support customer projects, meet legal or operational obligations, resolve disputes, prevent abuse and maintain security records.
Customers should export important reports before deleting projects or records.
Some billing, audit, security or fraud-prevention records may be retained where required.
Deleted records may take time to disappear from backups and logs.
Disconnecting Google removes or disables future use of the OAuth connection in Gatepass, but files previously created in your Google Drive may remain in your Drive account unless you delete them there.
Public submitters should usually contact the organization that collected their data first.
08
Your choices and rights
Depending on your location and relationship to Gatepass, you may request access, correction, export, deletion or restriction of certain personal data.
Use the Privacy Center for data request guidance.
Manage cookie choices through the cookie preference page where available.
Disconnect Google Drive or Google integrations from your profile where the feature is available, or revoke Gatepass from your Google Account permissions page.
Contact support for account, billing or workspace privacy questions.
Team admins can manage workspace members, exports and archived records.
Privacy reference
A summary of common data categories in Gatepass.
Area
How it applies
Note
Account data
Name, email, role, workspace, login and session details.
Required for service use
Google data
Google profile, email, Forms structure, Drive metadata and Gatepass-related Drive files where connected.
Feature dependent and limited to authorized scopes
Submission data
Answers, files, photos, event attendees, ID records, badges and verification references.
Customer controlled
WhatsApp data
Phone numbers, messages, media, link codes, support requests and session activity.
Feature dependent
Billing data
PayGo purchases, usage credits, receipts, payment references and billing support messages.
Account verification may be required
Technical data
Logs, cookies, device signals, rate limits and security events.
Security and reliability
Need help?
Contact support for questions about your account, workspace, billing, data request or published project.