Gated

Privacy

How Gated currently handles data.

This operational notice describes the website and limited product staging. Gated is operated by PB Web Design, LLC. This notice includes the private Founding billing pilot.

Operator

Gated is operated by PB Web Design, LLC, a Delaware limited liability company. Contact privacy@gated.sh for privacy requests, security@gated.sh for security reports, or support@gated.sh for pilot support.

Website waitlist

The waitlist stores your email address, signup source, interest and any preference you submit in the website’s Supabase database. Cloudflare Turnstile checks submissions for abuse and receives the verification token and client IP address. After a new signup, Gated attempts to send a confirmation through Resend. Email delivery can fail independently of a saved signup.

Contact page

Contact is email-only. This page has no message form and does not submit or store a message. Sending email shares the contents and sender details with the operator and mail providers.

Product staging

The separately hosted product uses a separate Supabase project for authentication, workspace membership, policies, scoped agent credentials and approval and execution evidence. The security release also records session identifiers, passkey public keys and security events; passkey private keys stay with your authenticator. GitHub requests include repository identity, branch, pinned commit and the task context supplied by the caller. The broker uses temporary GitHub App authority; provider credential values are not included in audit receipts. Do not put passwords, provider tokens or unrelated personal information in task context.

Support and security email

Email security@gated.sh for security reports, pilot support or privacy requests. Zoho Mail hosts these messages for the operator, including message contents, sender details and attachments. The security, support and privacy addresses are aliases of the operator’s main mailbox. Staging alerts are sent through Resend and contain alert and workspace identifiers, not provider credentials or request payloads. Avoid sending secrets or unrelated personal data. No guaranteed response time is offered.

Founding billing and feedback

Stripe processes payment details through hosted Checkout and its customer portal. Gated does not store raw card numbers or card security codes. Gated keeps account-linked Stripe customer, Checkout, subscription and webhook event identifiers; payment, cancellation and subscription state; first-payment and paid-through dates; lifetime allocation history; and feedback and human review records. Operators record country and state for U.S. pilot eligibility. Stripe collects the billing address for applicable tax. These records support billing, refunds, disputes, cancellation, eligibility and the one-time feedback obligation. They are not included in public analytics. See the Terms for the refund window and review process.

Billing retention

We keep billing and allocation records while needed to operate the subscription, resolve refunds or disputes and meet applicable recordkeeping duties. Minimal allocation history must be retained to enforce the lifetime 50-person cap after cancellation or refund. Other account data is subject to manual retention and deletion review. We do not currently have automatic billing-record or backup expiry, and do not promise immediate erasure from backups. On a verified deletion request we review what can be removed and explain any records that must be retained.

Analytics

The deployed site may use Vercel Analytics for aggregate site usage. Email addresses must not be included in analytics events.

Backups and onboarding records

Encrypted product database archives are stored separately in Cloudflare R2. The backup runner uses GitHub Actions; recovery material is held separately from the archive destination. Full recovery into a replacement service has not yet been demonstrated. Product onboarding reports reuse existing account and workspace records to show milestone timestamps; they do not collect keystrokes, session recordings or task prompts. The operator may keep a minimal observation sheet with the tester’s agreement.

Export and deletion requests

Email privacy@gated.sh with your account or workspace reference and the scope of your request; do not send credentials. The operator must verify authority before exporting or deleting data. Deletion is a manual request, not an automated guarantee. Audit evidence and encrypted backups require separate retention review; deleting an active record does not immediately remove it from existing backups. No automatic backup expiry is currently configured.

Before a pilot

Pilot retention periods and deletion and recovery arrangements must be agreed before accepting pilot data. This implementation notice does not promise a deletion deadline, a geographic storage location or a compliance certification that has not been verified.

Questions

Email security@gated.sh. The contact page lists the email addresses for support, privacy and security.