What stays on your computer
Event data, attendee information, QR payloads, and scan history stay on your computer by default and are never uploaded to GateFlow. QR codes contain no personal data; each one carries a random 32-character code.
GateFlow is local-first. Your events run in the app on your own computer, and GateFlow hosts only what is needed for your account, payments, and licences. This page summarises what stays with you and what we hold.
Event data, attendee information, QR payloads, and scan history stay on your computer by default and are never uploaded to GateFlow. QR codes contain no personal data; each one carries a random 32-character code.
If an organizer turns on Guest Claim for a Production Event, their Gate Controller pushes a claim projection to gateflow.vip: encrypted copies of the event's Access QRs and coded (hashed) forms of the guest contacts the organizer entered. GateFlow does not hold a readable guest list; matching happens against the coded contact forms, and claim pages answer neutrally whether or not a contact is on the list. To deliver a claim, the guest's chosen channel sees what delivery requires: our email provider processes the guest's email address, and WhatsApp claims are exchanged with Meta's WhatsApp Business platform, which processes the guest's WhatsApp number and the messages. Claim links are single-use and expire in 15 minutes. Claim data is deleted automatically within 24 hours after the event is closed, and within 60 days of being pushed; organizers can erase it at any time. The only exception to those two deadlines is claim data we are legally required to keep, for example under a court order: that legal hold is recorded, covers only the single event it names, and never stops an organizer erase.
Guest Claim is switched on centrally, one channel at a time, and it is not open for real guest data yet: the written Egyptian privacy and data-transfer basis for it has to be approved first. Organizers distributing Access QRs themselves send us no guest contact details at all.
When a claim message is delivered, the delivery provider holds its own copy on its own schedule. Our email provider retains delivery records and message content for its own operational period, and Meta retains the WhatsApp message and its metadata under its own policies. Both providers also keep their own system backups. An organizer's erase, and our own automatic deletion, remove the claim projection, challenges, and sessions from GateFlow-controlled storage immediately; they cannot reach into a provider's records or backups. The same is true of our own infrastructure backups, which are retained for a short recovery window and then expire.
We hold your account identity (name and email), payment records, licence and device-registration metadata, and the security and audit records needed to protect the service. Device registration uses machine identifier hashes, not hardware serials.
Checkout is handled by Paymob. GateFlow never sees card numbers. GateFlow sends Paymob the name and email address on your account with each checkout, so the payment can be raised in your name and receipted. We store the payment records needed to issue your licence and keep your receipts available on your account.
You can optionally sign in with Google or Microsoft; GateFlow receives only your name and email address from the provider. The account pages use Cloudflare Turnstile to block automated abuse and load fonts from Google Fonts; both services see standard request metadata (such as your IP address) but no GateFlow account data.
We use it to maintain account access, issue licence keys and signed licence files, apply capacity upgrades, support device transfers and remote recovery, and answer support requests. It is not sold for marketing.
Your events, passes, scan history, and labels are on your own computer. Deleting them is yours to do and needs nothing from us. Claim data on gateflow.vip can be erased by the organizer at any time and is deleted automatically as described above.
You can close your account yourself. Sign in at gateflow.vip, open Account settings, and choose Close this account. GateFlow shows you exactly what is removed and what has to be kept before anything happens, and asks for your password to confirm. Closing removes the account profile and its sign-in details, including any Google or Microsoft link, and ends every session on every device. Nothing on your own computer is touched and no running event is stopped.
Two things pause self-service closure, and both clear on their own. A payment that has not finished yet has to settle or be cancelled first, so a licence key can never be issued to a closed account. A licence you have paid for and never activated stays available until its activation deadline; activate it and you can close straight after. An account that signs in only with Google or Microsoft has no GateFlow password to confirm with, so email hello@gateflow.vip from the account's own address instead. You can also write to that address at any time to ask what we hold about you.
Some records cannot be deleted on request. Payment and receipt records, and the licence records tied to them (which licence key was issued, for what capacity, to which account, and where it was activated), are kept for the statutory Egyptian accounting and tax retention period and are deleted when it ends. Security and audit records are permanent. They are the tamper-evident trail of what happened to a purchase, a licence or an account, so they cannot be edited or deleted by anyone, including us. Your email address appears in them only as an unreadable one-way code, never as readable text.
For privacy or support requests, contact hello@gateflow.vip. Email is answered Sunday to Thursday, 10:00 to 18:00 Cairo time, excluding Egyptian public holidays.