Legal

Privacy Policy

Last updated: 29 July 2026

Summary: We collect only the data needed to deliver the GatePass service. We don't sell your data or use it for advertising. Attendance records are immutable and logged with a full audit trail. Questions? Email privacy@gatepasshq.com.

1. Who we are

GatePass is operated by GatePass Technologies Ltd ("GatePass", "we", "us", "our"). We provide a real-time gate check-in, attendance tracking, and visitor management platform for schools ("the Service").

If you have questions about this policy, contact us at privacy@gatepasshq.com.

2. What data we collect

We collect the following categories of data:

Account and organisation data: Organisation name, type, and country; administrator name and email address; billing contact information.

Staff and student data: Names, roles, class, and phone numbers for staff and students added to the platform by a school administrator.

Attendance and gate data: Timestamps and gate locations for every check-in and checkout event; late arrivals, sent-home events, boarding confirmations, and visitor check-ins.

Parent and guardian data: Phone numbers provided by the organisation, for OTP authentication once the GatePass mobile app is live; no additional personal data is required.

Visitor data: Name, purpose of visit, host name, and time in/out, as entered by the visitor at check-in.

Device and usage data: App version, device type, OS version, IP address, and session data for diagnostic and security purposes. We do not use this data for advertising.

3. How we use your data

We use the data we collect to:

  • Operate and deliver the GatePass Service, including processing gate scans, attendance records, and visitor logs
  • Send notifications to parents and managers (push notifications once the mobile app is live)
  • Generate attendance reports for organisation administrators
  • Authenticate parent users via OTP (once the GatePass mobile app is live)
  • Provide customer support
  • Detect, prevent, and investigate security incidents and misuse
  • Comply with legal obligations

We do not sell your data to third parties. We do not use your data for advertising.

5. Data sharing and third parties

We share data only with:

Infrastructure and hosting providers: We use managed cloud infrastructure (DigitalOcean) and object storage (Bunny.net) to operate the Service. These providers process data on our behalf under data processing agreements.

Push notification services: Firebase Cloud Messaging (Google) will be used to deliver mobile push notifications once the GatePass mobile app is live. Device tokens will be passed to Firebase for this purpose only.

Email providers: SendGrid or configurable SMTP will be used to send transactional email (invoices, account notices) once outbound email is enabled for our infrastructure; this is not yet live.

SMS/OTP providers: We use a third-party SMS gateway (currently Wesendall, Uganda) to deliver the one-time codes parents use to sign in to the mobile app. Your phone number and the code are passed to that gateway for delivery only. The code itself is generated and checked by GatePass, and is stored only in hashed form.

We do not share your data with advertising networks, data brokers, or analytics platforms.

6. Data retention

Our intended retention periods are:

  • Attendance and gate records: Retained for the duration of the organisation's active subscription plus 3 years, for compliance and dispute resolution purposes.
  • Visitor logs: Retained for 12 months by default. Organisations may request longer retention for compliance reasons.
  • Account and billing data: Retained for 7 years following account closure for financial compliance purposes.
  • Parent phone numbers: We aim to remove these within 30 days of the associated student being removed from the organisation's roster.

Automated enforcement of these periods (including timed deletion) is still being built. Until it ships, data may be retained longer than stated above; contact privacy@gatepasshq.com to request removal of specific data and we will action it manually.

7. Data security

We implement the following security measures:

  • All data is transmitted over TLS (HTTPS)
  • Databases are encrypted at rest
  • Access to production systems is restricted to authorised personnel only
  • Sensitive actions are logged in a tamper-evident audit trail
  • QR credentials are verified against live records on every scan, and can be cancelled immediately if lost
  • We have conducted a security review of the platform and intend to repeat this periodically as the platform grows

In the event of a data breach affecting your personal data, we will notify you as required by applicable law.

8. Your rights

Depending on your location, you may have the following rights:

  • Access: Request a copy of the personal data we hold about you
  • Correction: Request correction of inaccurate personal data
  • Deletion: Request deletion of your personal data (subject to retention obligations)
  • Portability: Request your data in a portable format
  • Objection: Object to certain types of processing
  • Restriction: Request that we restrict processing in certain circumstances

To exercise any of these rights, contact us at privacy@gatepasshq.com. We will respond within 30 days.

Note: For data held by an organisation on our platform (e.g. a school or employer), that organisation is the data controller. Requests relating to data entered by an organisation should be directed to that organisation in the first instance.

9. Cookies and tracking

The GatePass web dashboard uses cookies for:

  • Session management: Keeping you signed in across pages
  • Security: CSRF protection and fraud detection
  • Performance: Caching preferences and settings

We do not use advertising cookies, tracking pixels, or third-party analytics services that collect personal data across sites. You can control cookies through your browser settings, but disabling session cookies will prevent you from using the web dashboard.

10. Children's data

GatePass is used by schools to track student attendance. We recognise that this involves processing personal data relating to minors. We process this data strictly to deliver the attendance and notification service contracted by the school.

Schools are responsible for complying with applicable laws governing the processing of children's data (including GDPR Article 8, COPPA, or local equivalents) and for obtaining required parental consents.

We do not use student data for any purpose other than delivering the contracted service.

11. Changes to this policy

We may update this Privacy Policy from time to time. We will notify organisation administrators of material changes by email at least 14 days before they take effect. The current version is always available at gatepasshq.com/privacy.

This policy was last updated on 29 July 2026.

12. Contact

For privacy-related questions or to exercise your rights:

Email: privacy@gatepasshq.com General enquiries: hello@gatepasshq.com

GatePass Technologies Ltd Kampala, Uganda