Current service status. Premium checkout is embedded in Gateflow or hosted by Stripe, depending on configuration, and Gateflow activates access only after a signed provider confirmation. Google account access and transactional email are configurable, and the public homepage contains an OVGC Payments domain-verification request. A rewarded-video adapter for ayeT is configurable but disabled by default; while disabled, Gateflow does not load the ayeT SDK or request rewarded advertising. Publisher KYC and payout rails are separate from Premium checkout and remain subject to their own availability and review.
Who controls your data
The controller for Gateflow is CoinForge Capital Ltd., registration number 207122521. The registered-office address must be confirmed before this notice is used for a public launch.
Scope of this notice
This notice applies to visitors opening protected links, holders of personal or Premium accounts, publishers, administrators, people who submit a report, and users of Gateflow APIs. External destinations opened through Gateflow are controlled by their respective operators and have their own privacy notices.
Data we process
Email address, display and legal name where supplied, role, password hash where password access is used, session data, preferences, Premium status and account timestamps. If you choose Google, Gateflow also stores Google's stable account subject and verified email.
For signed-in personal accounts, Gateflow may store the protected-link identifier, first and most recent visit, visit count, last access state, history preference and links you deliberately mark as favorites. The dashboard does not store or expose the external destination URL as a favorite or history label, does not create a public profile and does not operate as a discovery feed.
Brand details, protected links, reusable link presets, creative uploads, wait-optimisation settings, optional API key metadata and internal notes.
Link and event type, a consented visitor identifier where enabled, signed-in user ID, two-letter country code resolved server-side, device class, source category, referring origin, experiment variant, assigned wait and event time. Raw IP addresses are not added to publisher analytics or shown to publishers. Gateflow does not intentionally store the full referring URL query.
Decision outcome, score band, safe reason codes, event time and pseudonymous relationships derived from access, account, device, order and payment signals. Correlation values such as IP address, email, device, payment instrument and order references are stored in the risk record as purpose-separated keyed HMAC pseudonyms rather than their raw values. Pseudonymisation reduces exposure but is not the same as anonymous data.
If ayeT is enabled and you separately allow advertising, Gateflow may process an opaque attempt identifier, placement and ad-slot identifiers, video result, provider conversion or transaction identifier, reward value, sandbox status and related timestamps. Gateflow is designed to send ayeT a random external identifier rather than your email or Gateflow account name. ayeT and participating advertising partners may receive network, browser, device and ad-interaction data as described in their own notices.
Subscription, revenue-share tier, ledger and payout configuration, including account holder, bank, BIC, IBAN or wallet details when supplied. Premium card payments are processed through the configured payment provider; publisher payouts remain subject to verification, approval and the selected payout rail.
Contact requests, URL reports, optional reporter email, reason, details, audit actions and security metadata.
Session tokens, CSRF values, optional API key hashes, short-lived OAuth state hashes, nonces and PKCE verifiers, waiting tickets, one-use redirect records, and transactional-email delivery status.
Why we process data
| Purpose | Typical data | Legal basis |
|---|---|---|
| Provide accounts, protected links, Premium access and requested payouts | Account, links, subscriptions and payout details | Performance of a contract or steps requested before a contract |
| Provide private history and favorites requested through a personal account | Account ID, protected-link ID, visit summary, favorite and history preference | Performance of the account service requested by you; legitimate interests in maintaining the feature securely |
| Secure the service, enforce waiting periods, prevent replay, assess fraud risk and investigate abuse | Session, audit, report, pseudonymous risk and security event data | Legitimate interests in operating a safe and reliable service, protecting users and preventing loss; legal obligations where applicable |
| Provide publisher analytics and improve link performance | Aggregated events, source, device and approximate country | Legitimate interests for minimal service measurement; consent for the persistent gf_visitor identifier |
| Offer an optional rewarded video and verify the time reduction, if enabled | Advertising consent, opaque attempt, ad-slot and signed provider result | Separate consent before loading the advertising integration where required; legitimate interests in fraud prevention and reconciliation may apply to necessary verification records |
| Maintain accounting, tax, KYC and compliance records when real providers are enabled | Identity, transaction and payout records | Legal obligations and performance of a contract |
| Respond to questions, rights requests and reports | Contact details and message content | Legitimate interests, legal obligations, or steps requested by you |
Gateflow does not sell personal data. Personal history and favorites are not shown to publishers; publishers receive aggregate performance information for their own links. No rewarded advertising is requested while the provider is disabled. If it is enabled, an optional video is offered only after the separate advertising choice described below; refusing it does not remove the ordinary free waiting route.
Retention
Google authentication flows expire after 10 minutes, are single-use and are purged after expiry or short operational retention. Account identity links remain while the account needs Google access. Transactional email delivery records are retained only for operational troubleshooting and service administration.
Personal history remains until you remove an item, clear the history or the associated account or protected link is deleted, subject to records Gateflow must separately retain for security or legal reasons. Disabling history stops new personal-history entries; favorites remain until you remove them or the associated record is deleted.
First-party risk-event records have a configurable routine retention period of 180 days by default. They may be deleted earlier when no longer necessary or preserved longer where a dispute, fraud investigation, legal hold, accounting rule or other legal obligation requires it. Changing the configuration does not override a valid preservation duty. HMAC pseudonyms remain personal data where Gateflow can use them to distinguish or correlate activity.
If rewarded video is activated, unfinished attempts should expire after a short operational period. Verified transaction, fraud-prevention and reconciliation records may need to remain longer to resolve duplicate callbacks, discrepancies or accounting claims.
Other operational records are retained according to account lifecycle, security needs, dispute windows and statutory accounting or KYC obligations. Data is deleted or anonymised when no longer required, unless applicable law or legal claims require longer retention.
Your privacy rights
Where the GDPR applies, you may request access, rectification, erasure, restriction, portability or object to processing. You may withdraw consent at any time without affecting earlier processing. Analytics and advertising choices are separate. Withdrawing advertising permission prevents future ayeT SDK requests from Gateflow, but does not necessarily erase records already required for security, reconciliation or legal claims. Gateflow may need to verify your identity before acting on a request.
Send requests to contact@coinforgecapital.net. You also have the right to complain to the Bulgarian Commission for Personal Data Protection (CPDP) or another competent supervisory authority. CPDP complaint information ↗
Security measures
The MVP uses password hashing, signed account sessions, opaque server-persisted waiting sessions, CSRF protection, HttpOnly cookies, one-use redirect tokens, strict URL scheme validation, access controls, security headers, audit records and purpose-separated HMAC pseudonyms for sensitive risk correlations. Google access additionally uses browser-bound state, nonce, PKCE and cryptographic ID-token verification; Google secrets and tokens are not exposed to the browser or stored as account credentials. No internet service is risk-free; production deployment also requires managed secrets, HTTPS, backups, monitoring, threshold calibration and provider security review.
Age limits and automated risk decisions
Gateflow accounts, Premium purchases and publisher payouts are intended for adults aged 18 or over. Adaptive waiting may assign a bounded experiment variant using source, approximate country, device and consented repeat-visit count to improve conversion. It does not price Premium and is separate from fraud controls.
Gateflow's first-party risk engine assesses categories such as request velocity; token, session and order integrity; authentication or unlock failures; account, device, payment-instrument and order relationships; approximate country; payment-provider evidence; dispute history; destination or traffic concerns; and administrator controls. It assigns one of four operational outcomes: allow, review, limit or block. Depending on the outcome and context, Gateflow may request additional authentication, pause or reject an attempt, quarantine a request or signed provider event before access is released, or place related earnings or a payout under proportionate review.
Rules and signals can be incomplete, delayed or wrong, and false positives and false negatives remain possible. Gateflow does not promise that the engine will prevent every fraudulent payment, malicious visit or account takeover, and third-party providers may make independent decisions. Where appropriate and legally permitted, an affected user or publisher may request human review through billing support; eligible appeals are not decided solely by the same automated signal. More detail is available in the Payments, Stripe & Publisher Payout Policy.
Changes and contact
Material changes will be reflected by updating the effective date and, where required, providing an additional notice. Questions can be sent to contact@coinforgecapital.net.
