Overview
Disrupt Dev LLC d/b/a Gate Booker ("Gate Booker," "we," "us," or "our") provides software for coordinating vendor truck arrivals at job sites, venues, and loading docks. This Privacy Policy explains what we collect, why we collect it, how long we keep it, who helps us process it, and your choices — including SMS messaging and California / EEA-UK rights.
This document is a practical baseline for product and carrier review. It is not a substitute for counsel review before production reliance or enterprise contracting.
Who is responsible
For Gate Booker-operated accounts and our public marketing site, Gate Booker is the controller (or "business" under CCPA). When a venue or organization configures Gate Booker for its docks, that organization may also act as an independent controller for booking and gate data it collects through its dispatch links. Contact the venue for questions about their site rules; contact us for questions about how the platform processes data.
Information we collect
- Account and organization data — name, email, organization name, roles, and authentication identifiers when coordinators sign up or are invited.
- Booking data — driver name, mobile number, license plate, company name, selected arrival slot, booking status, and gate check-in events.
- One-shot location check-ins — when a vendor taps I’m here (web manage link or vendor app) after explicit location consent, we capture a single latitude/longitude pair to verify they are inside the mapped staging zone. We do not track location in the background.
- SMS and messaging metadata — message body or template identifiers as needed to deliver service, delivery status, inbound keyword replies (for example C, N, LATE, STOP, START), consent records, and timestamps.
- Usage and device data — standard web logs (IP address, user agent), analytics events, and error diagnostics to keep the service reliable and secure.
- Payment metadata — billing email, plan, and payment-provider customer/subscription identifiers; card numbers are handled by our payment processor and are not stored by Gate Booker.
Why we process data (lawful bases)
Where GDPR or similar laws apply, we rely on: (1) performance of a contract — operating accounts, bookings, QR passes, and gate verification you request; (2) legitimate interests — securing the Service, preventing abuse, measuring reliability, and improving features in ways that do not override your rights; (3) consent — optional SMS transactional messaging and optional one-shot GPS check-ins; and (4) legal obligation — retaining records needed for tax, dispute, or regulatory requests. You may withdraw consent for SMS or location without affecting the lawfulness of prior processing.
How we use information
We use personal information to confirm dock arrival slots, deliver QR gate passes by SMS when you opt in, send schedule changes, authenticate users, verify staging-zone check-ins, bill subscriptions, improve performance, investigate abuse, and comply with law.
We do not sell personal information for money. We do not send marketing SMS without separate express consent. We do not use I’m here coordinates for advertising.
SMS messaging
Transactional text messages are sent only after you provide a mobile number and explicitly check the SMS consent box on our web forms. Consent is optional — you can complete a booking without receiving texts. See /policies/opt-in for collection methods. You may opt out anytime by replying STOP or visiting /policies/opt-out.
After you opt out, we will not send further SMS to that number until you opt in again on a Gate Booker web form (new booking or equivalent consent checkbox). Replying START after STOP does not by itself restore messaging; web re-consent is required. See /policies/opt-out.
Mobile Information Non-Sharing
No mobile information will be shared with third parties/affiliates for marketing or promotional purposes. All the above categories exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties.
Text messaging originator opt-in data and consent will not be shared with any third parties/affiliates.
California privacy (CCPA / CPRA)
If you are a California resident, you have the right to know, access, correct, and delete personal information we hold about you, and to not be discriminated against for exercising those rights. You may also limit use of sensitive personal information where applicable.
Do Not Sell or Share: We do not sell personal information as "sale" is commonly understood (exchanging data for money). We also do not "share" personal information for cross-context behavioral advertising. If that practice changes, we will update this policy and provide a clear opt-out. To exercise CCPA rights, email our support team with the subject line "California Privacy Request" and enough detail for us to verify your request.
EEA / UK rights (GDPR)
Subject to applicable law, you may request access, rectification, erasure, restriction, portability, or objection to processing based on legitimate interests. Where we rely on consent, you may withdraw it at any time. You may lodge a complaint with your local supervisory authority. Contact our support team to exercise these rights.
Sharing and subprocessors
We share data with service providers that process it only as needed to operate Gate Booker, under contractual confidentiality and security obligations. High-level categories and current providers include:
- Cloud hosting and database — application hosting and managed PostgreSQL with geospatial support.
- Authentication — identity and organization access provider.
- Payments — payment processor.
- SMS delivery — SMS messaging provider when messaging is enabled.
- Transactional email — email delivery provider.
- Maps / geocoding — mapping and geocoding providers as configured.
- Product analytics — product analytics tooling.
- Error monitoring — application error monitoring.
We may also disclose information if required by law, to protect rights and safety, or in connection with a merger, financing, or sale of assets (with notice where legally required). Venue coordinators see booking and check-in data needed to run their docks.
International transfers
We and our subprocessors may process data in the United States and other countries. Where required, we use appropriate transfer mechanisms (such as Standard Contractual Clauses) with subprocessors. Ask our support team for a current transfer summary if you need it for a vendor assessment.
Retention
We keep personal information only as long as needed for the purposes above, then delete or de-identify it. Unless a longer period is required for a legal hold, dispute, or security investigation, our baseline TTLs are:
- License plates — 180 days after the related booking ends or is canceled.
- I’m here GPS coordinates — 90 days after the check-in event.
- SMS message content and delivery metadata — 24 months (compliance and dispute support).
- SMS consent and opt-out / suppression records — retained while the number is suppressed, and for 24 months after a later web re-consent or permanent deletion request is completed.
- Active account and organization profile data — for the life of the account, then up to 30 days after a verified deletion request (backups age out on a rolling schedule).
- Booking operational history (without plate/GPS fields above) — up to 24 months unless the organization requests earlier deletion where feasible.
Security
We use industry-standard safeguards including encrypted transport (HTTPS/TLS), access controls, and webhook signature verification for payment and messaging providers when secrets are configured. No method of transmission or storage is perfectly secure; report suspected incidents to our support team.
Cookies and similar technologies
We use essential cookies for authentication and security, and limited analytics tooling to understand product usage. Browser controls can block some cookies; doing so may affect sign-in or session features.
Children
Gate Booker is a business service and is not directed to children under 16 (or under 13 where that higher standard applies). We do not knowingly collect children’s data.
Changes
We may update this policy from time to time. Material changes will be posted on this page with an updated effective date. For significant changes that require consent under applicable law, we will request consent where required.
Contact and data subject requests
Privacy and data subject requests (access, deletion, correction, Do Not Sell/Share): our support team. Include your name, the email or mobile number tied to the records, and the request type. Signed-in coordinators may also submit a support request from the Gate Booker account. We will verify requests and respond within the timeframes required by applicable law (generally 45 days under CCPA, subject to permitted extensions).
Related policies
- /policies/terms — Terms of Service
- /policies/opt-in — SMS Opt-In Policy
- /policies/opt-out — SMS Opt-Out