Privacy policy

Last updated 9 August 2026.

Who is responsible

GatewayCompare.com, 150C Jellyfish Avenue, Vista Del Mar, Belize District, Belize, is the controller for personal data collected through this site. Data protection enquiries: [email protected].

What we collect, and why

DataPurposeLawful basisRetention
Introduction requests
name, email, company, requirements
Sending your details to a payment provider you asked to be introduced to Consent (Art. 6(1)(a)), given explicitly and confirmed by email 24 months, then the personal data is destroyed
Matching answers Producing your shortlist and keeping the shareable result page working Legitimate interest (Art. 6(1)(f)) — you asked for the result Indefinitely, but it contains no personal data unless you signed in
Account details
email, name, company
Operating the provider portal Contract (Art. 6(1)(b)) While the account exists, plus 12 months
Contact and report messages Replying to you, and correcting our data Legitimate interest 24 months
Hashed IP address Rate limiting and abuse prevention Legitimate interest Hashed on collection and never reversible; counters expire within hours

What we do not do

  • No advertising or analytics trackers. No Google Analytics, no pixels, no third-party scripts beyond the anti-spam widget on forms.
  • No cookie banner, because we set no non-essential cookies. The only cookie is your session, and only once you sign in or submit a form.
  • We never sell personal data, and we never pass your details to a provider without your explicit, confirmed request.

How your data is protected

Contact details in introduction requests are encrypted at rest using authenticated encryption (libsodium crypto_secretbox). IP addresses are stored only as salted one-way hashes. Everything is served over TLS. Access to production data is limited to people who need it.

Who processes data for us

  • Mailgun (Sinch) — transactional email delivery.
  • Cloudflare — content delivery, TLS, and bot protection on forms.
  • Hetzner — server hosting, EU region.

Where a processor is outside the EEA, transfers rely on Standard Contractual Clauses.

Your rights

Under the GDPR you may request access to your data, correction, erasure, restriction, portability, or object to processing based on legitimate interest. Where processing is based on consent, you may withdraw it at any time — this does not affect what happened before.

Email [email protected]. We respond within one month. You also have the right to complain to your national supervisory authority.

Provider data

Information about payment providers — company names, fees, licences — is business information, not personal data, and is published in the public interest. Where a register entry names an individual we omit it. If you believe we hold personal data about you in a provider record, contact us and we will remove it.