Data Protection & Privacy

Privacy Policy

Effective Date: January 1, 2026 | Last Updated: April 5, 2026

What This Means for You at a Glance

We collect only what is needed to provide our services.
We never sell your data
You control your privacy choices
Your data is encrypted and stored securely on infrastructure provided by SOC 2 certified providers including AWS and Cloudflare

1. Introduction

Gateway Lines ("Gateway," "we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our services, platform, applications, or visit our website at gatewaylines.com and its subdomains. This policy applies to all users including customers, visitors, API users, and Anchor Miles Club members. Please read this privacy policy carefully. If you do not agree with the terms of this privacy policy, please do not access our services.

2. Information We Collect

2.1 Personal Information

We collect information that identifies you, including:

  • Name, company name, and job title
  • Email address and phone number
  • Billing and shipping addresses
  • Federal Tax ID / EIN and business registration details
  • Payment information (processed securely through Square — Gateway does not store credit card numbers)
  • Shipping and cargo details including commodity descriptions, HS codes, cargo values, weights, and dimensions
  • Importer/exporter identification numbers
  • Customs documentation including ISF data, commercial invoices, packing lists, and powers of attorney
  • Beneficial ownership information for corporate accounts (per KYC requirements)
  • Anchor Miles Club enrollment data and reward activity
  • Communications with Gateway including Poseidon conversations, support tickets, and emails
  • Referral information when participating in the AMC referral program

2.2 Automatically Collected Information

When you visit our website or use the Gateway platform, we automatically collect:

  • IP address, browser type, and language preference
  • Device information and operating system
  • Pages visited, features used, and time spent
  • Referring website addresses
  • Cookie and tracking data
  • API usage logs and request metadata
  • Poseidon Desktop application usage data (if installed)
  • Geolocation data (country/region level only, not precise location)
  • Platform interaction data including searches, quotes requested, and bookings initiated

3. How We Use Your Information

We use collected information for the following purposes:

Service Delivery

Process shipments, bookings, customs coordination, cargo insurance, and provide logistics services through our platform and carrier partners

Communication

Send shipment status updates, arrival notices, delivery notifications, and respond to support inquiries including through Poseidon

Billing

Process payments through Square, manage invoices, track outstanding balances, and administer credit accounts

Compliance

Screen parties against OFAC, BIS, and other restricted party lists, perform KYC verification, maintain records per FMC and CBP requirements, and report suspicious activities as required by law

Platform Improvement

Analyze usage patterns to enhance our services, improve Poseidon AI responses, optimize platform features, and develop new tools

Anchor Miles Club

Calculate and track nautical miles, manage tier status, process reward redemptions, and administer the referral program

Carbon Insetting

Calculate CO₂ emissions for Ship Green insetting purchases and generate certificates

Lead Qualification

Evaluate inquiries and Poseidon conversations to connect prospective customers with the appropriate Gateway services

Customs & Duties

Provide HS code suggestions, tariff estimates, and duty calculations through our tools and brokerage partners

Security

Detect and prevent fraud, unauthorized access, and abuse of the Gateway platform and API

Marketing

Send promotional materials, product updates, and industry news with your consent. You may opt out at any time

Analytics

Generate aggregated, anonymized insights about shipping trends, trade lanes, and platform usage. Aggregated data does not identify individual customers

4. Information Sharing and Disclosure

We may share your information in the following situations:

  • Ocean Carriers: MSC, CMA CGM, Hapag-Lloyd, ZIM, ONE, Yang Ming, and other carrier partners as necessary to book, transport, and track your shipments
  • Customs Brokerage: Our authorized customs brokerage partners for customs entry, clearance, ISF filing, and duty assessment
  • Cargo Insurance: Our insurance partners for quoting, underwriting, and processing cargo insurance policies and claims
  • Carbon Insetting: Our sustainability partners for processing insetting purchases and issuing certificates
  • Payment Processing: Square for processing payments and managing transactions. Square's privacy policy governs their handling of your payment data
  • Infrastructure Providers: AWS, Supabase, Cloudflare, and Vercel for hosting, data storage, content delivery, and platform operations
  • Port Authorities & Terminals: As required for cargo clearance, container pickup, and delivery coordination
  • Government Agencies: U.S. Customs and Border Protection, FMC, OFAC, FinCEN, and other regulatory bodies as required by law or in response to valid legal process
  • Legal Requirements: When required by law, subpoena, court order, or to protect Gateway's rights, property, or safety
  • Business Transfers: In connection with a merger, acquisition, reorganization, or sale of assets, your information may be transferred to the successor entity
  • Professional Advisors: Attorneys, accountants, and auditors as necessary for business operations
  • With Consent: With your explicit permission for any purpose not listed above

We do not sell, trade, or rent your personal information to third parties for marketing purposes. When sharing data with third parties for service delivery, we share only the minimum information necessary to complete the transaction.

5. Data Security

We implement appropriate technical and organizational security measures to protect your information:

Encryption

256-bit SSL/TLS encryption for all data in transit. Data at rest is encrypted using AES-256 encryption on all storage systems.

Access Control

Restricted access on a need-to-know basis with role-based permissions. Multi-factor authentication required for administrative access.

Monitoring

Continuous monitoring for unauthorized access, suspicious activity, and security anomalies.

Secure Storage

Infrastructure provided by SOC 2 certified providers including AWS and Cloudflare. Payment processing handled by PCI DSS Level 1 certified Square. Gateway does not store credit card numbers or full payment credentials.

API Security

All API requests require HTTPS encryption and authenticated API keys. Rate limiting and abuse detection are enforced.

Incident Response

In the event of a data breach that affects your personal information, Gateway will notify affected customers within 72 hours of discovery as required by applicable law and take immediate steps to mitigate the impact.

Despite our security measures, no method of electronic transmission or storage is 100% secure. While we strive to use commercially reasonable means to protect your information, we cannot guarantee absolute security.

6. Cookies and Tracking Technologies

We use cookies and similar tracking technologies to enhance your experience:

  • Essential cookies for website functionality
  • Analytics cookies to understand usage patterns
  • Preference cookies to remember your settings
  • Marketing cookies (with your consent)

When you first visit our website, you will be presented with a cookie consent notice. Essential cookies are required for site functionality and cannot be disabled. Analytics and marketing cookies are only activated after you provide consent where required by applicable law. You can also control cookies through your browser settings. Disabling cookies may affect website functionality.

Security & Bot Protection

We use the following services to protect our platform and ensure security:

  • Cloudflare Turnstile: Bot protection and human verification without intrusive CAPTCHAs
  • Cloudflare Security: DDoS protection, web application firewall, and threat detection
  • Vercel Analytics: Privacy-focused web analytics to improve user experience
  • Microsoft Clarity: Session recordings and heatmaps to understand how users interact with our platform. Recordings capture mouse movements, clicks, and scrolling behavior but do not capture text entered into password fields, payment forms, or other sensitive input fields. Recordings are anonymized and used solely for platform improvement
  • Google Analytics: Website traffic analysis and user behavior insights
  • IP & Bot Detection: Fraud prevention and security monitoring to protect against malicious activity
  • Sentry: Error tracking and performance monitoring to identify and fix issues

Do Not Track Signals

Our services do not currently respond to browser-based "Do Not Track" signals. However, you can control cookies through your browser settings and opt out of marketing communications at any time. For California residents, please refer to the California Privacy Rights section below for additional rights under the CCPA/CPRA.

7. Your Privacy Rights

7.1 General Rights

All customers have the following rights regarding their personal information:

Access: Request copies of your personal data that Gateway holds
Correction: Request correction of inaccurate or incomplete data
Deletion: Request deletion of your data, subject to legal retention requirements
Portability: Request your data in a machine-readable format for transfer
Opt-Out: Unsubscribe from marketing communications at any time
Restriction: Request limited processing of your data

To exercise any of these rights, contact privacy@gatewaylines.com. Gateway will respond to verified requests within 30 days.

7.2 California Residents (CCPA/CPRA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act and California Privacy Rights Act:

  • Right to Know: You may request that we disclose what personal information we have collected, used, disclosed, and sold in the preceding 12 months
  • Right to Delete: You may request deletion of your personal information, subject to certain exceptions required by law
  • Right to Opt-Out of Sale: We do not sell your personal information. If this practice changes, we will provide a clear opt-out mechanism
  • Right to Non-Discrimination: We will not discriminate against you for exercising your privacy rights
  • Authorized Agent: You may designate an authorized agent to submit requests on your behalf with proper written authorization

To submit a CCPA request, email privacy@gatewaylines.com with the subject line "CCPA Request" or call 844-542-8392.

7.3 European Residents (GDPR)

If you are located in the European Economic Area, United Kingdom, or Switzerland, you have additional rights under the General Data Protection Regulation:

  • Legal Basis: We process your data based on contractual necessity (to provide freight services), legitimate interest (platform improvement and security), legal obligation (regulatory compliance), and consent (marketing communications)
  • Right to Object: You may object to processing based on legitimate interest at any time
  • Right to Lodge a Complaint: You have the right to lodge a complaint with your local data protection authority
  • Data Transfers: Your data is transferred to and processed in the United States. We rely on appropriate safeguards for international transfers

7.4 Other State Privacy Laws

Residents of Virginia, Colorado, Connecticut, Utah, and other states with applicable privacy legislation may have similar rights to access, delete, correct, and opt out of certain data processing activities. To exercise any state-specific privacy rights, contact privacy@gatewaylines.com.

7.5 Verification

For your protection, we may need to verify your identity before processing any privacy request. Verification may require providing your name, email address, and account details matching our records. We will not fulfill requests that we cannot verify.

8. International Data Transfers

8.1 Service-Related Transfers

As an international logistics provider, we necessarily share your information with carriers, customs brokers, port authorities, insurance providers, and logistics partners in other countries to fulfill your shipments. The specific countries involved depend on your shipment origin and destination. By booking a shipment through Gateway, you consent to the transfer of your shipping data to parties in the applicable countries along your trade route.

8.2 Data Storage

All customer account data is processed and stored on servers located in the United States. Gateway does not store customer data on servers outside the United States. Our infrastructure providers (AWS, Supabase, Cloudflare) maintain US-based data centers for Gateway's operations.

8.3 Transfer Safeguards

When transferring data internationally for service delivery, Gateway takes the following measures:

  • Data shared with international parties is limited to the minimum necessary to complete the transaction
  • For transfers to countries outside the United States, Gateway relies on standard contractual clauses, data processing agreements, or other legally recognized transfer mechanisms where required
  • Carrier and partner data sharing is governed by industry-standard shipping documentation protocols and applicable international trade conventions

8.4 Data Protection Inquiries

For privacy inquiries from international jurisdictions, contact privacy@gatewaylines.com. Gateway will respond within 30 days and direct your inquiry to the appropriate representative for your region.

9. Children's Privacy

Our services are not intended for individuals under 18 years of age. We do not knowingly collect personal information from children. If we learn we have collected information from a child under 18, we will delete that information promptly.

10. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. For minor updates and clarifications, changes will be effective upon posting to this page with an updated "Last Updated" date. For material changes that significantly affect how we collect, use, or share your personal information, Gateway will provide 30 days advance notice via email to your registered address or through a notification in the Gateway dashboard. Your continued use of our services after the effective date of any changes constitutes acceptance of the updated policy. You are advised to review this Privacy Policy periodically.

11. Contact Us

If you have questions or concerns about this Privacy Policy, please contact us:

Privacy: privacy@gatewaylines.com

General: info@gatewaylines.com

Phone: 844-542-8392 (Mon-Fri 7am-6pm EST)

Gateway will acknowledge receipt of all privacy inquiries within 5 business days and provide a substantive response within 30 days.

12. API and Third-Party Integrations

12.1 API Data Processing

If you access Gateway services through our API, we process data transmitted through API requests including shipment details, cargo information, rate queries, and tracking requests. API usage logs including request timestamps, endpoints accessed, and response data are retained for 2 years for security and performance monitoring.

12.2 Third-Party Integrations

If you connect third-party systems to Gateway (such as ERP, e-commerce, or accounting platforms), we may process and transfer data exchanged through these integrations to provide our services. Gateway processes this data in accordance with this Privacy Policy.

  • You are responsible for ensuring that any data transmitted through integrations complies with applicable privacy laws
  • You are responsible for obtaining any necessary consent from your customers or end users before transmitting their data to Gateway through integrations
  • We do not control data practices of third-party applications you connect to Gateway. You should review their privacy policies separately
  • Gateway is not liable for data breaches or unauthorized access resulting from vulnerabilities in your third-party systems or integrations

12.3 API Security

  • API keys are confidential credentials and must not be shared with unauthorized parties, exposed publicly, or embedded in client-side code
  • You must immediately notify Gateway at api@gatewaylines.com if you believe your API keys have been compromised
  • Gateway reserves the right to revoke API keys immediately if unauthorized use or a security breach is detected
  • All API requests must use HTTPS encryption

13. Data Retention

We retain your data only as long as necessary to provide services, comply with legal obligations, resolve disputes, and enforce agreements.

  • Account & Shipping Data: Retained for the duration of your account plus 5 years after the last shipment per CBP and FMC record-keeping regulations (19 CFR 163). This includes shipment records, bills of lading, customs documentation, invoices, and booking confirmations.
  • Payment Data: Transaction records retained for 7 years per IRS requirements. Gateway does not store credit card numbers — payment credentials are held by Square in accordance with PCI DSS standards.
  • Poseidon & Support Data: Conversations with Poseidon and support tickets retained for 1 year, then automatically purged unless related to an active claim, dispute, or legal matter.
  • API Logs: API usage logs and request metadata retained for 2 years for security and performance monitoring.
  • Anchor Miles Club: Mile balances, tier history, and redemption records retained for the duration of your account plus 2 years after account closure or program termination.
  • Marketing Data: Retained until you unsubscribe or request deletion. Unsubscribe requests are processed within 10 business days.
  • Closed Accounts: Personal profile data is deleted within 90 days of account closure upon request. Shipping and customs records are retained per federal requirements regardless of account status.
  • Deletion Requests: You may request deletion of your personal data by emailing privacy@gatewaylines.com. Gateway will comply within 30 days, except where retention is required by federal law, regulatory obligation, active legal proceedings, or pending disputes. Gateway will inform you if any portion of your data cannot be deleted and the reason for continued retention.

14. Automated Decision-Making

We use algorithms and automated systems to process shipment data and assist with operational decisions including:

  • Risk scoring and delay prediction
  • Route optimization and carrier selection
  • Rate predictions and pricing calculations using machine learning models
  • Customs documentation preparation (filed through licensed customs brokers)
  • HS code suggestions and duty estimates
  • ETA predictions and shipment monitoring
  • Compliance screening against restricted party lists
  • Anchor Miles Club mile calculations and tier assignments
  • Poseidon AI responses and recommendations

Important: No automated system makes final binding decisions without human oversight for matters that materially affect your account, finances, or shipments. Automated outputs including rate quotes, HS code suggestions, duty estimates, and ETA predictions are estimates only and are subject to human review and confirmation before becoming binding.

Compliance screening matches that result in a potential denied-party hit are reviewed by Gateway personnel before any action is taken on your account or shipment.

Your Rights: You have the right to request human review of any decision made through automated processing that significantly affects you. Contact privacy@gatewaylines.com to request a review. Gateway will respond within 15 business days.

15. Third-Party Links

The Gateway platform and website may contain links to third-party websites, services, or tools including carrier portals, terminal websites, port authority systems, and government databases. Gateway is not responsible for the privacy practices or content of these third-party sites. We encourage you to review the privacy policies of any third-party site you visit through links on our platform.

16. SMS and Text Communications

If you provide a mobile phone number, you may receive shipment status updates, delivery notifications, and urgent alerts via SMS. By providing your mobile number, you consent to receiving these messages. Standard messaging rates may apply. You may opt out of non-essential SMS notifications at any time through the Gateway dashboard or by replying STOP to any message. Opting out of SMS does not affect legally required notifications which will be delivered via email or dashboard.

17. Do Not Sell or Share My Personal Information

Gateway does not sell or share your personal information for cross-context behavioral advertising as defined under the California Consumer Privacy Act. We have not sold personal information in the preceding 12 months and have no plans to do so.