Privacy policy
SeloGate opens gates. This page says what we keep in order to do that, who else receives any of it, and how to have it deleted. It covers the SeloGate app and the web app, for residents, gate managers, and installers.
What we keep about you
- Your phone number and your name. Your mobile number is your account — it is how we identify you and how access to a gate is granted to you, and we send a one-time code to it by SMS to sign you in. The app also asks you to choose a name before you can use it.
- Your sessions. Which devices are signed in, when each was last used, and a value that ties a session to the device that started it. At most three sessions are live at a time.
- Your access. Which gates you may open, your role at each, any validity window or schedule attached to it, and the label a gate's manager may write next to your name.
- The gate's location — its own section below.
- The gate-open log — its own section below.
- Your view of the app. A nickname, icon, colour, and tile order you give a gate. These are yours alone; other people at the same gate do not see them.
- Installation records, for installers — which gate was provisioned, when, and how it went.
- Technical data. App version, device or browser type, IP address, and language. The IP address is used to limit abuse of the service. We never use it to work out where you are.
The gate's location
Every gate has an address, entered when it is installed. Where the installer's device allows it, we also store the gate's precise coordinates, captured once from that device while the installer is standing at the gate.
- The position is stored for the gate, not tracked for the person. We do not follow your device, infer where you are or whether you are home, and we run no geofencing. Opening a gate through the app is not treated as evidence of where anyone was.
- The device's position is read once, at that moment during the installation, and never again.
- The installer can always type the address instead. Declining the location permission does not stop an installation.
- Coordinates are shown to that gate's managers only — never to residents.
- Where a gate is a private home, we treat its address and its coordinates as personal information.
The gate-open log
Every open is recorded: who opened which gate, when, over which connection, whether it was allowed or refused and on what ground, and how long the command took. Changes to a gate's operating state are recorded the same way.
Who can read it. You can see your own activity. A gate's managers can see that gate's log, because an access-control product has to be able to say who opened a gate. Nobody at SeloGate holds a standing right to read residents' data in the live service; access to it is scoped and audited.
How long we keep it. We keep this log for 12 months. Each entry is stamped with its own expiry when it is written, so it goes on schedule rather than when someone remembers to run something. Backup copies run on their own clocks, and they run longer: point-in-time recovery for 35 days, scheduled backups for up to 90 days, and a monthly archival copy kept for up to 12 months. A monthly copy taken shortly before an entry expires holds that entry for a further year, so an entry can sit in an archival copy for just under 24 months from the open it records. Backup copies are put beyond use — not searched, not read, not used for anything else — and are erased as those windows run out. Deleting your account removes your record from it — see below.
Before you have an account
A gate's manager grants access by mobile number, and they can do that before the person they are inviting has ever used SeloGate. When they do, we store that number against the gate, together with the role and any validity window, so that the access is already waiting when the person signs in with it. So we may hold your mobile number before you have an account and before you have heard of us.
We do not contact you about it. SeloGate sends nothing to a number that has been invited — the manager tells you themselves, through whatever they normally use. The only message we ever send to a number is the one-time sign-in code, and only when you have asked to sign in.
Telling you is the manager's obligation, not their courtesy. Our terms require a manager to have a lawful basis for adding anyone, to tell each person they have given access to SeloGate and that we hold their number to honour it, and to point them at this page. That is how you are meant to hear about it, and it is written down as a term rather than assumed.
What happens if nobody accepts. The invitation expires 30 days after it is made and is shown to the manager as expired. The record is kept rather than deleted, so that an invitation cannot vanish from a gate's history without a trace, and it stays revocable by the manager at any time.
Having it removed. Ask the manager who invited you to revoke it, or write to [email protected] — we can find an invitation by the number it was made to, and we can remove it even though you have no account with us.
Who else receives any of this
- Amazon Web Services hosts the service, in Frankfurt, Germany (eu-central-1). Everything above is stored there.
- Inforu delivers the one-time sign-in code by SMS on our instruction, and your mobile operator carries it to your phone. Your number and the code itself are what reach them.
-
Google. While a gate is being installed, the address the installer
types into the search box is sent from their browser directly to
Google, which suggests matching addresses. If the gate's position has
already been captured on that device, it is sent along with the text to bias the
suggestions. Google receives this in the United States, and it
acts as its own controller under its own terms rather than on our instruction —
so this is a sharing of data, and we name it here. Typing the address without using
the search box sends Google nothing at all.
The ground we rely on for it is our legitimate interest in siting a gate accurately at the moment it is installed, on a request the installer starts by typing. Because the United States has no adequacy recognition here, this transfer is made under the Privacy Protection Regulations (Transfer of Data to Databases Abroad), 2001. We name the instrument rather than describe it, and we would rather state the ground we are relying on than leave it to be inferred. - The gate vendor's message service. Opening a gate over the internet sends the gate's code and the command through a message broker operated by the gate hardware's vendor, which is how it reaches your gate.
We do not sell personal data, and we share none of it for advertising or for anyone else's own purposes beyond what is named here. One exception, stated rather than implied: we may disclose data where the law requires it — to a court, a regulator, or another authority acting under a legal power — or where it is needed to establish or defend a legal claim, including against someone who is abusing the service. We would rather say that here than promise something a court order would break.
What we do not do
- No tracking. There is no advertising identifier, no cross-app or cross-site tracking, and nothing in SeloGate is linked to data from anyone else for advertising or measurement.
- No analytics and no crash reporting. The app carries no analytics service, no session recording, and no crash-reporting service.
- No address book upload. When you invite someone, you may pick contacts from your phone instead of typing numbers. On iPhone and iPad this uses Apple's own picker and the app never reads your contacts at all. On Android, if you choose to invite several people at once, the app asks your permission and then reads your contacts — names and phone numbers only — to show you a list to choose from. That list exists only while it is open and is discarded the moment you close it: it is never saved on your device and never sent to us. Only the numbers you actually select reach us, exactly as if you had typed them. Picking a single contact asks for nothing on either phone, and if you decline the request you are simply returned to that single-contact picker.
- No camera images. Scanning a gate's QR sticker decodes it inside your browser. No frame, image, or video ever reaches us.
- No presence detection over Bluetooth. Your phone can open a gate directly over Bluetooth when it is in range, without going through the internet. That connection carries the gate's own credential and the open command — nothing about you — and it is never used to work out where you are or whether you are nearby.
- No continuous or background location, and no marketing messages.
Cookies, and what the app keeps on your device
SeloGate uses no cookies at all — not on this website, not in the app. There is no advertising cookie, no analytics cookie, and no cookie banner, because there is nothing to ask you about.
The app does keep things on your own device, so that it can start without a network and so that you are not asked to sign in again every time:
- The app itself — its pages, code, styles, fonts, icons, and translations, saved so it opens with no reception. These are the same public files anyone downloads; nothing about you is in them.
- Your sign-in — the token that keeps you signed in and the value that ties it to this device. On the app installed from a store these live in the device's own secure storage (Keychain or Keystore).
- A copy of your gate list, so Home appears immediately and can be read offline. It holds what that screen shows and no more — a gate's coordinates are never part of it.
- Anything the app did over Bluetooth while offline, held only until it can be handed to the activity log, then deleted.
- Your display preferences — light or dark, how Home is laid out, which opening animation you chose.
All of it stays on that device and is readable only by SeloGate on it. None of it is sent anywhere for advertising or measurement, and none of it is shared between your devices. Signing out clears your sign-in and your gate list; deleting the app, or clearing the site's data in your browser, removes the rest.
Children
Our terms set a minimum age of 18 to hold an account. We do not check anyone's age — there is no age field and no age check, and the app has no way to tell whether a person using it is an adult or a minor, so we may hold data about a minor without knowing it. Where a gate manager grants access to a minor, any consent that requires is the manager's to obtain — our terms say so as a term, not as a description — and we do not treat their grant as our own verification of anyone's age. Those terms also provide that a person under 18 who uses SeloGate does so with their parent or guardian's consent. That is a term and not a check, and this page would rather say which of the two it is.
Deleting your account
You can delete your account from inside SeloGate, and it is permanent — see how to delete your account. Your profile, your memberships and your personal views go; your history is anonymised.
One record survives on purpose, and only one: a note that a deletion happened, holding no phone number and no name, so that restoring a backup can never bring your data back. It exists to keep the deletion true, and it identifies nobody.
Your phone number goes as well. It is removed from the sign-in directory that sends your login codes, so it stops working as a way in. If you ever come back and sign up again with the same number, that is a new account with nothing of the old one attached to it.
Asking us about your data
You can ask to see what we hold about you, to correct it, or to have it erased. Write to contact@selogate.com. We may need to check that you control the phone number the account is on before we act on a request.
The law sets a 30-day limit for answering a request like this. We are stating the limit the law places on us, not adding a service promise of our own on top of it.
Two things we say plainly
Opening a gate through the app is not proof that anyone was physically at the gate. The log records that a command was sent and what the gate answered, and nothing more.
Setting a gate to stay closed stops the app. It does not stop someone holding a physical remote.
If you manage a gate
A manager decides who may open a gate and adds them by mobile number, so a manager puts other people's details into SeloGate. Our terms set out what that commits you to: a lawful basis for each person you add, telling them, obtaining any parental or guardian consent where you give access to someone under 18, keeping what you see about other people confidential, and using it only to run the gate.
If you are a management company and need a data processing agreement, ask us at contact@selogate.com and we will send you one.
Who we are, and how to reach us
SeloGate is operated by ERAN SINGER PROJECT MANAGEMENT LTD (in Hebrew, ערן זינגר ניהול פרויקטים בע"מ), a company registered in Israel under company number 516746187, of Hatam Sofer 4, Herzliya, Israel. The SeloGate apps are published on the App Store and Google Play under individual developer accounts held on the company's behalf, so a store listing shows a person's name as the seller; we say so because you may see both. We are the party responsible for the data described on this page.
Questions, and requests about your data, go to contact@selogate.com. You can also call support on 072-2511605, Sunday to Thursday, 08:30–16:00 Israel time.
If this page changes, the date at the top changes with it.