Legal

Privacy Policy

Last updated: March 20, 2026

1. Who we are

Gategram is a brand of COMMIT MEDIA SARL, a company registered in Luxembourg (registration number LU34811132), with its registered office at 147 route de Thionville, L-2611 Luxembourg.

Contact: bob@openletz.com

2. Data we collect

We collect the minimum data necessary to operate the service:

  • Telegram user data: Your Telegram user ID, username, and first name, provided by the Telegram Mini App SDK when you open Gategram. We do not access your phone number, contacts, or message history.
  • Creator profile data: Legal name, email address, country, and payout details (IBAN or PayPal email), provided voluntarily when you set up payouts.
  • Transaction data: Purchase records including product ID, buyer ID, amount paid, payment method, and timestamp.
  • Usage data: Page views and interaction events via Google Analytics (anonymized, no personal identifiers).

3. How we use your data

  • To authenticate you via Telegram and provide access to the service.
  • To process purchases and deliver paid content to buyers.
  • To calculate and process creator payouts.
  • To generate invoices for payout accounting.
  • To prevent fraud, abuse, and duplicate transactions.
  • To improve the service through anonymized analytics.

4. Data storage and security

Your data is stored in a Turso (libSQL) database hosted in the EU (AWS eu-west-1, Ireland). All data is encrypted in transit (TLS) and at rest. We do not store payment card details — payments are handled by Telegram (Stars) and Stripe.

Authentication uses Telegram's HMAC-SHA256 initData validation with timing-safe comparison and replay protection.

5. Data sharing

We do not sell your data. We share data only with:

  • Telegram: For payment processing via Stars.
  • Stripe: For card payment processing (when enabled).
  • Google Analytics: Anonymized usage data only.

6. Your rights

Under GDPR, you have the right to access, rectify, delete, or export your personal data. You can also object to processing or request restriction.

To exercise these rights, contact us at bob@openletz.com. We will respond within 30 days.

7. Data retention

Transaction records are retained for the duration required by Luxembourg tax law (10 years). Creator profiles are retained while the account is active and deleted upon request. Processed webhook update IDs are retained for 3 days and then automatically purged.

8. Cookies

Gategram does not use cookies for tracking. We use sessionStorage to cache your Telegram authentication token for the duration of your session. Google Analytics may set its own cookies according to its own policy.

9. Changes to this policy

We may update this policy from time to time. Changes will be posted on this page with an updated date. Continued use of the service constitutes acceptance of the revised policy.