GibGate ("we", "us", "the app") is published by Digital Nafta, Terrassa, Spain. This policy explains what data we collect, what we don't, and why. The app is fully GDPR-compliant.
1. Data We Do Not Collect
GibGate does not collect, store, or transmit:
- Your name, email, phone number, or any account information
- Your location (the app does not request location permissions)
- Your contacts, photos, calendar, or any device data
- Any personally identifiable information (PII)
- Analytics, crash reports, or device identifiers
- Third-party tracking cookies or SDKs
There is no login, no account, no profile. The app works fully anonymously.
2. Data Stays On-Device
Crossing preferences, notification settings, and personalized routines are stored locally on your iPhone, iPad, or Apple Watch using iOS UserDefaults and CoreData. None of this data ever leaves your device.
3. Data We Process
The app fetches the Gibraltar airport runway schedule from https://gibgate.digitalnafta.com/api/*. Each request includes only:
- Your device IP address (visible in server logs for 30 days, used solely for abuse prevention; never linked to identity)
- A generic User-Agent string identifying the app version
No request body, query, or identifier is stored beyond the standard nginx access log retention (30 days).
4. Third-Party Data Sources
To predict crossing times, the backend consults the published LXGB airport schedule and the public OpenSky Network ADS-B feed. No data about you is shared with these sources.
5. In-App Purchases
The optional one-time GibGate Pro €7.99 In-App Purchase is processed entirely by Apple via StoreKit 2. We never see your payment details, receipt, or Apple ID. Family Sharing is enabled — one purchase covers up to 6 family members.
6. Push Notifications
If you opt in, the app schedules local notifications (calculated on-device from the runway schedule). We do not use Apple Push Notification service to send anything from our servers.
7. Children's Privacy
GibGate is rated 4+ and contains no content directed at children, no advertising, no user-generated content, and no chat features. We do not knowingly collect data from anyone, including children under 13.
8. Data Retention & Security
nginx access logs are rotated every 7 days and purged after 30 days. The server is hosted on a private VPS, and the HTTPS endpoint uses Let's Encrypt TLS 1.3.
9. Your Rights (GDPR / CCPA)
Since we do not collect personal data, there is nothing for us to delete, export, or modify. If you are concerned about your IP address in our 30-day server logs, email support@digitalnafta.com with your approximate request time and we will purge those entries.
10. Changes to This Policy
We will update this page if our practices change. The "Last updated" date at the top reflects the most recent change.
11. Contact
Digital Nafta · Terrassa, Spain · support@digitalnafta.com