Effective date: July 17, 2026 · Last updated: July 17, 2026
Operated by Moonbeam Catcher LLC ("Moonbeam Catcher," "we," "us," or "our"). This Policy applies to GatewayBase (gatewaybase.app) and related services.
This Privacy Policy explains what personal information we collect, how we use it, how we share it, how long we keep it, and the choices you have. It should be read together with our Terms of Service.
Controller. For personal information processed in connection with GatewayBase, Moonbeam Catcher LLC is the business / data controller, unless a specific notice says otherwise. Contact details appear in Section 15.
This Policy covers personal information processed when you visit our websites, create an account, place an order, use formation, registered-agent, EIN, tax-form, dashboard, billing, support, or related features, or communicate with us.
It does not cover third-party websites or services that we do not control, even if linked from the Service. Government agencies (such as the IRS or a secretary of state) process information under their own rules once a filing or transmission reaches them.
We collect information in three main ways: (1) you provide it; (2) it is collected automatically from your device or browser; and (3) it comes from service providers or partners that help us operate the Service.
2.1 Information you provide
2.2 Information collected automatically
2.3 Information from third parties
Some of this information may be considered sensitive under certain laws (for example, government identifiers or precise financial account details you enter into forms). We process that information only as needed to provide the Service you request, to comply with law, or as otherwise described in this Policy.
We use personal information to:
We do not use your filing contents to train public generative AI models. If we use automated tools internally to help operate or improve the Service, we apply access controls and purpose limits consistent with this Policy.
If you are in the European Economic Area, United Kingdom, or another region that requires a legal basis for processing, we rely on one or more of the following, as applicable:
If you are a California resident, this section supplements the rest of this Policy.
Categories collected (as defined under California law) may include: identifiers; customer records information; commercial information; internet or electronic network activity; geolocation data (approximate); professional or employment-related information you choose to provide; and sensitive personal information such as government identifiers or account login credentials, to the extent you provide them or they are needed for the Service.
We use sensitive personal information only to provide the Service, prevent fraud/security incidents, and comply with law—not to infer characteristics about you for unrelated profiling.
Sale / share: We do not sell personal information for money. We also do not "share" personal information for cross-context behavioral advertising as those terms are defined under the CCPA/CPRA, except to the extent a specific advertising cookie or pixel is treated as a "share" under that law. Where such technologies are used, you may use browser controls, industry opt-out tools, and any in-product controls we provide. We do not have actual knowledge that we sell or share the personal information of consumers under 16.
Your rights: Subject to exceptions, California residents may request: (1) to know / access personal information; (2) to delete personal information; (3) to correct inaccurate personal information; (4) to receive a portable copy of certain information; and (5) to opt out of sale or sharing, if applicable. We will not discriminate against you for exercising these rights.
To submit a request, contact us as described in Section 15. We will verify your identity to a reasonable degree of certainty before fulfilling a request. You may use an authorized agent subject to our verification requirements.
We are based in the United States and process information primarily in the United States. If you access the Service from outside the United States, you understand that your information may be transferred to, stored in, and processed in the United States and other countries that may not provide the same level of data protection as your home country.
Where required, we use appropriate transfer mechanisms (such as Standard Contractual Clauses or a provider's certified transfer framework) for transfers from the EEA/UK or other restricted regions.
We keep personal information only as long as needed for the purposes described in this Policy, including to:
When information is no longer needed, we delete it or de-identify it, except where retention is required or permitted by law, or where deletion would impair the integrity of backups until they rotate in the ordinary course.
Company profiles may be soft-deleted in-product while residual billing, filing, or legal records remain as required. Account-level deletion requests are handled through support as described in Section 10.
We use technical and organizational measures designed to protect personal information, including access controls, encryption in transit where supported, and least-privilege practices for staff and systems. No method of transmission or storage is completely secure. You are responsible for protecting your login methods and for using a secure device and network.
If we become aware of a security incident that requires notice under applicable law, we will notify you and/or regulators as required.
Depending on your location, you may have the right to request access, correction, deletion, restriction, objection, or portability of your personal information, and to withdraw consent where processing is based on consent. You may also have the right to lodge a complaint with a supervisory authority in your country of residence.
To exercise these rights, contact us through the Help Center or using the details in Section 15. We may need to verify your identity and may deny requests as permitted by law (for example, where information must be kept for legal compliance, fraud prevention, or ongoing services you still use).
You can update certain account and company fields directly in the dashboard. You can stop optional marketing emails using the unsubscribe link in those emails. Transactional and service messages related to your account or filings may still be sent.
The Service is directed to adults and businesses. We do not knowingly collect personal information from children under 16 (or under 13 where that is the applicable standard). If you believe a child provided personal information, contact us and we will take appropriate steps to delete it.
Some browsers send "Do Not Track" signals. There is no common industry standard for responding to those signals. Outside of mechanisms described in this Policy (and any consent or opt-out tools we provide), we do not currently respond to Do Not Track signals in a differentiated way.
We may update this Policy from time to time. We will post the updated Policy on this page with a new effective date. If changes are material, we will provide additional notice as required by law (for example, by email or in-product notice). Continued use of the Service after the effective date means you acknowledge the updated Policy, except where a different form of consent is required.
Moonbeam Catcher LLC
Attn: Privacy / GatewayBase
919 Garvey Ave, Ste C2 # A139
Rosemead, CA 91770
United States
Privacy and support requests: support.gatewaybase.app
Operations email: [email protected]
For privacy requests, include the email address on your account and a clear description of your request so we can verify and respond.