Privacy Policy
Last Updated: August 21, 2026
Gammal Software, Inc. ("Company," "we," "us," or "our") respects your privacy and is committed to protecting your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website metadock.app and use the MetaDock desktop application.
Table of Contents
1. Information We Collect
Personal Information You Provide
- Email Address: When you request a trial key, subscribe to our mailing list, or contact us for support
- Contact Information: Name (optional) when provided in contact forms
- Trial Signup Context:The trial request form asks what you do, what industry you are in, and what you will mainly use MetaDock for, as a category and in your own words. Those four answers are required to submit the form. It also asks how many people work with you, where you heard about us, what you use today and where you work; those four are optional and can be left blank or answered "Prefer not to say". We use all of it only to understand who MetaDock is for and what it is compared against. It is not used to make any decision about you or your trial, is not shared with advertisers, and does not add you to marketing email.
- Payment Information: Processed by Stripe (we only store Stripe identifiers, not your credit card details)
Information Automatically Collected
- Website Analytics: Via Microsoft Clarity (session recordings, heatmaps, click data) and Google Analytics (aggregate traffic, page and referral reporting). Both are loaded only after you accept analytics cookies.
- Affiliate Referrals: Via Rewardful, if you arrived through an affiliate link. It records which affiliate referred you so a purchase can be credited to them. It is loaded only after you accept analytics cookies, and only for visitors who arrived on such a link.
- Application License Data: Hashed hardware ID, license key, activation status
- Application Telemetry: MetaDock periodically sends pseudonymous usage data to our servers to help us improve the product. Because this data carries a stable installation identifier that we can resolve to your licence record, we treat it as pseudonymous rather than anonymous. The full field list (kept in sync with the bundled EULA via
lib/legal-content.ts):- A stable installation identifier generated on your device
- Edition and application version
- Operating system version and CPU architecture
- Aggregate feature-usage counts: open browsers, mounted native applications, layouts, workspaces, and profiles. Counts only, never the contents of profiles, browsing history, scripts, or user data
- Application uptime in minutes
- IP address: used by our server to derive a country code. Only the country code is stored on the telemetry record; the IP address is not stored on it
Correlation: The installation identifier, which we can resolve to the licence it was activated against. Never directly to email, name, or other identifying fields. You can disable telemetry in Settings > Privacy & Security > "Anonymous Usage Telemetry".
Not collected via telemetry:
- Browsing history
- Sites visited inside MetaDock
- Bookmarks, passwords, or form data
- Wallet addresses, private keys, or cryptocurrency information
- Workspace configurations or browser profile data
- Script contents or automation payloads
What We Do NOT Collect
- We do not collect or access your browsing history
- We do not collect websites you visit using MetaDock
- We do not collect bookmarks, passwords, or form data
- We do not collect wallet addresses, private keys, or cryptocurrency information
- Your workspace data and browser profiles remain LOCAL on your device
2. How We Collect Information
- Directly from you: When you request a trial key, subscribe to our mailing list, contact support, or make a purchase.
- Automatically: Through website analytics (Microsoft Clarity, Google Analytics), affiliate referral tracking (Rewardful, only if you arrived through an affiliate link), application telemetry, and standard server logs when you visit our website or use our application.
- From third parties: Payment confirmation from Stripe.
- From your browser engine: Microsoft WebView2 (the browser engine in MetaDock) sends standard diagnostics and telemetry to Microsoft as part of its normal operation. See Section 11 for details.
Legal Basis for Processing (GDPR)
- Contract performance: Trial key delivery, license management, subscription processing, support.
- Consent: Marketing emails, analytics cookies (Microsoft Clarity, Google Analytics), affiliate referral cookies (Rewardful).
- Legitimate interest: Application telemetry for product improvement, fraud prevention, security.
- Legal obligation: Tax records, compliance with applicable law.
3. How We Use Your Information
To Provide Services
- • Process subscriptions
- • Verify licenses
- • Enforce one trial per device (EULA 9.1.1(c)), by hardware ID
- • Provide customer support
- • Send transactional emails
To Improve Services
- • Analyze website usage
- • Fix bugs and errors
- • Develop new features
- • Understand user behavior
To Communicate
- • Marketing emails (opt-in only)
- • Newsletters (if subscribed)
- • Support responses
- • Service updates
Legal & Security
- • Comply with legal obligations
- • Enforce Terms & Conditions
- • Protect against fraud
- • Maintain business records
5. Third-Party Service Providers
The list below is the canonical source of truth for our subprocessors. It is rendered from lib/legal-content.ts and is identical to the subprocessor table in our DPA and to /docs/privacy-policy.txt §5.
Stripe, Inc.
PaymentsSubscription payment processing
Location: United States & global • Privacy Policy
Mailjet
EmailTransactional and marketing email (subscription receipts, license keys, optional newsletter)
Location: France / European Union • Privacy Policy
Microsoft Clarity
Analytics (Consent Required)Website analytics: session replays, heatmaps, click maps on metadock.app (loaded only after analytics-cookie consent)
Location: United States, with global Microsoft infrastructure • Privacy Policy
Google Analytics
Analytics (Consent Required)Website analytics: aggregate traffic, page and referral reporting on metadock.app (loaded only after analytics-cookie consent; ad personalisation and Google Signals disabled)
Location: United States, with global Google infrastructure • Privacy Policy
Microsoft (WebView2 runtime)
Browser EngineBrowser engine inside the MetaDock desktop application; sends standard Edge diagnostics directly to Microsoft
Location: Global Microsoft infrastructure • Privacy Policy
Sentry (Functional Software, Inc.)
Error MonitoringApplication crash and error diagnostics (stack traces, application version, OS, MetaDock edition, Qt version; no hardware, installation, or user identifier is attached); retained ~90 days
Location: United States • Privacy Policy
Rewardful Inc.
Affiliate Tracking (Consent Required)Affiliate referral attribution on metadock.app: records the affiliate link a visitor arrived through, and on a completed purchase receives the billing email address so the sale can be credited to that affiliate (loaded only after analytics-cookie consent, and only for visitors who arrived through an affiliate link)
Location: United States (application and database hosting on Heroku/AWS); Rewardful Inc. is incorporated in Alberta, Canada • Privacy Policy
7. Data Retention
Active Subscriptions
We retain the information needed to provide an active subscription
Subscription Records
Retained for 7 years after cancellation for tax and legal compliance, then deleted
Mailing List
Until you unsubscribe (removed within 10 business days, per CASL)
Support Communications
Retained for 3 years, then deleted
8. Data Security
We implement reasonable technical and organizational measures to protect your personal information:
- Encryption: All website traffic is encrypted via TLS/HTTPS. Payment processing is handled by Stripe (PCI-DSS Level 1 certified).
- Credential security: License and API credentials are handled using appropriate access controls and are not displayed in plain text on this website.
- Access control: Our hosted licensing and billing endpoints authenticate with bearer tokens and apply short-window rate limiting and IP-based lockout after failed attempts. The MetaDock application's own API runs locally on your machine, is off until you create a key, and authenticates each request against that key's scopes.
- Local data: Your workspaces, browser profiles, bookmarks, and browsing data are stored locally on your computer and are not transmitted to our servers.
- Infrastructure: Our web infrastructure runs on hardened Linux servers operated by Gammal Software, Inc. in Canadian data centres.
No method of transmission or storage is completely secure. If we become aware of a data breach that affects your personal information, we will notify you and any applicable regulatory authorities as required by law. Where GDPR Article 33 applies, we notify the competent supervisory authority within 72 hours of becoming aware of a breach; under PIPEDA, we report breaches that pose a real risk of significant harm to the Office of the Privacy Commissioner of Canada and to affected individuals as soon as feasible.
9. Your Privacy Rights
Access
Request a copy of your personal information
Correction
Request correction of inaccurate data
Deletion
Request deletion of your data (subject to legal exceptions)
Opt-Out
Unsubscribe from marketing emails anytime
Object
Object to certain uses of your information
Portability
Get your data in a portable format
Restrict Processing
Request we limit how we use your data (GDPR Article 18)
10. Age Restriction & Children's Privacy
18+ Requirement
MetaDock is intended for users 18 years of age or older. By using MetaDock, you represent that you are at least 18 years old. If you are under 18, you may not use MetaDock.
Children's Privacy
MetaDock is designed for adults and business use. We do not knowingly collect personal information from children.
- • No Collection from Minors: We do not knowingly collect personal information from anyone under 18 years of age
- • No Marketing to Minors: Our marketing materials and services are directed at adults
- • Age Requirement: Users must be 18+ to use our services
Parental Notice
If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately at:
We will promptly investigate and delete any personal information belonging to users under the age of 18 from our systems.
11. Microsoft WebView2 Privacy Disclosure
Important Third-Party Disclosure
MetaDock uses Microsoft Edge WebView2 as its browser engine. WebView2 may send diagnostic and performance data to Microsoft, including crash reports, performance metrics, and feature usage statistics.
Important: Gammal Software, Inc. does NOT receive, access, or control the diagnostic data that WebView2 sends to Microsoft. This data is sent directly from your device to Microsoft's servers.
Microsoft's data collection is governed by Microsoft's Privacy Policy. You may have some control through Windows privacy settings.
12. Contact Us
Person in charge of personal information protection (Quebec Law 25 / Privacy Officer)
Gammal Software, Inc. has designated a Privacy Officer responsible for compliance with applicable privacy laws, including Quebec's Act respecting the protection of personal information in the private sector(as amended by Law 25), Canada's PIPEDA, the EU GDPR, and the California CCPA/CPRA. The Privacy Officer is the point of contact for any question, complaint, or request to exercise your rights.
Daniel Gammal, Privacy Officer
Email: [email protected]
Mail: Daniel Gammal (Privacy Officer), Gammal Software, Inc., 303D-2967 Dundas Street West, Toronto, Ontario M6P 1Z2, Canada
Privacy Inquiries
General Support
Mailing Address & Telephone
Gammal Software, Inc.
303D-2967 Dundas Street West
Toronto, Ontario M6P 1Z2
Canada
Telephone: +1 (647) 547-6803
13. Privacy Rights for Specific Jurisdictions
Canada (PIPEDA)
If you are a Canadian resident, you have specific rights under PIPEDA including:
- • Right to access your personal information
- • Right to correction of inaccurate data
- • Right to withdraw consent
- • Right to file a complaint with the Office of the Privacy Commissioner of Canada
Contact: www.priv.gc.ca • Phone: 1-800-282-1376
Quebec (Law 25 / Act respecting the protection of personal information in the private sector)
Quebec availability. MetaDock is not currently offered for sale to Quebec residents while we finalize French-language agreements and a Law 25 cross-border transfer assessment. The provisions in this section describe the protections we are putting in place and intend to honour; they reflect our intended compliance posture rather than a representation that every Law 25 obligation is fully operational today.
If you reside in Quebec, you have additional rights under Quebec's Act respecting the protection of personal information in the private sector, as amended by Law 25 (formerly Bill 64), in addition to your federal PIPEDA rights:
- • Right to be informed, in clear and simple terms, of what personal information is collected and why
- • Right to access, correct, and request deletion of your personal information
- • Right to data portability: receive your personal information in a structured, commonly-used technological format
- • Right to withdraw consent at any time
- • Right to be informed of, and to object to, decisions based exclusively on automated processing
- • Right to be informed of any cross-border transfer of your personal information and the associated risks (see below)
- • Right to file a complaint with the Commission d'accès à l'information du Québec (CAI)
Cross-border transfers
Some of our service providers store or process personal information outside Quebec, primarily in the United States and the European Union. Before transferring personal information outside Quebec, we assess whether the receiving jurisdiction provides protection equivalent to that offered under Quebec law, and we rely on contractual safeguards (Standard Contractual Clauses or equivalent) where necessary. The third-party processors involved are listed in Section 5 above.
Risks associated with US-routed transfers. Personal information processed in the United States (Stripe, Microsoft Clarity, Google Analytics, Rewardful, Microsoft for WebView2 diagnostics) may be subject to access by US government authorities under US law, including the Clarifying Lawful Overseas Use of Data Act (CLOUD Act) and Section 702 of the Foreign Intelligence Surveillance Act (FISA 702). These laws can compel a US-based service provider to disclose data without notice to the data subject, regardless of where the data is physically stored. Mailjet (France/EU) is not subject to those US laws but may receive requests under EU member-state laws or mutual legal assistance treaties. We disclose this so you can make an informed decision; if these risks are unacceptable for your use case, please do not provide personal information to us.
Automated decision-making
We do not currently use automated decision-making (including profiling that produces legal or significant effects) on personal information of Quebec residents. If that changes, we will update this Privacy Policy and notify affected users.
Person in charge of personal information protection
Our Privacy Officer is responsible for ensuring compliance with Quebec Law 25 and is your point of contact for any privacy-related question, complaint, or request. See Section 12 for contact details.
Commission d'accès à l'information: www.cai.gouv.qc.ca
European Union (GDPR)
If you are in the EEA, UK, or Switzerland, you have specific GDPR rights including:
- • Right of access and rectification
- • Right to erasure (“right to be forgotten”)
- • Right to data portability
- • Right to object to processing
- • Right to lodge a complaint with a supervisory authority
Transfers outside the EEA
Personal information processed by our US-based providers (Stripe, Microsoft Clarity, Google Analytics, Rewardful, Microsoft for WebView2 diagnostics) is transferred to the United States. The US is not the subject of a current EU adequacy decision; we rely on Standard Contractual Clauses with those providers as the transfer mechanism (GDPR Art. 46(2)(c)). Per the Schrems II judgment (CJEU C-311/18), US surveillance laws including the CLOUD Act and FISA Section 702 may compel disclosure of data without notice to the data subject, regardless of where the data is physically stored. Mailjet (France) processes email in the EU and is not subject to those US laws. We surface this risk so you can decide whether to provide personal information to us; you may also exercise the rights above to limit or terminate that processing.
For material changes to this policy, we will request your explicit consent.
California (CCPA/CPRA)
If you are a California resident, you have specific CCPA/CPRA rights including:
- • Right to know what personal information we collect
- • Right to delete your personal information
- • Right to correct inaccurate information
- • Right to opt-out of sale and "sharing" (see note below)
- • Right to limit use of sensitive personal information
- • Right to non-discrimination for exercising your rights
We do NOT sell your personal information to third parties for money.
"Sale" and "sharing" are defined broadly under the CCPA/CPRA. Some analytics activities we perform may fall within those definitions (see Section 4). You can opt out at any time by rejecting our analytics consent banner, clearing cookies, or emailing [email protected]. We do not transfer your identity to advertisers or data brokers.
ACKNOWLEDGMENT
BY USING OUR WEBSITE OR APPLICATION, YOU ACKNOWLEDGE THAT YOU HAVE READ AND UNDERSTOOD THIS PRIVACY POLICY. WHERE THE LAW REQUIRES CONSENT (FOR EXAMPLE, ANALYTICS COOKIES OR MARKETING EMAILS), WE OBTAIN IT SEPARATELY THROUGH A CLEAR OPT-IN, NOT THROUGH YOUR USE OF THE SITE ALONE.
Copyright © 2026 Gammal Software, Inc. All rights reserved.