Privacy Policy
How GALIKY collects, uses, protects, and handles customer data and Google Sign-In information across our hyperlocal delivery marketplace.
Minimal Data Collection
We only collect information strictly necessary to authenticate your account, fulfill food orders, and coordinate delivery.
Google OAuth Compliance
Google account information is strictly used for customer sign-in. We never access your Gmail, Drive, Calendar, or Contacts.
Zero Ad-Targeting
We never sell your data or share personal information with third-party data brokers or advertising networks.
Introduction
Welcome to GALIKY ("we", "us", "our", or the "Platform"), accessible at https://www.galiky.com. GALIKY is a hyperlocal food and commerce ordering and delivery platform built to connect customers with local restaurants, dhabas, sweet shops, and delivery partners across small-town and semi-urban communities in India (starting with Pilani, Rajasthan).
This Privacy Policy describes how GALIKY collects, uses, stores, and safeguards personal information when you visit our website, create a customer account, sign in using Google Sign-In, place an order for food delivery, or interact with our services.
By accessing or using GALIKY, you acknowledge that you have read, understood, and agreed to the practices described in this Privacy Policy. If you do not agree with this policy, please do not access or use our services.
Information We Collect
We collect only the minimum personal information required to deliver a reliable, secure food ordering experience. The information we collect falls into the following specific categories:
A. Account Identity & Google Sign-In Data
When you sign in as a customer using "Continue with Google", we receive basic profile identity data from Google via our authentication infrastructure (Supabase Auth). We receive and store only:
- Full Name: Your name as provided in your Google account profile, used to personalize your account and address you during delivery.
- Email Address: Your Google account email address, used to identify your account and send transactional order receipts or support communications.
- Supabase Authentication Identifier: An opaque system identifier linking your authentication session to your GALIKY customer profile.
B. Customer Profile & Contact Details
In our database, customer profiles are initialized with default preferences. Providing an account phone number during Google registration is optional. Delivery coordination phone numbers are collected separately per order delivery address to ensure delivery partners can coordinate handoff smoothly.
Note: Phone OTP verification infrastructure is maintained as a future capability; during the current pilot phase, external commercial SMS OTP dispatch is not active (SMS provider is set to zero-cost/inactive mode).
C. Delivery Address Information
When you add a delivery address to place an order, we collect:
- Recipient Contact Name: The name of the person receiving the order.
- Recipient Contact Phone Number: A phone number so the assigned delivery rider or restaurant can call for address directions.
- Address Details: House/room number, village or colony info, street, and nearby landmark (tailored for rural and semi-urban delivery where standard postal numbering may not exist).
- Town Hub & Pincode: The serviced town (e.g. Pilani) and postal code.
- Optional Geographic Coordinates: Latitude and longitude coordinates, only if you explicitly choose to pin your location on our map or allow browser location capture.
D. Order & Payment Transaction Records
When you place an order, we record the items ordered, quantities, selected variants, special preparation notes, order totals, and timestamps.
For payments, we support Cash on Delivery (COD) and Online Payments via Razorpay. For online transactions:
- Payment processing is handled directly by Razorpay Software Private Limited.
- GALIKY does not collect, receive, or store your credit card numbers, debit card numbers, CVVs, expiry dates, net banking credentials, or UPI MPINs.
- We only store the transaction reference tokens returned by Razorpay (Order ID, Payment ID, Signature, and status) in our database for verification, audit, and refund processing.
E. Device Location Data
If you tap "Use my location" or "Find what's near you", our web application uses your browser's standard HTML5 Geolocation API to detect your approximate coordinates. This is used solely client-side to identify the closest active market hub (e.g., Pilani) and show serviceable restaurants. We do not continuously track your location in the background.
Google User Data & Limited Use Policy Compliance
Google API Services User Data Policy Compliance Statement:
GALIKY's use and transfer to any other app of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically, in accordance with Google Limited Use specifications:
- Direct Service Functionality Only: We use Google user data (your name and email) solely to authenticate you, create your customer profile, and facilitate food delivery orders on GALIKY.
- No Advertising Transfers: We do not transfer, sell, or disclose Google user data to third parties for serving advertisements, personalized marketing, retargeting, or data broker sales.
- No Lending or Credit Scoring: Google user data is never used to determine creditworthiness or for financial lending decisions.
- No AI/ML Model Training: We do not use Google user data to train general-purpose machine learning or artificial intelligence models.
- Strict Human-Access Restrictions: No human personnel at GALIKY read or inspect your Google account data unless: (1) we have obtained your explicit affirmative permission to troubleshoot a specific technical account issue; (2) it is required for security purposes, such as investigating a security incident or bug; or (3) it is strictly necessary to comply with applicable law.
How We Use Your Information
We use the information we collect solely for the following operational and legitimate business purposes:
- Account Authentication: Verifying your identity through Google Sign-In and securing your active session.
- Order Fulfillment: Transmitting order details to the chosen restaurant to prepare your meal.
- Delivery Coordination: Sharing recipient contact name, contact phone, and address with the assigned rider.
- Transaction Processing: Recording payment status, issuing receipts, and reconciling Cash on Delivery or digital payments.
- Order Security & Verification: Generating 6-digit delivery confirmation OTPs to ensure correct order handoff.
- Platform Security & RBAC: Enforcing role boundaries so customer accounts cannot access merchant or rider dashboards.
Third-Party Service Providers
We share data only with trusted third-party infrastructure providers that are strictly required to operate the platform:
Provides our PostgreSQL cloud database, authentication authority (Supabase Auth SSR/PKCE), and secure token management.
Facilitates customer sign-in via Google accounts under Google's standard OAuth 2.0 protocols.
Processes online digital payments (UPI, debit/credit cards, netbanking) in India in compliance with PCI-DSS standards.
Delivers transactional security emails, such as restaurant partner email verification and password recovery links.
Hosts our web application and provides secure SSL/TLS termination, content delivery, and edge routing.
Note: We do not utilize third-party analytics trackers (such as Google Analytics, Mixpanel, or Facebook Pixel) or third-party ad networks on GALIKY.
Cookies & Local Storage
GALIKY uses only functional and security-essential cookies and browser storage technologies. We do not use advertising or cross-site tracking cookies.
Essential authentication cookies managed by `@supabase/ssr` that maintain your encrypted authentication token across page visits.
An HttpOnly, HMAC-signed security cookie containing server-verified role assertions (`isCustomer: true`, etc.). This protects administrative, merchant, and delivery portals from unauthorized access.
Maintains your active meal items and restaurant selection on your local device so your shopping bag is preserved as you browse dishes.
Data Security
We implement robust administrative, technical, and physical safeguards to protect your personal information against unauthorized access, loss, destruction, or alteration:
- Transport Encryption: All communications between your browser and our servers are encrypted via modern TLS/HTTPS.
- Zero-Trust Role Resolution: Role permissions (Admin, Merchant, Delivery Partner, Customer) are verified directly from database relations and signed server-side.
- Strict Authentication Boundaries: Customer Google accounts cannot link to or access privileged merchant or admin portals without authorized registration and verification.
- No Plaintext Passwords: For email/password accounts (merchants and riders), passwords are cryptographically salted and hashed using industry-standard algorithms managed by Supabase Auth.
Data Retention
We retain personal information for as long as reasonably necessary to fulfill the purposes described in this policy, provide our food delivery service, maintain accounting and tax records in compliance with Indian financial laws, resolve transaction disputes, and enforce our contractual agreements.
When personal data is no longer required for operational, legal, or audit purposes, we take reasonable steps to securely delete or anonymize it.
Your Rights & Account Deletion Requests
You have rights regarding the personal information we hold about you, including:
- Access: The right to request a summary of your personal information stored with GALIKY.
- Correction: The right to request correction of inaccurate or incomplete profile or address details.
- Deletion: The right to request deletion of your customer account and associated personal profile data.
How to Request Account or Data Deletion:
Because an automated self-service account deletion UI is currently in development, customer account deletion and personal data removal requests are handled directly by our support team.
To request account or data deletion, send an email from your registered Google or account email address to:
support@galiky.com (or operations@galiky.in) with the subject "Account Deletion Request"
We will verify your identity and process your deletion request within 30 business days, retaining only those transactional records required by law, taxation, or fraud-prevention obligations.
Children's Privacy
GALIKY is not intended for or targeted at individuals under the age of 18 (or the age of legal majority in your state/jurisdiction). We do not knowingly collect personal information from children under 13. If we discover that a child under 13 has provided us with personal information without parental consent, we will promptly delete such information.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect operational, legal, or regulatory changes. When changes are made, we will revise the "Last Updated" date at the top of this page. We encourage you to review this page periodically to stay informed about how we protect your information.
Contact Us & Grievance Redressal
If you have any questions, concerns, or requests regarding this Privacy Policy or your personal information, you may reach us through our official support channels: