GullyBharat Local shopping and services

India privacy notice

Privacy Policy

This Privacy Policy explains how GullyBharat handles information for customers, vendors, delivery partners, riders, service partners and administrators using the GullyBharat Android app and web portals.

Effective date 21 August 2026
Last updated 21 August 2026
Country India
Initial service area Visakhapatnam, Andhra Pradesh
No external tracking on this page. This static page does not load advertising scripts, analytics scripts, third-party fonts or unnecessary cookies.

1. Who Operates GullyBharat

GullyBharat is operated by GullyBharat for local commerce and services in India. The project source identifies the official support contact as GullyBharat Support Team, India. Privacy and grievance requests can be sent to support@gullybharat.com or raised by phone or WhatsApp at +91 9876543210.

2. Scope Of This Policy

This policy covers the GullyBharat Flutter Android application, the customer web experience, vendor and admin web portals, Firebase backend services and Cloud Functions used by the current project. It applies to services that may include local shopping, food ordering, delivery, Smart Print, Apartment Pool, tailoring, home services, rentals, resort enquiries and bookings, restaurant QR ordering and ride-booking features.

3. Data Categories Detected In The App

The following summary is based on the source code, Android permissions, Firebase rules, functions and dependencies reviewed for this project.

Data category Examples Source and purpose Storage or processor
Account and contact data Name, email, phone number, role, profile image, approval status Provided during sign-up, phone login, Google sign-in, profile updates and admin-managed account setup Firebase Authentication, Cloud Firestore, Cloud Storage for images
Address and location data Delivery addresses, landmarks, latitude and longitude, live delivery or ride location, heading, speed and accuracy Used for delivery, ride, service fulfilment, tracking, maps, ETA and address selection Cloud Firestore, Google Maps and geocoding/location services
Orders, bookings and service data Items, quantities, instructions, OTPs, status history, support tickets, reviews, resort/rental/service bookings Created when users place orders, book services, contact support or interact with vendors/delivery partners Cloud Firestore and Cloud Functions
Payments and transactions Amounts, order IDs, Razorpay order/payment IDs, payment signatures, COD collection status, ledgers, wallets and refunds Used to create and verify online payments, record COD collections and maintain settlement history Razorpay, Cloud Functions, Cloud Firestore
Uploads and documents Profile photos, product/service/resort/rental images, KYC images, Smart Print files and print settings Uploaded by users and partners to support profiles, listings, verification and print jobs Cloud Storage, Cloud Firestore, assigned vendors/admins where needed
Messages and communications Delivery chat messages, support ticket events, masked call session metadata, notification content Used for order support, delivery coordination and service updates Cloud Firestore, Firebase Cloud Messaging
Device, diagnostics and activity FCM tokens, Crashlytics reports, app activity metadata, promotion impressions/clicks, local preferences Used for notifications, reliability, abuse prevention, app operations and optional analytics features Firebase Cloud Messaging, Firebase Crashlytics, Firebase Analytics dependency, Cloud Firestore, local device storage

4. Information You Provide

Depending on how you use GullyBharat, you may provide:

5. Information Collected Automatically

The app may collect technical and operational information such as app version, device/app identifiers used by Firebase, crash reports, diagnostics, notification tokens, local preferences and service interaction metadata. Firebase Crashlytics is used in the non-web app for crash and error reporting. The project includes Firebase Analytics; advertising SDKs were not identified in the audit.

6. Location And Live Tracking

GullyBharat requests approximate and precise location permissions when location-based features are used. The current Android app does not request background location permission. Foreground service location is used only for active delivery, ride or service tracking that needs live progress updates.

Customer location. Customers may save addresses, select current location, view live delivery/ride tracking and receive ETA information.
Partner location. Delivery partners, riders or service partners may publish live latitude, longitude, heading, speed and accuracy during active tasks, rides or deliveries so customers, vendors and admins can track fulfilment.

Location data is used for app functionality, safety, fraud prevention, routing, delivery confirmation, pickup/drop coordination and customer support. You can revoke location permission from device settings, but some delivery, ride, service or map features may stop working.

7. Camera, Images, Documents And File Uploads

The app uses camera, gallery, scanner and file picker features for QR scanning, restaurant QR ordering, Smart Print, profile images, KYC documents, vendor listings, service listings, resort listings, rental listings and other user-submitted images. Android storage permissions are declared for file access on applicable devices.

8. Smart Print Document Handling

Smart Print supports uploads such as PDF, DOC, DOCX, JPG, JPEG, PNG and HEIC files. The current code encrypts Smart Print files before upload and stores metadata such as file name, size, page count, storage path, encrypted file URL, print settings and payment intent.

Assigned vendors and admins can access or decrypt print files only as needed to price, process, convert, print, deliver, resolve or audit a print job. Cloud Functions include checks for encrypted print metadata, vendor access and scheduled cleanup. Automatic cleanup is tied to job status, expiry metadata and scheduled functions; it should not be read as a promise of instant deletion in every case.

9. Vendor And Delivery Partner KYC

Vendor and delivery partner onboarding may collect identity, business, address, vehicle and bank details. Detected fields include Aadhaar number, PAN number, account holder name, bank name, account number, IFSC code, UPI ID, GST/FSSAI/trade licence information, driving licence, vehicle number, preferred delivery areas, emergency contact, shop details and uploaded images such as Aadhaar, PAN, driving licence, vehicle RC, insurance, shop/business proof and cancelled cheque images.

KYC information is used for partner verification, risk control, payouts, approvals, compliance, dispute handling and platform safety. It is restricted by role-based Firebase rules and admin review screens.

10. Orders, Bookings And Service Information

GullyBharat stores order, cart, booking and service records so it can process shopping orders, food orders, Smart Print jobs, apartment pool orders, resort bookings, rentals, restaurant QR orders, rides, tailoring and home services. These records may include customer/vendor/delivery identifiers, contact details, addresses, item details, fees, status history, OTPs, delivery task information and support context.

11. Payments Through Razorpay And Cash On Delivery

GullyBharat uses Razorpay for online payments and Cash on Delivery for eligible orders. The app and backend store payment amounts, currency, order IDs, Razorpay order IDs, payment IDs, verification signatures, statuses, refunds, wallet and ledger information, COD collection confirmation and related transaction metadata.

Razorpay processes payment instrument details such as card, UPI, net banking or wallet information in its checkout flow. GullyBharat sends basic prefill details such as name, email and contact number when opening Razorpay checkout, and verifies payments through Cloud Functions. GullyBharat does not need your full card number to operate the checkout flow.

12. Notifications And FCM Tokens

Firebase Cloud Messaging is used to send order, booking, delivery, payment, print, approval, support and account notifications. The app may store FCM tokens in user profiles and may refresh them when the app receives a new token. You can disable notifications in device settings, but important operational updates may be harder to receive.

13. Verified Third-Party Service Providers

The project also uses app libraries for camera, QR scanning, file picking, document/PDF viewing, printing, local notifications, local preferences and secure-screen flows. Advertising network SDKs were not detected in the source audit.

14. Purposes For Using Information

GullyBharat uses information for lawful and operational purposes such as:

16. When Information Is Shared

Information may be shared only where needed, including with:

GullyBharat does not sell personal data. The audit did not identify third-party advertising SDKs or data broker integrations.

17. Data Retention

GullyBharat keeps information for as long as needed for app functionality, account management, order history, payment verification, KYC review, payouts, taxes, fraud prevention, disputes, safety, audits and legal requirements. The code does not define a single fixed deletion period for all records.

Smart Print files are handled separately: the source includes scheduled cleanup for expired or completed print-job files when the required status and cleanup metadata are present. Some metadata, payment records and audit records may remain after uploaded files are removed.

18. Account Deletion And Data Rights

You can request account deletion and data deletion through the public account-deletion page at https://gullybharat.com/account-deletion or by contacting support. GullyBharat may need to verify your identity before acting on a request.

Some records may be retained where necessary for payment, tax, accounting, fraud prevention, security, KYC, regulatory, dispute, refund, chargeback, delivery, settlement or legal reasons.

19. Your Choices And Permissions

20. Security Safeguards

GullyBharat uses Firebase Authentication, role-based Firestore and Storage rules, Cloud Functions validation, HTTPS transport, admin controls, audit records, limited partner access and application-level Smart Print encryption in the current implementation. These are reasonable technical and organisational safeguards, but no app, network or storage system can be promised to be absolutely secure.

21. Children's Privacy

GullyBharat is not directed to children under 18. Users who are minors should use the service only with the involvement of a parent or guardian. If you believe a child has provided personal information without appropriate consent, contact support.

22. International Processing

GullyBharat operates in India. Firebase/Google, Razorpay and other technology providers may process or store information in India or in other locations where they operate infrastructure. Appropriate service provider safeguards apply according to their terms and policies.

23. Indian User Rights And Grievance Contact

Indian users may contact GullyBharat to request access, correction, withdrawal of consent where applicable, account deletion, grievance review or support with privacy concerns. Send requests to support@gullybharat.com or call/WhatsApp +91 9876543210.

Please include your registered mobile number or email address, role and relevant order, booking, print job or KYC reference so the support team can verify the request.

24. Changes To This Policy

GullyBharat may update this policy when the app, backend, services, permissions, providers or legal requirements change. The updated page will show a new last updated date. Material changes may also be communicated through the app, website or support channels where appropriate.

25. Contact And Grievance Information

Operator: GullyBharat
Support and grievance contact: GullyBharat Support Team, India
Email: support@gullybharat.com
Phone/WhatsApp: +91 9876543210
Website: https://gullybharat.com