India privacy notice
Privacy Policy
This Privacy Policy explains how GullyBharat handles information for customers, vendors, delivery partners, riders, service partners and administrators using the GullyBharat Android app and web portals.
1. Who Operates GullyBharat
GullyBharat is operated by GullyBharat for local commerce and services in India. The project source identifies the official support contact as GullyBharat Support Team, India. Privacy and grievance requests can be sent to support@gullybharat.com or raised by phone or WhatsApp at +91 9876543210.
2. Scope Of This Policy
This policy covers the GullyBharat Flutter Android application, the customer web experience, vendor and admin web portals, Firebase backend services and Cloud Functions used by the current project. It applies to services that may include local shopping, food ordering, delivery, Smart Print, Apartment Pool, tailoring, home services, rentals, resort enquiries and bookings, restaurant QR ordering and ride-booking features.
3. Data Categories Detected In The App
The following summary is based on the source code, Android permissions, Firebase rules, functions and dependencies reviewed for this project.
| Data category | Examples | Source and purpose | Storage or processor |
|---|---|---|---|
| Account and contact data | Name, email, phone number, role, profile image, approval status | Provided during sign-up, phone login, Google sign-in, profile updates and admin-managed account setup | Firebase Authentication, Cloud Firestore, Cloud Storage for images |
| Address and location data | Delivery addresses, landmarks, latitude and longitude, live delivery or ride location, heading, speed and accuracy | Used for delivery, ride, service fulfilment, tracking, maps, ETA and address selection | Cloud Firestore, Google Maps and geocoding/location services |
| Orders, bookings and service data | Items, quantities, instructions, OTPs, status history, support tickets, reviews, resort/rental/service bookings | Created when users place orders, book services, contact support or interact with vendors/delivery partners | Cloud Firestore and Cloud Functions |
| Payments and transactions | Amounts, order IDs, Razorpay order/payment IDs, payment signatures, COD collection status, ledgers, wallets and refunds | Used to create and verify online payments, record COD collections and maintain settlement history | Razorpay, Cloud Functions, Cloud Firestore |
| Uploads and documents | Profile photos, product/service/resort/rental images, KYC images, Smart Print files and print settings | Uploaded by users and partners to support profiles, listings, verification and print jobs | Cloud Storage, Cloud Firestore, assigned vendors/admins where needed |
| Messages and communications | Delivery chat messages, support ticket events, masked call session metadata, notification content | Used for order support, delivery coordination and service updates | Cloud Firestore, Firebase Cloud Messaging |
| Device, diagnostics and activity | FCM tokens, Crashlytics reports, app activity metadata, promotion impressions/clicks, local preferences | Used for notifications, reliability, abuse prevention, app operations and optional analytics features | Firebase Cloud Messaging, Firebase Crashlytics, Firebase Analytics dependency, Cloud Firestore, local device storage |
4. Information You Provide
Depending on how you use GullyBharat, you may provide:
- name, mobile number, email address, profile image and role selection;
- delivery addresses, apartment details, room details, landmarks and service addresses;
- cart items, order details, booking details, delivery instructions, ratings and reviews;
- support requests, messages, call-support metadata and complaint information;
- vendor, delivery partner and admin onboarding information, including business, vehicle, bank and KYC details where required;
- photos, images, QR images and documents that you choose to upload.
5. Information Collected Automatically
The app may collect technical and operational information such as app version, device/app identifiers used by Firebase, crash reports, diagnostics, notification tokens, local preferences and service interaction metadata. Firebase Crashlytics is used in the non-web app for crash and error reporting. The project includes Firebase Analytics; advertising SDKs were not identified in the audit.
6. Location And Live Tracking
GullyBharat requests approximate and precise location permissions when location-based features are used. The current Android app does not request background location permission. Foreground service location is used only for active delivery, ride or service tracking that needs live progress updates.
Location data is used for app functionality, safety, fraud prevention, routing, delivery confirmation, pickup/drop coordination and customer support. You can revoke location permission from device settings, but some delivery, ride, service or map features may stop working.
7. Camera, Images, Documents And File Uploads
The app uses camera, gallery, scanner and file picker features for QR scanning, restaurant QR ordering, Smart Print, profile images, KYC documents, vendor listings, service listings, resort listings, rental listings and other user-submitted images. Android storage permissions are declared for file access on applicable devices.
8. Smart Print Document Handling
Smart Print supports uploads such as PDF, DOC, DOCX, JPG, JPEG, PNG and HEIC files. The current code encrypts Smart Print files before upload and stores metadata such as file name, size, page count, storage path, encrypted file URL, print settings and payment intent.
Assigned vendors and admins can access or decrypt print files only as needed to price, process, convert, print, deliver, resolve or audit a print job. Cloud Functions include checks for encrypted print metadata, vendor access and scheduled cleanup. Automatic cleanup is tied to job status, expiry metadata and scheduled functions; it should not be read as a promise of instant deletion in every case.
9. Vendor And Delivery Partner KYC
Vendor and delivery partner onboarding may collect identity, business, address, vehicle and bank details. Detected fields include Aadhaar number, PAN number, account holder name, bank name, account number, IFSC code, UPI ID, GST/FSSAI/trade licence information, driving licence, vehicle number, preferred delivery areas, emergency contact, shop details and uploaded images such as Aadhaar, PAN, driving licence, vehicle RC, insurance, shop/business proof and cancelled cheque images.
KYC information is used for partner verification, risk control, payouts, approvals, compliance, dispute handling and platform safety. It is restricted by role-based Firebase rules and admin review screens.
10. Orders, Bookings And Service Information
GullyBharat stores order, cart, booking and service records so it can process shopping orders, food orders, Smart Print jobs, apartment pool orders, resort bookings, rentals, restaurant QR orders, rides, tailoring and home services. These records may include customer/vendor/delivery identifiers, contact details, addresses, item details, fees, status history, OTPs, delivery task information and support context.
11. Payments Through Razorpay And Cash On Delivery
GullyBharat uses Razorpay for online payments and Cash on Delivery for eligible orders. The app and backend store payment amounts, currency, order IDs, Razorpay order IDs, payment IDs, verification signatures, statuses, refunds, wallet and ledger information, COD collection confirmation and related transaction metadata.
Razorpay processes payment instrument details such as card, UPI, net banking or wallet information in its checkout flow. GullyBharat sends basic prefill details such as name, email and contact number when opening Razorpay checkout, and verifies payments through Cloud Functions. GullyBharat does not need your full card number to operate the checkout flow.
12. Notifications And FCM Tokens
Firebase Cloud Messaging is used to send order, booking, delivery, payment, print, approval, support and account notifications. The app may store FCM tokens in user profiles and may refresh them when the app receives a new token. You can disable notifications in device settings, but important operational updates may be harder to receive.
13. Verified Third-Party Service Providers
- Firebase Authentication
- Cloud Firestore
- Cloud Storage
- Cloud Functions
- Firebase Cloud Messaging
- Firebase Crashlytics
- Firebase Analytics dependency
- Google Maps and Geocoding
- Google Sign-In
- Razorpay
The project also uses app libraries for camera, QR scanning, file picking, document/PDF viewing, printing, local notifications, local preferences and secure-screen flows. Advertising network SDKs were not detected in the source audit.
14. Purposes For Using Information
GullyBharat uses information for lawful and operational purposes such as:
- creating, verifying and securing accounts;
- processing orders, bookings, delivery, print jobs, rides, services and payments;
- showing nearby vendors, maps, routes, ETA and live tracking;
- partner KYC, approvals, payouts, settlements and fraud prevention;
- customer support, complaints, refunds, disputes and audit logs;
- sending transactional notifications and important service updates;
- improving reliability, diagnosing crashes and maintaining platform safety;
- running promotions, referral flows and internal analytics where implemented.
15. Lawful Purposes
Where relevant, GullyBharat processes information to provide requested services, perform platform agreements, obtain consent for permissions or partner onboarding where needed, comply with legal and tax requirements, prevent fraud, protect users and operate the platform with legitimate business purposes.
17. Data Retention
GullyBharat keeps information for as long as needed for app functionality, account management, order history, payment verification, KYC review, payouts, taxes, fraud prevention, disputes, safety, audits and legal requirements. The code does not define a single fixed deletion period for all records.
Smart Print files are handled separately: the source includes scheduled cleanup for expired or completed print-job files when the required status and cleanup metadata are present. Some metadata, payment records and audit records may remain after uploaded files are removed.
18. Account Deletion And Data Rights
You can request account deletion and data deletion through the public account-deletion page at https://gullybharat.com/account-deletion or by contacting support. GullyBharat may need to verify your identity before acting on a request.
Some records may be retained where necessary for payment, tax, accounting, fraud prevention, security, KYC, regulatory, dispute, refund, chargeback, delivery, settlement or legal reasons.
19. Your Choices And Permissions
- You can update many profile and contact details in the app where the current role permits it.
- You can deny or revoke camera, files, notifications and location permissions from device settings.
- You can choose not to upload optional photos or files, but features that require them may not work.
- You can contact support to correct account, order, KYC or booking information where self-service editing is unavailable.
20. Security Safeguards
GullyBharat uses Firebase Authentication, role-based Firestore and Storage rules, Cloud Functions validation, HTTPS transport, admin controls, audit records, limited partner access and application-level Smart Print encryption in the current implementation. These are reasonable technical and organisational safeguards, but no app, network or storage system can be promised to be absolutely secure.
21. Children's Privacy
GullyBharat is not directed to children under 18. Users who are minors should use the service only with the involvement of a parent or guardian. If you believe a child has provided personal information without appropriate consent, contact support.
22. International Processing
GullyBharat operates in India. Firebase/Google, Razorpay and other technology providers may process or store information in India or in other locations where they operate infrastructure. Appropriate service provider safeguards apply according to their terms and policies.
23. Indian User Rights And Grievance Contact
Indian users may contact GullyBharat to request access, correction, withdrawal of consent where applicable, account deletion, grievance review or support with privacy concerns. Send requests to support@gullybharat.com or call/WhatsApp +91 9876543210.
Please include your registered mobile number or email address, role and relevant order, booking, print job or KYC reference so the support team can verify the request.
24. Changes To This Policy
GullyBharat may update this policy when the app, backend, services, permissions, providers or legal requirements change. The updated page will show a new last updated date. Material changes may also be communicated through the app, website or support channels where appropriate.
25. Contact And Grievance Information
Operator: GullyBharat
Support and grievance contact: GullyBharat Support Team, India
Email: support@gullybharat.com
Phone/WhatsApp: +91 9876543210
Website: https://gullybharat.com