galora.ai
← Back to app

Privacy Policy

Last updated: 26 June 2026  ·  Terms of Service →

1. Who We Are

Galora (“Galora”, “we”, “our”, or “us”) operates a studio management platform for professional wedding and event photographers, accessible at app.galora.in. This Privacy Policy explains how we collect, use, store, and protect personal data when you use our Service.

For questions, contact our Privacy team at privacy@galora.in.

2. Information We Collect

Account information: Email address, studio name, and password (hashed — we never store plain-text passwords) provided during registration.

Studio profile: Studio name, logo, tagline, bio, Instagram handle, business address, and GST number — used to personalise your account and appear on client-facing documents.

Photographs and event data: Photos you upload, event details, guest information, and client quotes. This content belongs to you and your clients.

Biometric data (facial embeddings): Mathematical representations of facial features generated from guest selfies and event photographs, used solely for AI-powered guest photo matching. See Section 5.

Payment information: Billing details are collected and processed by our payment partners (Razorpay / Cashfree). We store only plan identifiers and subscription status — never card numbers or bank credentials.

Usage data: Log data, IP addresses, browser type, pages visited, and actions taken within the platform — used for security, debugging, and improving the Service.

3. How We Use Your Information

  • Providing, operating, and improving the Service.
  • Processing payments and managing subscriptions.
  • Sending transactional emails (email verification, password reset, photo-ready notifications).
  • Sending WhatsApp notifications to event guests when their photos are ready (Meta WhatsApp Cloud API).
  • Security monitoring, fraud prevention, and abuse detection.
  • Responding to support requests.
  • Complying with applicable legal obligations.

We do not sell your personal data. We do not use your photographs or client data for advertising, AI model training, or any purpose outside of delivering the Service to you.

4. Data Storage and Security

Your photographs and data are stored on infrastructure located in India and Singapore:

  • Database: Neon Postgres (ap-southeast-1, Singapore). Encrypted at rest and in transit. Point-in-time recovery enabled with 5-minute RPO.
  • File storage: Cloudflare R2 (global edge with India PoPs). Encrypted at rest. Files are served over HTTPS only.
  • Application servers: AWS EC2 (ap-south-1, Mumbai). TLS 1.2+ enforced. Security headers including HSTS applied.

Access to production systems is restricted to authorised engineers. Secrets are stored in encrypted files with root-only access — not in source code or version control.

5. Biometric Data and Face Recognition

Galora's face search feature generates facial embeddings — numeric vectors representing facial geometry — from:

  • Photographs uploaded by the studio (to index faces present in event photos).
  • Selfies submitted by event guests via the gallery registration flow (to identify their photos).

Embeddings are processed on our secure servers and stored in the Neon database linked to the specific event. They are:

  • Never shared with third parties.
  • Never used to identify individuals outside the context of their specific event.
  • Never used for advertising, law enforcement, or any purpose other than photo delivery.
  • Deletable on guest request — contact the studio or email privacy@galora.in.

Studios are responsible for informing their event guests that face recognition is used and obtaining any consent required under applicable law, including the Digital Personal Data Protection Act 2023 (India) where applicable.

6. Third-Party Services

We use the following sub-processors to deliver the Service:

SupabaseAuthentication (email/password). JWT issuance. (Singapore)
NeonPostgres database hosting. (Singapore (ap-southeast-1))
Cloudflare R2Photo and file storage. (Global edge / India PoPs)
RazorpayPayment processing (subscriptions). (India (RBI regulated))
CashfreeUPI and payout processing. (India (RBI regulated))
ResendTransactional email delivery. (USA (EU SCCs apply))
Meta (WhatsApp)Guest photo-ready notifications. (USA / India)
AWS EC2Application server hosting. (Mumbai (ap-south-1))

Each sub-processor is bound by data processing agreements and operates under applicable data protection law.

7. Data Retention

  • Active accounts: Data is retained for as long as your account is active and for 90 days after deletion.
  • Cancelled subscriptions: Your data remains accessible in read-only mode for 90 days, then is scheduled for deletion.
  • Facial embeddings: Deleted when their associated event is deleted, or upon request.
  • Billing records: Retained for 7 years as required under the GST Act.
  • Logs: Rotated after 14 days.

8. Your Rights

Under the Digital Personal Data Protection Act 2023 (DPDP Act, India) and other applicable law, you have the right to:

  • Access: Request a copy of the personal data we hold about you.
  • Correction: Ask us to correct inaccurate personal data. Most data can be updated directly in your account settings.
  • Deletion: Request deletion of your account and associated personal data, subject to our retention obligations.
  • Portability: Request an export of your studio data in a machine-readable format.
  • Grievance redressal: Lodge a complaint with our Privacy team (privacy@galora.in). If unresolved, you may escalate to the Data Protection Board of India once operational.

To exercise any of these rights, email privacy@galora.in. We will respond within 30 days.

9. Cookies

Galora uses only functional cookies necessary to maintain your authenticated session. We do not use advertising cookies, tracking pixels, or third-party analytics cookies. No consent banner is required for strictly necessary cookies under applicable law.

10. Changes to This Policy

We may update this Privacy Policy periodically. For material changes, we will notify you via email or in-app notice at least 14 days before the change takes effect. Continued use of the Service after the effective date constitutes acceptance of the updated policy.

Terms of ServiceSign inCreate account