Legal

Privacy Policy

Effective date: 21 May 2026

1. Data Fiduciary

This Privacy Policy is issued by Lytespace Technologies Private Limited (CIN: U46909TZ2026PTC038984), the operator of GalaHub (galahub.in), acting as the Data Fiduciaryunder the Digital Personal Data Protection Act, 2023 ("DPDP Act").

Registered office: 107, Gurusamy Nagar, Thaneer Pandal, Peelamedu, Coimbatore South, Coimbatore - 641004, Tamil Nadu, India.

This Policy explains what personal data we collect, why we collect it, how we use and protect it, and your rights as a Data Principal under Indian law. By using the Platform, you consent to the practices described here.

2. Personal Data We Collect

Account and identity data
  • Name, email address, and profile photograph (collected at registration or via Google Sign-In / OAuth).
  • Phone number, if provided.
  • Role on the Platform (Customer or Vendor).
Vendor-specific data
  • Business name, business address, service category, service description, pricing, packages, and availability.
  • Portfolio photographs and media uploaded by the Vendor.
  • Bank account or UPI details (for future payout features (not currently collected)).
Booking and transaction data
  • Event date, guest count, time slot, venue details, and service preferences submitted during the booking flow.
  • Booking token amount, transaction ID, payment status, and timestamps. We do not store card numbers or CVVs; these are handled entirely by Razorpay.
  • Booking status history (pending, accepted, declined, expired, confirmed).
Communications data
  • Messages exchanged between Customers and Vendors through the Platform's messaging feature.
  • Email notifications and system messages sent to your registered email.
RSVP data
  • Name, email, phone number, and attendance response of guests who respond to an event RSVP created on the Platform.
Usage and technical data
  • IP address, browser type, operating system, pages visited, and session timestamps, collected automatically for security, analytics, and performance.
  • Authentication cookies and session tokens necessary for the Platform to function.

3. How We Use Your Personal Data

We process your personal data only for the following purposes:
  • To create and manage your account.
  • To facilitate the booking process between Customers and Vendors.
  • To process payments and issue refunds through Razorpay.
  • To send booking confirmations, status updates, RSVP notifications, and transactional emails via Resend.
  • To enable in-platform messaging between Customers and Vendors.
  • To detect, prevent, and investigate fraudulent activity, abuse, or Terms violations.
  • To comply with our legal obligations under Indian law (including tax records and the DPDP Act).
  • To improve the Platform's features and performance, based on aggregated and anonymised usage data.
We do not use your personal data for automated profiling or decision-making that produces legal effects on you.

4. Sharing Your Personal Data

We do not sell, rent, or trade your personal data. We share it only in the following circumstances:

With Vendors (for confirmed bookings): Your name, phone number, event details, and booking information are shared with the Vendor you have booked, solely to enable them to provide the requested service.

With our Data Processors (third-party service providers):
  • Supabase Inc. (USA): database hosting, authentication, and file storage. Your data is stored on Supabase's infrastructure. Supabase processes data under its Data Processing Agreement.
  • Vercel Inc. (USA): web hosting and deployment infrastructure for galahub.in.
  • Resend Inc. (USA): transactional email delivery (booking confirmations, notifications).
  • Razorpay Software Private Limited (India): payment processing. Razorpay independently handles all card and payment credential data under its own privacy policy and RBI regulations.
  • Google LLC (USA): Sign-In with Google (OAuth 2.0). If you use Google Sign-In, your name and email are shared with us by Google, subject to Google's privacy policy. We do not receive your Google password.
For legal compliance: We may disclose your personal data to government authorities, regulators, or courts if required by law, court order, or to protect the rights and safety of Lytespace, the Platform, or its users.

5. Data Retention

  • Account data: Retained for as long as your account remains active. If you delete your account, we will delete or anonymise your personal data within 30 days, except where retention is required by law.
  • Booking and transaction records: Retained for a minimum of 3 years from the date of the transaction, as required for tax and legal compliance under Indian law (Income Tax Act, GST Act).
  • RSVP data: Retained until the associated event date has passed, then deleted within 90 days.
  • Usage and log data: Retained for up to 12 months for security and fraud detection purposes.

6. Cookies and Tracking

GalaHub uses the following types of cookies:
  • Strictly necessary cookies: Set by Supabase to maintain your authenticated session. These are required for the Platform to function and cannot be disabled.
  • Analytics cookies: Anonymised usage data collected to understand how users interact with the Platform. No personally identifiable data is used for analytics.
You can manage cookie preferences in your browser settings. Disabling strictly necessary cookies will prevent you from logging in or using authenticated features.

7. Your Rights Under the DPDP Act 2023

As a Data Principal under the Digital Personal Data Protection Act, 2023, you have the following rights:
  • Right to access: You may request a summary of the personal data we hold about you and how it is being processed.
  • Right to correction: You may request correction of inaccurate or incomplete personal data.
  • Right to erasure: You may request deletion of your personal data, subject to our legal retention obligations. You can initiate account deletion by contacting us at contact@galahub.in.
  • Right to grievance redressal: You have the right to have your grievances addressed by our Grievance Officer within the timelines set out below.
  • Right to withdraw consent: Where processing is based on your consent (e.g., marketing communications), you may withdraw consent at any time by contacting us. Withdrawal does not affect the lawfulness of processing prior to withdrawal.
  • Right to nominate: You may nominate another individual to exercise your rights in the event of your death or incapacity, in accordance with the DPDP Act.
To exercise any of the above rights, contact our Grievance Officer (see Section 10).

8. Data Security

We implement the following security measures to protect your personal data:
  • All data transmitted between your browser and our servers is encrypted using HTTPS (TLS).
  • Our database enforces Row Level Security (RLS) policies ensuring each user can only access their own data.
  • Authentication is managed via Supabase Auth with industry-standard OAuth 2.0 flows.
  • Access to production data is restricted to authorised personnel only.
Despite these measures, no internet transmission or storage system is completely secure. If you suspect a security breach affecting your account, contact us immediately at contact@galahub.in.

9. Children's Privacy

GalaHub is intended exclusively for users aged 18 years and above. We do not knowingly collect personal data from individuals under 18. If we become aware that we have inadvertently collected data from a minor, we will delete it promptly. If you believe a minor has registered on the Platform, please notify us immediately at contact@galahub.in.

10. Grievance Officer

In accordance with the Digital Personal Data Protection Act, 2023 and the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, we have appointed a Grievance Officer:

Name: Deepu Jose
Designation: Grievance Officer, Lytespace Technologies Private Limited
Email: lytespace.deepu@outlook.com
Address: 107, Gurusamy Nagar, Thaneer Pandal, Peelamedu, Coimbatore South, Coimbatore - 641004, Tamil Nadu, India

Response timelines: We will acknowledge your grievance within 48 hours of receipt and endeavour to resolve it within 15 days.

If you are not satisfied with our response, you may approach the Data Protection Board of India once it is constituted under the DPDP Act, 2023.

11. Cross-Border Data Transfers

Some of our Data Processors (Supabase, Vercel, Resend, Google) are located outside India. By using the Platform, you consent to the transfer of your personal data to these processors under appropriate safeguards, including data processing agreements consistent with the DPDP Act 2023 and applicable Indian law.

12. Third-Party Links

The Platform may contain links to third-party websites (e.g., Vendor external websites, Google Maps). Lytespace is not responsible for the content or privacy practices of those third-party sites. We encourage you to read their privacy policies before providing any personal data.

13. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, the Platform, or applicable law. The updated Policy will be posted on this page with a revised effective date. For material changes, registered users will be notified by email. Continued use of the Platform after the effective date of any change constitutes your acceptance of the updated Policy.

14. Contact Us

For any privacy-related questions, data requests, or concerns not addressed by the Grievance Officer:

GalaHub, Lytespace Technologies Private Limited
107, Gurusamy Nagar, Thaneer Pandal, Peelamedu,
Coimbatore South, Coimbatore - 641004, Tamil Nadu, India
Email: contact@galahub.in
Website: galahub.in
Terms of Service · galahub.in