Effective: June 25, 2026
GalaTayo ("we," "us," "our") is a mobile application that helps Filipino friend groups plan trips, vote on activities, split expenses, and share memories. This policy explains how we collect, use, and protect your information when you use the GalaTayo app and website.
Account information. When you sign in with Google or Apple, we receive your name, email address, and profile photo. We store these to identify you within your trip groups.
Profile information. You may optionally add a bio, username, travel tags, avatar, cover photo, and favorite destination. Your social profile is only visible to others if you choose to make it public.
Trip data. Trip names, itinerary items, votes, and settings you create are stored to provide the trip planning features. This data is shared with members of the same trip.
Expense data. Expense descriptions, amounts, payer information, and split details are stored to compute balances. Receipt photos you attach are stored securely.
Photos and media. Photos you upload to trip vaults, journals, or Quick Galas are stored in cloud storage. These are visible only to members of the relevant trip or event.
Device information. We collect Firebase Cloud Messaging (FCM) tokens to send you push notifications. We do not collect device identifiers for advertising purposes.
Usage data. We collect basic app usage statistics (trips created, items suggested, votes cast) to power achievement badges and your profile stats. We do not use third-party analytics trackers.
We do not sell your data to third parties. We do not use your data for advertising. We do not share your data with third parties except as described in this policy.
Firebase (Google Cloud). Account data, trip data, expenses, votes, and journals are stored in Google Cloud Firestore. Authentication is handled by Firebase Authentication.
Cloudflare R2. Photos (expense receipts, vault images, journal photos) are stored in Cloudflare R2 object storage. Images may be served through a Cloudflare CDN edge cache for performance.
RevenueCat. If you subscribe to a paid tier (Barkada Host, Host+, or Legend), your purchase is processed through your device's app store (Google Play or Apple App Store). RevenueCat manages subscription entitlements on our behalf. We do not store your payment card details.
Within your trips. Your name, profile photo, and trip contributions (suggestions, votes, expenses, photos) are visible to other members of the same trip.
Public profile. If you enable a public profile, your username, bio, avatar, travel tags, and stats are visible to other GalaTayo users.
Service providers. We use Google (Firebase), Cloudflare (storage and CDN), and RevenueCat (subscriptions) to operate the app. These providers process data on our behalf under their own privacy policies.
Legal requirements. We may disclose information if required by law or to protect the safety of our users.
Export your data. You can export a copy of your data as JSON from Settings > Data & Privacy > Export my data.
Delete your account. You can permanently delete your account from Settings > Data & Privacy > Delete My Account. This removes your profile, personal data, and disassociates you from trips. Trip data shared with others (expenses, votes) is anonymized rather than deleted to preserve group records.
Notification preferences. You can toggle push notification categories (storage alerts, reminders) in Settings > Notifications.
Review consent. You can review what data we collect at any time from Settings > Data & Privacy > Review consent.
Block users. You can block other users from Settings > Data & Privacy > Blocked users.
We retain your data for as long as your account is active. Trip data is retained as long as the trip exists (the trip host controls archiving and deletion). If you delete your account, your personal data is removed within 30 days. Anonymized contributions to shared trips may persist.
Vault photos for free-tier trips are subject to a deletion countdown after the trip ends, as shown in the app. Paid-tier vaults are retained for the duration of the subscription.
GalaTayo is not intended for children under 13. We do not knowingly collect personal information from children under 13. The app includes an age gate during onboarding. If you believe a child under 13 has provided us with personal information, please contact us at hello@galatayo.com.
We use Firebase Authentication for secure sign-in, Firestore security rules to restrict data access to authorized users, and HTTPS for all data in transit. Photos are stored with access controls that limit visibility to trip members. While no system is 100% secure, we take reasonable measures to protect your data.
We may update this Privacy Policy from time to time. If we make material changes, we will notify you through the app or by updating the effective date above. Continued use of the app after changes constitutes acceptance of the updated policy.
If you have questions about this Privacy Policy or your data, contact us at:
Email: hello@galatayo.com