01. Introduction & Overview
Welcome to Gowaal ("we", "our", or "us"). Gowaal is a hyper-local digital daily services ledger designed for vendors (milk suppliers, water suppliers, tiffin providers) and consumers to record, verify, and settle daily deliveries with total transparency.
This Privacy Policy explains how our mobile application collects, uses, stores, and discloses information when you use the Gowaal mobile application on Android and our associated web endpoints.
Our Privacy Commitment
We believe your daily delivery ledger is confidential. We do not sell your personal data, we do not host third-party advertisements, and we only collect data essential for providing the service ledger functionality.
02. Information We Collect
We collect only the information strictly necessary to provide and synchronize the digital ledger:
A. Information You Provide Directly
- Account Profile Data: Mobile phone number (verified via OTP) and full name. If you choose to log in using Google Sign-In, we receive your email address, display name, and avatar URL.
- Business & Vendor Details: If you register as a vendor, your business name, dairy/distribution code, default supply rates, and delivery route labels.
- Ledger & Delivery Logs: Delivery quantity (e.g., liters of milk, jars of water), shifts (Morning/Evening), delivery timestamps, payment entries, vacation/pause schedules, and outstanding balance calculations.
- Customer Records: Names, phone numbers, and delivery addresses added by vendors or linked via QR claim codes to track deliveries.
B. Information Collected Automatically
- Device Tokens (FCM): Firebase Cloud Messaging tokens used exclusively to push delivery updates, vacation notices, and billing alerts to your device.
- App Performance & Diagnostics: Basic app crash logs, device model, and operating system version for bug fixing and app stability.
03. Android Device Permissions
Gowaal requests only the minimum permissions required for operation. Here is an explicit breakdown of what is requested and why:
| Permission | Purpose | Data Uploaded / Stored? |
|---|---|---|
android.permission.CAMERA |
Used strictly in real-time to scan customer/vendor pairing QR codes or claim codes. | No. Video frames are processed locally on-device. No photos or videos are ever saved, stored, or transmitted to any server. |
android.permission.POST_NOTIFICATIONS |
Used to display real-time push notifications when a delivery is recorded, a vacation pause is requested, or a monthly bill is generated. | Notification interaction timestamps may be recorded to confirm receipt. |
android.permission.INTERNET |
Used to synchronize your offline ledger records with the secure cloud database. | Encrypted ledger synchronization only. |
04. Offline Storage & Security
Gowaal is built with an offline-first architecture:
- Local SQLite / Room Database: Your daily ledger entries and customer lists are securely stored on your local device for instant offline access and morning delivery route operations without internet connectivity.
- Transit Encryption: All communications between your device and our cloud backend use TLS/HTTPS encryption with pinned security certificates.
- Access Control: We utilize strict Row-Level Security (RLS) policies at the database layer ensuring that customers only view records where their profile is authorized, and vendors only access ledgers belonging to their distribution network.
05. Third-Party Service Providers
We work with trusted third-party infrastructure providers to run our cloud backend and authentication:
- Supabase: Cloud database, authentication, and API hosting. Supabase adheres to industry-standard data security and SOC-2 compliance.
- Google Play Services / Firebase: Firebase Cloud Messaging (FCM) for push notifications and Google Identity Services for Google Sign-In authentication.
These third-party providers only process information on our behalf and are strictly prohibited from using your data for any other purpose.
06. Zero Advertising & Data Selling Policy
No Data Selling or Advertising Networks
Gowaal does NOT sell, rent, license, or monetize your personal or financial records to data brokers, advertising agencies, or marketing companies. There are zero third-party advertising SDKs integrated into Gowaal.
Your ledger records are shared exclusively between the paired vendor and customer for mutual verification and billing settlement.
07. Data Retention Policy
We retain your personal information and ledger history for as long as your account remains active or as needed to maintain your transaction records for mutual financial settlements between vendors and customers. When you delete your account or request data erasure, your records are deleted or anonymized in accordance with Section 8.
08. Account & Data Deletion Instructions
In full compliance with Google Play Store User Data policies, users have the right to request deletion of their account and all associated personal data.
Method 1: In-App Deletion
- Open the Gowaal mobile application.
- Navigate to Profile / Settings.
- Select Account & Security > Delete Account.
- Confirm the prompt. Your active session will be invalidated and your account queued for permanent deletion.
Method 2: Email / Web Deletion Request
If you have uninstalled the application or cannot access your device, you can request account and data deletion by contacting us via email:
- Email: technograde007@gmail.com
- Subject Line:
Request for Gowaal Account & Data Deletion - Details to Include: Your registered mobile phone number and full name associated with your Gowaal account.
Upon verification, your profile, authentication credentials, and personal ledger links will be permanently deleted within 30 days.
09. User Rights under India DPDP Act 2023
Under India's Digital Personal Data Protection (DPDP) Act 2023, you have the following rights regarding your personal data:
- Right to Access: You have the right to review the personal data and ledger history held by Gowaal.
- Right to Correction & Updating: You may update or correct your profile details directly in the app.
- Right to Erasure: You may request the deletion of your personal data when it is no longer needed for the service.
- Right to Grievance Redressal: You have the right to register complaints regarding data handling with our Grievance Officer.
10. Children's Privacy
Gowaal is intended for adult consumers and business vendors managing daily household services and khata ledgers. We do not knowingly collect personal information from children under 18 years of age. If we learn that a minor has provided personal information without parental consent, we will promptly delete that information.
11. Grievance Officer & Contact Information
If you have any questions, feedback, or grievances regarding this Privacy Policy or our data practices, please contact our designated Grievance Officer: