PRIVACY POLICY
Effective Date:01th April 2025
Last Updated:29th June 2026
Website: https://galla.app
Company Legal Name: Treewalker Digital Private Limited
Registered Office: Vikas Plaza.38/ 1A (4), Kanappana Agrahara, Hosur Rd, Phase II, Electronic City, Bengaluru, Karnataka 560100
Email: legal@treewalkerlabs.com
GSTIN: 29AAICT9733E1ZX
This Privacy Policy explains how Treewalker Digital Private Limited (“Treewalker Digital”, “Galla”, “Galla.app”, “Company”, “we”, “us”, or “our”) collects, uses, stores, processes, shares, protects, and deletes personal data and other information when you access or use Galla.app, our website, applications, SaaS platform, dashboards, APIs, integrations, support services, ecommerce development services, WhatsApp marketing tools, warehouse management tools, retail management tools, POS billing tools, and related services.
By accessing or using Galla.app, you acknowledge that you have read and understood this Privacy Policy.
This Privacy Policy should be read together with our Terms of Service, Cookie Policy, Data Processing Addendum, Subprocessor List, Acceptable Use Policy, WhatsApp Marketing Policy, SLA and Support Policy, and any applicable order form, proposal, quotation, invoice, statement of work, or written agreement.
1. About Galla.app
Galla.app is a SaaS platform for retail, warehouse, billing, inventory, ecommerce, customer communication, WhatsApp marketing, third-party integrations, and business operations.
Depending on the customer’s subscribed plan or commercial agreement, Galla.app may provide:
- Retail management software.
- POS billing and invoicing.
- Warehouse management system.
- Inventory and stock management.
- Product, vendor, customer, purchase, sales, order, and dispatch management.
- WhatsApp marketing and customer communication tools.
- Ecommerce website or store development and managed ecommerce services.
- Third-party integrations with ERP, accounting, payment gateway, ecommerce, marketplace, logistics, WhatsApp, SMS, email, cloud, analytics, and other platforms.
- Dashboards, reports, APIs, automations, and support services.
Because Galla.app processes business, operational, customer, employee, vendor, and transaction-related information, we take privacy and data protection seriously.
2. Scope of this Privacy Policy
This Privacy Policy applies to personal data and other information processed when:
- You visit https://galla.app or related websites.
- You create or use a Galla.app account.
- You use Galla.app as a customer, admin, employee, staff member, warehouse user, POS user, billing user, ecommerce user, or authorised user.
- You interact with us for sales, demo, onboarding, support, billing, training, or service delivery.
- You submit information through forms, chat, email, calls, WhatsApp, campaigns, landing pages, or support channels.
- You use Galla.app modules such as Retail Management, POS Billing, Warehouse Management, WhatsApp Marketing, Ecommerce Development, or Third-Party Integrations.
- You are an end customer, vendor, supplier, employee, contractor, shopper, recipient, or business contact whose data is processed by one of our customers through Galla.app.
This Privacy Policy does not apply to third-party websites, applications, payment gateways, ecommerce platforms, marketplaces, WhatsApp/Meta services, ERP systems, logistics platforms, or other third-party services that are not owned or controlled by Treewalker Digital Private Limited.
3. Our Role in Processing Personal Data
Depending on the context, Treewalker Digital Private Limited may act in different roles
3.1 When we act as an independent data fiduciary / controller
We may act as an independent data fiduciary or controller when we collect and use personal data for our own purposes, such as:
- Website visitors.
- Sales leads.
- Demo requests.
- Customer account creation.
- Billing and invoicing.
- Vendor and partner management.
- Customer support and service communications.
- Marketing communications sent by Treewalker Digital.
- Security, fraud prevention, and platform improvement.
- Legal, accounting, tax, and compliance requirements.
3.2 When we act as a data processor / service provider
We may act as a data processor or service provider when our business customers use Galla.app to process personal data of their own customers, employees, vendors, suppliers, shoppers, recipients, or business contacts.
In this case:
- The business customer decides what data is collected.
- The business customer decides why and how the data is used.
- The business customer is responsible for providing notices and obtaining consent where required.
- Galla.app processes such data only to provide, secure, support, maintain, and improve the services.
- Data processing may also be governed by a Data Processing Addendum or written agreement.
-
4. Types of Information We Collect
We may collect the following categories of information, depending on how you use Galla.app.
4.1 Business and account information
This may include:
- Business name.
- Legal entity name.
- GSTIN, CIN, tax registration, and billing details.
- Registered office or business address.
- Contact person name.
- Designation.
- Email address.
- Phone number.
- Login credentials.
- User roles and permissions.
- Store, warehouse, branch, company, or location details.
- Subscription plan, payment status, and order details.
4.2 User profile and access information
This may include:
- Name.
- Email address.
- Phone number.
- User ID.
- Role or designation.
- Department or location.
- Access permissions.
- Login time.
- IP address.
- Device and browser details.
- Activity logs.
- Security and authentication logs.
-
4.3 Retail, POS, billing, and transaction data
When customers use Galla.app for retail management or POS billing, the platform may process:
- Product details.
- SKU details.
- Price and discount details.
- Sales records.
- Purchase records.
- Invoice details.
- Credit notes and debit notes.
- Tax details.
- HSN/SAC details.
- Customer details.
- Vendor details.
- Payment mode.
- Billing counter details.
- Return and exchange details.
- Salesperson or user activity records.
4.4 Warehouse and inventory data
When customers use Galla.app for warehouse management, the platform may process:
- Stock records.
- Product movement details.
- Inward and outward records.
- Putaway, picking, packing, dispatch, and transfer details.
- Batch, serial number, barcode, QR code, or RFID-related data.
- Location and bin details.
- Cycle count and stock audit records.
- Warehouse user activity.
- Device or scanner logs.
- Integration logs with ERP, ecommerce, logistics, or marketplace systems.
4.5 WhatsApp marketing and communication data
When customers use Galla.app for WhatsApp marketing or communication, we may process:
- Recipient name.
- Mobile number.
- Message templates.
- Campaign details.
- Message content.
- Consent status, where recorded.
- Opt-out status, where recorded.
- Delivery, read, failed, or response status.
- Communication logs.
- WhatsApp Business Account or phone number details.
- Template approval status.
- Provider or Meta-related messaging metadata.
Customers are responsible for ensuring that all WhatsApp contacts are lawfully collected and that marketing communication is sent only with appropriate consent and in compliance with applicable rules and platform policies
4.6 Ecommerce data
When customers use Galla.app for ecommerce development, ecommerce management, or ecommerce integrations, we may process:
- Product catalogue data.
- Product images and descriptions.
- Order details.
- Buyer/customer details.
- Shipping and billing address.
- Payment status.
- Cart, checkout, return, refund, or cancellation data.
- Marketplace or channel data.
- Ecommerce website content.
- Support and service request data.
4.7 Third-party integration data
When customers connect Galla.app with third-party systems, we may process data received from or sent to:
- ERP systems.
- Accounting software.
- Tally or similar accounting platforms.
- Ecommerce platforms.
- Marketplaces.
- Payment gateways.
- Logistics platforms.
- WhatsApp or messaging providers.
- SMS and email gateways.
- Analytics tools.
- Cloud platforms.
- APIs or custom systems.
The exact data processed depends on the integration configured by the customer.
4.8 Support and communication data
When you contact us, we may collect:
- Name.
- Email address.
- Phone number.
- Company name.
- Query details.
- Support tickets.
- Chat messages.
- Call notes.
- Screenshots or attachments shared by you.
- Error logs.
- Remote support session details.
- Feedback and survey responses.
4.9 Website, device, and usage information
When you visit our website or use our platform, we may collect:
- IP address.
- Browser type.
- Device type.
- Operating system.
- Pages visited.
- Referring website.
- Time spent on pages.
- Click activity.
- Session information.
- Cookie identifiers.
- Approximate location based on IP address.
- Error, crash, or performance logs.
- Security event logs.
More information is available in our Cookie Policy.
5. How We Collect Information
We may collect information through:
- Website forms.
- Demo requests.
- Account registration.
- Subscription or order forms.
- Emails.
- Phone calls.
- WhatsApp communication.
- Support tickets.
- Chat tools.
- Platform usage.
- Uploaded files.
- API integrations.
- Third-party integrations.
- Cookies and similar technologies.
- Payment and billing systems.
- Training, onboarding, or implementation processes.
- Logs generated by the platform.
We may also receive information from authorised users, business customers, third-party platforms, partners, resellers, payment gateways, communication providers, cloud providers, and integration partners.
6. How We Use Information
We use information for the following purposes.
6.1 To provide and operate Galla.app
We use information to:
- Create and manage accounts.
- Provide access to subscribed modules.
- Process retail, POS, warehouse, inventory, ecommerce, WhatsApp, and integration workflows.
- Enable dashboards, reports, APIs, and automations.
- Configure customer accounts.
- Provide onboarding, training, and implementation.
- Deliver support and troubleshooting.
- Maintain platform availability and performance.
6.2 To process transactions and billing
We use information to:
- Generate invoices.
- Process payments.
- Track subscriptions.
- Manage renewals.
- Apply taxes.
- Handle overdue payments.
- Maintain accounting and statutory records.
- Respond to billing queries.
-
6.3 To provide customer support
We use information to:
- Respond to support requests.
- Investigate issues.
- Troubleshoot bugs.
- Review logs.
- Improve user experience.
- Provide remote assistance where authorised.
- Communicate about service issues or updates.
6.4 To enable WhatsApp marketing and communication features
We use information to:
- Send messages selected or configured by the customer.
- Manage message templates.
- Track campaign delivery.
- Process message status.
- Maintain communication logs.
- Support opt-out or consent records where configured.
- Integrate with WhatsApp Business providers.
Customers are responsible for lawful use of WhatsApp marketing features.
6.5 To enable third-party integrations
We use information to:
- Connect Galla.app with customer-authorised third-party systems.
- Send and receive data through APIs.
- Sync orders, invoices, stock, customers, vendors, payments, and reports.
- Maintain integration logs.
- Troubleshoot integration errors.
- Support customer workflows
6.6 To improve and secure our services
We use information to:
- Monitor service performance.
- Detect errors and bugs.
- Improve product features.
- Enhance security.
- Prevent fraud, abuse, spam, or unauthorised access.
- Conduct internal analytics.
- Test new features.
- Maintain audit logs.
- Protect the platform, customers, and users.
6.7 To communicate with you
We may use information to send:
- Account notifications.
- Security alerts.
- Service updates.
- Billing notices.
- Renewal reminders.
- Product updates.
- Training and onboarding communication.
- Support responses.
- Marketing communication, where permitted.
- Legal or policy notices.
You may opt out of non-essential marketing communication, but we may continue sending service, security, billing, legal, or transactional messages.
6.8 To comply with legal obligations
We may use information to:
- Comply with applicable law.
- Maintain tax, accounting, and statutory records.
- Respond to lawful requests by government, court, or regulatory authorities.
- Enforce our agreements and policies.
- Protect our legal rights.
- Investigate misuse, fraud, security incidents, or unlawful activity.
7. Legal Basis for Processing
Depending on the applicable law and context, we may process personal data based on one or more of the following grounds:
- Consent.
- Performance of a contract.
- Compliance with legal obligations.
- Legitimate business purposes.
- Security and fraud prevention.
- Customer instructions, where we act as a processor or service provider.
- Legal claims or dispute resolution.
- Any other lawful basis permitted under applicable law.
Where consent is required, you may have the right to withdraw consent, subject to legal, contractual, operational, and technical limitations.
8. Customer Responsibilities for End Customer Data
If you are a Galla.app business customer, you are responsible for personal data that you upload, import, collect, or process through Galla.app.
You are responsible for:
- Providing appropriate privacy notices to your customers, employees, vendors, suppliers, and users.
- Obtaining consent where required.
- Ensuring that personal data is collected lawfully.
- Ensuring that WhatsApp, SMS, email, or marketing communication is sent lawfully.
- Ensuring that uploaded contact lists are not purchased, scraped, unauthorised, or unlawful.
- Handling opt-out, unsubscribe, correction, deletion, and grievance requests from your end customers.
- Ensuring that your use of Galla.app complies with applicable laws and third-party platform policies.
- Configuring access controls and permissions correctly.
- Avoiding upload of unnecessary, excessive, or unlawful personal data.
Treewalker Digital Private Limited is not responsible for unlawful data collection, unlawful marketing, incorrect customer data, or misuse of the platform by the customer or its users.
9. Sharing of Information
We do not sell personal data.
We may share information in the following cases.
9.1 With service providers and subprocessors
We may share information with trusted service providers who help us operate, host, secure, support, and improve Galla.app.
These may include:
- Cloud hosting providers.
- Database and infrastructure providers.
- Email service providers.
- SMS providers.
- WhatsApp Business service providers.
- Payment gateways.
- Analytics providers.
- Customer support tools.
- Security and monitoring tools.
- Backup and storage providers.
- Professional advisors.
- Implementation or development partners.
Our Subprocessor List may provide additional information about such providers.
9.2 With third-party integrations selected by customers
If a customer connects Galla.app with a third-party service, we may share or receive data with that service as authorised by the customer.
Examples include:
- ERP systems.
- Accounting software.
- Ecommerce platforms.
- Marketplaces.
- Logistics providers.
- Payment gateways.
- WhatsApp/Meta or communication providers.
- SMS/email gateways.
- Custom APIs.
The customer is responsible for reviewing the privacy practices and terms of third-party services.
9.3 With business users and account admins
Information may be visible to account owners, admin users, authorised users, managers, or other users configured by the customer.
Customers are responsible for assigning correct user roles and permissions.
9.4 For legal and compliance reasons
We may disclose information if required to:
- Comply with law.
- Respond to court orders, legal process, or government requests.
- Protect our rights, property, customers, users, or the public.
- Investigate fraud, misuse, security incidents, or unlawful activity.
- Enforce our Terms of Service or agreements.
9.5 In connection with business transfers
If Treewalker Digital Private Limited is involved in a merger, acquisition, restructuring, investment, financing, sale of assets, or business transfer, information may be transferred as part of that transaction, subject to appropriate confidentiality and legal protections.
10. International Data Transfers
Galla.app may use cloud, infrastructure, support, communication, analytics, or integration providers located in India or other countries.
Where personal data is transferred outside the country where it was collected, we use reasonable safeguards as required by applicable law, which may include contractual protections, customer instructions, vendor due diligence, data processing agreements, and security measures.
Customers using Galla.app for international operations are responsible for ensuring that their own data transfer obligations are met.
11. Data Retention
We retain information only for as long as reasonably required for the purposes described in this Privacy Policy, unless a longer retention period is required or permitted by law, contract, tax requirements, accounting rules, audit obligations, dispute resolution, fraud prevention, security, or legitimate business purposes.
Retention periods may vary depending on the type of data.
11.1 Account and billing data
Account, invoice, payment, tax, and commercial records may be retained for the period required under applicable law and business record requirements.
11.2 Customer Data inside Galla.app
Customer Data may be retained while the subscription is active. After termination, cancellation, expiry, or prolonged non-payment, Customer Data may be retained for a limited period and then deleted as per our Data Retention and Deletion Policy.
11.3 Backups
Backup copies may remain for a limited period before being overwritten or deleted according to backup cycles.
11.4 Support records
Support tickets, emails, issue logs, chat records, and troubleshooting records may be retained for service quality, training, security, dispute resolution, and audit purposes.
11.5 Security logs
Security logs, access logs, error logs, and audit logs may be retained to detect, investigate, and prevent security incidents, misuse, fraud, or unauthorised access.
12. Data Deletion
Customers may request deletion of their account or Customer Data, subject to:
- Active subscription status.
- Contractual obligations.
- Payment obligations.
- Legal and tax retention requirements.
- Backup cycles.
- Dispute resolution.
- Fraud prevention.
- Security requirements.
- Technical limitations.
- Any applicable written agreement.
When deletion is completed, we may provide confirmation where commercially and technically feasible.
We may retain limited records where required for legal, tax, security, audit, or dispute purposes.
13. Data Security
We use reasonable technical and organisational measures designed to protect information from unauthorised access, misuse, alteration, disclosure, loss, or destruction.
Security measures may include:
- Encryption in transit.
- Access controls.
- Role-based permissions.
- Authentication controls.
- Secure development practices.
- Logging and monitoring.
- Backup processes.
- Vulnerability management.
- Limited access by authorised personnel.
- Administrative safeguards.
- Vendor due diligence.
- Incident response procedures.
However, no internet-based system, SaaS platform, cloud service, or electronic transmission is completely secure. Customers are responsible for securing their own devices, users, passwords, networks, browsers, printers, barcode scanners, POS hardware, and local systems.
14. Security Incidents
If we become aware of a security incident that affects personal data processed through Galla.app, we will take reasonable steps to investigate, contain, mitigate, and remediate the incident.
Where required by applicable law or contract, we will notify affected customers or authorities within applicable timelines.
Customers are responsible for notifying their own end customers, employees, vendors, suppliers, or regulators where the customer is legally responsible for such notification.
15. Children’s Personal Data
Galla.app is intended for business use and is not directed to children.
Customers should not use Galla.app to knowingly collect or process personal data of children unless they have a lawful basis, required parental or guardian consent, and appropriate safeguards under applicable law.
If we become aware that personal data of a child has been processed unlawfully through Galla.app, we may take steps to delete or restrict such data, subject to customer instructions and legal obligations.
16. Marketing Communications
We may send marketing communication about Galla.app products, services, events, webinars, updates, offers, or educational content.
You may opt out of marketing communication by using the unsubscribe link, replying with an opt-out request, or contacting us.
Even if you opt out of marketing communication, we may still send transactional, service, billing, legal, security, or account-related communication.
Customers using Galla.app for WhatsApp, SMS, email, or marketing campaigns are responsible for obtaining consent and managing opt-outs from their own recipients.
17. Cookies and Similar Technologies
Our website and platform may use cookies, local storage, pixels, tags, scripts, SDKs, and similar technologies to provide essential functionality, improve performance, analyse usage, remember preferences, secure the platform, and support marketing.
For more details, please read our Cookie Policy.
You can manage cookies through your browser settings or through our cookie consent tool where available.
18. Third-Party Websites and Services
Galla.app may contain links or integrations with third-party websites, applications, platforms, services, APIs, or tools.
We are not responsible for the privacy practices, content, security, availability, or data handling of third-party services.
Third-party services may include:
- WhatsApp/Meta.
- Payment gateways.
- Ecommerce platforms.
- Marketplaces.
- Logistics providers.
- ERP or accounting systems.
- Cloud providers.
- Analytics tools.
- SMS and email providers.
- Support tools.
You should review the privacy policies and terms of such third-party services before using them.
19. User Rights
Depending on applicable law, you may have rights in relation to your personal data, including:
- Right to access personal data.
- Right to correct inaccurate or incomplete data.
- Right to update data.
- Right to delete data.
- Right to withdraw consent.
- Right to object to or restrict certain processing.
- Right to receive a copy of data, where applicable.
- Right to grievance redressal.
- Right to nominate another person, where applicable.
- Right to complain to a regulatory authority, where applicable.
Rights may be subject to limitations under applicable law, contract, security requirements, tax retention rules, legal claims, and technical feasibility.
20. How to Exercise Your Rights
You may contact us at:
Privacy Email: legal@treewalkerlabs.com
Grievance Email: legal@treewalkerlabs.com
Company: Treewalker Digital Private Limited
Address: Vikas Plaza.38/ 1A (4), Kanappana Agrahara, Hosur Rd, Phase II, Electronic City, Bengaluru, Karnataka 560100
To process your request, we may need to verify your identity and confirm your relationship with the relevant account or organisation.
If your data is processed by one of our business customers through Galla.app, we may direct your request to that customer because the customer controls how such data is collected and used.
21. Customer Admin Controls
Business customers and admin users may be able to:
- Add or remove users.
- Assign roles and permissions.
- Export data.
- Configure integrations.
- Manage communication templates.
- Review activity logs.
- Configure access settings.
- Request deletion or closure of accounts.
- Manage connected services.
Customers are responsible for using these controls properly and ensuring that only authorised persons have access.
22. Automated Processing and Analytics
Galla.app may use automated processing, analytics, dashboards, reports, alerts, and system-generated insights to support business operations.
Such processing may help customers understand:
- Sales trends.
- Inventory movement.
- Stock levels.
- Order status.
- Billing activity.
- Warehouse activity.
- Campaign performance.
- User activity.
- Integration performance.
- Operational exceptions.
Customers should independently verify business-critical, financial, tax, accounting, warehouse, and compliance data before relying on it.
23. Aggregated and Anonymised Data
We may create aggregated, anonymised, or de-identified data that does not identify a specific individual or customer.
We may use such data to:
- Improve Galla.app.
- Develop new features.
- Analyse performance.
- Understand usage trends.
- Publish high-level insights.
- Improve security and reliability.
We will not use aggregated or anonymised data to identify individuals.
24. Payment Information
Payments may be processed through third-party payment gateways, banks, UPI providers, or financial service providers.
We may collect billing details, invoice details, payment status, transaction reference numbers, and related records.
We do not intentionally store full card numbers or sensitive payment authentication details unless specifically required and lawfully permitted. Payment providers may process payment information under their own terms and privacy policies.
25. Data Accuracy
Customers and users are responsible for ensuring that data uploaded, entered, imported, configured, or processed through Galla.app is accurate, updated, lawful, and complete.
Treewalker Digital Private Limited is not responsible for incorrect reports, invoices, messages, stock records, tax records, or integrations caused by inaccurate, incomplete, outdated, or unlawful customer-provided data.
26. Employee and Contractor Access
Access to customer information by our employees, contractors, or authorised personnel is limited to those who require access for legitimate business purposes such as support, implementation, troubleshooting, security, billing, or service delivery.
Such access may be subject to confidentiality obligations, internal controls, role-based permissions, and monitoring.
27. Subprocessors
We may use subprocessors and service providers to deliver Galla.app.
Subprocessors may help with:
- Hosting.
- Cloud infrastructure.
- Storage.
- Security monitoring.
- Analytics.
- Email delivery.
- SMS or WhatsApp communication.
- Payment processing.
- Customer support.
- Error monitoring.
- Backup and disaster recovery.
- Professional services.
We recommend maintaining a separate Subprocessor List on the website and updating it when vendors change.
28. Data Location
Customer Data may be stored in cloud infrastructure located in India or other regions depending on the hosting configuration, customer agreement, cloud provider, integration provider, and service architecture.
Enterprise customers with specific data residency requirements should contact us before subscribing or deploying Galla.app.
29. Do Not Track
Some browsers provide “Do Not Track” signals. Because there is no uniform industry standard for responding to such signals, our website may not respond to every browser-based Do Not Track signal.
You may manage cookies through browser settings or our cookie consent tool where available
30. Changes to this Privacy Policy
We may update this Privacy Policy from time to time.
When we update the Privacy Policy, we will revise the “Last Updated” date. If changes are material, we may notify users through email, dashboard notification, website notice, or other reasonable means.
Your continued use of Galla.app after the updated Privacy Policy becomes effective means that you acknowledge the updated policy
31. Contact Information
For privacy-related questions, requests, complaints, or grievances, contact:
Treewalker Digital Private Limited
Website: https://galla.app
Registered Office: Vikas Plaza.38/ 1A (4), Kanappana Agrahara, Hosur Rd, Phase II, Electronic City, Bengaluru, Karnataka 560100
Legal Email: legal@treewalkerlabs.com
Phone: +91-6366-740-274
GSTIN: 29AAICT9733E1ZX
32. Recommended Related Policies
This Privacy Policy should be published along with:
- Terms of Service.
- Cookie Policy.
- Data Processing Addendum.
- Subprocessor List.
- Acceptable Use Policy.
- WhatsApp Marketing Policy.
- Security Policy.
- Data Retention and Deletion Policy.
- SLA and Support Policy.
- Responsible Disclosure Policy.
