Privacy Policy
Last Updated: August 26, 2026 • Effective Date: August 09, 2026
At Glimzo (“we”, “us”, or “our”), we take your privacy and data security seriously. This Privacy Policy describes how Glimzo collects, uses, processes, stores, and protects your information when you visit or use our website (glimzo.app), merchant portal, and related services.
1. Information We Collect
We collect information in three primary ways: information you provide directly, information collected automatically, and location data granted with your consent.
A. Account & Profile Information: When you sign up, we collect your name, email address, password hash, and optional profile details (username, profile photo, banner photo, date of birth, and gender). For businesses and merchants, we also collect business name, physical store address, contact person details, and phone number.
B. User-Generated Content: Content you publish on Glimzo, including plans, meetups, activity descriptions, store listings, offers, deals, and photos uploaded to our media storage.
C. Technical & Device Data: IP address, device model, operating system, browser type, referring URLs, access timestamps, and error logs collected for diagnostic and anti-fraud purposes.
2. Location Data & Geospatial Processing
Glimzo is a real-world local discovery platform designed around the principle of Discover → Connect → Go.
When you grant device location permissions, your latitude and longitude coordinates are used in real time to calculate distance to nearby businesses, offers, and events using geospatial index queries (PostGIS and Uber H3 hexagonal indexes).
We do not persistently track your location in the background when the app is closed, nor do we sell your location history to third-party data brokers. You may revoke location permissions at any time via your browser or device settings, or manually select a city.
3. How We Use Your Information
- To provide, personalize, and optimize local discovery feeds, search results, and campaign listings.
- To facilitate user-created meetups, plans, and merchant promotions.
- To send critical transactional notifications (account verification, password changes, security alerts, and billing receipts).
- To prevent fraud, protect platform integrity, enforce acceptable use, and verify merchant store claims.
- To comply with statutory legal and financial accounting obligations.
4. Cookies, Tokens & Local Storage
We use essential cookies and browser storage technologies strictly necessary for security and functionality:
An HttpOnly, Secure refresh_token cookie used to securely maintain your session without exposing credentials to JavaScript.
A glimzo_ref cookie (30-day expiry) used exclusively to attribute referrals when a user joins through an invite link.
Browser localStorage used to store your preferred UI theme (Light, Dark, System) and cached location selector city.
We do not use third-party behavioral advertising cookies or cross-site tracking pixels.
5. Third-Party Service Providers & Sub-processors
We partner with trusted infrastructure and service providers to operate Glimzo. All sub-processors are bound by data processing agreements requiring strict confidentiality and security:
| Provider | Purpose | Data Processed |
|---|---|---|
| Resend | Transactional & Security Emails | Email address, recipient name |
| Gupshup | WhatsApp OTP Verification | Phone number, verification code |
| Cloudflare | R2 Media Storage & Stream Video | Uploaded images, videos, CDN delivery |
| Razorpay | PCI-DSS Payment Processing | Billing details, subscription status (no card numbers stored on Glimzo) |
| Google Cloud | Google OAuth & Geocoding API | OAuth email/name, address coordinate resolution |
| Sentry & Better Stack | Error Monitoring & Telemetry | Application stack traces, sanitized request logs |
6. Data Retention & Security
We employ industry-standard technical measures including encrypted transport (HTTPS / TLS 1.3), bcrypt password hashing, token versioning, and strict role-based access control.
We retain personal data for as long as your account remains active. Upon account deletion, personal identifiable details are anonymized or purged, and active sessions are terminated immediately.
7. Your Rights & Account Deletion
Under applicable data protection legislation (including the Digital Personal Data Protection Act 2023 and GDPR principles), you have the right to:
- Access & Rectify: Review and update your personal information anytime via Profile Settings.
- Delete Your Account: Permanently delete your account and invalidate all active credentials directly from Settings → Account Status → Delete Account.
- Revoke Permissions: Toggle notification channel delivery preferences or disable location sharing at any time.
8. Contact & Grievance Redressal
For privacy inquiries, data requests, or grievance redressal, please contact our Data Protection Officer:
Glimzo Legal & Privacy Operations
Email: [email protected]
Support: [email protected]
Location: Pune, Maharashtra, India
© 2026 Glimzo. All rights reserved.