We collect what we need to run a verified, trust-first community on Puerto Galera, and no more. Sensitive material like your verification documents is encrypted and access is tightly restricted. This page reflects how the product actually handles data.
What we collect
- Account
- Email, password (stored only as a hash), your first and last name, and — if you use it — a phone number.
- Profile
- Display name, date of birth, gender and who you’re interested in, your role on the island, languages, interests, a short bio, and your area (with optional approximate coordinates).
- Personality read
- Your answers to the short compatibility questions, plus five derived scores.
- Verification
- The selfie, ID or other proof you submit, and the outcome of the human review.
Your personality read stays private
The personality questionnaire is hidden from your profile — other members never see it. It is used only to score compatibility. If you export your data, you receive the five derived compatibility scores, not your raw answers.
Verification documents
- Selfies and ID documents are stored encrypted (server-side encryption) in dedicated secure storage.
- Reviewers see redacted metadata only, through short-lived signed links that expire in minutes.
- Access is limited to a small set of trust & safety roles, and every access is logged.
Location
Your area — and optional approximate coordinates — is used to rank who you see and to pick fair meetup venues. There is no continuous or background location tracking. Sharing live location is strictly opt-in, per meetup, when you choose to share an emergency contact.
Payments
Payments (for example premium verification or boosts) run through PayMongo’s hosted checkout. GaleraMatch never sees or stores your card or wallet details — only a payment reference, amount and status. Card, GCash and Maya data stay with the payment provider.
Who can see what
- Your trust score is never shown to other members.
- Your personality answers are never shown to other members.
- New profiles start with limited visibility until onboarding and verification progress.
Your controls
- You choose to join — nothing goes live until you accept the guidelines and safety protocol.
- You can export your account data at any time.
- You can delete your account; it is removed from discovery immediately and deactivated.
Security
Credentials and signing keys are held in managed secret storage, never in our source code, and are rotated on a schedule. Sessions use signed tokens, and sensitive storage is encrypted. If a key is ever exposed we revoke and rotate it and re-run our readiness checks.
This reflects current behaviour and will be updated as the product grows. Questions about your data? Reach us through the app.