GalileiPay

Privacy Policy

Last updated: July 21, 2026

This policy is published in English and Spanish. In case of any discrepancy, the English version governs.

Who we are

GalileiPay is a product of Galilei Technologies LLC, a Delaware limited liability company located at 131 Continental Dr, Suite 305, Newark, DE 19713. This policy covers both our public website and the application at app.galileipay.com.

What we collect

Account information: your name, email address and the language you prefer. Business information: your company's legal name, EIN, address, licenses, the projects you work on, and the name of the person authorized to sign for your company (your authorized signatory) — used for the eligibility checks described in "Public records and background checks" below. EINs are stored encrypted. Documents you upload: invoices, pay-apps and subcontracts. These are stored encrypted in Amazon Web Services. Identity verification: a government-issued identity document and a selfie, collected by our verification provider. Banking information: when you connect a bank account for payouts or payments, that connection is handled by our payment processor. We never see or store your online banking credentials. Technical information: pages visited on our site and in the application, plus error diagnostics — see "Cookies and analytics" below.

Automated processing of your documents

We use OpenAI to read the invoices and subcontracts you upload, in order to extract amounts and dates and to flag contract clauses that affect whether we can buy a receivable. This means the content of those documents is transmitted to OpenAI for processing. We do not use them to train any model, and a person reviews every funding decision. If you would rather we process a document manually, write to us before uploading it.

Identity verification

To comply with know-your-customer obligations, we use Didit to verify identity. That process collects an identity document and a facial image, which are biometric information. We do not store the facial image that our verification provider captures. We keep the verification result and metadata from that process as part of your account record.

Who we share information with

We share only what each provider needs to do its job: Stripe (payments, payouts and bank connections), Didit (identity verification), OpenAI (document processing, described above), Resend (transactional email), Amazon Web Services (encrypted storage of the documents you upload and of our audit records), Sentry (error monitoring) and Google (Google Analytics, described in "Cookies and analytics" below, and Google sign-in if you use it). If you turn on WhatsApp notifications, we share your phone number and the content of those notices with Meta. That is optional and off unless you enable it. We also share information with your general contractor or subcontractor when the transaction requires it — for example, a notice of assignment. We do not sell your information.

Cookies and analytics

We use Google Analytics to measure how our public site and the application are used. Google Analytics sets cookies to do this. We have turned off Google's advertising signals and ad personalization for this data, and we do not use it for advertising or share it for advertising purposes. It is used only to understand product usage.

Public records and background checks

To underwrite a transaction we look up your company, and the person authorized to sign for it, in public sources: the OFAC sanctions list and secondary sanctions lists, federal court records (PACER) — including a federal criminal background search on your authorized signatory — the Texas Comptroller, and Florida's corporate, UCC and licensing registries. We keep the results of these checks as part of the transaction file, and they inform our decision on whether to buy a receivable from you.

How long we keep it

We keep transaction and audit records for as long as we are required to, and our audit log is written to storage that cannot be altered after the fact. If you close your account, we keep what we must for legal and accounting purposes and stop using the rest.

Your choices

You can change your language at any time in Settings, and turn WhatsApp notifications off there as well. For any other request about your information — access, correction or deletion — write to support@galileipay.com and we will handle it. We do not yet offer a self-service tool for this.

Security

Traffic is encrypted in transit, sensitive identifiers such as EINs are encrypted at rest, and access to production data is limited to the people who need it. No system is perfectly secure. If you believe your account has been compromised, write to support@galileipay.com immediately.

Not for children

GalileiPay is a service for businesses. It is not directed at anyone under 18 and we do not knowingly collect information from children.

Changes to this policy

If we change this policy we will update the date at the top. If the change is significant, we will tell you by email.

Contact

Questions about this policy: support@galileipay.com, or Galilei Technologies LLC, 131 Continental Dr, Suite 305, Newark, DE 19713.

Privacy Policy