1. Who we are
[Registered legal name — NOT SET] is the Data Fiduciary for personal data processed through this platform, under the Digital Personal Data Protection Act, 2023.
Data protection contact: [Data protection contact — NOT SET]. Registered address: [Principal registered address — NOT SET].
A tour operator you book with is a separate Data Fiduciary for the data we pass to them, and is responsible for their own handling of it.
2. What we collect
We collect only what a booking or an operator account requires.
- •Travellers: name, email, phone, gender (for room and seat allocation), booking and payment records
- •Operators: business identity, PAN, GSTIN, tourism registration, insurance details, bank details for payouts, authorised signatory contact
- •Everyone: device and usage data from analytics
3. Why we use it
To take and confirm bookings, share the details an operator needs to run your trip, process payments and refunds, meet tax and regulatory obligations, and prevent fraud.
Gender is collected because group-trip operators allocate shared rooms on a same-gender basis. It is used for that and for ladies-only seat rules, and for nothing else.
4. Who we share it with
The operator running your trip receives the details needed to carry you. Payment processors receive what they need to take payment. We share with authorities where the law requires it.
We do not sell personal data, and we do not use it for advertising profiling.
- •Tour operators — traveller name, age, gender, contact and ID type, for the trip you booked
- •Payment processors — the amount, order reference and contact details needed to take payment
- •Communication providers — phone number for booking SMS and one-time passwords
- •Cloud hosting and database providers — encrypted storage of the above
- •Government authorities, courts and law enforcement — only on lawful demand
5. ID documents
Operators must verify who is travelling. We ask for an ID type and number so a booking can be validated at the pickup point.
Aadhaar is one option among several — Passport, Driving Licence and Voter ID are equally accepted, and we will never make Aadhaar the only route to a booking. Following the Supreme Court's judgment in Puttaswamy (2018), a private company cannot compel Aadhaar.
We store the ID type and only the last four digits. The full number is not retained in our systems. The operator inspects the physical document at the pickup point.
6. Travellers under 18
Bookings must be made by someone aged 18 or over. Where a minor travels, the booking adult confirms they are the parent or lawful guardian, or act with that person's authority.
Under s.9 of the DPDP Act we do not knowingly process a child's personal data without verifiable parental consent, and we do not track, profile or direct advertising at children. Tell us if you believe we hold a child's data without that consent and we will delete it.
7. How long we keep it
We keep personal data only as long as the purpose requires, then delete it.
- •Booking and traveller records — 8 years, to meet tax and limitation-period requirements
- •Payment and invoice records — 8 years, as required by GST and income tax rules
- •Enquiries that never became a booking — 12 months
- •Account data — until you close the account, then 90 days
- •Server and security logs — 180 days
8. Your rights
Under the DPDP Act, 2023 you may exercise the following rights by writing to our data protection contact. We respond within 30 days.
- •Access — a summary of the personal data we hold about you and who it has gone to
- •Correction — to have inaccurate or incomplete data corrected or completed
- •Erasure — to have data deleted where it is no longer needed and no law requires us to keep it
- •Withdraw consent — as easily as it was given, without affecting processing already carried out
- •Nominate — to name someone who may exercise these rights if you die or become incapacitated
- •Grievance — to complain to us first, and to the Data Protection Board of India if unsatisfied
9. Security
Data is encrypted in transit. Passwords are stored using scrypt, never in plain text. Access to production data is restricted to staff who need it, and payment card details never touch our servers — they are handled by the payment processor.
No system is perfectly secure. If a breach occurs that is likely to affect you, we will notify you and the Data Protection Board of India as the DPDP Act requires.
10. Where data is processed
Our infrastructure is hosted in India. Some providers may process data outside India; where they do, transfers are limited to countries not restricted by the Central Government under s.16 of the DPDP Act, under contractual safeguards.
5. Retention
Booking and tax records are kept for the period Indian tax law requires. Operator KYC documents are kept for the life of the account plus the statutory retention period. Beyond that we delete or anonymise.
6. Your rights
Under the DPDP Act you may:
- •Ask what personal data we hold about you and how it is processed
- •Ask us to correct or complete inaccurate data
- •Ask us to erase data we no longer need
- •Nominate someone to exercise your rights if you cannot
- •Withdraw consent, and complain to the Data Protection Board of India
7. Security
Data is encrypted in transit and at rest. Access to KYC and payout data is limited to staff who need it. Report a suspected security issue to [Customer care email — NOT SET].