Privacy Policy

Effective: January 2011 | Last Updated: June 2026 | Compliant with DPDPA 2023 & GDPR

1 Applicability & Governing Law

This Privacy Policy governs the collection, processing, and protection of personal data by TraveloChat (legally registered as UDYAM-HR-02-0031559, Shops Act PSA/REG/HSR/LI-Hsr-III/0354734), having its principal place of business at E61 Model Town Extension, Vidhut Nagar, Industrial Area, Hisar, Haryana – 125001, India.

This policy complies with:

  • Information Technology Act, 2000 (IT Act) and IT (Amendment) Act, 2008
  • Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011
  • Digital Personal Data Protection Act, 2023 (DPDPA 2023) – India
  • General Data Protection Regulation (GDPR) – applicable to EU/EEA travellers
  • Payment Card Industry Data Security Standard (PCI-DSS)

2 Data We Collect

We collect the following categories of data when you interact with us:

  • Identity Data: Full name, date of birth, nationality, passport/Aadhaar/PAN details (where required for booking)
  • Contact Data: Email address, mobile number, postal address
  • Travel Data: Travel dates, destinations, co-traveller names, dietary/medical requirements provided voluntarily
  • Financial Data: Payment method type (we do NOT store full card numbers — payments are processed by PCI-DSS compliant gateways)
  • Technical Data: IP address, browser type, device identifiers, cookies, pages visited, session duration
  • Communication Data: Enquiry forms, WhatsApp messages, emails, and call records for quality and training purposes

3 Purpose & Legal Basis for Processing

Under the DPDPA 2023 and GDPR, we process your data only on a lawful basis:

  • Contract Performance: To confirm bookings, arrange itineraries, and deliver travel services
  • Consent: To send promotional offers, newsletters (you may withdraw consent anytime)
  • Legal Obligation: To comply with GST, RBI, FEMA, and immigration authorities as required
  • Legitimate Interest: To improve our platform, detect fraud, and ensure website security

We will never sell, rent, or trade your personal data to any third party for marketing purposes.

4 International Data Transfers

When you book international tours, we may share necessary booking data (name, passport details, travel dates) with overseas hotels, airlines, ground handlers, and visa authorities in the destination country. Such transfers are made solely to fulfil your travel booking and are governed by:

  • Standard Contractual Clauses (SCCs) for EU/EEA travellers under GDPR
  • Ministry of External Affairs / Embassy requirements for visa-related data
  • IATA and airline-specific data transfer agreements

5 Cookies & Tracking

Our website uses essential, functional, and analytical cookies to enhance your experience. You can manage cookie preferences via your browser settings. Third-party analytics (Google Analytics) may collect anonymised usage data subject to their own privacy policies. You may opt out of Google Analytics at tools.google.com/dlpage/gaoptout.

6 Data Retention

We retain personal data only for as long as necessary:

  • Active booking records: 7 years (as required by Indian tax law under Income Tax Act, 1961)
  • Marketing consent records: Until withdrawal of consent
  • Website analytics data: 26 months (anonymised)
  • Payment transaction records: As required by RBI and FEMA guidelines

7 Your Rights

Under the DPDPA 2023, you have the right to:

  • Access your personal data held by us
  • Correct inaccurate or incomplete data
  • Erase data that is no longer required (right to be forgotten)
  • Nominate a person to exercise rights on your behalf in case of death or incapacity
  • Grievance Redressal — contact our Data Protection Officer at Infotravelochat.in@gmail.com

EU/EEA residents additionally have rights under GDPR including data portability and right to lodge a complaint with your national supervisory authority.

8 Data Security

We implement industry-standard security measures including:

  • SSL/TLS 256-bit encryption for all data in transit
  • Secure servers hosted in India with restricted access controls
  • PCI-DSS compliant payment processing via Razorpay
  • Regular security audits and vulnerability assessments
  • Employee data protection training

In the event of a data breach affecting your rights, we will notify you within 72 hours as required under DPDPA 2023.

9 Children's Privacy

Our services are not directed at children under 18 without verified parental/guardian consent. We do not knowingly collect personal data from minors. If you believe a child's data has been submitted without consent, please contact us immediately for deletion.

10 Grievance Officer

As required under Rule 5(9) of the IT (SPDI) Rules 2011 and DPDPA 2023, our designated Grievance Officer is:

TraveloChat — Data Grievance Officer
E61 Model Town Extension, Vidhut Nagar, Industrial Area, Hisar, Haryana – 125001
Email: Infotravelochat.in@gmail.com
Phone: +91 96535 92713
Grievances will be acknowledged within 24 hours and resolved within 30 days.
Questions about this policy? Contact us at Infotravelochat.in@gmail.com | +91 96535 92713