Legal
Privacy Policy
Booking a holiday means handing over more personal information than almost anything else you buy — your passport, your dates, sometimes your medical needs. This page explains exactly what we do with it.
Who we are
Tripido Travels, of Forum DLF Cyber City, DLF Phase 3, Sector 24, Gurugram, Haryana 122002, is the Data Fiduciary for the personal data described here — meaning we decide why and how it is used, and we are accountable for it under the Digital Personal Data Protection Act, 2023.
This policy covers the website tripido.in and everything we do with your data when you enquire about or book a holiday with us, whether that starts on this site, on WhatsApp, over the phone or by email.
CONFIRM Add the registered legal entity name and registration number, so a customer can identify who holds their data.
The short version
- We collect what we need to plan, book and run your holiday — nothing is sold to anyone.
- We share your details with the airlines, hotels and visa authorities your trip actually requires, and with nobody else for marketing.
- Your passport data goes to third-party visa centres because that is the only way a visa gets issued. Section 8 explains this in full.
- This website itself sets no advertising cookies and runs no analytics. What it does store is described in section 12.
- You can ask us what we hold, correct it, or ask us to delete it — section 13.
This summary is for orientation only; the sections below govern.
What we collect
Information you give us
- Identity and contact details — name, phone number, email address, postal address.
- Trip details — destination, dates, number of travellers, ages of children, budget, and preferences you tell us about.
- Travel document data — passport number, date and place of issue, expiry date, nationality, date of birth, and a scan or photograph of the passport.
- Photographs where a visa application requires them.
- Supporting documents for visas — which, depending on the destination, can include bank statements, salary slips, income tax returns, employment letters, invitation letters and proof of accommodation.
- Health, dietary and accessibility information you choose to tell us so we can plan around it.
- Payment information — the record that a payment was made, its amount, date and reference.
- Correspondence — your messages to us on WhatsApp, email or phone, and our replies.
Information collected automatically
When you visit this site, our hosting provider records standard web server logs: IP address, date and time, the pages requested, referring page, and browser and device type. These are generated by the server, not by tracking code we have added.
We do not store your full card number, CVV or UPI PIN. Card and UPI payments are processed by a payment gateway, which handles those details directly. We see only that the payment succeeded, for how much, and a masked reference. CONFIRM: name the payment gateway you use — e.g. Razorpay, PayU, CCAvenue — so customers know whose systems their card details enter.
Passport and other sensitive data
Some of what we handle is sensitive personal data under the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 — in particular passport and identity documents, financial documents submitted for visas, and any health information you give us.
For that category we commit to the following:
- we collect it only where a specific booking, visa or airline requirement makes it necessary;
- we tell you why we need it before you send it;
- we use it only for that purpose;
- we do not disclose it to anyone other than the suppliers and authorities your trip requires, unless the law compels us;
- we never publish it, and never use it for marketing.
Health information you volunteer is used solely to plan your trip — a ground-floor room, a dietary requirement, a slower itinerary — and is shared only with the specific supplier who needs to act on it.
How we collect it
- Enquiry forms on this website. The forms on this site do not submit to a database. They assemble what you typed into a message and open WhatsApp so you can send it to us. Your details reach us as a WhatsApp message, and WhatsApp's own privacy policy applies to that message in transit.
- WhatsApp, telephone and email, when you contact us directly.
- During booking, when we ask for passport and traveller details.
- From the person who books, where one member of a party supplies details for everyone. If you book for others, you confirm you have their permission to give us their data and that you have shown them this policy.
Why we use it
| Purpose | Data used | Basis |
|---|---|---|
| Answering your enquiry and preparing a quotation | Contact and trip details | Your consent |
| Booking flights, hotels and transfers | Name, passport, trip details | Performing our contract |
| Applying for visas and permits | Passport, photographs, supporting documents | Performing our contract |
| Taking payment and issuing receipts | Payment records | Performing our contract |
| Supporting you during the trip | Contact and itinerary details | Performing our contract |
| Accounting, tax and statutory records | Booking and payment records | Legal obligation |
| Handling a complaint or dispute | Correspondence and booking records | Legal claims |
| Sending offers and trip ideas | Name, contact details | Your consent — withdrawable at any time |
We do not sell your personal data, and we do not share it with third parties for their own marketing.
Third-party visa services
Visa applications are rarely handled by the destination's embassy directly. Most are outsourced to independent visa application centres — organisations such as VFS Global and BLS International — and in some cases to correspondent visa agencies abroad. To obtain your visa, your documents must go to them.
What this means for your data
- What is shared: your passport and its scan, photographs, and whichever supporting documents that destination demands — which can extend to bank statements, salary slips, tax returns and employment letters.
- Who receives it: the visa application centre, and through them the embassy, consulate or high commission of the destination country, and its immigration authorities.
- Where it goes: outside India, to the destination country. See section 9.
- Whose rules then apply: once your application is submitted, that provider and that government hold your data under their privacy policies and their national law — not this one. We cannot control how long they keep it, how they secure it, or who within that government sees it.
- What we retain: our own copy, handled as described in sections 10 and 11.
We will tell you which provider your application is going to before we submit it. If you would rather not have your documents pass through a third-party centre, the practical consequence is that we cannot obtain that visa for you and you would need to apply yourself where the destination allows it — the commercial effect of that is covered in section 8 of our Terms & Conditions.
Sending data outside India
International travel makes cross-border transfer unavoidable: a hotel in Bali, an airline in Vietnam or a consulate processing a Schengen application all sit outside India, and all need your details to deliver what you booked.
We transfer personal data outside India only where it is necessary to perform your booking, and only to the supplier or authority concerned. Countries receiving it may have data protection standards different from India's. Transfers are made in accordance with the Digital Personal Data Protection Act, 2023 and any restrictions the Central Government notifies under it.
How long we keep it
| What | Kept for |
|---|---|
| Enquiries that never became bookings | CONFIRM: 12–24 months is typical |
| Booking and payment records | CONFIRM: normally 8 years, for tax |
| Passport scans and visa documents | CONFIRM: recommend deleting shortly after travel |
| Complaint correspondence | CONFIRM |
| Marketing consent records | Until you withdraw consent |
Recommendation. Passport scans are the highest-risk data any travel business holds and have no use once a trip is over. Deleting them soon after travel — while keeping the booking record itself for tax — sharply reduces what a breach could expose. The DPDP Act expects data to be erased once its purpose is served.
How we protect it
This website is served over HTTPS, so what passes between your browser and the site is encrypted in transit. The site sends security headers instructing browsers not to allow the page to be framed or content types to be guessed.
Beyond the website, we restrict access to booking and passport data to the people who need it to do their job, and we require them to keep it confidential.
CONFIRM Describe your actual internal measures honestly — where passport scans are stored, who can open them, whether devices are password-protected and encrypted, and whether accounts use two-factor authentication. Do not claim controls you do not have; an overstated security section is a liability rather than a defence.
No method of transmission or storage is completely secure. If a breach occurs that is likely to affect you, we will notify you and the Data Protection Board of India as the Digital Personal Data Protection Act, 2023 requires.
Your rights over your data
Under the Digital Personal Data Protection Act, 2023 you have the right to:
- Know what we hold — a summary of your personal data and who we have shared it with.
- Have it corrected — inaccurate or incomplete data put right. Passport details in particular must be exact, so tell us immediately if anything changes.
- Have it erased, where we no longer need it for the purpose it was collected for and no law requires us to keep it.
- Withdraw consent at any time, as easily as you gave it. Withdrawing consent to marketing stops the marketing; withdrawing consent to data we need for a booking may mean we can no longer deliver that booking.
- Nominate another person to exercise these rights on your behalf in the event of your death or incapacity.
- Complain — to our Grievance Officer first, and afterwards to the Data Protection Board of India.
To exercise any of these, email sales@tripido.in. We may ask you to verify your identity before we act — we are not going to hand someone's passport data to a stranger who asks nicely. We will respond within 30 days.
To stop marketing messages, reply STOP to any WhatsApp message from us, or email us. This has no effect on messages about a trip you have already booked, which we must keep sending.
Grievance Officer
If you are unhappy with how we have handled your personal data, contact our Grievance Officer:
CONFIRM — REQUIRED BY LAW
Name: ____________________
Designation: ____________________
Email: ____________________
Telephone: ____________________
Address: Forum DLF Cyber City, DLF Phase 3, Sector 24, Gurugram, Haryana 122002
Naming a Grievance Officer with contact details is mandatory under the Digital Personal Data Protection Act, 2023, the Information Technology Act, 2000 and the Consumer Protection (E-Commerce) Rules, 2020. This page should not go live with these blanks unfilled.
We will acknowledge your grievance within 48 hours and resolve it within 30 days. If you remain dissatisfied, you may complain to the Data Protection Board of India.
Children
This website is not directed at children, and we do not knowingly collect data directly from anyone under 18.
We do process children's data when they travel — names, ages and passport details supplied by a parent or guardian who is booking the family's holiday. Under the Digital Personal Data Protection Act, 2023 we rely on that parent or guardian's consent, and we use children's details only to make the booking. We do not use them for tracking, profiling or advertising.
Changes to this policy
We may update this page as our practices or the law change. The date at the top shows the last revision. Where a change materially affects how we use data you have already given us, we will tell you directly rather than relying on you to notice.
How to contact us
Tripido Travels
Forum DLF Cyber City, DLF Phase 3, Sector 24, Gurugram, Haryana 122002
Telephone: +91 99582 23023
Email: sales@tripido.in
Hours: Real people, 24×7
See also our Terms & Conditions.