Privacy policy
Version 1.0 · Updated · 11 min read
TripVoyaa is a Data Fiduciary under India's Digital Personal Data Protection Act, 2023 (DPDPA). This notice explains what personal data we collect, why, how long we keep it, and the rights available to you under the DPDPA and the DPDP Rules, 2025.
The short version
- We collect data progressively — only what an identified feature actually needs, not "just in case".
- We never collect biometric data. A passkey's fingerprint/face unlock never leaves your device.
- We don't sell your data or hand it to third parties for their own marketing.
- You control promotional communications separately from essential booking and safety alerts.
- The Wallet is powered by Razorpay — see the Wallet Terms tab for exactly what that means for your data.
1. Who We Are and What This Notice Covers
This Notice is issued by [insert full legal name of the entity], incorporated under the Companies Act, 2013, CIN [insert CIN], registered office at [insert registered office address] ("TripVoyaa", "we", "us"), which owns and operates the TripVoyaa mobile application and website at tripvoyaa.com (the "Platform"). TripVoyaa operates the Platform as a technology platform through which Tour Operators publish and sell tours, bus routes and related travel services. In respect of the personal data described here, TripVoyaa determines the purpose and means of processing and is therefore a Data Fiduciary under the DPDP Act. This Notice applies to you as a customer, registered user, prospective user or visitor. Where a Tour Operator receives your personal data to deliver a service you booked, that Tour Operator processes it under its own obligations and its contract with TripVoyaa — the identity of the Tour Operator relevant to your booking is disclosed to you at the time of booking.
2. Personal Data We Collect
We collect personal data progressively — we ask for information at the point it's needed for an identified purpose, not because a future feature might need it. What we collect, when, why, and what it's used for is set out in the "What We Collect" section of this notice. We do not require data that isn't necessary for the service you asked for; where a field is optional, that's stated at the point of collection. We do not collect your biometric information — where you register a passkey, the biometric or device-unlock mechanism stays on your device under your device operating system's control; TripVoyaa receives only the public key credential and related authentication metadata. We do not knowingly collect personal data relating to a child except with verifiable parental/guardian consent.
3. Purposes for Which We Process Your Personal Data
We process your personal data to: create, authenticate, secure and recover your account (including OTP verification and Google/Apple Login or a passkey); create and personalise your profile; let you search, book, modify and cancel tours, seats and bus routes; process payments, retries, receipts, refunds and settlements; operate the TripVoyaa Wallet (loading, applying a balance to a booking, refunds, promotional credit, the transaction ledger, and returning unutilised balance); send essential service communications (confirmations, tickets, payment status) and operational/safety communications (boarding points, delays, emergencies); provide customer support; prevent and investigate fraud; verify your identity where lawfully required; comply with law and respond to lawful requests; analyse Platform usage using aggregated/anonymised data where possible; and send promotional communications only where you've separately enabled them. We never use your data for a purpose materially different from what we told you at collection, unless we give you fresh notice and get your consent to the new purpose.
4. Our Lawful Basis for Processing
We process your personal data on the basis of your free, specific, informed and unambiguous consent under Section 6 of the DPDP Act. Where you voluntarily give us data for a specified purpose without indicating you don't consent, we may process it for that purpose as a "legitimate use" under Section 7(a) — for example, contact details you give us in a support request, so we can respond. Where we're required to process or retain data to comply with Indian law or a court order, we do so under Sections 7(c) and 7(d). Consent is not the basis on which we can avoid a statutory retention obligation.
5. Consent, Communication Preferences and Withdrawal
We maintain three independently controllable categories: essential service communications (booking confirmations, payment status, security notices — you can't opt out while you hold an active account/booking, since they're part of the service itself); operational and safety communications (boarding changes, delay and emergency alerts, tied to a live booking); and promotional/marketing communications, sent only where you've separately enabled them. We never treat your mobile number given for authentication as consent to market to that number. You may withdraw consent at any time within the app or by writing to us — withdrawal is as easy as giving it. We'll stop the dependent processing within a reasonable time, though this may mean we can no longer provide the account or associated bookings, and we'll tell you before acting on the withdrawal. Withdrawal never affects the lawfulness of processing already done, or a booking or payment already made.
6. Device Permissions
Notification and location permissions are requested only at the point a feature that needs them is used — never as a condition of creating an account. Notification permission delivers essential, operational and safety notifications; promotional notifications only if you've separately enabled them, and you can disable those without disabling service notifications. Location permission is used only when a location-aware feature is active (nearby boarding points, distance calculation) — we do not collect your location continuously in the background by default. You are never required to share your live location just to view a vehicle's position on a map — that comes from the vehicle or an approved operational device, not your phone. You may withdraw a device permission at any time through your device settings; the features that depend on it will stop working.
7. Sharing and Disclosure of Personal Data
We share your data only as necessary: with the Tour Operator responsible for your booking (limited to what's needed to prepare the manifest, verify boarding and deliver the service — never your payment instrument or bank details); with the Volunteer assigned to your journey (limited to boarding coordination); with payment gateways/banks for collecting payment and processing refunds; with Razorpay for operating the Wallet; with communication providers to deliver the notices in Section 5; with our cloud hosting, analytics, support and fraud-detection processors under contract; with an identity verification provider where relevant; with our professional advisers under confidentiality; with a court, regulator or law enforcement authority where legally required; and with an acquirer in a merger or restructuring, bound by this Notice or an equivalent. We do not sell your personal data, and we do not disclose it to third parties for their own independent marketing. Where the Platform integrates with a service you choose, like Google or Apple Login, that provider's own processing in its own capacity is governed by its own privacy policy, not this Notice.
7A. The Wallet and the Role of Razorpay
TripVoyaa makes available a wallet facility powered by Razorpay. For the Wallet, we process your balance, the ledger of loading/application/refund/reversal transactions, transaction and order references, a reference to the payment instrument a balance was loaded from, bank account details you give us where a return of balance requires it, and any verification data the applicable regime requires. Razorpay is regulated by the Reserve Bank of India. In respect of the functions it performs under that regulation, Razorpay processes personal data in its own capacity and under its own statutory and contractual obligations, governed by its own privacy policy. We do not use your Wallet transaction history for marketing or personalisation unless you've separately enabled personalisation. See the full Wallet Terms tab for exactly how loading, refunds and the return of an unutilised balance work.
8. Retention and Erasure
We retain personal data only as long as necessary for the purpose it was collected, or for as long as applicable law requires. We erase it once its purpose is no longer served, unless retention is legally required — consent withdrawal, account closure and purpose-completion each trigger this check. Certain records are retained after account closure because the law requires it — transaction and invoicing records under GST and Income Tax law, and logs required under the DPDP Rules for the minimum period needed to identify a user and respond to lawful requests. Where an erasure obligation is triggered under the DPDP Rules, we'll notify you at least 48 hours before erasure so you have a chance to log in and preserve the data if you wish. We may retain data in aggregated or anonymised form indefinitely — that data doesn't identify you and isn't subject to these erasure obligations.
9. Identity Verification and Aadhaar
Where TripVoyaa has an identified, lawful requirement to verify your identity, we use the minimum information necessary. Aadhaar-based verification is subject to a distinct statutory regime — TripVoyaa will not carry out Aadhaar authentication or offline verification unless and until it holds the approvals and registrations that regime requires. Where Aadhaar verification is lawfully carried out, we obtain your consent for it specifically, use the information only for that purpose, never publish or share your Aadhaar number, and retain only the verification status or reference rather than the full document, unless the document itself must be retained by law.
10. Security Safeguards and Personal Data Breach
We implement reasonable security safeguards including encryption in transit and at rest, access control, logging and monitoring, and backup/recovery arrangements, and we require our processors to maintain equivalent safeguards. In the event of a personal data breach, we will notify each affected user without delay, describing the nature of the breach, its likely consequences, what we're doing about it, and what you can do — and we'll notify the Data Protection Board of India as required. No method of transmission or storage is completely secure; you're responsible for keeping your credentials and device secure, and for telling us promptly about any suspected unauthorised use of your account.
11. Children and Persons with Disability
The Platform is intended for individuals eighteen or older; we do not knowingly create an account for a child. Where we do process a child's personal data, we obtain verifiable parental or guardian consent first, and we never direct targeted advertising at children or track their behaviour. Where a booking is made for a child passenger, that data is processed on the verifiable consent of the parent or guardian and limited to what's necessary to deliver the journey safely. The same applies where a Data Principal has a lawful guardian.
12. Transfer of Personal Data Outside India
We may transfer personal data outside India where a service provider we've engaged processes or stores data outside India. Any such transfer is subject to Section 16 of the DPDP Act and any restriction the Central Government notifies for a particular country. We remain responsible to you for that data, and we impose contractual security and confidentiality obligations on the recipient.
13. Your Rights
Subject to the DPDP Act, you have the right to: a summary of the personal data we're processing about you and who we've shared it with; correction, completion and updating of your data, and erasure of data no longer necessary for its purpose (unless retention is legally required); grievance redressal for any act or omission of ours affecting your data; and to nominate someone to exercise your rights in the event of your death or incapacity. You can exercise these rights in the app or by writing to our Grievance Officer. We may ask you to authenticate yourself first, to stop your data being disclosed to the wrong person. If you're not satisfied with our response, or we miss the prescribed response period, you may complain to the Data Protection Board of India — after first going through our own grievance process.
14. Your Duties as a Data Principal
The DPDP Act places duties on you too: you must comply with applicable law when exercising your rights, must not impersonate another person, must not suppress material information when providing data for a document or identifier, must not register a false or frivolous grievance, and must furnish only verifiably authentic information when seeking correction or erasure. Breach of these duties can attract a financial penalty from the Data Protection Board of India.
15. Changes to this Notice
We may revise this Notice. Where a revision materially changes the purposes of processing or the categories of data we collect, we'll notify you of the change and, where required, get your fresh consent before the new purposes take effect. We keep a record of prior versions and of which version each user has accepted.
16. Language
You may access this Notice in English and in the languages specified in the Eighth Schedule to the Constitution of India, as required under the DPDP Act.
What we collect
- Mobile number, name, email — Account creation, OTP login, Google/Apple Login, booking confirmations and receipts (Kept while your account is active)
- Location — Only while a location-aware feature is active — nearby boarding points, nearby tours, distance calculation (Not collected continuously; not stored after the feature is used)
- Identity documents (where verification applies) — Operator verification for boarding, where a lawful verification requirement exists (Minimum information only; deleted once verification is complete unless law requires retention)
- Wallet balance and transaction ledger — Operating the TripVoyaa Wallet — loading, applying balance to a booking, refunds, promotional credit (Retained per the statutory minimum for the instrument type (see the Wallet Terms tab))
- Device, session and log data — Security, fraud prevention, diagnostics and performance (Minimum period prescribed under the DPDP Rules)