Privacy Policy
Your trip plans and personal details are protected under India's Digital Personal Data Protection Act, 2023. We maintain a privacy-first, spam-free platform with zero cold calls.
By creating an account, unlocking an itinerary, booking a tour, setting up your travel profile, or using The Vacation Code ("the platform", "we", "us", "Data Fiduciary"), you acknowledge and consent to the data processing practices set out in this statutory document. This policy complies strictly with India's Digital Personal Data Protection Act, 2023 (DPDP Act), the Information Technology Act, 2000, and the SPDI Rules, 2011.
1. Information We Collect
We collect only the essential personal data required to fulfill travel bookings and provide curated trip planning services:
- Account & Profile Data: Full name, verified email address, mobile phone number, and account access credentials.
- Travel Preferences & Vibe: Destination wishlists, travel pacing, budget styles, and dietary choices shared to generate customized itineraries.
- Financial & Transaction Logs: Itinerary unlocks, tour package bookings, and gift card purchases. All online payments are handled directly by Razorpay (PCI-DSS Level 1 Certified). We never store or view credit card numbers, UPI PINs, or net-banking credentials.
- Traveller Identity Documents: For verified tour bookings, you may provide Passport, PAN, or government ID copies. These are stored in access-controlled, non-public storage outside the public web root and accessible solely to authorized booking compliance personnel.
- Security & Referral Logs: Aggregated usage analytics. Referral IP addresses are hashed using a one-way salt to protect your geographic privacy.
2. Legal Basis & How We Use Your Data
Under Section 4 of the DPDP Act 2023, we operate as a Data Fiduciary. The lawful basis for processing your data is your explicit consent or fulfilling a contractual travel booking:
- Delivering purchased itineraries, tour bookings, and Travel Club benefits.
- Issuing essential booking confirmations, GST invoices, and travel alerts.
- Calculating loyalty coin credits and referral rewards.
- Validating on-ground routing accuracy and fraud prevention.
3. Strict Zero Unsolicited Calls Guarantee
4. Data Sharing & International Transfers
We do not sell, rent, or monetize your personal data. We disclose information only under strict confidentiality contracts with:
- Authorized Processors: Payment gateways (Razorpay), cloud infrastructure (AWS/GCP), and SMS/Email dispatch nodes.
- Tour Operators & Hoteliers: Name and passenger details provided to executing hotel and transport partners for confirmed bookings.
- Cross-Border Data Transfers: For international tours, passenger details are securely transmitted to foreign hotel and visa suppliers as required under Section 16 of the DPDP Act 2023 to execute your booking.
5. Your Rights as a Data Principal
Under Sections 11–14 of the DPDP Act 2023, you hold full statutory rights over your personal data. You may write to to enforce:
- Right to Access: Summary of personal data held and third-party sharing history.
- Right to Correction & Erasure: Immediate correction of inaccurate data or deletion of your account (subject to statutory tax auditing rules).
- Right to Withdraw Consent: Revoke consent at any time through your user dashboard or support email.
- Right to Nominate: Designate a nominee to exercise data rights in the event of death or incapacity.
6. Security & Data Retention Schedule
We implement AES-256-GCM encryption at rest, HTTPS/TLS 1.3 in transit, bcrypt password hashing, and isolated document stores. Statutory data retention limits:
- Invoices & Tax Transaction Logs: Retained for 8 years to comply with Income Tax Act & GST laws.
- Identity Verification Docs: Retained during trip execution and deleted or archived within 30 days after trip completion.
- User Account Profile: Retained until account closure, after which personal data is purged within 30 days.
7. Minor & Children Data Protection
Our platform is designed for users aged 18 and older. We do not knowingly profile or target advertising at minors under Section 9 of the DPDP Act 2023. Minor passenger details for family package bookings are collected solely from consenting adult guardians to fulfill the trip reservation.
8. Cookie & Tracking Framework
We use essential cookies for session security, authentication, and cart state preservation. Non-essential analytics cookies are loaded only with your explicit consent and do not track cross-site activity.
9. Grievance Officer & Statutory Redressal
Pursuant to Rule 5(9) of the IT (SPDI) Rules 2011 and Section 10 of the DPDP Act 2023, you may contact our designated Grievance Officer for data protection concerns:
Related Documents: Terms of Service · Refund & Cancellation Policy · Contact Us
