Last updated: 1 July 2026
Privacy Policy
This Privacy Policy describes how GoIndiaGo Pvt. Ltd. ("GoIndiaGo", "we", "us") collects, uses, shares, and protects personal data when you use the GoIndiaGo corporate travel platform. It is compliant with India's Digital Personal Data Protection (DPDP) Act, 2023 and the DPDP Rules, 2025.
1. Who This Policy Applies To
This policy applies to:
- Corporate administrators who set up and manage a GoIndiaGo organisation account.
- Employee travellers who book flights, hotels, or other travel services through GoIndiaGo.
- Approvers and finance team members who access booking reports and invoices.
- Visitors to the GoIndiaGo landing page or marketing pages.
2. Data We Collect
2.1 Account & Identity Data
- Full name, work email address, mobile number.
- Employee ID, designation, department, cost centre.
- Profile photo (optional).
- Government-issued ID type and number (passport, Aadhaar, PAN) — collected only when required by airlines or hotels for booking.
2.2 Travel & Booking Data
- Flight and hotel search queries (origin, destination, dates, passenger count).
- Booking details: PNR, ticket numbers, hotel confirmation codes, fare class.
- Travel preferences: seat preferences, meal preferences, frequent flyer numbers.
- Passport / visa details when required for international bookings.
- Co-traveller names and details entered during booking.
2.3 Payment Data
- We do not store full card numbers. Payments are processed by Razorpay (PCI-DSS Level 1 certified).
- We store transaction IDs, order IDs, UPI transaction IDs, payment amounts, and GST invoice details.
- Corporate billing details: company name, GSTIN, registered address.
2.4 Usage & Device Data
- IP address, browser type, operating system.
- Pages visited, features used, time spent, click patterns.
- App version, device model (for mobile app users).
2.5 Communications Data
- Support tickets and chat messages sent to our team.
- Email and SMS communications we send you (booking confirmations, itinerary updates, policy alerts).
3. How We Use Your Data
| Purpose | Legal Basis (DPDP Act 2023) |
|---|---|
| Create and manage your GoIndiaGo account | Consent / Contractual necessity |
| Process flight and hotel bookings | Contractual necessity |
| Generate GST-compliant tax invoices | Legal obligation (GST Act, 2017) |
| Send booking confirmations and e-tickets | Contractual necessity |
| Enable travel policy enforcement and approvals | Contractual necessity |
| Provide spend reports and analytics to your finance team | Contractual necessity |
| Detect fraud and prevent unauthorised bookings | Legitimate interest / Legal obligation |
| Comply with DGCA, MCA, and tax authority requirements | Legal obligation |
| Improve platform features and performance | Legitimate interest (anonymised) |
| Send promotional offers (opt-in only) | Consent |
5. International Data Transfers
Some of our service providers (Vercel, Supabase, AWS EC2, Razorpay) may process data on servers outside India. Where personal data is transferred internationally, we ensure appropriate safeguards through Standard Contractual Clauses or equivalent mechanisms recognised under the DPDP Act 2023 and Rules 2025. Sensitive data is encrypted in transit (TLS 1.2+) and at rest (AES-256).
6. Data Retention
| Data Type | Retention Period |
|---|---|
| Account profile data | 7 years after account closure (GST audit compliance) |
| Booking records and invoices | 8 years (Income Tax Act requirement) |
| Payment transaction logs | 8 years (Income Tax / GST audit trail) |
| Passport / travel document copies | Deleted within 90 days of trip completion |
| Support chat and email logs | 2 years |
| Usage analytics (anonymised) | Indefinitely |
| Marketing consent records | Until consent withdrawn + 3 years |
7. Your Rights Under the DPDP Act, 2023
As a Data Principal under the DPDP Act, 2023, you have the following rights:
- Right to Access — request a summary of personal data we hold about you and how it is being processed.
- Right to Correction — request correction of inaccurate or incomplete personal data.
- Right to Erasure — request deletion of your personal data, subject to legal retention requirements.
- Right to Withdraw Consent — withdraw consent for processing at any time (does not affect prior lawful processing).
- Right to Grievance Redressal — raise a complaint with our Grievance Officer.
- Right to Nominate — nominate a person to exercise rights on your behalf in the event of death or incapacity.
7.1 Account Deletion
You may request permanent deletion of your GoIndiaGo account by emailing privacy@goindiago.travel. We will delete your account within 30 days of a verified request, subject to the mandatory retention requirements under GST and Income Tax law described in Sections 2 and 6 above — booking, invoice, and payment records that must be retained by law will be retained for their required period even after account deletion, but will no longer be linked to an active account.
9. Data Security
- All data in transit is encrypted using TLS 1.2 or higher.
- Database records are encrypted at rest using AES-256.
- Access to production data is restricted to authorised personnel on a need-to-know basis.
- We conduct periodic security audits and penetration tests.
- In the event of a data breach, we will notify you and the Data Protection Board within prescribed DPDP Act timelines.
10. App Permissions & Third-Party SDKs
10.1 Device Permissions (Mobile App)
Our mobile app may request the following device permissions:
- Location — to auto-detect your origin city for flight search. Optional; you can enter a city manually instead.
- Storage — to save e-tickets and invoices locally on your device. Optional.
- Camera (planned) — to scan travel documents for faster check-in. Not yet available; this policy will be updated when it ships.
- Notifications (planned) — to send booking alerts and flight status updates. Booking confirmations are currently sent by email; push notifications are not yet implemented.
All permissions above are optional and can be revoked at any time via your device settings, except where a feature cannot function without it (e.g. seat selection without location).
10.2 Third-Party SDKs (Mobile App)
- Razorpay — payment processing SDK. See Section 2.3 and 4 for what payment data is shared with Razorpay.
- Google Sign-In — authentication SDK. When you sign in with Google, we receive your name, email address, and profile photo from your Google account to create and log you into your GoIndiaGo account.
11. Children's Privacy
GoIndiaGo is a B2B corporate travel platform intended for adults (18+) in a professional capacity. We do not knowingly collect personal data from persons under 18. If you believe a minor's data has been submitted, contact us at privacy@goindiago.travel and we will delete it promptly.
12. Changes to This Policy
We may update this policy to reflect changes in law or our practices. When we make material changes, we will notify registered users by email and display a prominent notice on the portal at least 14 days before the change takes effect. Continued use after the effective date constitutes acceptance.
13. Grievance Officer & Contact
For any privacy-related queries, requests, or complaints:
GoIndiaGo Pvt. Ltd.
[ADDRESS PLACEHOLDER — fill in registered office address before Play Store submission]
Email: privacy@goindiago.travel
Support: support@goindiago.travel
Response time: within 72 hours