Last updated: 1 July 2026

Privacy Policy

This Privacy Policy describes how GoIndiaGo Pvt. Ltd. ("GoIndiaGo", "we", "us") collects, uses, shares, and protects personal data when you use the GoIndiaGo corporate travel platform. It is compliant with India's Digital Personal Data Protection (DPDP) Act, 2023 and the DPDP Rules, 2025.

1. Who This Policy Applies To

This policy applies to:

  • Corporate administrators who set up and manage a GoIndiaGo organisation account.
  • Employee travellers who book flights, hotels, or other travel services through GoIndiaGo.
  • Approvers and finance team members who access booking reports and invoices.
  • Visitors to the GoIndiaGo landing page or marketing pages.

2. Data We Collect

2.1 Account & Identity Data

  • Full name, work email address, mobile number.
  • Employee ID, designation, department, cost centre.
  • Profile photo (optional).
  • Government-issued ID type and number (passport, Aadhaar, PAN) — collected only when required by airlines or hotels for booking.

2.2 Travel & Booking Data

  • Flight and hotel search queries (origin, destination, dates, passenger count).
  • Booking details: PNR, ticket numbers, hotel confirmation codes, fare class.
  • Travel preferences: seat preferences, meal preferences, frequent flyer numbers.
  • Passport / visa details when required for international bookings.
  • Co-traveller names and details entered during booking.

2.3 Payment Data

  • We do not store full card numbers. Payments are processed by Razorpay (PCI-DSS Level 1 certified).
  • We store transaction IDs, order IDs, UPI transaction IDs, payment amounts, and GST invoice details.
  • Corporate billing details: company name, GSTIN, registered address.

2.4 Usage & Device Data

  • IP address, browser type, operating system.
  • Pages visited, features used, time spent, click patterns.
  • App version, device model (for mobile app users).

2.5 Communications Data

  • Support tickets and chat messages sent to our team.
  • Email and SMS communications we send you (booking confirmations, itinerary updates, policy alerts).

3. How We Use Your Data

PurposeLegal Basis (DPDP Act 2023)
Create and manage your GoIndiaGo accountConsent / Contractual necessity
Process flight and hotel bookingsContractual necessity
Generate GST-compliant tax invoicesLegal obligation (GST Act, 2017)
Send booking confirmations and e-ticketsContractual necessity
Enable travel policy enforcement and approvalsContractual necessity
Provide spend reports and analytics to your finance teamContractual necessity
Detect fraud and prevent unauthorised bookingsLegitimate interest / Legal obligation
Comply with DGCA, MCA, and tax authority requirementsLegal obligation
Improve platform features and performanceLegitimate interest (anonymised)
Send promotional offers (opt-in only)Consent

4. Data Sharing

We share personal data only as necessary to fulfil your bookings or comply with law:

  • Airlines & GDS providers (TekTravels, TBO) — to issue tickets and confirm reservations.
  • Hotels & accommodation providers — to confirm hotel reservations and check-in details.
  • Razorpay Payment Gateway — to process payments securely.
  • ASEGO / insurance providers — when you purchase travel insurance.
  • GST Network (GSTN) — to file returns and generate e-invoices as required by law.
  • DGCA / Government authorities — when legally required to comply with aviation or tax regulations.
  • Your employer's designated administrators — booking data, expense reports, and travel history visible to your company's GoIndiaGo admin.
  • Cloud infrastructure: Supabase (database), Vercel (web app hosting), AWS EC2 (backend API compute) — governed by data processing agreements.

We do not sell your personal data to third parties for marketing purposes.

5. International Data Transfers

Some of our service providers (Vercel, Supabase, AWS EC2, Razorpay) may process data on servers outside India. Where personal data is transferred internationally, we ensure appropriate safeguards through Standard Contractual Clauses or equivalent mechanisms recognised under the DPDP Act 2023 and Rules 2025. Sensitive data is encrypted in transit (TLS 1.2+) and at rest (AES-256).

We obtain explicit, informed consent separately before transferring your personal data internationally, via a clear consent screen during onboarding — this consent is not bundled into your acceptance of the Terms of Service. If you decline or withdraw this consent, we may not be able to confirm or fulfil bookings that require processing by an overseas provider.

6. Data Retention

Data TypeRetention Period
Account profile data7 years after account closure (GST audit compliance)
Booking records and invoices8 years (Income Tax Act requirement)
Payment transaction logs8 years (Income Tax / GST audit trail)
Passport / travel document copiesDeleted within 90 days of trip completion
Support chat and email logs2 years
Usage analytics (anonymised)Indefinitely
Marketing consent recordsUntil consent withdrawn + 3 years

7. Your Rights Under the DPDP Act, 2023

As a Data Principal under the DPDP Act, 2023, you have the following rights:

  • Right to Access — request a summary of personal data we hold about you and how it is being processed.
  • Right to Correction — request correction of inaccurate or incomplete personal data.
  • Right to Erasure — request deletion of your personal data, subject to legal retention requirements.
  • Right to Withdraw Consent — withdraw consent for processing at any time (does not affect prior lawful processing).
  • Right to Grievance Redressal — raise a complaint with our Grievance Officer.
  • Right to Nominate — nominate a person to exercise rights on your behalf in the event of death or incapacity.
To exercise any right, email privacy@goindiago.travel from your registered email with a description of your request. We respond within 72 hours and resolve within 30 days. Unresolved grievances may be escalated to the Data Protection Board of India.

7.1 Account Deletion

You may request permanent deletion of your GoIndiaGo account by emailing privacy@goindiago.travel. We will delete your account within 30 days of a verified request, subject to the mandatory retention requirements under GST and Income Tax law described in Sections 2 and 6 above — booking, invoice, and payment records that must be retained by law will be retained for their required period even after account deletion, but will no longer be linked to an active account.

8. Cookies & Tracking

8.1 What We Use

  • Essential cookies: session management, login tokens, CSRF protection. Cannot be disabled.
  • Analytics cookies: anonymous usage tracking to improve the product.
  • Preference cookies: remember your language, currency, and UI settings.

8.2 Your Choices

You can control non-essential cookies via your browser settings. Disabling analytics cookies does not affect core booking functionality. We do not use third-party advertising cookies or cross-site tracking.

9. Data Security

  • All data in transit is encrypted using TLS 1.2 or higher.
  • Database records are encrypted at rest using AES-256.
  • Access to production data is restricted to authorised personnel on a need-to-know basis.
  • We conduct periodic security audits and penetration tests.
  • In the event of a data breach, we will notify you and the Data Protection Board within prescribed DPDP Act timelines.

10. App Permissions & Third-Party SDKs

10.1 Device Permissions (Mobile App)

Our mobile app may request the following device permissions:

  • Location — to auto-detect your origin city for flight search. Optional; you can enter a city manually instead.
  • Storage — to save e-tickets and invoices locally on your device. Optional.
  • Camera (planned) — to scan travel documents for faster check-in. Not yet available; this policy will be updated when it ships.
  • Notifications (planned) — to send booking alerts and flight status updates. Booking confirmations are currently sent by email; push notifications are not yet implemented.

All permissions above are optional and can be revoked at any time via your device settings, except where a feature cannot function without it (e.g. seat selection without location).

10.2 Third-Party SDKs (Mobile App)

  • Razorpay — payment processing SDK. See Section 2.3 and 4 for what payment data is shared with Razorpay.
  • Google Sign-In — authentication SDK. When you sign in with Google, we receive your name, email address, and profile photo from your Google account to create and log you into your GoIndiaGo account.

11. Children's Privacy

GoIndiaGo is a B2B corporate travel platform intended for adults (18+) in a professional capacity. We do not knowingly collect personal data from persons under 18. If you believe a minor's data has been submitted, contact us at privacy@goindiago.travel and we will delete it promptly.

12. Changes to This Policy

We may update this policy to reflect changes in law or our practices. When we make material changes, we will notify registered users by email and display a prominent notice on the portal at least 14 days before the change takes effect. Continued use after the effective date constitutes acceptance.

13. Grievance Officer & Contact

For any privacy-related queries, requests, or complaints:

Grievance Officer — Data Privacy
GoIndiaGo Pvt. Ltd.
[ADDRESS PLACEHOLDER — fill in registered office address before Play Store submission]
Email: privacy@goindiago.travel
Support: support@goindiago.travel
Response time: within 72 hours