Privacy Policy

This Privacy Policy explains how Tripiffic Travels Pvt. Ltd. collects, processes, secures, and discloses corporate and individual traveler personal information across our flight booking, hotel reservation, and corporate travel management platforms.

Last Used: March 15, 2026
~9 min read
Digital Personal Data Protection Act (DPDP), 2023 & GDPR

Verified Compliance: This policy has been audited to comply with the Indian DPDP Act 2023, RBI tokenization directives, and international civil aviation data transfer standards.

Introduction & Scope of Application

Plain English Summary (Section 01)

We are committed to safeguarding corporate traveler confidentiality. We act as both a Data Fiduciary/Controller and a Data Processor when facilitating reservations for your organization.

Welcome to Tripiffic Travels Pvt. Ltd. ('Tripiffic', 'we', 'us', or 'our'). We provide end-to-end corporate travel management platforms, enterprise booking software, flight search aggregations, hotel reservation portals, and AI-assisted itinerary planning services (collectively, the 'Platform').

This Privacy Policy applies to all users of our digital platforms, including corporate travel administrators, authorized employee travelers, corporate guest travelers, and website visitors. It outlines our practices regarding the collection, processing, transfer, storage, and erasure of personal data under applicable data protection laws, including the Indian Digital Personal Data Protection Act, 2023 (DPDP Act), the Information Technology Act, 2000, and where applicable, the EU General Data Protection Regulation (GDPR).

When an enterprise company ('Corporate Client') contracts with Tripiffic to manage corporate employee travel, the Corporate Client determines travel policies and authorized passenger details. In such instances, Tripiffic acts as a Data Processor/Intermediary, while the Corporate Client is the Data Controller/Fiduciary.

Enterprise Client Travel Policies

If you are booking travel through your employer's corporate workspace, your employer may have distinct data retention and approval rules that govern travel itinerary data. Tripiffic adheres to those contractual directives alongside statutory requirements.

Personal Information We Collect

Plain English Summary (Section 02)

We collect traveler identity details, travel preferences, corporate employer information, transactional records, and telemetry strictly required to issue airline tickets and confirm hotel stays.

To fulfill corporate travel bookings, issue airline tickets (PNRs), reserve accommodations, and maintain administrative duty of care, we collect and process several categories of personal data:

No Storage of Unmasked Payment Credentials

Tripiffic complies with RBI (Reserve Bank of India) card-on-file tokenization guidelines. All credit card processing is routed through PCI-DSS Level 1 certified payment partners. Full primary account numbers (PAN) are never stored on Tripiffic servers.

A. Traveler Identity & Travel Document Information

We collect legal full names (first, middle, last as per government passport/ID), date of birth, gender, nationality, passport numbers, issuing country, passport expiry dates, visa credentials, frequent flyer program numbers, and national identification numbers where required by airlines or immigration authorities.

B. Corporate Affiliation & Employment Data

We collect corporate email addresses, corporate domain credentials, department names, cost center identifiers, employee ID numbers, reporting manager hierarchy, and corporate travel policy tiers.

C. Transaction, Payment & Billing Details

We process corporate credit card billing addresses, corporate credit line balances, GST numbers (Goods and Services Tax Identification Number), invoice recipient details, and tokenized payment identifiers via authorized payment gateways (e.g., Cashfree). We do not store raw card CVV numbers.

D. AI Assistant Queries & System Telemetry

When using our AI Travel Assistant, we log user travel search prompts, flight filter preferences, device IP addresses, browser types, session cookies, and system error diagnostic logs to improve routing accuracy and booking reliability.

How We Use Your Personal Data & Legal Bases

Plain English Summary (Section 03)

We process your data strictly to fulfill your travel bookings, ensure passenger safety and duty of care, satisfy statutory tax and invoicing mandates, and enhance platform security.

We rely on lawful grounds under the DPDP Act 2023 and GDPR to process personal data. These purposes include:

  • Booking Fulfillment: Transmitting passenger manifests to commercial airlines, Global Distribution Systems (GDS: Sabre, Amadeus, Travelport), and hotel inventory providers (TBO) to issue valid tickets and room confirmations.
  • Corporate Policy Compliance: Enforcing corporate travel approval matrices, travel budget caps, manager verification workflows, and out-of-policy notifications.
  • Traveler Safety & Duty of Care: Allowing corporate travel managers to locate traveling employees during flight disruptions, extreme weather events, or geopolitical emergencies.
  • Statutory & Tax Compliance: Issuing GST-compliant corporate tax invoices, maintaining accounting records mandated by the Indian Companies Act 2013, and complying with civil aviation safety mandates.
  • Customer Service & Travel Assistance: Providing 24/7 urgent flight rescheduling, baggage delay coordination, cancellation assistance, and refund disbursements.
  • Platform Security & Fraud Prevention: Monitoring for unauthorized corporate account access, fraudulent booking attempts, bot traffic, and payment chargebacks.

Third-Party Disclosures & Sub-Processors

Plain English Summary (Section 04)

We disclose passenger data only to authorized airlines, hotel suppliers, payment gateways, and verified enterprise cloud infrastructure providers under strict Data Processing Agreements.

To fulfill international and domestic travel bookings, Tripiffic must transmit personal information to third-party travel suppliers and technology sub-processors. The table below outlines our primary sub-processors, their roles, and processing jurisdictions:

Airline & Immigration Mandatory Requirements

Civil aviation security regulations require airlines to transmit Passenger Name Record (PNR) and Advance Passenger Information (API) data to government customs and immigration authorities prior to international departures.

Authorized Third-Party Service Providers and Sub-Processors

Partner / Sub-ProcessorCategory & PurposeData TransferredHosting / Region
Commercial Airlines & GDS (Amadeus, Sabre, Air India, IndiGo)Flight Reservation & TicketingPassenger legal name, DOB, passport/visa details, contact infoGlobal / Carrier Specific
TBO (Tek Travels) Universal APIHotel & Airline Inventory AggregationGuest legal names, contact numbers, corporate booking IDsIndia & Global
Cashfree PaymentsPCI-DSS Payment GatewayTokenized payment data, transaction amounts, billing addressIndia (RBI Regulated)
Amazon Web Services (AWS) / Google CloudCloud Infrastructure & Database HostingEncrypted traveler databases, booking logs, application codeIndia (Mumbai / Hyderabad)
Enterprise Communication (SendGrid / Twilio)Flight Alerts, OTPs & Itinerary DeliveryPhone number, email address, flight booking summariesUnited States / EU

Cross-Border & International Data Transfers

Plain English Summary (Section 05)

When you reserve international flights or overseas hotels, relevant passenger details are securely transmitted to suppliers located in destination jurisdictions.

Tripiffic operates its core platform within secure cloud data centers located in India. However, when an authorized traveler books an overseas itinerary (such as a flight between New Delhi and London or a hotel in Singapore), personal data must necessarily be transmitted to airlines, ground handling agents, and hotel properties located outside India.

We implement Standard Contractual Clauses (SCCs), robust Data Transfer Addendums, and strict technical safeguards to guarantee that overseas recipients uphold equivalent data protection standards as prescribed under Indian data privacy laws and international treaties.

Data Security Architecture & Encryption

Plain English Summary (Section 06)

We employ industry-leading TLS 1.3 encryption in transit, AES-256 encryption at rest, role-based access controls, and annual penetration testing.

Tripiffic maintains strict organizational, operational, and technical safeguards to preserve the confidentiality, integrity, and availability of all customer records:

  • Encryption in Transit: All data transferred between your browser, mobile app, and Tripiffic servers is encrypted using Transport Layer Security (TLS 1.3) with HSTS enforcement.
  • Encryption at Rest: All production databases containing passport numbers, traveler profiles, and booking histories are encrypted using AES-256 standard cryptographic keys.
  • Role-Based Access Control (RBAC): Employee access to customer records is restricted on a strict least-privilege basis, requiring multi-factor authentication (MFA) and immutable audit logging.
  • Vulnerability Assessments: We conduct recurring vulnerability scans, automated dependency audits, and annual third-party penetration tests on all web applications and APIs.
  • Network Isolation: Production workloads reside inside private virtual cloud subnets with strict web application firewall (WAF) rule sets guarding against DDoS attacks and SQL injection.

Data Retention & Erasure Schedule

Plain English Summary (Section 07)

We retain personal data only as long as necessary to fulfill corporate bookings, adhere to tax audit regulations, and resolve potential booking disputes.

Different types of personal records are governed by specific statutory retention mandates:

Data Retention Periods

Record TypeRetention DurationStatutory / Operational Reason
Corporate Tax Invoices & GST Filings8 Years from filing dateMandated by Indian Companies Act 2013 and GST statutory audits
Active Traveler Profile & PreferencesDuration of corporate employmentActive booking convenience; deleted upon employer de-provisioning
Completed Flight & Hotel Itineraries3 Years post travel completionDispute resolution, airline warranty claims, and corporate audits
AI Chat Queries & Telemetry Logs90 Days rolling windowModel improvement, bug investigation, and query performance tuning

Your Legal Privacy Rights

Plain English Summary (Section 08)

You possess legal rights to access your profile data, correct inaccuracies, request data erasure, and withdraw consent under the DPDP Act 2023 and GDPR.

Under applicable privacy legislations, travelers and corporate administrators have the following enforceable rights:

  • Right of Access & Summary: Request a comprehensive summary of personal data held about you by Tripiffic and the specific third parties with whom it was shared.
  • Right to Rectification: Correct out-of-date or incomplete passport, name spelling, or contact details directly through your Traveler Profile portal.
  • Right to Erasure / Deletion: Request the permanent deletion of personal data when travel bookings are concluded and legal retention periods have expired.
  • Right to Data Portability: Receive an export of your historical booking records and profile data in a structured, machine-readable (JSON/CSV) format.
  • Right to Withdraw Consent: Withdraw consent for optional processing activities (such as marketing newsletters or AI personalized recommendations) without penalty.
  • Right to Nominate: Under Section 14 of the DPDP Act 2023, you have the right to nominate an authorized individual who may exercise your data rights in the event of death or incapacity.

How to Exercise Your Rights

To exercise any of the rights listed above, email our Data Protection Officer at sriyansh@tripiffic.com or submit a request directly through your corporate account settings. We process verified requests within 30 days free of charge.

Cookies, Web Storage & Tracking Technologies

Plain English Summary (Section 09)

We use strictly essential session cookies and privacy-respecting analytics cookies to keep your login session secure and preserve your flight search criteria.

Our web platform uses HTTP cookies, local storage tokens, and session identifiers to provide a seamless booking experience:

  • Strictly Essential Cookies: Necessary for authentication, maintaining your corporate login session, CSRF token security, and booking cart state.
  • Functional Cookies: Remember your preferred currency, airport code origins, departure dates, and passenger counts during complex multi-city searches.
  • Performance & Analytics: Help our engineering team understand search latency, booking completion rates, and page error rates to optimize platform performance.

Modifications to this Privacy Policy

Plain English Summary (Section 10)

We may revise this policy periodically to reflect statutory updates or new platform features. Notice of material changes will be posted prominently.

Tripiffic reserves the right to amend this Privacy Policy at any time. When we enact material modifications, we will update the 'Last Updated' date at the top of this document, post a prominent banner on the corporate dashboard, and where appropriate, send an email notification to registered corporate administrators.

Your continued use of our booking services and corporate portal following notice of revisions constitutes acknowledgment of the updated policy terms.

Grievance Redressal & Contact Information

Plain English Summary (Section 11)

If you have queries, concerns, or grievances regarding our privacy practices, our designated Grievance Officer is available to assist you within statutory timeframes.

In accordance with the Information Technology Act, 2000 and the DPDP Act, 2023, Tripiffic has designated a full-time Grievance Officer and Data Protection Officer to address consumer privacy matters and regulatory queries.

Statutory Redressal Desk
Acknowledgment within 24 hours; resolution within 15 business days

Questions, Grievances, or Privacy Rights Inquiries?

If you have questions regarding this Privacy Policy, need to exercise your statutory rights under the DPDP Act 2023 or GDPR, or wish to file a formal escalation, you may reach our designated compliance officer directly:

Designated Officer

Sriyansh Jain

Principal Grievance & Data Protection Officer (DPO)

Direct Email

Monitored during business hours

Direct Phone

10:00 AM – 6:00 PM IST (Mon–Fri)

Physical Office: Tripiffic Travels Pvt. Ltd. - Corporate Legal Operations, Block A, 5th Floor, Tripiffic Tech Park, Sector 62, Noida, Uttar Pradesh - 201309, India