Privacy Policy
Last updated: 16 June 2026
1. Who we are
Travelsate ("we", "us", "our") is operated from India and offers travel-booking services on travelsate.in. We process personal data in line with India's Digital Personal Data Protection Act 2023 and, where applicable, the EU General Data Protection Regulation.
2. Data we collect
When you book or browse, we collect:
- Identity: name, email, phone, pincode.
- Travel details: destination, dates, traveller names, genders, meal preferences, infant DOBs.
- Payment metadata: Razorpay order/subscription/payment IDs. We never see or store full card numbers — those stay inside Razorpay's PCI-certified vault.
- Technical: IP address, browser, device, cookies set for session continuity.
3. How we use it
- To create, fulfil, and service your bookings.
- To send transactional emails / SMS (confirmation, EMI reminders, cancellation, invoices).
- To run live flight/hotel pricing via SerpAPI and AI-generated itineraries via OpenAI/Anthropic — the destination + date is shared, never your name or contact.
- To detect fraud, deter abuse, and improve the service.
4. Who we share it with
Strictly limited processors who help us deliver the service:
- Razorpay — payment processing.
- Twilio — phone OTP & SMS.
- SendGrid — email OTP & transactional email.
- SerpAPI — live flight / hotel / reviews lookup (destination only).
- Google Maps — distance lookups (origin / destination cities only).
- Cloud hosting on the Emergent platform.
We do not sell or rent personal data.
5. How long we keep it
Booking records are retained for 7 years (Indian Companies Act + tax-audit requirement). OTP codes are deleted within minutes of use. Marketing email opt-outs are honoured immediately.
6. Your rights
You can request access, correction, erasure (where lawful), or a copy of your data by writing to admin@travelsate.in or calling +91 99727 44308. Under DPDP Act 2023 you may also nominate a representative to exercise these rights after death/incapacity, and lodge a complaint with the Data Protection Board of India.
7. Cookies
We use strictly necessary cookies for login session continuity (JWT in httpOnly cookie) and an analytics cookie that tracks page visits without identifying you. You can withdraw consent any time by clearing your browser data or via your browser's cookie controls.
8. Security
HTTPS site-wide, JWT bearer auth on every API, rate-limited OTP endpoints, signature-verified Razorpay webhooks, OWASP-standard security headers (HSTS, CSP, X-Frame-Options, etc.).
9. Changes
Material changes will be notified by email and posted here with an updated "Last updated" date.
10. Contact
Grievance / DPO: admin@travelsate.in · +91 99727 44308