Privacy Policy
Effective date: April 17, 2026 · Version: 1.0.0
1. Introduction and Scope
TripBuilt("TripBuilt," "we," "us," or "our") is committed to protecting the privacy and security of personal data. This Privacy Policy explains how we collect, use, store, share, and protect Personal Data in connection with our platform at https://tripbuilt.com.
This Policy applies to: (a) Operators — travel agencies and tour operators who subscribe to the Platform; (b) authorized sub-users; and (c) End-Clients whose data Operators process through the Platform.
This Policy is published in compliance with: the Digital Personal Data Protection Act, 2023 ("DPDP Act"); the Information Technology Act, 2000 ("IT Act"); the IT (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 ("SPDI Rules"); and the IT (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021.
If you are an Operator processing End-Client Data through the Platform, please also refer to our Data Processing Addendum.
2. Categories of Personal Data Collected
- Account and Registration Data: Business name, GSTIN, registered address, contact name, email address, phone number, designation, and password (hashed, never stored in plaintext).
- Billing and Payment Data: Name, billing address, last 4 digits of payment instrument, transaction IDs, GST invoice details, and payment history. Full card numbers are processed by Razorpay and not stored by TripBuilt.
- Usage Telemetry: Pages visited, features used, session duration, click data, and event logs.
- Device and Technical Data: IP address, browser type and version, operating system, screen resolution, time zone, and referring URLs.
- Communication Data: Support tickets, emails, and any other communications sent to TripBuilt.
- Integration-Scoped Data: Gmail API: email metadata and message content for messages you import. WhatsApp Cloud API: message content, delivery status, and opt-in/opt-out signals.
- End-Client Data: Personal Data of End-Clients entered by Operators, which may include names, email addresses, phone numbers, passport details, travel preferences, and payment information.
3. How We Collect Data
- Directly from you when you register, subscribe, or interact with the Platform.
- Automatically through server logs, analytics, and cookies when you use the Platform.
- From third parties via integrations you authorize (Gmail OAuth, Meta WhatsApp Business, Razorpay).
- From Operators when they enter, import, or upload End-Client Data.
4. Purposes and Legal Bases (DPDP Act §7)
- Account creation and management — necessary to perform the Terms of Service contract.
- Service delivery — necessary to provide the subscribed Platform features.
- Payment processing and billing — necessary to perform the contract and comply with GST law and RBI regulations.
- Customer support — legitimate interest in providing assistance.
- Platform security and fraud prevention — legitimate interest in Platform integrity.
- Usage analytics and product improvement — legitimate interest, subject to anonymization.
- Marketing communications — consent or legitimate interest (existing Operators), with opt-out available.
- Legal compliance — IT Act, DPDP Act, GST law, and court/regulatory orders.
- End-Client Data — processed on the Operator's instructions per the DPA; not used for TripBuilt's own commercial purposes.
5. Sharing and Disclosure
TripBuilt does not sell Personal Data. We may share it only in these limited circumstances: with Sub-Processors as necessary to provide the Platform (see Section 6); as required by Applicable Law or court order; in connection with a business transfer (merger, acquisition, or asset sale); to protect TripBuilt's rights or detect fraud; or with your prior written consent.
6. Sub-Processors
| Sub-Processor | Purpose | Location |
|---|---|---|
| Supabase Inc. | Database, auth, storage | Singapore (AP) |
| Vercel Inc. | Hosting, CDN, edge functions | United States |
| Razorpay Software Pvt Ltd | Payment processing | India |
| Meta Platforms, Inc. | WhatsApp Cloud API messaging | United States |
| Google LLC | Gmail API, Google Workspace | United States |
| OpenAI LLC | AI-assisted features | United States |
| Upstash Inc. | Rate limiting, caching (Redis) | United States / EU |
7. Cross-Border Transfers
Some Personal Data is processed by Sub-Processors outside India (see Section 6). TripBuilt complies with Section 16 of the DPDP Act. Where the destination country is not designated as adequate, TripBuilt ensures contractual safeguards with Sub-Processors require equivalent data protection standards. All cross-border transfers comply with FEMA, 1999.
8. Data Retention
| Category | Retention Period |
|---|---|
| Account and registration data | Account duration + 12 months post-closure |
| Usage logs and telemetry | 90 days |
| Payment and billing records | 8 years (GST and RBI audit requirements) |
| Support communications | 3 years |
| End-Client Data | Duration of Operator's account + 30-day export window, then deletion |
| Audit logs (security) | 12 months |
9. Your Rights (DPDP Act §§11–14)
- Right of Access: Obtain a summary of Personal Data processed and processing activities.
- Right of Correction and Erasure: Request correction of inaccurate data or erasure where processing is no longer required.
- Right to Grievance Redressal: Have grievances addressed promptly.
- Right to Nomination: Nominate another individual to exercise rights in the event of death or incapacity.
- Right to Withdraw Consent: Withdraw consent at any time without affecting prior lawful processing.
To exercise any right, submit a written request to grievance@tripbuilt.com. We will respond within timelines prescribed under the DPDP Act.
End-Clients seeking to exercise rights over data stored in the Platform should contact the Operator first (the Data Fiduciary). Operators may relay rights requests to TripBuilt via the DPA mechanism.
10. Consent and Withdrawal
Where we rely on consent as the legal basis for processing (DPDP Act §6), you may withdraw consent at any time by: updating communication preferences in Account settings; using the unsubscribe link in marketing emails; or contacting us at support@tripbuilt.com.
Children's data (DPDP Act §9): If End-Client Data relates to individuals under 18, Operators are responsible for obtaining verifiable parental or guardian consent. TripBuilt does not knowingly process Personal Data of children through the general registration process.
11. Security Measures
- Encryption in Transit: TLS 1.2 or higher on all data transmissions.
- Encryption at Rest: AES-256 encryption via Supabase's storage layer.
- Access Controls: Role-based access controls with multi-factor authentication for production systems.
- Audit Logs: All access to sensitive data is logged and retained for 12 months.
- Vulnerability Management: Regular dependency audits (Dependabot, npm audit) and code reviews.
- Incident Response: Written incident response procedure with priority triage.
12. Breach Notification (DPDP Act §8(6))
In the event of a Personal Data breach, TripBuilt will: (a) contain and assess the breach promptly; (b) notify the Data Protection Board of India within 72 hours of becoming aware; (c) notify affected Data Principals as required by the DPDP Act. Where a breach involves End-Client Data, TripBuilt will notify the Operator within 48 hours per the DPA.
13. Cookies
The Platform uses cookies for: session authentication (strictly necessary, cannot be disabled); usage analytics (can be disabled via browser settings); user preferences such as language; and third-party integrations. You may configure your browser to refuse or delete non-essential cookies, but doing so may affect Platform functionality.
14. Grievance Officer
Name: TripBuilt Grievance Team
Email: grievance@tripbuilt.com
Phone: +91 98765 43210
Address: Hyderabad, Telangana, India
Privacy grievances acknowledged within 24 hours, resolved within 15 days (IT Rules 2021).
15. Changes to This Policy
TripBuilt may update this Privacy Policy from time to time. Material changes will be notified via email and in-app notification at least 30 days before taking effect. Continued use of the Platform after the effective date constitutes acceptance of the revised Policy.
For all privacy-related queries, contact: support@tripbuilt.com · TripBuilt · Hyderabad, Telangana, India