Legal · Data Protection
Privacy Policy
Tickettrix is an online travel agency serving both individual travellers and travel trade partners. This policy explains exactly what personal data we collect when you search, book or issue a flight, hotel, bus ticket, holiday package or visa application through us — what we do with it, who we must pass it to in order to actually confirm a booking, and the rights you hold over it under India's Digital Personal Data Protection Act, 2023.
Introduction & Scope
Who we are, which products this policy covers, and where it applies.
Tickettrix India Private Limited ("Tickettrix", "we", "us" or "our") operates an online travel booking platform for domestic and international flights, hotel reservations, bus tickets, holiday packages, visa assistance and corporate travel management, together with a B2B travel distribution portal used by registered travel agents and their sub-agents.
For the personal data described in this policy, Tickettrix acts as a Data Fiduciary under the Digital Personal Data Protection Act, 2023 (DPDP Act), and you are the Data Principal. We also process data in line with the Information Technology Act, 2000 and the IT (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011.
Where this policy applies
- The Tickettrix website at www.tickettrix.com and any regional or campaign sub-domain we operate
- Our mobile applications and mobile web experience
- The B2B agent portal, agent wallet and sub-agent dashboards
- Our XML / API distribution layer and white-label storefronts operated on our technology
- The corporate travel desk, self-booking tool and MICE enquiry flows
- Support channels — phone, email, WhatsApp, live chat and support tickets
What this policy does not cover
Once a booking is confirmed, airlines, hotels, bus operators, consolidators, visa centres and payment gateways process your data under their own privacy policies as independent controllers. We tell you in Section 8 exactly what reaches them and why, but we cannot govern what they do with it afterwards.
Definitions
Travel and data-protection terms used throughout this document.
- Data Principal
- The individual the personal data relates to — the traveller. Where the traveller is a child, it includes the parent or lawful guardian.
- Data Fiduciary
- The entity that decides why and how personal data is processed. Tickettrix is a Data Fiduciary for the data described here.
- B2C user
- An individual who books on Tickettrix for themselves, their family or their companions.
- B2B partner
- A registered travel agent, sub-agent, tour operator or corporate travel desk that books on behalf of its own customers or employees using our agent portal, wallet or API.
- Traveller data
- Personal data about the person actually flying, staying or travelling — which, on the B2B side, is usually not the person logged in.
- PNR
- Passenger Name Record — the booking record held by an airline, GDS or supplier containing itinerary, passenger and contact details.
- GDS / Supplier
- Global Distribution System (such as an airline's own host system or a consolidator platform) through which inventory is searched, held and ticketed.
- SSR
- Special Service Request — meal preference, wheelchair assistance, extra baggage, seat request and similar add-ons attached to a booking.
- APIS
- Advance Passenger Information System — passport and travel-document data that airlines are legally required to transmit to destination authorities.
- Processing
- Any operation on personal data — collection, storage, use, sharing, retention, erasure.
Who This Policy Covers
The privacy relationship differs depending on which side of the platform you use.
Tickettrix is a single platform with two very different user populations. The table below sets out our role for each, because it determines who is responsible for obtaining consent from the traveller.
| You are | What you do | Our role | Whose consent is needed |
|---|---|---|---|
| A traveller (B2C) | Search and book for yourself or your co-travellers | Data Fiduciary for your data | Yours, given directly to us |
| A registered travel agent (B2B) | Book, issue and manage tickets for your own walk-in and online customers | Data Fiduciary for your agency's account data; Data Processor for the traveller data you upload | Your customer's — collected by you, before you enter it |
| A sub-agent | Book under a parent agency's credit or wallet | Same as above, with the parent agency as your accountable principal | Your customer's — collected by you |
| A corporate travel desk | Book travel for employees under a company policy | Data Processor for employee traveller data on the company's instruction | Managed by the employer under its own HR notice |
| A visitor | Browse fares, read content, never sign in | Data Fiduciary for cookie and analytics data | Yours, via the cookie banner |
Swipe to see all columns →
If you booked through a travel agent and want your data corrected or erased, contact that agent first — they hold the customer relationship. We will always assist if they cannot.
Information We Collect
Grouped by category, with the reason we need each one.
We practise data minimisation: with narrow exceptions we collect only what a supplier requires to confirm, ticket and service a booking. A domestic bus ticket therefore needs far less from you than an international itinerary with a visa application.
4a. Account and identity data
| Data | Collected from | Why we need it |
|---|---|---|
| Name, email, mobile number | You, at sign-up or checkout | Account creation, booking confirmations, OTP and login |
| Password (hashed) or Google sign-in identifier | You / Google OAuth | Authenticating you securely; we never see your Google password |
| Date of birth, gender, nationality | You, at traveller-details stage | Mandatory airline and hotel passenger fields; fare eligibility (child/infant/senior) |
| Postal and billing address | You | Invoicing, GST documentation, payment verification |
| Profile photo, saved travellers, saved preferences | You, optionally | Faster repeat checkout; you can delete these at any time |
Swipe to see all columns →
4b. Travel and booking data
| Data | Collected from | Why we need it |
|---|---|---|
| Itinerary — route, dates, cabin, fare family, room type, seat, boarding point | You, and the supplier's response | To hold, price and issue the booking |
| Passport number, issuing country, expiry, visa details | You, for international travel and visa services | Airline ticketing rules, APIS transmission, immigration and visa filing |
| Frequent-flyer / loyalty numbers | You | Passing mileage credit to the airline programme |
| SSR data — meals, wheelchair, extra baggage, infant details | You | Requesting the service from the airline or operator |
| Government ID for hotel check-in, and Form C details for foreign nationals | You or the property | Statutory hotel guest registration in India |
| PNR, ticket number, e-ticket, voucher and cancellation records | Supplier / GDS | Servicing, re-issue, refunds and dispute resolution |
Swipe to see all columns →
Passport, visa and health-assistance data are treated as sensitive and given the strictest access controls we operate. We do not ask for biometric data.
4c. Payment data
| Data | Where it lives | Why we need it |
|---|---|---|
| Card number, expiry, CVV | Never on Tickettrix servers — captured directly by the PCI-DSS certified payment gateway | Authorising the transaction |
| Tokenised card reference (last 4 digits, network, token) | Gateway vault, per RBI card-on-file tokenisation norms | Optional saved-card checkout, without storing the real number |
| UPI VPA, net-banking bank name, wallet reference | Payment partner; only the reference reaches us | Completing and reconciling payment |
| Transaction ID, amount, status, refund trail | Tickettrix | Reconciliation, refunds, chargeback defence, statutory accounting |
| GSTIN, PAN, business name | You, if you claim GST input credit or register as an agency | Tax invoicing and KYC |
Swipe to see all columns →
4d. B2B partner and agency data
- Agency KYC — trade name, constitution, registered address, GSTIN, PAN, cancelled cheque or bank proof, and identity documents of authorised signatories
- Financial records — wallet top-ups, ledger entries, credit limit, outstanding balance, deposit and settlement history
- Commercial configuration — negotiated markup, commission slabs, service-fee rules and route-level settings applied to your account
- Sub-agent structure — the sub-agent accounts you create, their permissions and the bookings attributable to each
- Technical access data — API credentials, IP allow-lists, request volumes, error rates and rate-limit events on your XML/API integration
- Traveller data you upload on behalf of your own customers, which we process on your instruction
4e. Automatically collected technical data
- IP address and approximate city-level location
- Device type, operating system and screen size
- Browser type, language and time zone
- Referring URL and campaign parameters
- Pages viewed, searches run and time on page
- Fare and destination searches, and abandoned carts
- Clickstream through the booking funnel
- Crash, latency and API-error diagnostics
- Session identifiers and security tokens
- Fraud-prevention signals and device fingerprint
We do not ask for these — ever
Tickettrix will never ask you for your card CVV, UPI PIN, net-banking password, OTP or account password over phone, email, WhatsApp or chat. Any message that does is a fraud attempt. Report it to support@tickettrix.com immediately.
How We Collect It
Directly from you, automatically, and back from travel suppliers.
- 5.1
Directly from you
When you create an account, run a search, enter traveller details, make a payment, raise a support ticket, submit a visa application, request a holiday-package quote or apply for an agency account.
- 5.2
Automatically, as you use the platform
Through cookies, SDKs, server logs and analytics — described in Section 7. Essential cookies operate without consent because the booking flow cannot function without them; analytics and marketing cookies are set only if you allow them.
- 5.3
Back from travel suppliers and GDS
Airlines, hotels, bus operators and consolidators return PNRs, ticket numbers, vouchers, schedule changes, cancellation records and refund confirmations, which we attach to your booking so support can service it.
- 5.4
From payment and verification partners
Gateways confirm authorisation status, tokenised card references, refund status and fraud signals. We receive the outcome, not your raw card credentials.
- 5.5
From a travel agent or your employer
If someone booked for you — an agent, a company travel desk, or a family member — your data reaches us from them. We rely on that party having a lawful basis and having given you notice.
- 5.6
From marketing and referral sources
Campaign, referral and affiliate parameters tell us how you found us. This is aggregated for attribution and is never used to build a profile of your health, finances or beliefs.
Why We Use Your Information
Each purpose, with the lawful basis we rely on under the DPDP Act.
| Purpose | What this involves | Lawful basis |
|---|---|---|
| Fulfilling your booking | Searching and holding inventory, ticketing, issuing e-tickets, hotel vouchers and bus tickets, transmitting SSRs, handling schedule changes | Performance of contract |
| Payments and refunds | Charging you, applying wallet or credit, reconciling settlements, processing refunds and chargebacks | Performance of contract; legal obligation |
| Customer support | Identifying you, retrieving your PNR, arranging date changes, cancellations, re-issues and escalations to the supplier | Performance of contract |
| Statutory and regulatory compliance | GST invoicing, TDS/TCS where applicable, APIS and immigration reporting, hotel guest registration, CERT-In incident reporting, lawful requests | Legal obligation |
| Fraud, security and platform integrity | Detecting stolen-card use, fake bookings, coupon abuse, scripted scraping of fares, credential-stuffing and account takeover | Legitimate use; legal obligation |
| Service improvement | Understanding drop-offs in the booking funnel, fixing errors, load-testing search, improving fare and hotel relevance | Legitimate use, on aggregated or de-identified data wherever possible |
| Personalisation | Recalling recent searches, suggesting routes and properties, showing fares in your chosen currency | Consent, withdrawable at any time |
| Marketing communication | Fare alerts, seasonal offers, holiday-package campaigns, agent scheme announcements | Consent, withdrawable at any time |
| B2B account management | Verifying agency KYC, setting credit limits, applying markup and commission, reconciling ledgers, managing API access | Performance of contract; legal obligation |
Swipe to see all columns →
We do not sell or rent personal data
Tickettrix does not sell, rent or trade personal data to data brokers, advertisers or any third party for their independent commercial use. Data leaves our systems only for the purposes set out in Section 8.
Cookies & Tracking Technologies
What each cookie category does and how to control it.
| Category | What it does | Examples | Can you switch it off? |
|---|---|---|---|
| Strictly necessary | Keeps you signed in, holds your search session and cart, protects forms against CSRF, enforces rate limits | Session token, auth cookie, security token, currency preference | No — search, checkout and payment stop working without these |
| Functional | Remembers preferences you have set | Recent searches, saved travellers, language, currency | Yes — some convenience is lost |
| Analytics | Measures traffic and funnel performance in aggregate so we can fix what is broken | Page-view and event counters, funnel drop-off, error and performance monitoring | Yes |
| Marketing | Measures campaign performance and shows relevant travel offers on other platforms | Conversion tags, retargeting audiences, affiliate attribution | Yes |
Swipe to see all columns →
You can change your choice at any time from the cookie banner, or clear and block cookies in your browser settings. Blocking strictly-necessary cookies will prevent you from completing a booking. Where your browser sends a Global Privacy Control or Do Not Track signal, we treat it as a withdrawal of consent for analytics and marketing cookies.
Who We Share Information With
The specific recipients a travel booking necessarily involves.
A travel booking cannot be confirmed without passing data to the party actually providing the service. Here is every category of recipient, and the minimum that reaches them.
| Recipient | What we share | Why |
|---|---|---|
| Airlines, GDS and consolidators | Passenger names as per ID, date of birth, gender, contact details, itinerary, passport and visa data for international sectors, SSRs, frequent-flyer number | To create the PNR and issue the e-ticket. Airlines are independent controllers of the PNR. |
| Hotels and accommodation partners | Guest names, stay dates, occupancy, contact number, special requests, and ID details required at check-in | To confirm the reservation and register guests as the law requires |
| Bus operators | Passenger name, age, gender, seat, boarding and dropping point, mobile number | To issue the ticket and allow boarding verification |
| Tour operators and DMCs | Traveller list, itinerary, room and transfer requirements, dietary needs | To operate the ground portion of a holiday package |
| Payment gateways, banks and card networks | Transaction amount, order reference, billing details, fraud signals | To authorise, settle, refund and defend chargebacks |
| Visa service partners, embassies and consulates | Passport, photograph, application forms, supporting documents, itinerary and hotel confirmation | To lodge and track your visa application |
| Government and regulatory authorities | Whatever a specific law or valid order requires — including APIS data, immigration and customs reporting, hotel guest registration and tax filings | Legal obligation |
| Your travel agent or corporate travel desk | Booking, ticketing and cancellation records for bookings they made or paid for | They hold the commercial relationship and must service the booking |
| Technology and service providers | Only what each vendor's function requires — cloud hosting, email and SMS delivery, WhatsApp Business messaging, analytics, CRM, error monitoring | Under written contracts restricting them to our instructions |
| Professional advisers and successors | Records relevant to an audit, dispute, financing round, merger or restructuring | Legitimate use, under confidentiality |
Swipe to see all columns →
Name changes are not always possible
Because passenger names are transmitted to the airline exactly as you enter them, a mismatch against your government ID can invalidate the ticket, and many fares do not permit a name correction at all. Please check spellings against your passport or ID before you pay.
Travel Agent & Corporate Data Responsibilities
If you book for other people, part of the privacy duty is yours.
When a registered agent, sub-agent or corporate travel desk enters a traveller's details into Tickettrix, that traveller is your customer or employee. You are the party in direct contact with them, so you are the party who must have a lawful basis for handing their data to us. This section forms part of your agency agreement.
- 9.1
Obtain consent and give notice
Before entering traveller data, you must have collected the traveller's consent — or another lawful basis — for booking through an online travel platform, and you must have told them that their data will be shared with Tickettrix, the airline or supplier, and where required with government authorities.
- 9.2
Enter accurate data only
You warrant that names, dates of birth, passport numbers and contact details you enter belong to real travellers who have actually authorised the booking. Speculative, blocked or dummy-name bookings are a breach of these terms and of supplier rules.
- 9.3
Use traveller data only for the booking
Traveller data visible in your agent dashboard may be used only to make and service that booking. It must not be exported for your own marketing lists, sold on, or shared with anyone other than the traveller and their authorised representative.
- 9.4
Control your own access
You are responsible for the sub-agent and staff logins you create, for revoking access when someone leaves, and for everything done under your credentials or API key. Credentials must not be shared, embedded in client-side code, or reused across environments.
- 9.5
Handle your customers' requests first
Access, correction and erasure requests from your customers come to you, because we do not hold their consent record. Raise a support ticket and we will action anything you cannot do from the dashboard yourself.
- 9.6
Tell us about a breach
If you suspect your agent account, sub-agent logins or API credentials have been compromised, notify us at support@tickettrix.com within 24 hours so we can suspend access, preserve logs and assess whether traveller data was exposed.
- 9.7
Corporate travel desks
Where you book for employees, you decide the travel policy, the approval chain and what employee data enters the platform. We process that data on your instruction; your own employee privacy notice must cover it.
White-label and API partners
If you distribute our inventory through a white-label storefront or our XML/API, your own site is the point of collection. You must publish your own privacy policy, run your own cookie consent, and make clear to end customers who they are contracting with.
Cross-Border Data Transfers
Why international travel necessarily moves data outside India.
International travel is inherently cross-border. If you book a flight to Dubai, a hotel in Bangkok or a Schengen visa appointment, your data must reach a carrier, property, consolidator or consulate outside India — there is no way to confirm that booking otherwise.
- Transfers happen only where they are necessary to deliver the service you asked for, or where a law requires it
- Recipients receive the minimum data set their function needs
- Vendors we appoint are bound by written contracts imposing confidentiality and security obligations equivalent to ours
- We do not transfer personal data to any territory that the Central Government has restricted under Section 16 of the DPDP Act
- Airlines and immigration authorities receive APIS and passenger data under the destination country's own legal regime, which we cannot vary
How We Protect Your Information
Technical and organisational safeguards in place.
- Encryption in transit — TLS across the site, the agent portal and every API call
- No raw card data — card capture happens inside the PCI-DSS certified gateway; we hold only tokens and last-four digits, per RBI card-on-file norms
- Password hygiene — passwords stored as salted hashes, never in plain text or a reversible form
- Role-based access control — staff and agent permissions are scoped to role, with a documented need-to-know rule for passport and payment data
- Audit logging — administrative actions on bookings, refunds, wallets and markup are logged with actor and timestamp
- Session security — HttpOnly cookies, short-lived access tokens, refresh-token rotation and forced re-authentication on sensitive actions
- Network defences — rate limiting, bot and scraping controls, security headers and continuous monitoring for anomalous access
- Vendor diligence — cloud, messaging and analytics providers are assessed before onboarding and bound by data-processing terms
- Incident response — a documented process to contain, assess and notify, including reporting to CERT-In and affected Data Principals where the law requires
ISO 27001-aligned practices
Our information-security programme is structured along ISO/IEC 27001 lines. No platform can promise absolute security, so we ask you to help: use a unique password, enable every verification step we offer, never share an OTP, and always verify that you are on www.tickettrix.com before entering payment details.
How Long We Keep It
Retention periods and what drives each one.
We keep personal data only as long as the purpose it was collected for survives, plus any statutory retention period. Travel records outlive the trip because refunds, chargebacks, tax audits and airline debit memos routinely surface months or years later.
| Record | Retention | Reason |
|---|---|---|
| Active account profile and saved travellers | While your account is open | You use it at every checkout |
| Booking, ticket, PNR and cancellation records | Retained after travel to cover refund, re-issue and dispute windows | Contractual servicing and supplier dispute resolution |
| Invoices, GST records and payment ledgers | As required by tax and companies legislation | Statutory financial record-keeping |
| Agent wallet, credit and settlement ledgers | For the life of the agency relationship and the statutory period after it | Reconciliation, audit, recovery of dues |
| Passport, visa and immigration documents | Only as long as the application or trip requires, then deleted or archived under restricted access | Sensitive data, minimised deliberately |
| Support tickets, call notes and chat transcripts | Retained while a complaint or escalation can still be reopened | Grievance redressal and quality assurance |
| Fraud, chargeback and abuse records | Retained to defend claims and prevent repeat abuse | Legitimate use and legal defence |
| Cookie, analytics and server-log data | Short-term, then aggregated or de-identified | Security forensics and product analytics |
Swipe to see all columns →
When a retention period ends we delete the data or de-identify it so it can no longer be linked to you. Closing your account does not delete records we are legally required to keep — see Section 13.
Your Rights & How to Exercise Them
Your rights as a Data Principal, and our response timelines.
- 13.1
Right to access
Ask for a summary of the personal data we hold about you, the processing we carry out, and the categories of recipient we have shared it with.
- 13.2
Right to correction and completion
Have inaccurate or incomplete data corrected. Note that a name already ticketed cannot always be corrected — that depends on the airline's fare rules, not on us.
- 13.3
Right to erasure
Ask us to delete your data where it is no longer needed for the purpose it was collected for, unless retention is required by law or to complete a live booking, refund or dispute.
- 13.4
Right to withdraw consent
Withdraw consent for personalisation, marketing or non-essential cookies at any time, with no effect on processing carried out lawfully before you withdrew it.
- 13.5
Right to nominate
Nominate another individual to exercise your rights on your behalf in the event of your death or incapacity, as the DPDP Act provides.
- 13.6
Right to grievance redressal
Raise a complaint with our Grievance Officer (Section 18) and receive a response within the timelines below, before approaching the Data Protection Board of India.
- 13.7
Right to account closure
Close your Tickettrix account. We will deactivate it, stop marketing, and retain only what statute or a live obligation requires.
How to raise a request
| Step | What happens | Timeline |
|---|---|---|
| 1. Submit | Email info@tickettrix.com from your registered email address, with the request type and your booking reference if relevant | — |
| 2. Verification | We confirm your identity so we do not disclose data to the wrong person; be ready to verify a booking detail | Within 48 hours |
| 3. Acknowledgement | We acknowledge the request in writing with a reference number | Within 48 hours |
| 4. Resolution | We action the request, or explain in writing why we cannot | Within 30 days |
| 5. Escalation | Not satisfied? Reply to your request reference with "Grievance" in the subject — it routes to our Grievance Officer | Response within 15 days |
Swipe to see all columns →
Requests are free. We may decline a request that is manifestly excessive or repetitive, or where acting on it would breach another person's privacy or a legal obligation — and we will tell you why.
Marketing & Communication Preferences
The difference between transactional and promotional messages.
Transactional messages cannot be switched off while you hold a live booking. Ticket confirmations, payment receipts, schedule changes, gate and platform updates, cancellation notices and refund status are part of the service you paid for, and we send them by email, SMS and WhatsApp.
Promotional messages — fare alerts, seasonal offers, holiday-package campaigns and agent scheme announcements — go only to users who have opted in. You can opt out at any time by using the unsubscribe link in any email, replying STOP to a WhatsApp or SMS campaign, or changing your notification preferences in your account.
- Commercial voice and SMS traffic follows TRAI's TCCCPR framework; registering for DND with your telecom operator blocks promotional traffic but not transactional booking alerts
- WhatsApp messages are sent through the official WhatsApp Business API against approved templates
- Agent-facing operational notices — credit limit, wallet balance, scheme and API changes — are treated as transactional for as long as you hold an active agency account
Children & Minors
How we handle bookings that include children and infants.
You must be 18 or older to hold a Tickettrix account or make a booking. We do not knowingly create accounts for children, and we do not offer behavioural advertising, tracking or profiling directed at children.
Children and infants can of course travel. Where a booking includes a minor, the child's name, date of birth and — for international travel — passport details are entered by the parent, lawful guardian or an authorised adult, who is treated as giving consent on the child's behalf. We collect only the fields the airline, hotel or operator requires for that child to travel.
If you believe a child has created an account or supplied us data without guardian consent, write to info@tickettrix.com and we will verify and delete it.
Third-Party Sites & Supplier Platforms
Where our responsibility ends and someone else's begins.
The booking journey routinely hands you off to someone else's website: a bank's 3-D Secure page, an airline's web check-in or seat-selection portal, a hotel's own guest portal, a visa appointment system, or a partner's white-label storefront.
- Once you are on a third-party page, their privacy policy and cookie practices apply
- We do not control, and are not responsible for, their content, security or data handling
- Review their policy before entering personal or payment data
- Links to third-party sites are not an endorsement of their privacy practices
Changes to This Policy
How we version and notify updates.
We update this policy when our products, vendors or legal obligations change. Every revision carries a new version number and an updated date at the top of this page, and superseded versions are archived so a past state of the policy can be reconstructed if a dispute needs it.
- Material changes — a new purpose, a new category of recipient, or a change in retention — are notified by email to registered users and by an in-product notice, ahead of the effective date
- Minor changes — clarifications, formatting and contact updates — take effect on publication
- Registered agency partners additionally receive notice through the agent portal, because their agreement incorporates this policy by reference
- Continuing to use Tickettrix after a revision takes effect means you accept the revised policy
Grievance Officer & Contact
Who to write to, and what happens next.
For any question, request or complaint about this policy or how your personal data has been handled, contact our Grievance Officer. Please include your booking reference or registered email so we can locate your records quickly.
Escalation beyond Tickettrix
We acknowledge every grievance within 48 hours and aim to resolve it within 30 days. If you remain dissatisfied with our response, you may escalate the matter to the Data Protection Board of India under the DPDP Act, 2023.
For booking-related help — cancellations, refunds and date changes — use support@tickettrix.com instead, which reaches the support desk directly. This policy should be read alongside our Terms & Conditions.
Questions about your data?
Our Grievance Officer handles access, correction, erasure and consent-withdrawal requests, and every privacy complaint. Registered agency partners can also raise data queries directly from the agent portal.
