Data Retention and Deletion Policy
How long we keep each type of personal data, why, and how it is erased when that time is up
Effective: October 2026
Version 1.0
In plain words
We keep personal data only for as long as we need it to deliver your booking, meet a legal duty or settle a dispute. Each type of data has its own clock, listed in the schedule below. When the clock runs out, the data is deleted or anonymised, and we keep a record that it was done.
Purpose
This policy sets out how long T4Travelonline Private Limited keeps personal data and what happens to it afterwards. It gives effect to section 8(7) of the DPDP Act, which requires us to erase personal data once the purpose is served and no law requires us to keep it, and to Rule 8 of the DPDP Rules 2025, which sets a minimum one-year retention for certain processing logs. It also respects the record-keeping duties in tax, company, aviation and cyber-security law, which sometimes require us to keep a record longer than we otherwise would.
Principles
- Purpose-bound. Every type of data has a stated purpose and a retention period. If we cannot say why we hold something, we delete it.
- Shortest lawful period. Where two laws apply, we keep the data for the longer required period and no longer.
- Minimise before deleting. Where only part of a record must be kept (for example a tax invoice), the rest is removed or masked.
- Deletion is real. Deactivating an account is not deletion. Data is erased from live systems and ages out of backups on a fixed cycle.
- Legal hold. Retention is paused for data linked to an open complaint, dispute, chargeback, investigation or court order, and resumes when it closes.
Retention schedule
Periods run from the trigger shown. “FY” means the Indian financial year (April to March).
| Data category | Examples | Retention period | Reason / legal basis |
|---|---|---|---|
| Account profile | Name, email, mobile, password hash, preferences | While the account is active; erased within 30 days of a deletion request or after 3 years of inactivity, after a 48-hour warning | Delivering the service; DPDP Act s.8(7) |
| Saved travellers | Co-traveller names, DOB, gender, nationality, contact | Until the user removes them or deletes the account | User convenience, with consent |
| Booking records | PNR, itinerary, passenger names, fares paid, supplier references | 8 years from the end of the FY of travel | Companies Act s.128; CGST s.36; consumer and aviation disputes |
| Invoices and tax records | Tax invoices, GSTIN, PAN, TCS records | 8 years from the end of the FY | CGST Act s.36; Income Tax Act; Companies Act s.128 |
| Identity and travel documents | Passport number, expiry, issue date, nationality | Removed 90 days after the last travel date, unless saved to the user's profile at their request | Airline and immigration requirements for the trip |
| PAN verification results | PAN, name returned by the verification service | Kept with the related booking and tax record (8 years) | TCS and Income Tax obligations |
| Payment records | Transaction ID, amount, status, payment mode, last 4 digits (from the gateway) | 8 years from the end of the FY | Accounting and RBI requirements. Full card numbers are never stored by us. |
| Travel insurance | Insured traveller details, nominee, policy number | 8 years after the policy end date, or as the insurer requires | Insurance claims and IRDAI-regulated records, held mainly by the insurer |
| Complaints and support tickets | Messages, call notes, outcomes | 3 years after closure | Showing fair handling; limitation periods |
| Enquiry forms (tour, transfer, group, holiday) | Contact details and trip requirements | 12 months after the last contact if no booking follows | Responding to the enquiry |
| Marketing consent records | What was agreed, when, notice version, withdrawals | For as long as consent is active plus 3 years | Proving consent; DPDP Act s.6(10) |
| Marketing contact list | Email and mobile for promotions | Removed within 7 days of withdrawal of consent | Consent; TRAI TCCCPR 2018 |
| Security and access logs | Logins, admin actions, API access, IP address | At least 1 year, and 180 days within India for ICT logs | DPDP Rules, Rule 8; CERT-In Directions 2022 |
| Push notification tokens | Firebase device token | Until logout, app uninstall or account deletion | Delivering booking alerts |
| Cookies and analytics | Session cookies, preference cookies | As listed in the Cookie Policy (session to 12 months) | Consent, where applicable |
| Data breach records | Incident reports, notifications sent | At least 5 years | Accountability under the DPDP Act and CERT-In |
| Corporate client data | Employee travellers, approval chains, credit limits | For the contract term plus 8 years for financial records | Contract; Companies Act |
How deletion is carried out
- 1Trigger: the retention period ends, the user deletes their account, or a valid erasure request is approved.
- 2Check for holds: the system checks for open bookings, refunds, chargebacks, disputes or legal holds before anything is erased.
- 3Erase or anonymise: live records are deleted, or anonymised where we only need statistics (for example route popularity).
- 4Propagate: the same instruction goes to processors who hold the data on our behalf, such as messaging and support tools, as set out in the Vendor Policy.
- 5Backups: encrypted backups age out on a rolling cycle of no more than 35 days. Deleted data is not restored to live systems from a backup.
- 6Evidence: an erasure log records what was deleted, when and by which job, without keeping the deleted personal data itself.
Data we may keep after an account is deleted
Deleting an account removes the profile, saved travellers, preferences and marketing data. Some records must be kept by law even after that, and are restricted so that they are used only for that legal purpose:
- booking, invoice, tax and payment records (8 years);
- records of consent and of the deletion itself;
- security logs (at least 1 year);
- anything linked to an open refund, dispute or investigation, until it is resolved.
Roles and review
| Role | Responsibility |
|---|---|
| Grievance and Data Protection Officer | Owns this policy, approves exceptions and legal holds, reviews it every year. |
| Engineering lead | Runs the automated deletion jobs, keeps the erasure log and the backup cycle. |
| Finance | Confirms which records must be kept for tax and audit. |
| Every team that holds data | Keeps no copies outside approved systems (no personal exports on laptops or in chat). |
Document ref: T4T-POL-RET-02 · Version 1.0 · Effective October 2026. Questions about this policy: privacy@t4travelonline.com