logo

Data Retention and Deletion Policy

How long we keep each type of personal data, why, and how it is erased when that time is up

Effective: October 2026

Version 1.0

In plain words

We keep personal data only for as long as we need it to deliver your booking, meet a legal duty or settle a dispute. Each type of data has its own clock, listed in the schedule below. When the clock runs out, the data is deleted or anonymised, and we keep a record that it was done.

Purpose

This policy sets out how long T4Travelonline Private Limited keeps personal data and what happens to it afterwards. It gives effect to section 8(7) of the DPDP Act, which requires us to erase personal data once the purpose is served and no law requires us to keep it, and to Rule 8 of the DPDP Rules 2025, which sets a minimum one-year retention for certain processing logs. It also respects the record-keeping duties in tax, company, aviation and cyber-security law, which sometimes require us to keep a record longer than we otherwise would.

Principles

  • Purpose-bound. Every type of data has a stated purpose and a retention period. If we cannot say why we hold something, we delete it.
  • Shortest lawful period. Where two laws apply, we keep the data for the longer required period and no longer.
  • Minimise before deleting. Where only part of a record must be kept (for example a tax invoice), the rest is removed or masked.
  • Deletion is real. Deactivating an account is not deletion. Data is erased from live systems and ages out of backups on a fixed cycle.
  • Legal hold. Retention is paused for data linked to an open complaint, dispute, chargeback, investigation or court order, and resumes when it closes.

Retention schedule

Periods run from the trigger shown. “FY” means the Indian financial year (April to March).

Data categoryExamplesRetention periodReason / legal basis
Account profileName, email, mobile, password hash, preferencesWhile the account is active; erased within 30 days of a deletion request or after 3 years of inactivity, after a 48-hour warningDelivering the service; DPDP Act s.8(7)
Saved travellersCo-traveller names, DOB, gender, nationality, contactUntil the user removes them or deletes the accountUser convenience, with consent
Booking recordsPNR, itinerary, passenger names, fares paid, supplier references8 years from the end of the FY of travelCompanies Act s.128; CGST s.36; consumer and aviation disputes
Invoices and tax recordsTax invoices, GSTIN, PAN, TCS records8 years from the end of the FYCGST Act s.36; Income Tax Act; Companies Act s.128
Identity and travel documentsPassport number, expiry, issue date, nationalityRemoved 90 days after the last travel date, unless saved to the user's profile at their requestAirline and immigration requirements for the trip
PAN verification resultsPAN, name returned by the verification serviceKept with the related booking and tax record (8 years)TCS and Income Tax obligations
Payment recordsTransaction ID, amount, status, payment mode, last 4 digits (from the gateway)8 years from the end of the FYAccounting and RBI requirements. Full card numbers are never stored by us.
Travel insuranceInsured traveller details, nominee, policy number8 years after the policy end date, or as the insurer requiresInsurance claims and IRDAI-regulated records, held mainly by the insurer
Complaints and support ticketsMessages, call notes, outcomes3 years after closureShowing fair handling; limitation periods
Enquiry forms (tour, transfer, group, holiday)Contact details and trip requirements12 months after the last contact if no booking followsResponding to the enquiry
Marketing consent recordsWhat was agreed, when, notice version, withdrawalsFor as long as consent is active plus 3 yearsProving consent; DPDP Act s.6(10)
Marketing contact listEmail and mobile for promotionsRemoved within 7 days of withdrawal of consentConsent; TRAI TCCCPR 2018
Security and access logsLogins, admin actions, API access, IP addressAt least 1 year, and 180 days within India for ICT logsDPDP Rules, Rule 8; CERT-In Directions 2022
Push notification tokensFirebase device tokenUntil logout, app uninstall or account deletionDelivering booking alerts
Cookies and analyticsSession cookies, preference cookiesAs listed in the Cookie Policy (session to 12 months)Consent, where applicable
Data breach recordsIncident reports, notifications sentAt least 5 yearsAccountability under the DPDP Act and CERT-In
Corporate client dataEmployee travellers, approval chains, credit limitsFor the contract term plus 8 years for financial recordsContract; Companies Act
Why we chose this. Inactive accounts: the three-year inactivity rule in the DPDP Rules applies by law only to specified classes of very large platforms. We apply it voluntarily, because holding dormant accounts adds risk without benefit. We give at least 48 hours' notice by email before erasure, and logging in keeps the account.

How deletion is carried out

  1. 1Trigger: the retention period ends, the user deletes their account, or a valid erasure request is approved.
  2. 2Check for holds: the system checks for open bookings, refunds, chargebacks, disputes or legal holds before anything is erased.
  3. 3Erase or anonymise: live records are deleted, or anonymised where we only need statistics (for example route popularity).
  4. 4Propagate: the same instruction goes to processors who hold the data on our behalf, such as messaging and support tools, as set out in the Vendor Policy.
  5. 5Backups: encrypted backups age out on a rolling cycle of no more than 35 days. Deleted data is not restored to live systems from a backup.
  6. 6Evidence: an erasure log records what was deleted, when and by which job, without keeping the deleted personal data itself.

Data we may keep after an account is deleted

Deleting an account removes the profile, saved travellers, preferences and marketing data. Some records must be kept by law even after that, and are restricted so that they are used only for that legal purpose:

  • booking, invoice, tax and payment records (8 years);
  • records of consent and of the deletion itself;
  • security logs (at least 1 year);
  • anything linked to an open refund, dispute or investigation, until it is resolved.

Roles and review

RoleResponsibility
Grievance and Data Protection OfficerOwns this policy, approves exceptions and legal holds, reviews it every year.
Engineering leadRuns the automated deletion jobs, keeps the erasure log and the backup cycle.
FinanceConfirms which records must be kept for tax and audit.
Every team that holds dataKeeps no copies outside approved systems (no personal exports on laptops or in chat).

Document ref: T4T-POL-RET-02 · Version 1.0 · Effective October 2026. Questions about this policy: privacy@t4travelonline.com

Company Logo
T4Travelonline Private Limited
109 Shree Krishna Commercial Centre, 6 Udyog Nagar, S V Road, Goregaon West, Mumbai 400104, Maharashtra
+91 22 4016 2333, +91 97695 45777
travel@t4travelonline.com
Privacy & grievances: privacy@t4travelonline.com

Payment Methods

  • UPI (GPay, PhonePe, Paytm, BHIM)
  • Credit & Debit Cards (Visa, Mastercard, RuPay)
  • Net Banking
  • Wallets & EMI

Secured via Easebuzz payment gateway

Company

  • Become a Tour Guide for us
© 2026 t4travelonline.