Privacy Policy
How T4Travel collects, uses, shares and protects your personal data, and the rights you have over it
Effective: October 2026
Version 2.0
In plain words
We collect the details needed to book your travel, share them only with the airlines, hotels and partners who deliver it, and protect them with strong security. We never sell your data. You can see, correct or delete it, withdraw consent, name a nominee and complain to us or to the Data Protection Board. This policy explains each of these in plain words.
Who we are
T4Travelonline Private Limited (“T4Travel”, “we”, “us”) runs www.t4travelonline.com, the T4Travel mobile app (Android and iOS), our corporate travel portal and our offline sales channels. For the personal data described here we are the Data Fiduciary under the Digital Personal Data Protection Act, 2023: we decide why and how it is processed, and we are responsible for it. Our registered office is at 109 Shree Krishna Commercial Centre, 6 Udyog Nagar, S V Road, Goregaon West, Mumbai 400104, Maharashtra, India.
This policy applies to customers, travellers booked by customers, corporate users, people who send us an enquiry, and visitors to our website and app. It does not cover third-party websites linked from ours, or airlines, hotels and insurers, which have their own privacy policies for the data they receive to deliver your service.
The data we collect
| Category | Examples | Where it comes from |
|---|---|---|
| Identity and contact | Name, title, gender, date of birth, email, mobile number | You, when you sign up or book |
| Traveller details | Co-travellers' names, dates of birth, gender, nationality, passport number, issue and expiry dates | You, for each booking or saved traveller |
| Booking details | Itinerary, PNR, hotel, room, seat, meal and baggage choices, fares paid, cancellations | Your bookings with us |
| Tax and billing | PAN, GSTIN, billing address, residency status (Resident or NRI), TCS declarations | You, where tax law requires it |
| Payment | Transaction ID, amount, status and payment method. We never see or store your full card number, CVV or UPI PIN; these are entered on our RBI-authorised payment partner's page. | Our payment partner |
| Insurance | Insured travellers' details and nominee | You, if you add travel insurance |
| Corporate | Employer, employee ID, approval chain, travel limits | Your employer, under its contract with us |
| Communications | Support tickets, emails, chat and call notes, feedback | You, when you contact us |
| Technical | Device type, operating system, app version, IP address, notification token, cookies | Your device, automatically |
We do not ask for Aadhaar. If you choose to share an Aadhaar card as ID, we mask all but the last four digits.
Why we use it, and on what basis
| Purpose | Legal basis under the DPDP Act |
|---|---|
| Search, book, ticket and manage your travel; send confirmations, changes and refund updates | Legitimate use: you gave us the data to get this service (s.7(a)), and our contract with you |
| Meet tax, accounting, aviation, immigration and other legal duties | Legitimate use: compliance with law (s.7) |
| Verify PAN and collect TCS where required | Legitimate use: compliance with the Income Tax Act |
| Keep our platform secure; detect and prevent fraud | Legitimate use and reasonable security safeguards (s.8(5)) |
| Handle complaints and support requests | Legitimate use: you asked us to |
| Save travellers to your profile for later bookings | Your consent |
| Send offers by email, SMS, WhatsApp or push | Your consent, which you can withdraw at any time |
| Remember preferences and measure website use with non-essential cookies | Your consent through the cookie banner |
We use only what each purpose needs. We do not use your data for automated decisions that have legal or similarly significant effects on you.
Who we share it with
We share personal data only with those who need it to deliver your booking or support our service:
- Airlines and hotels, and our booking platform partner TBO, to issue tickets and confirm stays;
- Easebuzz, our payment aggregator, to process payments and refunds;
- Asego and partner insurers, if you add travel insurance;
- Cashfree, to verify PAN;
- Service providers who host our systems, send emails, SMS and WhatsApp messages, deliver app notifications (Google Firebase) and build and support our software (Wooshelf), all under contracts that limit their use of the data;
- Your employer, if you book under a corporate account;
- Government authorities, only when the law requires it.
We do not sell or rent personal data, and we do not share it with advertisers. Full details are in our Third-Party Data Sharing and Vendor Management Policy.
International transfers
An international booking means sharing data with an airline or hotel abroad, and some service providers process data outside India. We transfer data abroad only as permitted by section 16 of the DPDP Act and never to a country restricted by the Central Government, and we require the same protection from overseas partners as from Indian ones.
How long we keep it
We keep data only as long as the purpose needs, or as the law requires. For example: your account until you delete it; booking, invoice and tax records for 8 years from the end of the financial year; passport details for 90 days after travel unless you save them to your profile; security logs for at least one year. The full schedule is in our Data Retention and Deletion Policy.
How we protect it
- All traffic to our website, app and APIs is encrypted with HTTPS (TLS 1.2 or higher).
- Databases and backups are encrypted at rest; passwords are stored only as salted hashes.
- Staff and partners see only the data their role needs, with multi-factor authentication for administrative access.
- Access and changes are logged, and logs are kept as the DPDP Rules and CERT-In Directions require.
- We test our systems for vulnerabilities and fix them on a set timeline.
- If a breach affects your data, we tell you and the Data Protection Board without delay, as set out in our incident response policy.
No system is perfectly secure. Please keep your password private, and remember that we will never ask for your OTP, password or card PIN by phone, email or chat.
Your rights
| Right | What it means | How to use it |
|---|---|---|
| Access (s.11) | A summary of the personal data we hold about you, what we do with it, and who we have shared it with | Profile → Privacy & Data → My data, or email us |
| Correction and update (s.12) | Fix anything inaccurate or incomplete | Edit your profile, or ask us |
| Erasure (s.12) | Delete data we no longer need, or your whole account | Profile → Settings → Delete Account, or our web form |
| Withdraw consent (s.6(4)) | Stop processing based on consent, as easily as you gave it | Privacy & Data switches, or the unsubscribe link |
| Grievance redressal (s.13) | Complain to us, then to the Data Protection Board | See “Contact us and complaints” below |
| Nominate (s.14) | Name someone to exercise your rights if you die or become unable to | Privacy & Data → Nominee, or email us |
We respond within 30 days, and in every case within the 90-day limit set by the DPDP Rules. We may ask you to confirm your identity first. Withdrawing consent does not affect processing already done, or processing we need for your booking or by law. Under section 15 of the Act you also have duties: to give accurate information and not to file false or frivolous complaints.
Children
You must be 18 or older to create an account or make a booking. When an adult books for a child or infant, the adult confirms they are the child's parent or lawful guardian or acting with the guardian's permission, and we use the child's data only to deliver that booking. We do not track children's behaviour or show them targeted advertising.
Cookies and the mobile app
Our website uses cookies as described in our Cookie Policy, where you can choose which non-essential cookies to allow. Our mobile app's data practices and device permissions are described in our Mobile App Privacy Policy.
Contact us and complaints
Questions, requests and complaints about personal data go to our Grievance Officer. We acknowledge within 24 hours.
| Contact | Details |
|---|---|
| Email (privacy and data requests) | privacy@t4travelonline.com |
| Phone | +91 22 4016 2333 / +91 97695 45777 (Monday to Saturday, 10:00 to 19:00 IST) |
| Post | T4Travelonline Private Limited, 109 Shree Krishna Commercial Centre, 6 Udyog Nagar, S V Road, Goregaon West, Mumbai 400104, Maharashtra, India |
If you are not satisfied with our response, you may complain to the Data Protection Board of India once our process has been completed, as provided in section 13(3) of the DPDP Act. The process is described in our Grievance Redressal Policy.
Changes to this policy
We review this policy at least once a year. If we make a material change, such as a new purpose or a new kind of recipient, we will tell you by email or in the app before it applies, and ask for fresh consent where the law requires. The version and effective date are shown at the top of this document.
Laws this policy follows
| Law | Relevance |
|---|---|
| Digital Personal Data Protection Act, 2023 (DPDP Act) | Notice and consent, legitimate uses, duties of a Data Fiduciary, children's data, rights of Data Principals (access, correction, erasure, grievance, nomination), cross-border transfer, penalties. |
| Digital Personal Data Protection Rules, 2025 (DPDP Rules) | Content of notices, reasonable security safeguards, breach intimation (including the 72-hour detailed report to the Board), minimum one-year log retention, verifiable parental consent, rights procedure and the outer limit of 90 days for grievances. Commencement is phased; the main obligations apply from May 2027. |
| Information Technology Act, 2000 | Section 43A (compensation for failure to protect sensitive data, until replaced by the DPDP Act), section 72A (disclosure in breach of contract), section 70B (CERT-In) and section 79 (intermediary safe harbour). |
| IT (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 | Privacy policy, consent for sensitive data such as financial information, Grievance Officer to resolve within one month, and reasonable security practices such as ISO/IEC 27001. Applies until superseded. |
| CERT-In Directions under section 70B(6) of the IT Act (28 April 2022) | Report specified cyber incidents to CERT-In within 6 hours, keep ICT system logs for 180 days within India, synchronise clocks to NIC/NPL time servers and name a point of contact. |
| IT (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 | Where the Company acts as an intermediary: publish rules and policies, appoint a Grievance Officer, acknowledge complaints within 24 hours and resolve them within 15 days. |
| Consumer Protection Act, 2019 and Consumer Protection (E-Commerce) Rules, 2020 | Display seller and service details, refund, cancellation and grievance policies; Grievance Officer to acknowledge within 48 hours and redress within one month; no unfair trade practices or hidden charges. |
| DGCA Civil Aviation Requirements, Section 3, Series M, Part II | Airline refund timelines (7 days for card payments, 30 days for tickets bought through an agent), no additional charge for processing a refund, and the passenger's right to a refund of statutory taxes. |
| RBI directions on Payment Aggregators and card tokenisation | Card data is not stored by the merchant; payments run through an RBI-authorised payment aggregator. |
| Income Tax Act, 1961 | PAN collection and Tax Collected at Source under section 206C(1G) on overseas tour packages; record keeping. |
| Central Goods and Services Tax Act, 2017 and Companies Act, 2013 | Retention of tax invoices and books of account (CGST section 36: 72 months from the due date of the annual return; Companies Act section 128: 8 financial years). |
| TRAI Telecom Commercial Communications Customer Preference Regulations, 2018 | Promotional SMS and calls only to consenting customers, through DLT-registered headers and templates, respecting Do-Not-Disturb preferences. |
| Aadhaar (Targeted Delivery of Financial and Other Subsidies, Benefits and Services) Act, 2016 | The Company does not require Aadhaar; where a customer shares an Aadhaar card as ID, the number is masked and not stored in full. |
Document ref: T4T-POL-PRV-08 · Version 2.0 · Effective October 2026. Questions about this policy: privacy@t4travelonline.com