logo

Third-Party Data Sharing and Vendor Management Policy

Who we share personal data with, why, and the controls every vendor must meet

Effective: October 2026

Version 1.0

In plain words

To book your trip we have to share some of your data with airlines, hotels, booking platforms, the payment gateway and the insurer. We share only what each one needs, under a written contract, and we stay responsible for your data even when a vendor holds it. We do not sell personal data, and we do not share it for other companies' advertising.

Purpose

T4Travelonline Private Limited is the Data Fiduciary for the personal data of its customers. Under section 8(1) and 8(2) of the DPDP Act, we remain responsible for that data even when a Data Processor handles it for us, and we may engage a processor only under a valid contract. This policy lists who receives data, sets the rules for choosing and managing vendors, and explains how customers' rights reach the vendors that hold their data.

Who receives personal data

RecipientRoleData sharedPurpose
Airlines (through TBO and directly)Independent Data FiduciariesPassenger names, DOB, gender, nationality, passport details, contact, meal and seat choicesIssue tickets, meet DGCA and immigration (APIS) requirements
TBO (Tek Travels Pvt Ltd)Processor and travel inventory providerSearch details, passenger and guest details, contactFlight and hotel search, pricing and booking
Hotels and accommodation suppliersIndependent Data FiduciariesGuest names, nationality, contact, special requestsConfirm the stay and check-in
Easebuzz (payment aggregator)Processor / independent regulated entityName, email, mobile, amount, transaction IDProcess payments and refunds. Card details are entered on Easebuzz and never reach us.
Asego and partner insurersIndependent Data FiduciariesInsured travellers' name, DOB, gender, contact, passport, nomineeQuote and issue travel insurance, handle claims
Cashfree (PAN verification)ProcessorPAN numberVerify PAN for TCS and invoicing
Google Firebase Cloud MessagingProcessorDevice notification tokenSend booking and trip notifications to the app
Email, SMS and WhatsApp providersProcessorsName, mobile, email, message contentBooking confirmations, OTPs and, with consent, offers.
Cloud hosting providerProcessorAll data held in our systemsHosting the website, app back end and databases.
Wooshelf (technology partner)ProcessorAccess as needed to build and support the app and portalSoftware development and support, under a confidentiality agreement
Government and law enforcementRecipients by lawAs specified in the lawful requestOnly when required by law, court order or a lawful notice

Corporate clients see the bookings their employees make under the company account, as agreed in their contract.

What we never do

  • We do not sell, rent or trade personal data.
  • We do not share personal data with advertising networks or data brokers.
  • We do not let vendors use our customers' data for their own marketing.
  • We do not share more than a vendor needs for its task.

Transfers outside India

Some recipients are outside India by nature: a foreign airline, an overseas hotel, or a global cloud or messaging service. Section 16 of the DPDP Act allows such transfers except to countries the Central Government restricts by notification. We check that list before onboarding a vendor and before any new transfer, and we require the same level of protection from overseas vendors as from Indian ones. CERT-In logs are kept within India.

Choosing a vendor (internal)

  1. 1Need: the requesting team writes down what data the vendor needs and why. The Data Protection Officer approves the scope.
  2. 2Due diligence: security questionnaire; certifications such as ISO/IEC 27001, SOC 2 or PCI DSS where relevant; data location; sub-processors; breach history.
  3. 3Risk rating: High (sensitive data such as passport, PAN, payment or ID documents, or bulk access); Medium (contact and booking data); Low (no personal data).
  4. 4Contract: signed before any data is shared (see section 6).
  5. 5Register: the vendor is added to the vendor register with owner, data, purpose, location, risk and review date.

Minimum contract terms (internal)

  • Process data only on our documented instructions and only for the stated purpose.
  • Reasonable security safeguards at least equal to Rule 6 of the DPDP Rules: encryption, access control, logging, backups.
  • Confidentiality obligations on all their staff who see the data.
  • Notify us of any personal data breach within 24 hours of discovery, and cooperate with our investigation.
  • Help us respond to customers' access, correction and erasure requests within 7 days of our request.
  • No sub-processors without our prior written approval, and the same terms passed down to them.
  • Return or delete all data at the end of the contract, with written confirmation.
  • Allow audit or provide independent audit reports on request.
  • Keep logs as required by the DPDP Rules and CERT-In Directions.

Ongoing management (internal)

ActivityFrequency
Review of the vendor register and accessEvery 6 months for High-risk vendors; every year for others
Re-assessment of security and certificationsEvery year, and after any incident
Passing on customers' erasure and withdrawal requestsWithin 7 days of the request being approved
Offboarding: revoke access, recover or delete data, confirm in writingAt the end of every contract

Responsibilities

RoleResponsibility
Data Protection OfficerOwns this policy and the vendor register, approves High-risk vendors.
Business owner of each vendorKeeps the contract current and tells the DPO about any change in data or purpose.
Engineering leadGrants least-privilege technical access and removes it on offboarding.
FinancePays only vendors that are in the register with a signed contract.

Document ref: T4T-POL-VEN-06 · Version 1.0 · Effective October 2026. Questions about this policy: privacy@t4travelonline.com

Company Logo
T4Travelonline Private Limited
109 Shree Krishna Commercial Centre, 6 Udyog Nagar, S V Road, Goregaon West, Mumbai 400104, Maharashtra
+91 22 4016 2333, +91 97695 45777
travel@t4travelonline.com
Privacy & grievances: privacy@t4travelonline.com

Payment Methods

  • UPI (GPay, PhonePe, Paytm, BHIM)
  • Credit & Debit Cards (Visa, Mastercard, RuPay)
  • Net Banking
  • Wallets & EMI

Secured via Easebuzz payment gateway

Company

  • Become a Tour Guide for us
© 2026 t4travelonline.