Third-Party Data Sharing and Vendor Management Policy
Who we share personal data with, why, and the controls every vendor must meet
Effective: October 2026
Version 1.0
In plain words
To book your trip we have to share some of your data with airlines, hotels, booking platforms, the payment gateway and the insurer. We share only what each one needs, under a written contract, and we stay responsible for your data even when a vendor holds it. We do not sell personal data, and we do not share it for other companies' advertising.
Purpose
T4Travelonline Private Limited is the Data Fiduciary for the personal data of its customers. Under section 8(1) and 8(2) of the DPDP Act, we remain responsible for that data even when a Data Processor handles it for us, and we may engage a processor only under a valid contract. This policy lists who receives data, sets the rules for choosing and managing vendors, and explains how customers' rights reach the vendors that hold their data.
Who receives personal data
| Recipient | Role | Data shared | Purpose |
|---|---|---|---|
| Airlines (through TBO and directly) | Independent Data Fiduciaries | Passenger names, DOB, gender, nationality, passport details, contact, meal and seat choices | Issue tickets, meet DGCA and immigration (APIS) requirements |
| TBO (Tek Travels Pvt Ltd) | Processor and travel inventory provider | Search details, passenger and guest details, contact | Flight and hotel search, pricing and booking |
| Hotels and accommodation suppliers | Independent Data Fiduciaries | Guest names, nationality, contact, special requests | Confirm the stay and check-in |
| Easebuzz (payment aggregator) | Processor / independent regulated entity | Name, email, mobile, amount, transaction ID | Process payments and refunds. Card details are entered on Easebuzz and never reach us. |
| Asego and partner insurers | Independent Data Fiduciaries | Insured travellers' name, DOB, gender, contact, passport, nominee | Quote and issue travel insurance, handle claims |
| Cashfree (PAN verification) | Processor | PAN number | Verify PAN for TCS and invoicing |
| Google Firebase Cloud Messaging | Processor | Device notification token | Send booking and trip notifications to the app |
| Email, SMS and WhatsApp providers | Processors | Name, mobile, email, message content | Booking confirmations, OTPs and, with consent, offers. |
| Cloud hosting provider | Processor | All data held in our systems | Hosting the website, app back end and databases. |
| Wooshelf (technology partner) | Processor | Access as needed to build and support the app and portal | Software development and support, under a confidentiality agreement |
| Government and law enforcement | Recipients by law | As specified in the lawful request | Only when required by law, court order or a lawful notice |
Corporate clients see the bookings their employees make under the company account, as agreed in their contract.
What we never do
- We do not sell, rent or trade personal data.
- We do not share personal data with advertising networks or data brokers.
- We do not let vendors use our customers' data for their own marketing.
- We do not share more than a vendor needs for its task.
Transfers outside India
Some recipients are outside India by nature: a foreign airline, an overseas hotel, or a global cloud or messaging service. Section 16 of the DPDP Act allows such transfers except to countries the Central Government restricts by notification. We check that list before onboarding a vendor and before any new transfer, and we require the same level of protection from overseas vendors as from Indian ones. CERT-In logs are kept within India.
Choosing a vendor (internal)
- 1Need: the requesting team writes down what data the vendor needs and why. The Data Protection Officer approves the scope.
- 2Due diligence: security questionnaire; certifications such as ISO/IEC 27001, SOC 2 or PCI DSS where relevant; data location; sub-processors; breach history.
- 3Risk rating: High (sensitive data such as passport, PAN, payment or ID documents, or bulk access); Medium (contact and booking data); Low (no personal data).
- 4Contract: signed before any data is shared (see section 6).
- 5Register: the vendor is added to the vendor register with owner, data, purpose, location, risk and review date.
Minimum contract terms (internal)
- Process data only on our documented instructions and only for the stated purpose.
- Reasonable security safeguards at least equal to Rule 6 of the DPDP Rules: encryption, access control, logging, backups.
- Confidentiality obligations on all their staff who see the data.
- Notify us of any personal data breach within 24 hours of discovery, and cooperate with our investigation.
- Help us respond to customers' access, correction and erasure requests within 7 days of our request.
- No sub-processors without our prior written approval, and the same terms passed down to them.
- Return or delete all data at the end of the contract, with written confirmation.
- Allow audit or provide independent audit reports on request.
- Keep logs as required by the DPDP Rules and CERT-In Directions.
Ongoing management (internal)
| Activity | Frequency |
|---|---|
| Review of the vendor register and access | Every 6 months for High-risk vendors; every year for others |
| Re-assessment of security and certifications | Every year, and after any incident |
| Passing on customers' erasure and withdrawal requests | Within 7 days of the request being approved |
| Offboarding: revoke access, recover or delete data, confirm in writing | At the end of every contract |
Responsibilities
| Role | Responsibility |
|---|---|
| Data Protection Officer | Owns this policy and the vendor register, approves High-risk vendors. |
| Business owner of each vendor | Keeps the contract current and tells the DPO about any change in data or purpose. |
| Engineering lead | Grants least-privilege technical access and removes it on offboarding. |
| Finance | Pays only vendors that are in the register with a signed contract. |
Document ref: T4T-POL-VEN-06 · Version 1.0 · Effective October 2026. Questions about this policy: privacy@t4travelonline.com