← Back to AlgoTrips

Privacy Policy

Last updated: 4 August 2026

This Privacy Policy explains how Epic Escapes LLP (“AlgoTrips”, “we”, “us”) collects, uses, shares, stores, and protects personal data when registered travel advisors use our platform to plan and book travel for their customers. It applies to algotrips.com and to every related application, dashboard, and interface we operate (the “Platform”). It should be read together with our Terms of Service. We follow the Digital Personal Data Protection Act, 2023 (“DPDP Act”) and other applicable Indian law.

1. Who we are

Epic Escapes LLP, a limited liability partnership registered in Delhi, India, trading as AlgoTrips, GSTIN 07AALFE3957H1Z5, is the data fiduciary responsible for the personal data described in this policy. “Data fiduciary” is the term the DPDP Act uses for the entity that decides why and how personal data is processed.

Grievance Officer: tushar@algotrips.com. General support: support@algotrips.com.

Note on roles: for data about a travel advisor and their agency, we act as the data fiduciary. For traveller data that an advisor enters in order to make a booking, the advisor determines the customer relationship and we process that data to deliver the booking the advisor has asked us to make.

2. Personal data we collect

Account and agency data. Name, business email address, phone number, agency or firm name, business address, logo and branding you upload, user role, and login credentials (passwords are stored only as a salted hash). If you sign in with Google, we receive your name, email address, and profile image from that sign-in.

Verification data. GSTIN, PAN, and any identity or business documents you provide so that we can verify your agency, approve your account, and issue tax-compliant invoices. This data is treated as sensitive and is stored encrypted.

Traveller data entered for bookings. Passenger names, salutation, date of birth, gender, nationality, contact email and phone, and, where an airline, hotel, or destination requires it, passport or government-identification numbers and expiry dates, frequent-flyer numbers, and meal or accessibility preferences.

Transaction and payment data. Booking records, itineraries, quotations, invoices, wallet ledger entries, refund records, and payment references such as the transaction or order identifier, payment method type, amount, status, and the last four digits of a card where the payment aggregator returns them. We do not collect or store full card numbers, CVV, UPI PINs, or net-banking credentials — those are entered on and processed by RBI-authorised payment aggregators on their own PCI-DSS compliant systems.

Usage, device, and support data. IP address, browser and device type, pages viewed, features used, timestamps, error and server logs, session recordings in which anything you type is masked, and the content of the messages you send us for support.

3. Why we use it, and our lawful basis

Under the DPDP Act we process personal data either with your consent or for the legitimate uses the Act permits, including delivering a service you have asked for. Our purposes are:

  • Providing the service — creating and running your account, building itineraries and quotations, searching availability, and making and managing flight, hotel, activity, and transfer bookings with suppliers.
  • Payments, wallet, and invoicing — processing payments through payment aggregators, maintaining your wallet ledger, issuing GST invoices and vouchers, and handling refunds and chargebacks.
  • Verification and onboarding — checking GSTIN and PAN details and approving accounts.
  • Security and fraud prevention — authentication, monitoring for unauthorised access, abuse, and payment fraud, and keeping audit logs.
  • Service communications — booking confirmations, payment receipts, schedule changes, and important notices about your account.
  • Improving the Platform — analytics and diagnostics to understand how features are used and to fix problems. For signed-in accounts this is part of providing the service under our Terms; for visitors who are not signed in, it happens only with cookie consent.
  • Legal and tax compliance — meeting our obligations under tax, accounting, and travel-industry rules, and responding to lawful requests from authorities.

We do not use traveller data for advertising, and we do not sell personal data. We do not carry out automated decision-making that produces legal effects on an individual.

4. Who we share it with

Travel suppliers. To confirm a booking we pass the necessary details to the airline, hotel, activity operator, transfer provider, or the consolidator through whom we book. This is unavoidable for fulfilment — a booking cannot be issued without the traveller’s name and the documentation the supplier requires.

Payment aggregators and banks. RBI-authorised payment aggregators and gateways process the payment and return the transaction status to us. They handle payment credentials under their own privacy terms; we receive only references.

Service providers we rely on. Cloud hosting and database infrastructure, email and messaging delivery, error monitoring and analytics, verification services, and customer-support tooling. They act on our instructions under contract, may use the data only to provide the service to us, and are required to keep it secure.

Within your agency. Users on your agency account can see the bookings and itineraries created under that account.

Legal and corporate. We may disclose data where required by law, court order, or a regulator, to establish or defend legal claims, to prevent fraud, or in connection with a merger, acquisition, or transfer of business — in which case the recipient remains bound by this policy.

Cross-border transfers. Some suppliers and service providers operate outside India, so booking data may be transferred abroad to fulfil an international booking. Such transfers are made in line with the DPDP Act and any restrictions notified by the Government of India, and under contractual safeguards with the recipient.

We never sell personal data and we do not share it with third parties for their own marketing.

5. How we store and protect it

Personal data is stored on access-controlled servers hosted in secure data centres. Our security measures include encryption of data in transit over TLS; field-level AES-256 encryption of sensitive identifiers such as PAN, document numbers, and traveller identification details; hashed passwords; role-based access control and least-privilege administrative access; authentication and session controls; audit logging of administrative activity; automated error monitoring with personal data scrubbed from reports; regular encrypted backups; and periodic security review of the Platform.

No system can be guaranteed completely secure, but we take reasonable technical and organisational measures appropriate to the risk. If a personal-data breach occurs, we will notify the Data Protection Board of India and affected individuals as required by the DPDP Act.

6. How long we keep it

We keep personal data only as long as it is needed for the purposes above, or as long as the law requires. In practice:

  • account and agency data — for as long as your account is active, and for a reasonable period afterwards to handle disputes and closing formalities;
  • booking, invoice, wallet, and tax records — for the statutory retention period under Indian tax and accounting law, after which they are deleted or de-identified;
  • traveller data — for the duration of the booking and the period in which a claim, refund, or dispute can arise, then deleted or anonymised; and
  • logs, analytics, and support correspondence — for a limited period for security, debugging, and service-quality purposes.

7. Your rights under the DPDP Act

Subject to the conditions in the Act, you have the right to:

  • Access — obtain a summary of the personal data we process about you and of the processing activities, and the identities of those with whom we have shared it;
  • Correction and completion — have inaccurate or misleading data corrected, and incomplete data completed or updated;
  • Erasure — have your personal data deleted where it is no longer needed for the purpose it was collected for and we are not required by law to retain it;
  • Withdrawal of consent — withdraw consent at any time for processing that relies on consent, such as optional analytics cookies or marketing messages. Withdrawal does not affect processing done before it, and some processing necessary to deliver a booking or to meet a legal obligation will continue;
  • Nomination — nominate another individual to exercise your rights in the event of death or incapacity; and
  • Grievance redressal — have your complaint about our handling of your data addressed by us before approaching the Data Protection Board of India.

To exercise any of these rights, use the tools in your account where available, or email our Grievance Officer at tushar@algotrips.com from the address registered on your account, describing the right you wish to exercise. We acknowledge requests within 48 hours and respond within the timelines required by law, and in any case within 30 days. We may ask for information to verify your identity before acting, and we may decline a request where the law allows — in which case we will explain why.

If a request relates to a traveller whose data was entered by an advisor, please raise it with the advisor who made the booking; where the request comes to us directly, we will act on it and coordinate with that advisor as needed.

8. Cookies and similar technologies

We use cookies and similar browser storage for three purposes: strictly necessary cookies that keep you signed in and protect the session; analytics cookies that help us measure how the Platform is used; and marketing cookies, where enabled. Necessary cookies cannot be switched off because the Platform will not work without them.

Optional cookies are off by default. When you first visit, our cookie banner asks what you want to allow, and nothing optional loads until you choose. You can change or withdraw that choice at any time using the link in the site footer, or by clearing cookies in your browser.

While you are signed in, usage analytics are collected as part of providing and improving the service under our Terms of Service, as described there. Session recordings mask anything you type.

9. Children

The Platform is a business tool for registered travel agents and is not directed at children. You must be 18 or older to hold an account, and we do not knowingly collect personal data from a child for account purposes. Where an advisor enters details of a child travelling on a booking, that data is provided by the advisor with the consent of the child’s parent or lawful guardian, is used only to make and deliver the booking, and is never used for tracking, profiling, or advertising directed at children. If you believe a child’s data has been provided to us without the required consent, contact our Grievance Officer and we will delete it.

10. Grievance Officer

Questions or complaints about your data: email our Grievance Officer at tushar@algotrips.com (Epic Escapes LLP, Delhi, India). Please include your account email, the nature of the complaint, and any booking reference involved.

We acknowledge every grievance within 48 hours and aim to resolve it within 30 days. If you are not satisfied with our response, you may escalate the matter to the Data Protection Board of India under the DPDP Act.

11. Changes to this policy

We may update this policy to reflect changes in our services, our processors, or the law. The current version is always published on this page with the “Last updated” date above. Where a change is material, we will notify you by email or through the Platform before it takes effect, and where the law requires it, ask for fresh consent.

12. Contact

Epic Escapes LLP (trading as AlgoTrips), Delhi, India. Support: support@algotrips.com. Data protection and grievances: tushar@algotrips.com. Other contact details are listed on our Contact Us page.