Privacy Policy
Plan My Safar ("we", "us", "our") operates the Plan My Safar mobile application and the website planmysafar.in (together, the "Platform"). This Privacy Policy explains what personal data we collect, why we collect it, who we share it with, how long we keep it, and the choices and rights you have. It is written to satisfy the requirements of the Google Play User Data policy and applicable Indian law, including the Digital Personal Data Protection Act, 2023.
By using the Platform you agree to this Policy.
1. Data we collect
Data you give us
- Mobile phone number (required) — used to create and sign in to your account via OTP verification.
- Name and email address — collected when you complete your profile; used on bookings and vouchers.
- Saved addresses — address lines, city, state, pincode and an optional contact phone number that you choose to save in "My Addresses".
- Profile photo (avatar) — an image you optionally upload for your profile.
- Booking and traveller details — travel dates, traveller names, ages, gender, and contact details for the people you book for. If you enter another person's details, you confirm you have their permission.
- Enquiries and support messages — the content of messages you send us.
Data collected with your permission (optional)
- Approximate location — if you grant the location permission, we use your device location to detect your city and personalise destination suggestions. Location is used for city detection; we store the detected city, not a movement history. You can decline or revoke the permission at any time in your device settings; the app remains fully usable and you can pick your city manually.
- Push notification token — if you allow notifications, your device's Firebase Cloud Messaging (FCM) token is stored so we can send booking updates and offers. Revoking notification permission or logging out stops this.
Data collected automatically
- Transaction data — booking numbers, amounts, payment status, and payment identifiers returned by our payment gateway. We never see or store your full card number, CVV or banking passwords.
- Technical data — device type, app version, IP address and basic request logs used for security, fraud prevention and debugging.
We do not knowingly collect data from children under 18 as account holders. Traveller entries for minors are provided by the adult account holder as part of a booking.
2. Why we use your data (purposes)
- Creating and securing your account (OTP login, session management).
- Processing bookings and payments, issuing vouchers and invoices, and delivering the travel services you purchase.
- Sending transactional messages: OTPs, booking confirmations, payment receipts, trip reminders and status updates via SMS, push notification, email and WhatsApp (where enabled).
- Personalising the Platform, such as showing packages relevant to your detected or chosen city.
- Providing customer support and resolving disputes.
- Preventing fraud, enforcing our Terms, and complying with legal obligations (tax, accounting, law-enforcement requests made under due process).
- Sending promotional offers — only where permitted, and always with the ability to opt out.
We do not sell your personal data. We do not use your data for third-party advertising.
3. Who we share data with (third parties)
We share personal data only with the service providers needed to run the Platform, under their own published privacy terms:
- Razorpay (payment gateway) — receives your payment details to process payments, refunds and payment verification. Card and banking data is handled entirely by Razorpay.
- MSG91 (SMS provider) — receives your phone number to deliver OTP and transactional SMS.
- WhatsApp Business Platform (Meta) — when WhatsApp updates are enabled, receives your phone number and the message content (for example a booking confirmation) to deliver WhatsApp messages.
- Google Firebase (Firebase Cloud Messaging) — when push notifications are enabled, receives your device token to deliver notifications.
- Travel suppliers — hotels, transport operators and local operators receive the traveller names, ages and contact details necessary to fulfil your booking, and nothing more.
- Authorities — where required by applicable law, court order or enforceable government request.
We require service providers to use your data only to provide their service to us.
4. Data storage and security
- Data is stored on our servers with access restricted to authorised personnel.
- OTPs are stored only as one-way hashes and expire within minutes.
- Authentication uses signed tokens; admin and customer access are strictly separated.
- Payment card data never touches our servers.
- Uploaded images (such as avatars) are stored on our server and served over the web; upload types and sizes are restricted.
- No system is perfectly secure; in the event of a data breach affecting you we will notify you and the authorities as required by law.
5. Data retention
- Account data (profile, addresses, avatar, saved packages, device tokens) — kept while your account is active, and deleted or anonymized when your account deletion request is processed.
- Bookings, payments and invoices — retained for the period required by Indian tax, accounting and consumer-protection law (generally up to 8 years), even after account deletion, in a form unlinked from your identity wherever possible.
- OTP sessions — deleted automatically within about an hour of creation.
- Support correspondence — kept as long as needed to resolve the matter and for a reasonable period afterwards.
6. Your rights and choices
Subject to applicable law, you have the right to:
- Access and correct your data — view and edit your profile and addresses in the app at any time.
- Withdraw permissions — disable location or notification access in your device settings at any time.
- Opt out of promotions — via notification settings; transactional messages continue as they are part of the service.
- Delete your account and data — request deletion at any time:
- in the app: Settings → Delete account, or
- on the web: planmysafar.in/delete (no app required).
Both flows verify your mobile number by OTP and are described in our Account Deletion policy, including what is deleted and what must be retained.
- Grievance redressal — raise a concern with our grievance contact below; if unresolved, you may approach the Data Protection Board of India or other competent authority.
7. Cookies and website analytics
The website uses only the cookies and local storage necessary for it to function (for example keeping you signed in). We do not run third-party advertising trackers.
8. Changes to this Policy
We may update this Policy from time to time. Material changes will be announced in the app or on the website, and the "Last updated" date below always reflects the current version.
9. Contact us
Data controller: Plan My Safar
- Email: support@planmysafar.com
- Phone / WhatsApp: +91 98765 43210 (24x7)
- Grievance officer: reachable at support@planmysafar.com with the subject "Privacy Grievance"
---
_Last updated: 22 August 2026_
_This document is provided as a template and does not constitute legal advice. The operator of Plan My Safar should have it reviewed by qualified legal counsel before relying on it._