This Privacy Policy explains how eTrip Online collects, uses, shares, and protects personal data in connection with our flight search, booking, ticketing, and related travel services.
It applies to personal data collected through:
· Our website
· Our mobile applications
· Our Partner Portal
By using our Services, you agree to the practices described in this Policy.
The data controller for a booking is the contracting eTrip Online entity identified at the time of booking.
Contact details for each entity are available on our Contact page.
· Name
· Address
· Email
· Phone number
· Passenger name
· Date of birth
· Passport or ID details
· Frequent flyer numbers
· Booking reference
· Ticket number
· Travel itinerary
· Payment instrument details (card token, last four digits)
· Billing address
· Transaction records
Full card details are processed by PCIcompliant payment providers and are not stored by eTrip Online except where legally permitted.
· Emails and messages
· Support tickets
· Call recordings (where legally permitted)
· IP address
· Device identifiers
· Browser information
· Usage logs
· Cookies and analytics data
Depending on the service, we may also collect:
· Aadhar Card / PAN Card / Driver’s License/National IDs
· Passport number
· Credit or debit card details
We use personal data to:
· Process and confirm bookings
· Issue tickets and deliver travel documents
· Process payments, refunds, and settlements
· Comply with supplier and regulatory requirements (security checks, immigration, manifests)
· Provide customer support and manage disputes
· Detect and prevent fraud and abuse
· Send transactional communications
· Send marketing communications (only where consented)
· Improve our Services and perform analytics
We process personal data based on:
· Contract necessity — to complete bookings and ticketing
· Legal obligations — security, immigration, tax, and regulatory requirements
· Legitimate interests — fraud prevention, service improvement, analytics
· Consent — where required by law (e.g., marketing communications)
Where consent is required, we will obtain and record it.
We may share personal data with:
· Airlines
· Payment processors
· GDSs (Global Distribution Systems)
· Consolidators
· Government authorities (as required by law)
· Fraudprevention providers
· Service providers acting on our behalf
International transfers may occur for ticketing, settlement, and regulatory compliance.
Where required, we implement safeguards such as:
· Standard Contractual Clauses
· Local legal mechanisms
· Industrystandard protections
We retain booking and transactional records for the period required by:
· Applicable laws
· Regulatory obligations
· Legitimate business needs (support, audit, dispute resolution)
Retention periods vary by jurisdiction and record type.
We implement technical and organizational measures to protect personal data, including:
· Encryption in transit and at rest
· Tokenization for payment data
· Rolebased access controls
· Logging and monitoring
· Regular security audits
Depending on your jurisdiction, you may have the right to:
· Access your personal data
· Correct inaccurate data
· Delete your data
· Restrict processing
· Object to processing
· Request data portability
· Withdraw consent
Requests should be sent to the local data contact listed on our Contact page.
We will respond in accordance with applicable law.
We use cookies and similar technologies for:
· Essential site functions
· Analytics
· Marketing (where permitted)
A cookie banner and cookie settings page will be provided to allow optin/optout controls as required by law.
Our Services are not directed to children under applicable minimum age requirements.
We do not knowingly collect personal data from children.
If we learn that such data has been collected, we will take steps to delete it.
We may update this Privacy Policy from time to time.
We'll post material changes with a new effective date and, where required, notify users.