Privacy Policy


eTrip Online - Effective Date: November 1st, 2026

1. Introduction and Scope

This Privacy Policy explains how eTrip Online collects, uses, shares, and protects personal data in connection with our flight search, booking, ticketing, and related travel services.
It applies to personal data collected through:

· Our website

· Our mobile applications

· Our Partner Portal

By using our Services, you agree to the practices described in this Policy.

 

2. Data Controller and Contracting Entities

The data controller for a booking is the contracting eTrip Online entity identified at the time of booking.
Contact details for each entity are available on our Contact page.

 

3. Personal Data We Collect

Identity & Contact Information

· Name

· Address

· Email

· Phone number

Travel & Booking Information

· Passenger name

· Date of birth

· Passport or ID details

· Frequent flyer numbers

· Booking reference

· Ticket number

· Travel itinerary

Payment Information

· Payment instrument details (card token, last four digits)

· Billing address

· Transaction records

Full card details are processed by PCIcompliant payment providers and are not stored by eTrip Online except where legally permitted.

Support & Communications

· Emails and messages

· Support tickets

· Call recordings (where legally permitted)

Device & Usage Data

· IP address

· Device identifiers

· Browser information

· Usage logs

· Cookies and analytics data

Additional Information (When Required)

Depending on the service, we may also collect:

· Aadhar Card / PAN Card / Driver’s License/National IDs

· Passport number

· Credit or debit card details

 

4. How We Use Personal Data

We use personal data to:

· Process and confirm bookings

· Issue tickets and deliver travel documents

· Process payments, refunds, and settlements

· Comply with supplier and regulatory requirements (security checks, immigration, manifests)

· Provide customer support and manage disputes

· Detect and prevent fraud and abuse

· Send transactional communications

· Send marketing communications (only where consented)

· Improve our Services and perform analytics


5. Legal Bases for Processing

We process personal data based on:

· Contract necessity — to complete bookings and ticketing

· Legal obligations — security, immigration, tax, and regulatory requirements

· Legitimate interests — fraud prevention, service improvement, analytics

· Consent — where required by law (e.g., marketing communications)

Where consent is required, we will obtain and record it.

 

6. Sharing and Disclosure

We may share personal data with:

· Airlines

· Payment processors

· GDSs (Global Distribution Systems)

· Consolidators

· Government authorities (as required by law)

· Fraudprevention providers

· Service providers acting on our behalf

Cross-Border Transfers

International transfers may occur for ticketing, settlement, and regulatory compliance.
Where required, we implement safeguards such as:

· Standard Contractual Clauses

· Local legal mechanisms

· Industrystandard protections

 

7. Data Retention

We retain booking and transactional records for the period required by:

· Applicable laws

· Regulatory obligations

· Legitimate business needs (support, audit, dispute resolution)

Retention periods vary by jurisdiction and record type.

 

8. Security

We implement technical and organizational measures to protect personal data, including:

· Encryption in transit and at rest

· Tokenization for payment data

· Rolebased access controls

· Logging and monitoring

· Regular security audits


9. Your Rights

Depending on your jurisdiction, you may have the right to:

· Access your personal data

· Correct inaccurate data

· Delete your data

· Restrict processing

· Object to processing

· Request data portability

· Withdraw consent

Requests should be sent to the local data contact listed on our Contact page.
We will respond in accordance with applicable law.

 

10. Cookies and Tracking

We use cookies and similar technologies for:

· Essential site functions

· Analytics

· Marketing (where permitted)

A cookie banner and cookie settings page will be provided to allow optin/optout controls as required by law.

 

11. Children

Our Services are not directed to children under applicable minimum age requirements.
We do not knowingly collect personal data from children.
If we learn that such data has been collected, we will take steps to delete it.


12. Changes to This Policy

We may update this Privacy Policy from time to time.
We'll post material changes with a new effective date and, where required, notify users.