01Information We Collect
We collect information in three broad categories, depending on how you interact with our platform:
- Account & Partner data — name, email, phone, agency name, business address, tax/registration details, and login credentials when you register as a Partner or agent.
- Booking & traveler data — passenger names, passport/travel document numbers, dates of birth, contact details, frequent-flyer numbers, and itinerary details submitted through a booking flow, as required to issue a valid PNR through connected GDS systems.
- Technical & usage data — IP address, browser and device information, pages visited, search queries, and log data collected automatically as you use our sites and dashboards.
02How We Use Your Data
We use collected information to:
- Create and manage Partner, agent, and traveler accounts
- Process flight and hotel searches, quotes, and bookings, including issuing PNRs and e-tickets
- Process subscription billing and manage Partner plans
- Provide customer and technical support
- Send booking confirmations, itinerary changes, and essential service communications
- Monitor, secure, and improve platform performance and reliability
- Detect and prevent fraud, abuse, or violations of our Terms of Service
- Comply with legal, regulatory, and airline/GDS reporting obligations
03Booking & GDS Data Sharing
To search fares and issue tickets, booking details you submit are transmitted to the relevant Global Distribution System(s) connected to your Partner account, and from there to the operating airline(s) and any relevant government authorities (for example, Advance Passenger Information / API-PNR requirements on certain routes).
| GDS Partner | Purpose |
|---|---|
| Amadeus | Fare search, availability, PNR creation & ticketing |
| Sabre | Fare search, availability, PNR creation & ticketing |
| Galileo | Fare search, availability, PNR creation & ticketing |
Once data leaves our platform for GDS or airline processing, its handling is also subject to that GDS or airline's own privacy policy, over which we do not have direct control.
04Payments & Billing Data
Partner subscription payments and end-traveler booking payments are processed by third-party payment gateways, including Stripe, Razorpay, and PayPal, depending on your region and plan. We do not store full card numbers or CVV codes on our servers — these are handled directly by the payment processor under its own PCI-DSS compliant systems. We retain limited billing metadata (such as plan type, billing dates, and transaction status) needed to manage subscriptions and provide receipts.
05Cookies & Tracking
We use cookies and similar technologies to keep you logged in, remember search preferences, and understand how our sites are used. This may include:
- Essential cookies — required for login sessions and checkout flows
- Preference cookies — remember currency, language, and search filters
- Analytics cookies — help us understand aggregate site usage and performance
You can control or disable cookies through your browser settings, though some features may not work correctly without them.
06Third-Party Services
Beyond GDS and payment providers, we may share limited data with:
- Email and transactional messaging providers, to deliver confirmations and support replies
- Cloud hosting and infrastructure providers, to operate and secure our platform
- Analytics providers, in aggregated or anonymized form where possible
07Data Retention
We retain account and booking data for as long as your Partner account is active, and for a reasonable period afterward to comply with tax, accounting, and airline/GDS record-keeping requirements — typically up to 7 years for financial and booking records, unless a longer period is required by applicable law.
08Data Security
We apply industry-standard safeguards — including encryption in transit (HTTPS/TLS), access controls, and monitoring — to protect data against unauthorized access, alteration, or disclosure. No system is completely secure, and we cannot guarantee absolute security, but we work continuously to keep our platform and Partner sites protected.
09Your Rights & Choices
Depending on your location, you may have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate data
- Request deletion of your data, subject to legal/booking retention requirements
- Object to or restrict certain processing
- Request a copy of your data in a portable format
To exercise any of these rights, contact us using the details at the bottom of this page.
10Children's Privacy
Our platform is intended for use by travel agencies, their agents, and adult travelers. We do not knowingly collect personal data directly from children under 16 outside the context of a booked itinerary (e.g., a minor traveling with a parent/guardian), where such information is limited to what is required for ticketing.
11International Transfers
As a platform serving Partners across India, Southeast Asia, the Middle East, Europe, and beyond, your data may be processed and stored in countries other than your own, including wherever our hosting and GDS partners operate infrastructure. We take steps to ensure such transfers are subject to appropriate safeguards consistent with applicable data protection law.
12Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. We will post the updated version on this page with a revised "Last updated" date. Continued use of our platform after changes take effect constitutes acceptance of the revised policy.
13Contact Us
If you have questions about this Privacy Policy or how your data is handled, reach out to us:
Email us at diytravelportal@gmail.com or use our contact form — we typically reply within 24 hours.