1. Introduction and Scope
ORVI Travel Pvt. Ltd. (CIN: [CIN Number], GSTIN: [GSTIN Number]) ("ORVI", "we", "us", "our") is committed to protecting the privacy of every user ("you", "your") who accesses or uses our website orvitravel.com, mobile applications, or any related services (collectively, "Platform").
This Privacy Policy describes how we collect, use, disclose, transfer, store, and protect your Personal Data as defined under the Digital Personal Data Protection Act, 2023 ("DPDPA") and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 under the IT Act, 2000.
This policy is governed by the laws of India. By using our Platform, you consent to the collection and use of information as described herein. If you do not agree, please discontinue use of the Platform.
2. Who We Are — Data Fiduciary
Under the DPDPA 2023, ORVI Travel Pvt. Ltd. acts as the Data Fiduciary — the entity that determines the purpose and means of processing your personal data.
| Detail | Information |
|---|---|
| Company Name | ORVI Travel Pvt. Ltd. |
| CIN | [CIN Number] |
| GSTIN | [GSTIN Number] |
| Registered Office | [Registered Office Address], India |
| Privacy Contact | legal@orvitravel.com |
| Phone | +91 98765 43210 |
3. Personal Data We Collect
3.1 Data You Provide to Us
- Identity data: Full name, date of birth, gender, passport number, photograph
- Contact data: Email address, mobile number, WhatsApp number, residential address
- Booking data: Travel dates, destinations, co-traveller details, dietary preferences, medical requirements disclosed for travel purposes
- Financial data: Payment method, partial card details (processed via PCI DSS-compliant gateways — we do not store full card details), bank account details for refunds
- Account data: Username, password (encrypted), booking history, wishlist
- Communication data: Emails, chat messages, call records with our support team
3.2 Data We Collect Automatically
- Device data: IP address, browser type, operating system, device identifiers
- Usage data: Pages visited, time spent, clicks, search queries, referral source
- Location data: Approximate location inferred from IP address (precise location only with explicit permission)
- Cookie data: As described in our Cookie Policy
3.3 Sensitive Personal Data (SPDI)
Under IT Rules 2011, the following Sensitive Personal Data or Information (SPDI) may be collected only with your explicit consent:
4. Legal Basis for Processing
Under the DPDPA 2023, we process your personal data on the following lawful bases:
| Purpose | Lawful Basis |
|---|---|
| Processing tour bookings and payments | Performance of contract |
| Sending booking confirmations and itineraries | Performance of contract |
| Marketing newsletters (with opt-in) | Consent |
| Fraud prevention and security | Legitimate interest / Legal obligation |
| Legal compliance (tax, RBI, IATA obligations) | Legal obligation |
| Improving our Platform and services | Legitimate interest |
| Processing visa applications on your behalf | Consent + Legal obligation |
5. How We Use Your Personal Data
- Confirm, manage and fulfil your travel bookings and payments
- Communicate booking updates, itinerary changes, and travel advisories
- Process visa applications, insurance policies, and travel documents on your behalf
- Send marketing communications (only if you have opted in; you may opt out at any time)
- Respond to customer service inquiries and grievances
- Detect fraud, unauthorised transactions, and enforce our Terms
- Comply with applicable laws — including FEMA, GST, RBI regulations, and IATA requirements
- Improve and personalise your experience on our Platform
- Conduct analytics, surveys, and research (in anonymised/aggregated form)
6. Sharing and Disclosure of Personal Data
We do not sell your personal data. We may share it with the following parties, only to the extent necessary:
6.1 Service Partners
- Hotels, resorts, airlines, transport providers, and activity operators (to fulfil your booking)
- Visa processing agents and government immigration authorities
- Travel insurance partners (ICICI Lombard and others)
6.2 Technology and Payment Partners
- Payment gateways: RazorpayX, Stripe, PayU (PCI DSS-compliant processors)
- Cloud hosting: AWS / Microsoft Azure (data stored in India-region servers)
- Analytics: Google Analytics (anonymised), Mixpanel
- Communication: Twilio, SendGrid (for SMS and email)
6.3 Legal and Regulatory
- Government authorities, courts, law enforcement when required by law
- IATA and tourism boards for certification and compliance purposes
- Auditors, legal counsel, and professional advisers under confidentiality obligations
Cross-border transfers: Where data is transferred outside India (e.g., to international hotel partners), we ensure adequate protections are in place through contractual safeguards consistent with DPDPA 2023 requirements and applicable Central Government notifications.
7. Your Rights as a Data Principal
Under the DPDPA 2023, you (as a "Data Principal") have the following rights:
| Right | What it means | How to exercise |
|---|---|---|
| Right to Access | Obtain a summary of your personal data we process | Email legal@orvitravel.com |
| Right to Correction | Correct inaccurate or incomplete personal data | Your account settings or email us |
| Right to Erasure | Request deletion of personal data (subject to legal retention requirements) | Email legal@orvitravel.com |
| Right to Grievance Redressal | File a complaint about processing of your data | See Section 12 below |
| Right to Nominate | Nominate a person to exercise rights on your behalf in case of death/incapacity | Email legal@orvitravel.com |
| Right to Withdraw Consent | Withdraw consent for non-essential processing at any time | Unsubscribe link or email us |
We will respond to all rights requests within 30 days as required under the DPDPA 2023.
8. Data Retention
We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by law:
| Data Category | Retention Period | Basis |
|---|---|---|
| Booking and transaction records | 8 years from transaction date | Income Tax Act, GST Act |
| Customer account data | 3 years after account closure | Consumer Protection Act |
| Visa and travel documents | 5 years | FEMA / Passport Act |
| Marketing consent records | Until consent withdrawn | DPDPA 2023 |
| Server logs and access records | 90 days | IT Act / CERT-In directives |
| Call recordings (support) | 90 days | Operational requirement |
9. Security of Your Personal Data
We implement reasonable security practices and procedures as required under Rule 8 of the IT (SPDI) Rules, 2011, including:
- Encryption: AES-256 encryption for data at rest; TLS 1.3 for data in transit
- Access controls: Role-based access; multi-factor authentication for internal systems
- Payment security: PCI DSS-compliant payment processing; we never store full card numbers
- Infrastructure: Hosted on ISO 27001-certified cloud infrastructure (India region)
- Incident response: We will notify you of any data breach affecting your personal data within the timeframes mandated by CERT-In and the DPDPA 2023
- Periodic audits: Annual security audits conducted by independent third parties
10. Children's Privacy
Our Platform is not directed at children below the age of 18 years. We do not knowingly collect personal data of minors. Where a booking includes a minor traveller, data is collected with explicit parental or guardian consent. If you believe we have inadvertently collected data of a child, please contact us at legal@orvitravel.com immediately for deletion.
11. Third-Party Websites
Our Platform may contain links to third-party websites (airlines, hotel booking engines, visa portals). We are not responsible for the privacy practices of those sites. We encourage you to read their privacy policies before providing any personal data.
12. Grievance Redressal
If you have any complaint or grievance regarding the processing of your personal data, you may contact our Grievance Officer:
Name: [Grievance Officer Name]
Email: grievance@orvitravel.com
Address: [Registered Office Address], India
Response time: We will acknowledge within 48 hours and resolve within 30 days.
If your grievance is not resolved satisfactorily, you may approach the Data Protection Board of India as established under the DPDPA 2023.
13. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in law, our practices, or our services. We will notify you of material changes via email or a prominent notice on our Platform at least 30 days before the changes take effect. Your continued use of the Platform after the effective date constitutes acceptance of the revised policy.