1. Introduction and Scope

ORVI Travel Pvt. Ltd. (CIN: [CIN Number], GSTIN: [GSTIN Number]) ("ORVI", "we", "us", "our") is committed to protecting the privacy of every user ("you", "your") who accesses or uses our website orvitravel.com, mobile applications, or any related services (collectively, "Platform").

This Privacy Policy describes how we collect, use, disclose, transfer, store, and protect your Personal Data as defined under the Digital Personal Data Protection Act, 2023 ("DPDPA") and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 under the IT Act, 2000.

Governing Law

This policy is governed by the laws of India. By using our Platform, you consent to the collection and use of information as described herein. If you do not agree, please discontinue use of the Platform.

2. Who We Are — Data Fiduciary

Under the DPDPA 2023, ORVI Travel Pvt. Ltd. acts as the Data Fiduciary — the entity that determines the purpose and means of processing your personal data.

DetailInformation
Company NameORVI Travel Pvt. Ltd.
CIN[CIN Number]
GSTIN[GSTIN Number]
Registered Office[Registered Office Address], India
Privacy Contactlegal@orvitravel.com
Phone+91 98765 43210

3. Personal Data We Collect

3.1 Data You Provide to Us

  • Identity data: Full name, date of birth, gender, passport number, photograph
  • Contact data: Email address, mobile number, WhatsApp number, residential address
  • Booking data: Travel dates, destinations, co-traveller details, dietary preferences, medical requirements disclosed for travel purposes
  • Financial data: Payment method, partial card details (processed via PCI DSS-compliant gateways — we do not store full card details), bank account details for refunds
  • Account data: Username, password (encrypted), booking history, wishlist
  • Communication data: Emails, chat messages, call records with our support team

3.2 Data We Collect Automatically

  • Device data: IP address, browser type, operating system, device identifiers
  • Usage data: Pages visited, time spent, clicks, search queries, referral source
  • Location data: Approximate location inferred from IP address (precise location only with explicit permission)
  • Cookie data: As described in our Cookie Policy

3.3 Sensitive Personal Data (SPDI)

Under IT Rules 2011, the following Sensitive Personal Data or Information (SPDI) may be collected only with your explicit consent:

Health/Medical information (for accessibility needs) Financial information (payment processing) Biometric data (if applicable for visa processing)

4. Legal Basis for Processing

Under the DPDPA 2023, we process your personal data on the following lawful bases:

PurposeLawful Basis
Processing tour bookings and paymentsPerformance of contract
Sending booking confirmations and itinerariesPerformance of contract
Marketing newsletters (with opt-in)Consent
Fraud prevention and securityLegitimate interest / Legal obligation
Legal compliance (tax, RBI, IATA obligations)Legal obligation
Improving our Platform and servicesLegitimate interest
Processing visa applications on your behalfConsent + Legal obligation

5. How We Use Your Personal Data

  • Confirm, manage and fulfil your travel bookings and payments
  • Communicate booking updates, itinerary changes, and travel advisories
  • Process visa applications, insurance policies, and travel documents on your behalf
  • Send marketing communications (only if you have opted in; you may opt out at any time)
  • Respond to customer service inquiries and grievances
  • Detect fraud, unauthorised transactions, and enforce our Terms
  • Comply with applicable laws — including FEMA, GST, RBI regulations, and IATA requirements
  • Improve and personalise your experience on our Platform
  • Conduct analytics, surveys, and research (in anonymised/aggregated form)

6. Sharing and Disclosure of Personal Data

We do not sell your personal data. We may share it with the following parties, only to the extent necessary:

6.1 Service Partners

  • Hotels, resorts, airlines, transport providers, and activity operators (to fulfil your booking)
  • Visa processing agents and government immigration authorities
  • Travel insurance partners (ICICI Lombard and others)

6.2 Technology and Payment Partners

  • Payment gateways: RazorpayX, Stripe, PayU (PCI DSS-compliant processors)
  • Cloud hosting: AWS / Microsoft Azure (data stored in India-region servers)
  • Analytics: Google Analytics (anonymised), Mixpanel
  • Communication: Twilio, SendGrid (for SMS and email)

6.3 Legal and Regulatory

  • Government authorities, courts, law enforcement when required by law
  • IATA and tourism boards for certification and compliance purposes
  • Auditors, legal counsel, and professional advisers under confidentiality obligations

Cross-border transfers: Where data is transferred outside India (e.g., to international hotel partners), we ensure adequate protections are in place through contractual safeguards consistent with DPDPA 2023 requirements and applicable Central Government notifications.

7. Your Rights as a Data Principal

Under the DPDPA 2023, you (as a "Data Principal") have the following rights:

RightWhat it meansHow to exercise
Right to AccessObtain a summary of your personal data we processEmail legal@orvitravel.com
Right to CorrectionCorrect inaccurate or incomplete personal dataYour account settings or email us
Right to ErasureRequest deletion of personal data (subject to legal retention requirements)Email legal@orvitravel.com
Right to Grievance RedressalFile a complaint about processing of your dataSee Section 12 below
Right to NominateNominate a person to exercise rights on your behalf in case of death/incapacityEmail legal@orvitravel.com
Right to Withdraw ConsentWithdraw consent for non-essential processing at any timeUnsubscribe link or email us

We will respond to all rights requests within 30 days as required under the DPDPA 2023.

8. Data Retention

We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by law:

Data CategoryRetention PeriodBasis
Booking and transaction records8 years from transaction dateIncome Tax Act, GST Act
Customer account data3 years after account closureConsumer Protection Act
Visa and travel documents5 yearsFEMA / Passport Act
Marketing consent recordsUntil consent withdrawnDPDPA 2023
Server logs and access records90 daysIT Act / CERT-In directives
Call recordings (support)90 daysOperational requirement

9. Security of Your Personal Data

We implement reasonable security practices and procedures as required under Rule 8 of the IT (SPDI) Rules, 2011, including:

  • Encryption: AES-256 encryption for data at rest; TLS 1.3 for data in transit
  • Access controls: Role-based access; multi-factor authentication for internal systems
  • Payment security: PCI DSS-compliant payment processing; we never store full card numbers
  • Infrastructure: Hosted on ISO 27001-certified cloud infrastructure (India region)
  • Incident response: We will notify you of any data breach affecting your personal data within the timeframes mandated by CERT-In and the DPDPA 2023
  • Periodic audits: Annual security audits conducted by independent third parties

10. Children's Privacy

Our Platform is not directed at children below the age of 18 years. We do not knowingly collect personal data of minors. Where a booking includes a minor traveller, data is collected with explicit parental or guardian consent. If you believe we have inadvertently collected data of a child, please contact us at legal@orvitravel.com immediately for deletion.

11. Third-Party Websites

Our Platform may contain links to third-party websites (airlines, hotel booking engines, visa portals). We are not responsible for the privacy practices of those sites. We encourage you to read their privacy policies before providing any personal data.

12. Grievance Redressal

If you have any complaint or grievance regarding the processing of your personal data, you may contact our Grievance Officer:

Grievance Officer — ORVI Travel Pvt. Ltd.

Name: [Grievance Officer Name]
Email: grievance@orvitravel.com
Address: [Registered Office Address], India
Response time: We will acknowledge within 48 hours and resolve within 30 days.

If your grievance is not resolved satisfactorily, you may approach the Data Protection Board of India as established under the DPDPA 2023.

13. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in law, our practices, or our services. We will notify you of material changes via email or a prominent notice on our Platform at least 30 days before the changes take effect. Your continued use of the Platform after the effective date constitutes acceptance of the revised policy.