Privacy at a Glance — What We Collect and Why
OnlyOnTrip collects only the information necessary to deliver our travel booking services. This includes your name, email address, mobile number, and payment details for processing bookings; travel documents (passport number, date of birth, nationality) required by airlines and immigration authorities; and usage data (pages visited, search queries, device type) used to improve the platform. We do not sell your personal data to third parties.
Data We Share and Why
- Airlines and hotels: Passenger and guest names, passport details, and contact information required to complete your booking.
- Payment processors: Razorpay receives transaction data to process payments securely. No card data is stored on OnlyOnTrip servers.
- Analytics providers: Aggregated, anonymised usage data to understand how users interact with the platform. No personally identifiable information is shared.
- Legal obligations: We may disclose data to Indian regulatory authorities (IRDA, RBI, DGCA) or law enforcement when required by law.
Your Rights Under DPDP Act 2023
Under India's Digital Personal Data Protection Act 2023, you have the right to access the personal data we hold about you, request correction of inaccurate information, withdraw consent for non-essential processing, and request erasure of your data subject to legal obligations. To exercise these rights, contact us at privacy@onlyontrip.com. We will respond within 30 days.
Cookies and Tracking
OnlyOnTrip uses essential cookies for session management and login security, analytical cookies (Google Analytics) to understand usage patterns, and marketing cookies for personalised flight and hotel recommendations. You can manage cookie preferences in your browser settings or via our Cookie Policy page. Disabling analytical cookies does not affect core booking functionality.
How We Protect Your Data
All data transmitted between your browser and OnlyOnTrip servers is encrypted using TLS 1.2 or higher. Our API servers are hosted in ISO 27001-certified data centres with restricted physical and network access. We conduct regular security audits and penetration tests. Payment card data is never stored on OnlyOnTrip servers — it is tokenised by Razorpay, which is PCI-DSS Level 1 certified. Employee access to personal data is restricted on a need-to-know basis and subject to confidentiality agreements.
Data Transfers Outside India
When you book international flights or hotels abroad, your booking details (passenger name, contact, passport number) are necessarily shared with foreign airlines, hotels, and ground operators. These transfers are required to fulfil the service you requested and are covered by your consent to the booking. For analytical data, Google Analytics servers may process data outside India. We rely on standard contractual clauses for such cross-border data transfers to ensure adequate protection.
Privacy Questions and Contact
For any privacy-related query — including subject access requests, data correction, consent withdrawal, or complaints — contact our Data Protection Officer at privacy@onlyontrip.com. We aim to respond within 7 days for general queries and within 30 days for formal data subject requests. If you are not satisfied with our response, you may file a complaint with the Data Protection Board of India under the Digital Personal Data Protection Act 2023.