Privacy Policy

How OnlyOnTrip collects, uses, shares and protects your personal data.

Last updated: 6 June 2026

Journey Express LLP ("we") respects your privacy and is committed to protecting the personal data you share with us when you use OnlyOnTrip. This Privacy Policy explains what we collect, how we use it, and the choices you have.

Information We Collect

  • Account data — name, email, phone, password hash.
  • Booking data — passenger / guest details, travel dates, passport information for international travel.
  • Payment data — handled by our PCI-DSS compliant gateway (Razorpay). We never store full card numbers or CVV.
  • Usage data — pages visited, search queries, device, IP address, cookies (see Cookie Policy).

How We Use Your Information

  • To process and fulfil your bookings.
  • To send booking confirmations, e-tickets and important trip updates.
  • To provide customer support.
  • To improve our products and detect fraud.
  • With your consent, to send promotional offers (which you can opt out of at any time).

Sharing of Data

We share the minimum data necessary with: airlines, hotels and other Service Providers to fulfil your booking; our payment processor for transactions; our SMS / email / WhatsApp partners for notifications; and regulators or law-enforcement where legally required.

Data Retention

Booking records are retained for the period required by Indian tax and aviation regulations (typically 7 years). Account data is retained while your account is active; you may request deletion at any time by writing to support@onlyontrip.com.

Your Rights

Under the Digital Personal Data Protection Act, 2023, you have the right to access, correct, and erase your personal data, withdraw consent, and lodge a grievance. To exercise these rights, contact our Grievance Officer at support@onlyontrip.com.

Security

We use HTTPS, encrypted storage of sensitive fields, and access controls to protect your data. No system is 100% secure — if you suspect any breach, please contact us immediately.

Changes to This Policy

We may update this policy from time to time. Material changes will be highlighted on the Platform and, where appropriate, communicated by email.

Privacy at a Glance — What We Collect and Why

OnlyOnTrip collects only the information necessary to deliver our travel booking services. This includes your name, email address, mobile number, and payment details for processing bookings; travel documents (passport number, date of birth, nationality) required by airlines and immigration authorities; and usage data (pages visited, search queries, device type) used to improve the platform. We do not sell your personal data to third parties.

Data We Share and Why

  • Airlines and hotels: Passenger and guest names, passport details, and contact information required to complete your booking.
  • Payment processors: Razorpay receives transaction data to process payments securely. No card data is stored on OnlyOnTrip servers.
  • Analytics providers: Aggregated, anonymised usage data to understand how users interact with the platform. No personally identifiable information is shared.
  • Legal obligations: We may disclose data to Indian regulatory authorities (IRDA, RBI, DGCA) or law enforcement when required by law.

Your Rights Under DPDP Act 2023

Under India's Digital Personal Data Protection Act 2023, you have the right to access the personal data we hold about you, request correction of inaccurate information, withdraw consent for non-essential processing, and request erasure of your data subject to legal obligations. To exercise these rights, contact us at privacy@onlyontrip.com. We will respond within 30 days.

Cookies and Tracking

OnlyOnTrip uses essential cookies for session management and login security, analytical cookies (Google Analytics) to understand usage patterns, and marketing cookies for personalised flight and hotel recommendations. You can manage cookie preferences in your browser settings or via our Cookie Policy page. Disabling analytical cookies does not affect core booking functionality.

How We Protect Your Data

All data transmitted between your browser and OnlyOnTrip servers is encrypted using TLS 1.2 or higher. Our API servers are hosted in ISO 27001-certified data centres with restricted physical and network access. We conduct regular security audits and penetration tests. Payment card data is never stored on OnlyOnTrip servers — it is tokenised by Razorpay, which is PCI-DSS Level 1 certified. Employee access to personal data is restricted on a need-to-know basis and subject to confidentiality agreements.

Data Transfers Outside India

When you book international flights or hotels abroad, your booking details (passenger name, contact, passport number) are necessarily shared with foreign airlines, hotels, and ground operators. These transfers are required to fulfil the service you requested and are covered by your consent to the booking. For analytical data, Google Analytics servers may process data outside India. We rely on standard contractual clauses for such cross-border data transfers to ensure adequate protection.

Privacy Questions and Contact

For any privacy-related query — including subject access requests, data correction, consent withdrawal, or complaints — contact our Data Protection Officer at privacy@onlyontrip.com. We aim to respond within 7 days for general queries and within 30 days for formal data subject requests. If you are not satisfied with our response, you may file a complaint with the Data Protection Board of India under the Digital Personal Data Protection Act 2023.