Privacy Policy
TravelnFlex Privacy Policy
This Privacy Policy explains how SIFAKA LABS LLP collects, uses, shares, stores, protects, and deletes personal data through the TravelnFlex marketplace, website, booking flow, support channels, and related services.
Legal entity: SIFAKA LABS LLP
Product / brand: TravelnFlex
LLPIN: ADB-6926
Address: Badri Kedar Enclave, Zero Point, Nakronda, Dehradun, Uttarakhand, India - 248001
Privacy and grievance contact: support@travelnflex.com
Grievance officer: Shwetanshu Bhatt, Chief Executive Officer
TravelnFlex is a B2C travel marketplace. Agencies publish packages and itineraries, customers book them, SIFAKA LABS LLP collects online payments through its approved payment account, and relevant booking information is shared with the agency and other service providers needed to deliver the booking.
This Policy should be read with the Customer Terms & Conditions, Refund & Cancellation Policy, Payment & Booking Confirmation Policy, and Cookie Policy / Consent Notice. It is intended to operate consistently with applicable Indian data-protection, consumer-protection, contract, tax, accounting, and information-technology requirements. Where a legal requirement differs from this Policy, the legal requirement controls.
1. Data controller and roles
For customer account, marketplace, booking, payment, support, security, and platform records, SIFAKA LABS LLP determines the purposes and principal means of processing and acts as the responsible platform entity.
Travel agencies, guides, hotels, transport providers, payment providers, email providers, hosting providers, analytics providers, and other vendors may process data for their own service delivery or on SIFAKA LABS LLP’s instructions, depending on the service and contract. The agency responsible for a package may also have its own legal responsibilities for data it receives and uses to deliver that package.
2. Personal data we collect
2.1 Account and identity data
- Name, email address, phone number, and account credentials
- Login and authentication information, including Google sign-in identifiers where Google sign-in is used
- Email-verification and account-security records
2.2 Traveller and profile data
- Traveller type, age group, gender, and location where supplied
- Pickup type, pickup state, city, address, pincode, and landmark
- Emergency-contact name and phone number
- Food preferences and medical notes where voluntarily supplied and relevant to safe or suitable travel planning
- Passport details for foreign travellers where required for booking or service delivery
- Identification type, masked identification number, and identification-document reference where the Platform requests it for a legitimate booking, verification, or compliance purpose
Customers should provide only information needed for the selected service. Do not enter full payment-card numbers, CVV, UPI PINs, passwords, or other payment secrets into a profile, support message, or booking form.
2.3 Booking and travel data
- Selected destination, package, itinerary, activities, date, package type, travellers, rooms, pickup details, and booking preferences
- Booking reference, pricing and cancellation-policy snapshot, confirmation status, payment status, balance information, agency, guide, hotel, vehicle, and departure-allocation information
- Booking communications, support requests, issue reports, cancellation requests, refund requests, reviews, ratings, and evidence submitted for those matters
Some booking information is copied into a booking snapshot so that the transaction can be confirmed, supported, reconciled, and reviewed consistently even if the customer later changes profile information.
2.4 Payment and refund data
- Payment amount, currency, payment method, provider order ID, provider payment ID, payment status, timestamps, and reconciliation records
- Refund amount, refund status, refund reason, provider refund reference, cancellation reference, and refund communications
- Direct agency-payment amount and evidence where an agency records a balance collected at or after pickup
SIFAKA LABS LLP does not intentionally store full card numbers, CVV, UPI PINs, or net-banking passwords. Razorpay and other payment providers process payment credentials under their own security and privacy terms.
2.5 Support and communication data
- Messages, email addresses, booking references, call or contact details, issue descriptions, attachments, screenshots, payment references, and support outcomes
- Communication preferences and delivery records for booking, payment, refund, safety, service, and support notifications
Support may route a request to an agency or service provider where that is necessary to investigate or deliver the booked service. Customers should avoid sending unnecessary sensitive information in ordinary support messages.
2.6 Technical, device, and usage data
- IP address, browser type, operating system, device or session identifiers, request timestamps, error records, and security logs
- Pages viewed, searches, filters, listing interactions, booking-flow events, referrer information, and approximate funnel session identifiers
- Cookie and local-storage values used for session continuity, analytics deduplication, security, preferences, and essential Platform functions
The customer funnel analytics endpoint may receive event names, page and referrer information, searches, filters, item or booking references, selected metadata, and a truncated user-agent value. Analytics are best-effort and should not receive payment credentials or unnecessary sensitive data.
2.7 Images and uploaded content
Profile images and other permitted media may be uploaded to Cloudinary or another configured media provider. Public listing images and agency content may be supplied by agencies or other rights holders and may contain information chosen by those providers.
3. How we use personal data
We use personal data only for purposes such as:
- creating, authenticating, securing, and maintaining accounts;
- displaying relevant packages and managing searches, favourites, and preferences;
- validating traveller and booking information;
- creating, confirming, changing, cancelling, supporting, and reconciling bookings;
- processing online payments, direct-payment records, refunds, receipts, invoices, chargebacks, and finance controls;
- sharing necessary information with the agency, guide, hotel, transport provider, or other provider responsible for delivery;
- responding to support, safety, activity, complaint, and grievance requests;
- detecting fraud, abuse, duplicate payment, security incidents, and policy violations;
- sending essential booking, payment, refund, service, and safety communications;
- measuring Platform performance and improving discovery, checkout, and customer experience;
- maintaining backups, logs, audit records, and operational continuity; and
- complying with law, lawful requests, contracts, accounting, tax, dispute, and regulatory obligations.
We do not sell or rent customer personal data. We do not use medical notes, emergency contacts, passport details, or identification data for advertising or unrelated profiling.
4. Grounds and consent
Depending on the processing activity and applicable law, we process personal data to provide or prepare for a booking contract, perform a requested service, comply with a legal obligation, protect the Platform and customers, respond to a support request, or act on consent where consent is required.
Where a feature requests optional information, the customer may decline it, but the selected package or support service may not be possible without information that is necessary for that service. Marketing consent, where used, is separate from essential booking and service communications.
5. Who receives personal data
We share only the data reasonably necessary for the relevant purpose with:
- the agency that publishes or fulfils the selected package;
- guides, hotels, transport providers, activity operators, and other suppliers needed to deliver the booking;
- Razorpay, banks, payment processors, and refund or reconciliation partners;
- email, SMS, WhatsApp, notification, customer-support, and communications providers where configured;
- hosting, database, backup, media-storage, security, monitoring, and infrastructure providers;
- analytics providers or internal analytics systems using the limited event data needed for measurement;
- professional advisors, insurers, auditors, or service providers where needed for operations or legal compliance; and
- courts, regulators, law-enforcement authorities, or other parties when disclosure is required or permitted by law.
Agencies and suppliers may receive customer name, contact, traveller, pickup, emergency, medical, identification, itinerary, and booking information only to the extent needed to deliver, support, secure, or reconcile the selected service. They must not use it to divert customers, send unrelated marketing without a lawful basis, or retain it longer than permitted by their obligations.
6. Payment providers and third-party services
Payment details are entered into the payment provider’s checkout and processed under that provider’s terms. TravelnFlex receives payment references and transaction status needed to confirm and reconcile the booking.
Google sign-in, Cloudinary media hosting, email delivery, analytics, hosting, database, security, and other integrated services may process data under their own terms and privacy policies. We select and configure such services for the Platform’s purposes, but a third party may process data in another jurisdiction where its infrastructure operates.
The Platform may contain links or integrations to third-party websites. Their privacy practices are governed by their own policies, not this Policy.
7. International processing and transfers
Some providers may store or process personal data outside India. Before enabling a provider for production data, SIFAKA LABS LLP should review its security, contractual protections, data-location requirements, subprocessors, deletion process, and applicable transfer obligations. Customers may contact support@travelnflex.com for a current provider-specific question.
8. Retention
We retain data only for as long as necessary for the purpose collected, including:
- active account operation, authentication, security, and customer support;
- booking delivery, cancellation, refund, payment, agency settlement, accounting, tax, audit, and dispute resolution;
- fraud prevention, security investigations, incident response, and enforcement; and
- backup, business-continuity, and legal or regulatory requirements.
When a customer requests account deletion, the current account lifecycle provides a 30-day reactivation period. After finalisation, identifying account and profile fields are removed or anonymised where the workflow supports it, while booking, payment, refund, invoice, audit, complaint, and legal records may be retained in restricted form for the periods required to reconcile transactions, resolve disputes, comply with law, or protect rights.
When retention is no longer required, data is securely deleted, anonymised, or aggregated. Deletion from one provider may take additional time where backups, legal holds, or provider retention controls apply.
9. Security
We use reasonable technical and organisational measures appropriate to the data and risk, including access controls, server-side authorization, authentication safeguards, payment-provider tokenisation or references, rate limiting, logging, transactional records, and restricted operational access.
No internet transmission or storage system is risk-free. Customers should use strong, unique credentials and contact support promptly if they suspect account misuse, payment fraud, or unauthorised disclosure. We will investigate and manage incidents under our security and incident-response procedures.
10. Customer rights and choices
Subject to applicable law and necessary exceptions, a customer may request:
- confirmation of whether we process their personal data and access to relevant information;
- correction or completion of inaccurate or outdated information;
- deletion or erasure where the data is no longer required or the law permits deletion;
- withdrawal of consent where processing is based on consent;
- restriction or objection where an applicable law provides that right;
- correction of a booking or profile record through the available account controls; and
- review or escalation of a privacy complaint.
To make a request, email support@travelnflex.com from the account email address where possible and include the request type, account email, booking reference if relevant, and enough information for us to verify identity. We may ask for reasonable verification and may retain information that must be kept for legal, payment, fraud, safety, accounting, tax, or dispute purposes.
Customers may unsubscribe from non-essential marketing communications. Essential account, booking, payment, refund, safety, and support communications cannot be disabled while the relevant service or issue is active.
11. Children
The Platform is intended for adults who can enter into a binding contract. A parent or lawful guardian must arrange any booking involving a person under 18 and should provide only the information necessary for that booking. We do not knowingly create independent customer accounts for children. If we learn that unnecessary child data was collected, contact support so it can be reviewed and deleted where legally permitted.
12. Grievance and complaints
Grievance officer: Shwetanshu Bhatt, Chief Executive Officer
Email: support@travelnflex.com
Address: Badri Kedar Enclave, Zero Point, Nakronda, Dehradun, Uttarakhand, India - 248001
For a privacy request or complaint, include the account email, booking reference if relevant, the data or processing concern, and the outcome requested. We will acknowledge and handle the request under our support and grievance process and applicable law.
13. Changes to this Policy
We may update this Policy when the Platform, vendors, booking model, data practices, or applicable law changes. The latest version and update date will be published on the Platform. If a change materially affects an existing service or requires consent, we will provide the notice or choice required by applicable law.
14. Contact and legal entity
SIFAKA LABS LLP
TravelnFlex marketplace
support@travelnflex.com
Badri Kedar Enclave, Zero Point, Nakronda, Dehradun, Uttarakhand, India - 248001
This Policy is a launch document and should be reviewed against the final production vendor list, retention schedule, consent implementation, and applicable professional privacy advice before publication.