Privacy Policy
This Privacy Policy explains how GoINNga Technologies Pvt Ltd collects, uses, stores, and protects your personal and business data when you use the GoINNga platform. We are committed to transparent, lawful data handling under applicable Indian law.
Overview
GoINNga Technologies Pvt Ltd ("GoINNga", "we", "us") operates the GoINNga platform — a B2B travel SaaS for Indian travel agencies. In operating this platform, we process two distinct categories of data:
- Account Data — Information about your agency and team members, for which GoINNga acts as a data controller.
- Customer Data — Your clients' and leads' data that you input into GoINNga, for which you are the data controller and GoINNga acts as a data processor on your behalf.
This policy covers both categories. As a GoINNga customer, you are responsible for obtaining necessary consents from your own clients when entering their data into our platform.
1. What We Collect
Agency & Account Information
- Agency name, registered address, city, state, country, pincode
- GST registration number (GSTIN) and PAN
- Agency email address and phone number
- Unique agency code assigned on registration
- Subscription plan and billing history
- Branding assets (logo, brand colours) if uploaded
User Account Information
- Full name, email address, phone number of each team member
- Role and permission level within the agency
- Hashed password (we never store plaintext passwords)
- Login timestamps, IP address, and device/browser identifier at login
- Session token (rotated on each login; invalidated on logout)
Business Data (Customer Data — processed on your behalf)
- Travel lead and enquiry details (client name, contact, travel preferences, dates)
- Quotations and itinerary components (hotels, transfers, activities, pricing)
- Booking confirmations, passenger details, travel documents
- Supplier records (hotel names, contacts, rates)
- Sub-agent profiles and partner agency information
Usage & Technical Data
- Pages visited, features used, and actions taken within the platform
- API request logs (endpoint, timestamp, response code)
- Error logs and diagnostic data
- Device type, browser, and operating system
Payment Data
Payment card details and bank account information are handled exclusively by our authorised payment gateway partner. GoINNga does not store raw payment credentials. We receive and retain transaction references, amounts, and status for billing records.
2. How We Use It
We use the data we collect for the following purposes:
- Service Delivery — To operate, maintain, and improve the GoINNga platform and deliver the features your subscription covers.
- Account Management — To create and manage your agency account, process subscription payments, and issue GST-compliant invoices.
- Authentication & Security — To verify identity, prevent unauthorised access, enforce single-session policies, and detect abuse.
- Support — To respond to your support requests, investigate issues, and troubleshoot bugs.
- Product Improvement — To analyse aggregate, anonymised usage patterns to improve platform features. We do not sell or share individual usage profiles.
- Legal & Compliance — To comply with applicable Indian laws, respond to valid legal requests, and resolve disputes.
- Communications — To send transactional emails (account activation, invoice, password reset) and, where you have opted in, product updates and feature announcements. You may opt out of marketing communications at any time.
3. Data Storage
All GoINNga data is stored on Amazon Web Services (AWS) infrastructure located in the ap-south-1 (Mumbai) region, ensuring your data remains within India's geographic boundaries.
We use the following AWS services for data storage and processing:
- MongoDB (via managed MongoDB Atlas cluster in ap-south-1) for primary application data
- AWS EC2 for application server compute (Mumbai region)
- SSL/TLS encryption in transit (HTTPS enforced at all entry points)
- Encryption at rest for database volumes
GoINNga does not transfer your data to servers outside of India without your explicit consent, except where required by law or for emergency maintenance operations conducted under strict access controls and documented justification.
4. Data Sharing
We do not sell, rent, or trade your personal data or Customer Data to any third party.
We share data only in the following limited circumstances:
- Service Providers — With carefully vetted sub-processors (e.g., cloud hosting, payment gateway, email delivery) strictly to provide the Service. These providers are contractually prohibited from using your data for their own purposes.
- Legal Requirements — Where required by Indian law, court order, or a legitimate request from a competent government authority. We will notify you of such requests where legally permitted to do so.
- Business Transfers — In the event of a merger, acquisition, or sale of assets, we will notify you and ensure data protection obligations transfer to the acquiring entity.
- Aggregated Analytics — We may share aggregated, anonymised, non-identifiable statistical data about platform usage with the public or partners. This data cannot be used to identify you or your clients.
6. Your Rights
Under the Digital Personal Data Protection Act, 2023 (DPDP Act) and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, you have the following rights:
- Right to Access — Request a copy of the personal data we hold about you and your agency.
- Right to Correction — Request correction of inaccurate or incomplete personal data. You can update most account data directly through your profile settings.
- Right to Erasure — Request deletion of your personal data. Note that certain data must be retained for legal compliance (see Data Retention below).
- Right to Data Portability — Request your Customer Data in a structured, commonly used, machine-readable format (CSV/JSON). Available via account settings or by request to support.
- Right to Withdraw Consent — Where processing is based on consent (e.g., marketing emails, optional analytics), you may withdraw consent at any time without affecting prior processing.
- Right to Grievance Redressal — File a complaint with our Data Protection Officer if you believe your data rights have been violated.
To exercise any of these rights, contact our DPO at privacy@goinnga.com. We will respond within 30 days. Complex requests may take up to 60 days, with notification of the extension.
7. Data Retention
We retain data for the following periods:
- Active account data — Retained for the duration of your subscription plus 30 days after termination (to allow data export).
- Financial records (invoices, payments) — Retained for 7 years from the date of transaction, as required under the Goods and Services Tax Act and the Companies Act, 2013, for audit purposes.
- Login and security logs — Retained for 90 days for security investigation purposes.
- Support communications — Retained for 2 years after resolution.
- Anonymised analytics data — May be retained indefinitely as it contains no personal identifiers.
After the applicable retention period, data is permanently deleted from all GoINNga systems, including backups. Where deletion is technically constrained by backup rotation cycles, data is isolated and queued for deletion within the next scheduled cycle (maximum 30 days).
8. Security Measures
GoINNga implements reasonable technical and organisational security measures consistent with industry best practices and the requirements of the IT Act, 2000 and the SPDI Rules, 2011:
- Encryption in Transit — All communications between your browser and GoINNga servers use TLS 1.2+ (HTTPS enforced, HTTP redirect to HTTPS at all entry points).
- Encryption at Rest — Database volumes are encrypted at rest using AES-256.
- Password Hashing — Passwords are hashed using bcrypt with a cost factor of 10. Plaintext passwords are never stored or logged.
- Session Security — Cryptographically random session tokens (256-bit) are issued on login and rotated on each login, password change, and forced logout. A single active session is enforced per user account.
- Bot & Abuse Protection — Rate limiting, IP reputation checks, and bot detection on all API endpoints.
- Access Controls — Role-based access control (RBAC) with granular permissions. Super-admin access is restricted to named individuals with audit logging.
- Audit Logging — Critical actions (logins, data exports, admin operations) are logged with timestamp and IP address.
- Vulnerability Management — Regular dependency updates and periodic security reviews of the codebase.
In the event of a personal data breach that poses a risk to individuals, we will notify affected users and the relevant authority as required under applicable law.
9. Legal Basis for Processing
Under the DPDP Act, 2023 and applicable rules, our legal basis for processing personal data is:
- Contractual Necessity — Processing your account data is necessary to provide the Service you have contracted for.
- Consent — For optional analytics, marketing communications, and cookie-based tracking, we rely on your explicit consent obtained at registration or through the cookie consent banner.
- Legal Obligation — Retention of financial records for GST compliance and response to valid legal requests.
- Legitimate Interests — Security logging, fraud prevention, and aggregate product analytics, where these interests are not overridden by your rights and freedoms.
10. Children's Data
The GoINNga platform is designed for business use and is not intended for individuals under 18 years of age. We do not knowingly collect personal data from minors. If you believe we have inadvertently collected data from a minor, please contact privacy@goinnga.com and we will delete it promptly.
Travel booking data for minor passengers (children listed on bookings) is Customer Data processed on your behalf as data controller. You are responsible for obtaining any required parental consent for such data.
11. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or Service features. The "Last updated" date at the top of this page indicates the most recent revision.
For material changes, we will notify registered users via email and an in-app notification at least 14 days before the changes take effect. Continued use of the Service after the effective date constitutes acceptance of the revised policy.
We recommend reviewing this policy periodically. Archived versions are available upon request from privacy@goinnga.com.
12. Contact — Data Protection Officer
For all privacy-related enquiries, data rights requests, or to report a data concern, contact our Data Protection Officer:
- Email: privacy@goinnga.com
- Company: GoINNga Technologies Pvt Ltd
- Address: Bengaluru, Karnataka, India
You also have the right to lodge a complaint with the Data Protection Board of India once operational under the DPDP Act, 2023, if you believe your privacy rights have not been adequately addressed.