Privacy Policy

Last updated: June 27, 2026 Version: 1.0
Applicable law: IT Act 2000 IT (Amendment) Act 2008 DPDP Act 2023

This Privacy Policy explains how GoINNga Technologies Pvt Ltd collects, uses, stores, and protects your personal and business data when you use the GoINNga platform. We are committed to transparent, lawful data handling under applicable Indian law.

Overview

GoINNga Technologies Pvt Ltd ("GoINNga", "we", "us") operates the GoINNga platform — a B2B travel SaaS for Indian travel agencies. In operating this platform, we process two distinct categories of data:

  • Account Data — Information about your agency and team members, for which GoINNga acts as a data controller.
  • Customer Data — Your clients' and leads' data that you input into GoINNga, for which you are the data controller and GoINNga acts as a data processor on your behalf.

This policy covers both categories. As a GoINNga customer, you are responsible for obtaining necessary consents from your own clients when entering their data into our platform.

1. What We Collect

Agency & Account Information

  • Agency name, registered address, city, state, country, pincode
  • GST registration number (GSTIN) and PAN
  • Agency email address and phone number
  • Unique agency code assigned on registration
  • Subscription plan and billing history
  • Branding assets (logo, brand colours) if uploaded

User Account Information

  • Full name, email address, phone number of each team member
  • Role and permission level within the agency
  • Hashed password (we never store plaintext passwords)
  • Login timestamps, IP address, and device/browser identifier at login
  • Session token (rotated on each login; invalidated on logout)

Business Data (Customer Data — processed on your behalf)

  • Travel lead and enquiry details (client name, contact, travel preferences, dates)
  • Quotations and itinerary components (hotels, transfers, activities, pricing)
  • Booking confirmations, passenger details, travel documents
  • Supplier records (hotel names, contacts, rates)
  • Sub-agent profiles and partner agency information

Usage & Technical Data

  • Pages visited, features used, and actions taken within the platform
  • API request logs (endpoint, timestamp, response code)
  • Error logs and diagnostic data
  • Device type, browser, and operating system

Payment Data

Payment card details and bank account information are handled exclusively by our authorised payment gateway partner. GoINNga does not store raw payment credentials. We receive and retain transaction references, amounts, and status for billing records.

2. How We Use It

We use the data we collect for the following purposes:

  • Service Delivery — To operate, maintain, and improve the GoINNga platform and deliver the features your subscription covers.
  • Account Management — To create and manage your agency account, process subscription payments, and issue GST-compliant invoices.
  • Authentication & Security — To verify identity, prevent unauthorised access, enforce single-session policies, and detect abuse.
  • Support — To respond to your support requests, investigate issues, and troubleshoot bugs.
  • Product Improvement — To analyse aggregate, anonymised usage patterns to improve platform features. We do not sell or share individual usage profiles.
  • Legal & Compliance — To comply with applicable Indian laws, respond to valid legal requests, and resolve disputes.
  • Communications — To send transactional emails (account activation, invoice, password reset) and, where you have opted in, product updates and feature announcements. You may opt out of marketing communications at any time.

3. Data Storage

All GoINNga data is stored on Amazon Web Services (AWS) infrastructure located in the ap-south-1 (Mumbai) region, ensuring your data remains within India's geographic boundaries.

We use the following AWS services for data storage and processing:

  • MongoDB (via managed MongoDB Atlas cluster in ap-south-1) for primary application data
  • AWS EC2 for application server compute (Mumbai region)
  • SSL/TLS encryption in transit (HTTPS enforced at all entry points)
  • Encryption at rest for database volumes

GoINNga does not transfer your data to servers outside of India without your explicit consent, except where required by law or for emergency maintenance operations conducted under strict access controls and documented justification.

4. Data Sharing

We do not sell, rent, or trade your personal data or Customer Data to any third party.

We share data only in the following limited circumstances:

  • Service Providers — With carefully vetted sub-processors (e.g., cloud hosting, payment gateway, email delivery) strictly to provide the Service. These providers are contractually prohibited from using your data for their own purposes.
  • Legal Requirements — Where required by Indian law, court order, or a legitimate request from a competent government authority. We will notify you of such requests where legally permitted to do so.
  • Business Transfers — In the event of a merger, acquisition, or sale of assets, we will notify you and ensure data protection obligations transfer to the acquiring entity.
  • Aggregated Analytics — We may share aggregated, anonymised, non-identifiable statistical data about platform usage with the public or partners. This data cannot be used to identify you or your clients.

5. Cookies & Tracking

GoINNga uses the following types of cookies and local storage mechanisms:

  • Essential Session Cookies — Used to maintain your authenticated session. These are strictly necessary and cannot be disabled without breaking the platform. They expire when you log out or the session times out.
  • Local Storage — We use browser localStorage to cache your portal context data (agency settings, navigation preferences) to improve load times. This data is scoped to your browser and never shared with third parties.
  • Analytics (Optional) — If you accept the cookie consent banner, we may collect anonymised usage analytics to improve the platform. You can withdraw consent at any time by clicking "Decline" or clearing your browser's localStorage.

We do not use third-party advertising cookies, cross-site trackers, or behavioural profiling tools. GoINNga does not integrate Facebook Pixel, Google Ads tags, or similar advertising technologies on the authenticated platform.

Your cookie preference is stored in localStorage under the key gn_cookie_consent and is respected on every page load.

6. Your Rights

Under the Digital Personal Data Protection Act, 2023 (DPDP Act) and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, you have the following rights:

  • Right to Access — Request a copy of the personal data we hold about you and your agency.
  • Right to Correction — Request correction of inaccurate or incomplete personal data. You can update most account data directly through your profile settings.
  • Right to Erasure — Request deletion of your personal data. Note that certain data must be retained for legal compliance (see Data Retention below).
  • Right to Data Portability — Request your Customer Data in a structured, commonly used, machine-readable format (CSV/JSON). Available via account settings or by request to support.
  • Right to Withdraw Consent — Where processing is based on consent (e.g., marketing emails, optional analytics), you may withdraw consent at any time without affecting prior processing.
  • Right to Grievance Redressal — File a complaint with our Data Protection Officer if you believe your data rights have been violated.

To exercise any of these rights, contact our DPO at privacy@goinnga.com. We will respond within 30 days. Complex requests may take up to 60 days, with notification of the extension.

7. Data Retention

We retain data for the following periods:

  • Active account data — Retained for the duration of your subscription plus 30 days after termination (to allow data export).
  • Financial records (invoices, payments) — Retained for 7 years from the date of transaction, as required under the Goods and Services Tax Act and the Companies Act, 2013, for audit purposes.
  • Login and security logs — Retained for 90 days for security investigation purposes.
  • Support communications — Retained for 2 years after resolution.
  • Anonymised analytics data — May be retained indefinitely as it contains no personal identifiers.

After the applicable retention period, data is permanently deleted from all GoINNga systems, including backups. Where deletion is technically constrained by backup rotation cycles, data is isolated and queued for deletion within the next scheduled cycle (maximum 30 days).

8. Security Measures

GoINNga implements reasonable technical and organisational security measures consistent with industry best practices and the requirements of the IT Act, 2000 and the SPDI Rules, 2011:

  • Encryption in Transit — All communications between your browser and GoINNga servers use TLS 1.2+ (HTTPS enforced, HTTP redirect to HTTPS at all entry points).
  • Encryption at Rest — Database volumes are encrypted at rest using AES-256.
  • Password Hashing — Passwords are hashed using bcrypt with a cost factor of 10. Plaintext passwords are never stored or logged.
  • Session Security — Cryptographically random session tokens (256-bit) are issued on login and rotated on each login, password change, and forced logout. A single active session is enforced per user account.
  • Bot & Abuse Protection — Rate limiting, IP reputation checks, and bot detection on all API endpoints.
  • Access Controls — Role-based access control (RBAC) with granular permissions. Super-admin access is restricted to named individuals with audit logging.
  • Audit Logging — Critical actions (logins, data exports, admin operations) are logged with timestamp and IP address.
  • Vulnerability Management — Regular dependency updates and periodic security reviews of the codebase.

In the event of a personal data breach that poses a risk to individuals, we will notify affected users and the relevant authority as required under applicable law.

10. Children's Data

The GoINNga platform is designed for business use and is not intended for individuals under 18 years of age. We do not knowingly collect personal data from minors. If you believe we have inadvertently collected data from a minor, please contact privacy@goinnga.com and we will delete it promptly.

Travel booking data for minor passengers (children listed on bookings) is Customer Data processed on your behalf as data controller. You are responsible for obtaining any required parental consent for such data.

11. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or Service features. The "Last updated" date at the top of this page indicates the most recent revision.

For material changes, we will notify registered users via email and an in-app notification at least 14 days before the changes take effect. Continued use of the Service after the effective date constitutes acceptance of the revised policy.

We recommend reviewing this policy periodically. Archived versions are available upon request from privacy@goinnga.com.

12. Contact — Data Protection Officer

For all privacy-related enquiries, data rights requests, or to report a data concern, contact our Data Protection Officer:

  • Email: privacy@goinnga.com
  • Company: GoINNga Technologies Pvt Ltd
  • Address: Bengaluru, Karnataka, India

You also have the right to lodge a complaint with the Data Protection Board of India once operational under the DPDP Act, 2023, if you believe your privacy rights have not been adequately addressed.