1. Introduction
Welcome to Plan Out Trip ("we", "us", or "our"). We operate the travel booking and enquiry platform at planouttrip.com and any associated mobile applications or services (collectively, the "Platform"). Our registered address is Panjipara, Uttar Dinajpur, West Bengal, India.
This Privacy Policy explains what personal information we collect from you, why we collect it, how we use and share it, and the choices and rights you have over your information. We are committed to protecting your privacy in accordance with applicable Indian law.
By accessing or using our Platform, registering an account, or submitting an enquiry, you acknowledge that you have read, understood, and consent to the practices described in this Privacy Policy. If you do not agree, please discontinue use of our services immediately.
This policy is governed by the Information Technology Act, 2000, the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, and the emerging framework of India's Digital Personal Data Protection Act, 2023.
2. Information We Collect
We collect information in the following ways and categories:
2.1 Information You Provide Directly
- Account registration: Full name, email address, mobile number, and password (stored as a bcrypt hash)
- Profile details (optional): Address, city, state, country, pincode, date of birth, and gender
- Enquiry & booking forms: Destination preferences, travel dates, group size, dietary or accessibility requirements, and any special requests
- Communication: Messages, feedback, complaints, and reviews you submit through our contact, enquiry, or review forms
- Payment information: Payment is processed entirely by third-party PCI-DSS-compliant gateways. We do not receive or store your full card number, CVV, or net-banking credentials. We may store transaction reference numbers and payment status for our records
- Identity verification (if requested): Scanned copies of government-issued ID for specific tour types that require permit applications or entry clearances
2.2 Information Collected Automatically
- Device & browser data: IP address, browser type and version, operating system, screen resolution, device type, and unique device identifiers
- Usage data: Pages visited, time and duration of visits, referral URLs, links clicked, search queries entered on our Platform, and clickstream data
- Log data: Server logs including access time, error events, and security events (e.g. failed login attempts)
- Location data: General geographic location inferred from your IP address. We do not collect precise GPS location unless you explicitly grant permission
- Cookies and similar technologies: See Section 6 for details
2.3 Information from Third Parties
- Social login (if enabled): If you log in via Google or another social provider, we receive your name, email address, and profile picture from that provider per their data-sharing permissions
- Partners: Service providers (hotels, cab operators, activity vendors) may share booking-relevant information with us for the purpose of fulfilling your reservation
3. How We Use Your Data
We use the information we collect strictly for the following purposes:
- Service delivery: Processing tour, hotel, cab, and activity enquiries and confirmed bookings; coordinating with third-party service providers to fulfil your reservation
- Account management: Creating and maintaining your user account, authenticating your identity, and managing preferences
- Transactional communications: Sending booking confirmations, receipts, itineraries, e-tickets, pre-departure information, and travel updates by email and SMS
- Customer support: Responding to enquiries, complaints, and requests; providing post-trip assistance
- Marketing (with consent): Sending promotional emails, newsletter updates, special offers, and personalised recommendations. You may withdraw consent at any time
- Platform improvement: Analysing usage patterns to improve website functionality, user experience, content, and service offerings
- Security & fraud prevention: Detecting, investigating, and preventing fraudulent transactions, unauthorised access, and other illegal or harmful activities; maintaining security logs
- Legal compliance: Meeting obligations under applicable Indian laws, responding to lawful governmental requests, and exercising or defending legal claims
- Business analytics: Generating internal reports on enquiry trends, conversion rates, and operational performance (always in aggregate or anonymised form where possible)
We will never use your personal data for any purpose incompatible with those listed above without obtaining your explicit consent first.
4. Legal Basis for Processing
We process your personal data on the following legal grounds:
- Performance of a contract: Processing is necessary to fulfil your booking or enquiry, or to take pre-contractual steps at your request
- Consent: For marketing emails, newsletters, and optional data collection. You may withdraw consent at any time without affecting the lawfulness of processing already carried out
- Legitimate interests: For fraud prevention, security logging, and improving our platform, where these interests are not overridden by your data protection rights
- Legal obligation: Where processing is required to comply with applicable Indian laws, court orders, or regulatory requirements
5. Sharing Your Data
We do not sell, rent, or trade your personal data to any third party. We share it only in the following limited circumstances:
- Service fulfilment partners: Hotels, resort operators, cab/taxi vendors, activity providers, and tour guides — only the information necessary to complete your booking (name, contact number, dates, group size)
- Payment processors: Verified PCI-DSS-compliant payment gateways to process your transactions securely
- Email service providers: We use Brevo (formerly Sendinblue) and/or ZeptoMail (Zoho) to send transactional and marketing emails on our behalf. These processors are contractually bound to protect your data and not use it for their own marketing
- Analytics providers: Anonymised, aggregated usage data may be shared with analytics tools to help us understand site performance
- Legal and regulatory authorities: When required by law, court order, subpoena, or governmental authority in India; or to protect our legal rights and the safety of our users
- Business successors: In the event of a merger, acquisition, restructuring, or sale of all or part of our assets, your data may be transferred to the successor entity, with prior notice provided to you
- With your explicit consent: For any other purpose not listed above, we will seek your prior written or electronic consent
Third-party service providers who receive your data for booking fulfilment purposes have their own privacy policies governing how they handle your information. We encourage you to review those policies before your trip.
6. Cookies & Tracking Technologies
We use cookies (small text files stored on your browser) and similar technologies to enable certain features and improve your experience. Below is a summary of the cookies we use:
| Cookie Name / Type | Purpose | Duration |
|---|---|---|
POT_SESSION | Maintains your login session and authentication state | Session (deleted on browser close) |
| CSRF token cookie | Security: prevents cross-site request forgery attacks on forms | Session |
| Preference cookies | Remembers your language, currency, and UI preferences across visits | 30 days |
| Analytics cookies | Tracks page views, referral source, and user flow to help us improve the Platform (anonymised) | Up to 13 months |
| Marketing cookies (if opted in) | Enables personalised promotional content and remarketing | Up to 90 days |
You can manage or disable cookies at any time through your browser settings (typically under "Privacy" or "Security"). Please note that disabling essential cookies (such as POT_SESSION) will prevent you from logging in or submitting enquiries. Disabling analytics or marketing cookies will not affect core site functionality.
We do not currently use third-party advertising networks or retargeting pixels. If this changes, we will update this Policy and seek appropriate consent.
7. Data Security
We take the security of your personal information seriously and implement a layered set of technical and organisational measures:
- Encryption in transit: All data exchanged between your browser and our servers is encrypted using HTTPS/TLS (minimum TLS 1.2)
- Password security: User passwords are hashed using bcrypt with a cost factor of at least 10. Passwords are never stored, logged, or transmitted in plain text
- CSRF protection: All forms are protected by server-generated CSRF tokens that expire after each request
- Rate limiting: Login attempts, enquiry submissions, and sensitive API endpoints are rate-limited by IP address to prevent brute-force attacks
- Security logging: Failed login attempts, CSRF violations, and suspicious activity are logged to a secure, access-restricted log file for up to 12 months
- Access control: Admin panel access is restricted to authorised personnel only, with separate authentication and session management
- Input sanitisation: All user inputs are sanitised and validated server-side to prevent SQL injection and XSS attacks
- Minimal data principle: We collect only the data necessary for the purposes described in this Policy
No method of transmission over the internet or electronic storage is 100% secure. While we implement industry-standard safeguards, we cannot guarantee absolute security. In the event of a data breach that is likely to result in a high risk to your rights, we will notify you as required by applicable law. Please use a strong, unique password for your account and do not share it with anyone.
8. Your Rights
Under applicable Indian law, and as a matter of our policy, you have the following rights regarding your personal data:
- Right to access: Request a copy of the personal data we hold about you, including the categories of data, purposes of processing, and any third parties with whom we have shared it
- Right to correction: Request that we correct any inaccurate, incomplete, or outdated personal information. You can update most details directly from your Profile page
- Right to deletion ("right to be forgotten"): Request the deletion of your account and all associated personal data. We will action this within 7 working days, subject to any legal retention obligations
- Right to opt out of marketing: Unsubscribe from promotional emails at any time via the "Unsubscribe" link in any email, or by contacting us. Transactional emails (booking confirmations etc.) cannot be opted out of while an active booking exists
- Right to data portability: Request your personal data in a structured, machine-readable format (JSON or CSV)
- Right to restrict processing: Request that we limit how we use your data in certain circumstances (e.g. while a correction request is being resolved)
- Right to withdraw consent: Where processing is based on your consent, withdraw it at any time without affecting the lawfulness of prior processing
- Right to lodge a complaint: File a grievance with our Grievance Officer (see Section 13) or with the relevant Indian regulatory authority
To exercise any of these rights, please email us at admin@planouttrip.com from your registered email address with the subject line "Data Rights Request". We will respond within 30 days.
9. Data Retention
We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by applicable law:
- Active account data: Retained for the duration of your account. You may request deletion at any time
- Booking and transaction records: Retained for a minimum of 7 years as required for financial record-keeping and GST compliance under Indian tax law
- Enquiry data: Retained for 2 years after the last interaction, then anonymised or deleted
- Security and login logs: Retained for 12 months, then purged by our automated cron jobs
- Marketing consent records: Retained until consent is withdrawn plus 1 year for legal evidence purposes
- Deleted accounts: Upon account deletion, personal identifiers are removed within 7 working days; anonymised aggregate data (e.g. booking counts) may be retained for statistical purposes
10. International Data Transfers
Our primary infrastructure is hosted in India. However, some of our third-party service providers (such as email service providers) may process your data on servers located outside India. Where such transfers occur, we ensure that appropriate safeguards are in place, including contractual data processing agreements that require the recipient to protect your data to at least the standard required under Indian law.
By using our Platform, you consent to the transfer of your information to countries outside India for the purposes described in this Policy, subject to the safeguards described above.
11. Third-Party Links
Our Platform may contain links to third-party websites, including partner hotels, tour operators, activity vendors, and travel blogs. Clicking on such links will take you away from our Platform. We are not responsible for the privacy practices, content, or security of those external websites. We encourage you to review the privacy policy of each website you visit before providing any personal information.
The presence of a link on our Platform does not constitute an endorsement of the linked website's privacy practices.
12. Children's Privacy
Our Platform and services are intended for individuals who are 18 years of age or older. We do not knowingly solicit or collect personal information from children under the age of 18. If you are a parent or guardian and believe that your child has provided us with personal information without your consent, please contact us immediately at admin@planouttrip.com. We will promptly investigate and, if confirmed, delete the child's information from our records.
Where travel bookings include minors as travellers, the consenting adult making the booking is responsible for providing any necessary information about the child and for ensuring the child's participation is lawful and appropriate.
13. Grievance Officer
In accordance with the Information Technology Act, 2000 and the IT (Reasonable Security Practices) Rules, 2011, we have designated a Grievance Officer to address privacy-related concerns:
- Name: Grievance Officer, Plan Out Trip
- Email: admin@planouttrip.com
- Response time: We will acknowledge your grievance within 72 hours and resolve it within 30 days of receipt
If you are not satisfied with our response, you may approach the Adjudicating Officer appointed under the IT Act or file a complaint with the National Consumer Disputes Redressal Commission (NCDRC) under the Consumer Protection Act, 2019.
14. Changes to This Policy
We reserve the right to update or modify this Privacy Policy at any time. When we make material changes, we will:
- Update the "Last updated" date at the top of this page
- Send a notification email to all registered users at least 7 days before the changes take effect
- Display a prominent notice on our website homepage and login page
We encourage you to review this Policy periodically. Continued use of our Platform after the effective date of any update constitutes your acceptance of the revised Policy. If you do not agree to the updated Policy, please stop using our services and request account deletion.
15. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our data handling practices, please contact us through any of the following channels:
- Email: contact@planouttrip.com
We aim to respond to all privacy-related enquiries within 2 business days.