Legal

Privacy Policy

Last updated: 1 May 2026

This policy describes how THE GITCO Travel handles your personal data when you use our website, apps, and services. By using THE GITCO Travel you agree to the practices described here.

1. Who We Are

THE GITCO Travel ("THE GITCO", "we", "us") operates a B2B and consumer travel platform for hotel, flight, and allied travel bookings. This policy explains how we collect, use, store, and protect your personal data, and your rights under India's Digital Personal Data Protection Act, 2023 (DPDP Act).

2. Data We Collect

Account & contact data: name, email, phone, organisation, and role.

Booking data: traveller names, stay/travel dates, guest details, and special requests.

Payment data: transaction references and invoice details. Card and bank credentials are processed by our payment partners and are never stored by us.

Identity documents: where required by a hotel or by law, government ID is collected with your consent and shared only within a strict, time-limited access window.

Usage data: device, log, and interaction data used to operate and secure the service.

3. How We Use Your Data

To create and manage bookings, issue invoices, and provide customer support.

To meet legal, tax (GST/TCS), and regulatory obligations.

To detect and prevent fraud and to secure the platform.

With your separate, explicit consent, to send you offers, news, and personalised recommendations. You can withdraw marketing consent at any time without affecting service.

4. Consent & Your Rights (DPDP Act)

We process personal data on the basis of consent or a lawful purpose. You may access, correct, or request erasure of your data, withdraw consent, and nominate a representative, subject to legal retention requirements.

Identity documents shared with a hotel are accessible only during a limited window around check-in, are never exposed as public links, and every access is logged. Consent for this sharing is recorded and can be reviewed.

5. Sharing & Disclosure

We share data with suppliers (hotels, airlines, channel managers) strictly to fulfil your booking, with payment and communication processors, and with authorities where legally required. We do not sell your personal data.

6. Data Retention & Security

We retain personal data only as long as needed for the purposes above or as required by law, then delete or anonymise it. We apply technical and organisational safeguards including access controls, encryption in transit, and audit logging.

7. Grievance Officer

For any privacy request or complaint, contact our Grievance Officer at privacy@thegitco.com. We respond within the timelines prescribed under the DPDP Act.

Questions about your data? Contact privacy@thegitco.com.