Skip to content
TripDrafts.
Legal · Data

Data Processing Policy

Last updated: June 2026DPDP Act 2023GDPR referenceData in Mumbai
Table of contents
01

Data controller

WhereTo Studios (operating TripDrafts) is the data controller for all personal data processed through the TripDrafts platform.

03

Data residency

All primary data - account information, quotes, uploaded files - is stored in our cloud infrastructure in the ap-south-1 region (Mumbai, India).

We do not transfer primary personal data outside India except as required by the sub-processors listed in Section 04. Where data is transferred outside India, we ensure appropriate safeguards are in place (standard contractual clauses or equivalent).

Enquiry text processed by our AI provider for AI parsing is transmitted to US servers for processing only and is not retained by our AI provider beyond the API call.

04

Sub-processors

We use the following sub-processors to deliver the TripDrafts service. Each is bound by a data processing agreement.

Sub-processorPurposeData processedLocation
Cloud database & storageDatabase, authentication, file storageAccount data, quotes, filesMumbai (ap-south-1)
Payment gatewayPayment processing, subscription managementPayment details, billing addressIndia
Email deliveryTransactional email deliveryEmail address, invoice dataUS (GDPR compliant)
PostHogProduct analyticsUsage events, session data (anonymized)EU/US (GDPR compliant)
Google AnalyticsWeb analyticsPage views, events (anonymized IP)Global (GDPR compliant)
AI providerAI enquiry parsingEnquiry text only - not retainedUS
Stock imagesDestination image suggestionsSearch queries onlyUS
Hosting & CDNApplication hosting and CDNRequest logs (IP, user agent)Global edge
SentryError tracking and diagnosticsError logs, stack tracesUS (GDPR compliant)

We will notify you of any material changes to this sub-processor list at least 14 days before they take effect.

05

Categories of personal data

  • Identity data: Full name, company name, username.
  • Contact data: Email address, phone number (optional), WhatsApp number (optional).
  • Financial data: Subscription plan, billing history. Payment card details are processed by our PCI-DSS compliant payment gateway and never stored by TripDrafts.
  • Professional data: IATA number, TAAI membership, years in business, specialisations - provided voluntarily during onboarding.
  • Client data: Names, phone numbers, email addresses, and travel preferences of your clients - entered by you. You are the data controller for your clients' data.
  • Usage data: Feature usage, session duration, click events - collected via our privacy-friendly analytics provider.
  • Technical data: IP address, browser type, device type - collected in server logs and error tracking.
06

Retention periods

Data categoryRetention periodBasis
Account and profile dataDuration of account + 30 days after deletionContract performance
Quote and client dataDuration of account + 30 days after deletionContract performance
GST invoices7 years from issue dateIncome Tax Act, 1961
Uploaded files (logos, images)Duration of account - deleted immediately on account deletionContract performance
Analytics data (PostHog, Google Analytics)12 monthsLegitimate interest
Error logs (Sentry)90 daysLegitimate interest
Payment records7 yearsLegal obligation
Enquiry text (AI parsing)Not retained beyond API callMinimal processing
07

Your rights

Under the DPDP Act 2023 (and GDPR for EU users), you have the following rights:

  • Right to access: Request a copy of the personal data we hold about you.
  • Right to correction: Request correction of inaccurate or incomplete data.
  • Right to erasure: Request deletion of your account and personal data (subject to legal retention obligations).
  • Right to data portability: Request your data in a machine-readable format.
  • Right to withdraw consent: Withdraw consent for analytics or marketing at any time.
  • Right to grievance redressal: Lodge a complaint with our grievance officer.
To exercise any right, email privacy@tripdrafts.com with your account email and the right you wish to exercise. We will respond within 30 days.
08

Security measures

  • All data encrypted in transit (TLS 1.2+) and at rest (AES-256 via our cloud database & storage provider).
  • Row-level security (RLS) enforced at the database layer - agents can only access their own data.
  • Authentication via our cloud database & storage provider with Google OAuth and email/password options.
  • API rate limiting via our rate-limiting service to prevent abuse.
  • CSRF protection on all state-changing API requests.
  • Regular security reviews and dependency audits.
09

Contact and grievance officer

  • Privacy and data requests: privacy@tripdrafts.com
  • Response time: Within 30 days of receipt
  • Company: WhereTo Studios · TripDrafts by WhereTo · India

TripDrafts by WhereTo · © 2026 WhereTo Studios