Data Processing Policy
Table of contents
Data controller
WhereTo Studios (operating TripDrafts) is the data controller for all personal data processed through the TripDrafts platform.
- Contact: privacy@tripdrafts.com
- Product: TripDrafts by WhereTo
- Jurisdiction: India
Legal basis for processing
We process personal data under the following legal bases as defined by the DPDP Act 2023:
- Contract performance: Processing your account data and quote data to provide the TripDrafts service you have subscribed to.
- Legitimate interest: Product analytics to understand usage patterns and improve the platform. We conduct a balancing test to ensure this does not override your rights.
- Legal obligation: GST invoice generation and retention for 7 years as required by the Income Tax Act, 1961.
- Consent: Marketing communications - opt-in only. You can withdraw consent at any time.
Data residency
We do not transfer primary personal data outside India except as required by the sub-processors listed in Section 04. Where data is transferred outside India, we ensure appropriate safeguards are in place (standard contractual clauses or equivalent).
Enquiry text processed by our AI provider for AI parsing is transmitted to US servers for processing only and is not retained by our AI provider beyond the API call.
Sub-processors
We use the following sub-processors to deliver the TripDrafts service. Each is bound by a data processing agreement.
| Sub-processor | Purpose | Data processed | Location |
|---|---|---|---|
| Cloud database & storage | Database, authentication, file storage | Account data, quotes, files | Mumbai (ap-south-1) |
| Payment gateway | Payment processing, subscription management | Payment details, billing address | India |
| Email delivery | Transactional email delivery | Email address, invoice data | US (GDPR compliant) |
| PostHog | Product analytics | Usage events, session data (anonymized) | EU/US (GDPR compliant) |
| Google Analytics | Web analytics | Page views, events (anonymized IP) | Global (GDPR compliant) |
| AI provider | AI enquiry parsing | Enquiry text only - not retained | US |
| Stock images | Destination image suggestions | Search queries only | US |
| Hosting & CDN | Application hosting and CDN | Request logs (IP, user agent) | Global edge |
| Sentry | Error tracking and diagnostics | Error logs, stack traces | US (GDPR compliant) |
We will notify you of any material changes to this sub-processor list at least 14 days before they take effect.
Categories of personal data
- Identity data: Full name, company name, username.
- Contact data: Email address, phone number (optional), WhatsApp number (optional).
- Financial data: Subscription plan, billing history. Payment card details are processed by our PCI-DSS compliant payment gateway and never stored by TripDrafts.
- Professional data: IATA number, TAAI membership, years in business, specialisations - provided voluntarily during onboarding.
- Client data: Names, phone numbers, email addresses, and travel preferences of your clients - entered by you. You are the data controller for your clients' data.
- Usage data: Feature usage, session duration, click events - collected via our privacy-friendly analytics provider.
- Technical data: IP address, browser type, device type - collected in server logs and error tracking.
Retention periods
| Data category | Retention period | Basis |
|---|---|---|
| Account and profile data | Duration of account + 30 days after deletion | Contract performance |
| Quote and client data | Duration of account + 30 days after deletion | Contract performance |
| GST invoices | 7 years from issue date | Income Tax Act, 1961 |
| Uploaded files (logos, images) | Duration of account - deleted immediately on account deletion | Contract performance |
| Analytics data (PostHog, Google Analytics) | 12 months | Legitimate interest |
| Error logs (Sentry) | 90 days | Legitimate interest |
| Payment records | 7 years | Legal obligation |
| Enquiry text (AI parsing) | Not retained beyond API call | Minimal processing |
Your rights
Under the DPDP Act 2023 (and GDPR for EU users), you have the following rights:
- Right to access: Request a copy of the personal data we hold about you.
- Right to correction: Request correction of inaccurate or incomplete data.
- Right to erasure: Request deletion of your account and personal data (subject to legal retention obligations).
- Right to data portability: Request your data in a machine-readable format.
- Right to withdraw consent: Withdraw consent for analytics or marketing at any time.
- Right to grievance redressal: Lodge a complaint with our grievance officer.
Security measures
- All data encrypted in transit (TLS 1.2+) and at rest (AES-256 via our cloud database & storage provider).
- Row-level security (RLS) enforced at the database layer - agents can only access their own data.
- Authentication via our cloud database & storage provider with Google OAuth and email/password options.
- API rate limiting via our rate-limiting service to prevent abuse.
- CSRF protection on all state-changing API requests.
- Regular security reviews and dependency audits.
Contact and grievance officer
- Privacy and data requests: privacy@tripdrafts.com
- Response time: Within 30 days of receipt
- Company: WhereTo Studios · TripDrafts by WhereTo · India