HumsafarSetu

Privacy policy

Effective 18 Aug 2026

HUMSAFARSETU PRIVACY POLICY Effective date: 18 August 2026 Last updated: 18 August 2026 1. SCOPE AND DATA ROLES This Privacy Policy explains how HumsafarSetu collects, uses, stores, shares and protects personal data when people visit humsafarsetu.com, request a demonstration, purchase or administer a subscription, use our applications or APIs, contact support, or otherwise interact with the HumsafarSetu service (“Service”). “HumsafarSetu”, “we”, “us” and “our” mean the person or entity identified as seller on the applicable order or invoice and operating the Service from Ahmedabad, Gujarat, India under the HumsafarSetu brand. Contact: support@humsafarsetu.com. For website visitors, prospects, account owners, billing contacts and direct support interactions, HumsafarSetu determines the purpose and means of processing and acts as the relevant data fiduciary/controller. Travel agencies and other subscribing organisations determine why and how they collect traveller, customer, employee and supplier data through their tenant. For that Customer Data, the subscribing organisation is ordinarily the primary data fiduciary/controller and HumsafarSetu processes the data to provide the contracted Service and follow lawful instructions. Individuals should usually direct requests about an agency’s Customer Data to that agency; we will reasonably assist the agency and respond directly where law requires. 2. DATA WE COLLECT Depending on how the Service is used, we may process: • Identity and contact data: name, business name, role, email, mobile number, postal address and support communications. • Account and authentication data: user identifiers, password hashes, role permissions, multifactor-authentication status, login history, device identifiers, access tokens and security events. We do not store plaintext account passwords. • Business and billing data: plan, order and subscription details, billing address, state, GSTIN, PAN where lawfully required, invoices, payment status, refunds and transaction references. • Payment data: gateway order and payment identifiers, status, amount, method category and fraud signals. Complete card numbers, CVV, UPI PINs and online-banking credentials are entered with regulated payment providers and are not ordinarily received by HumsafarSetu. • Agency Customer Data: customer and traveller identity and contact details, dates of birth, booking details, itineraries, tickets, hotel and transport information, invoices, support requests, uploaded documents and agency communications. • Potentially high-risk data entered by an agency: passport or government-ID documents, visa records, financial documents, health, accessibility or dietary information, information about children and emergency contacts. Agencies must collect only what is necessary and legally authorised. • Technical and usage data: IP address, browser, operating system, app version, device and installation identifiers, page or feature activity, timestamps, crash data, diagnostics, rate-limit events and audit logs. • Communications and integrations: messages and delivery status associated with configured email, WhatsApp, push-notification, Firebase or similar integrations. Third-party providers separately process data under their own terms. • Cookies and local storage: essential session, security, preference and consent records. We will obtain consent before using non-essential advertising or analytics cookies where required. We receive data directly from users, subscribing organisations and their authorised personnel; from travellers or customers using agency-facing applications; from configured integrations and payment providers; automatically from devices and logs; and from public or lawful business sources. 3. WHY WE PROCESS DATA We process personal data only for lawful purposes, including to: • create, authenticate, secure and administer accounts; • provide tenant isolation, travel workflows, customer applications, reports, invoices, exports, notifications and support; • process subscriptions, payments, tax records, refunds and accounting; • communicate service, security, billing and policy notices; • respond to enquiries, demonstration requests, complaints and rights requests; • detect fraud, abuse, malicious files, account compromise and violations; • monitor reliability, diagnose faults and improve features and usability; • comply with tax, accounting, corporate, consumer, data-protection, court and lawful government requirements; • establish, exercise or defend legal claims; and • send optional marketing only where permitted and subject to unsubscribe or withdrawal rights. Depending on the activity and applicable law, processing is based on consent, performance of a contract or requested pre-contract steps, compliance with law, specified legitimate uses recognised by applicable law, protection against fraud and security threats, or our and our customers’ legitimate business interests where those interests are not overridden by individual rights. Where consent is the basis, it may be withdrawn through the provided control or by contacting us. Withdrawal does not affect prior lawful processing and may make a requested feature unavailable. We do not make a person subject to a decision producing legal or similarly significant effects based solely on automated processing unless it is necessary, lawfully authorised and accompanied by required safeguards. 4. AGENCY RESPONSIBILITIES Subscribing agencies must provide their own accurate privacy notice, identify HumsafarSetu and relevant integrations where required, collect only necessary data, obtain valid consent or another lawful basis, configure access controls, honour individual rights, define retention periods, and avoid uploading data they are not authorised to process. An agency collecting children’s data must obtain verifiable consent from a parent or lawful guardian where required and must not use such data for tracking, behavioural monitoring or targeted advertising prohibited by law. HumsafarSetu is a business platform and is not offered directly for independent use by children under 18. 5. SHARING AND PROCESSORS We do not sell personal data. We may share limited data with: • the subscribing organisation and its authorised users; • infrastructure, hosting, storage, security, malware-scanning, support and software vendors; • payment gateways, banks, accounting and tax service providers; • email, SMS, WhatsApp, Firebase, push-notification, maps or other integrations enabled by the customer; • professional advisers, auditors and insurers under confidentiality duties; • a successor in a merger, financing, restructuring or transfer of the Service, subject to appropriate safeguards; and • courts, regulators, law enforcement or other persons where disclosure is legally required or reasonably necessary to protect rights, safety and security. Processors are authorised to use data only for contracted services and must provide appropriate confidentiality and security. The exact providers may change as the Service evolves. Third-party travel suppliers and services chosen independently by an agency are controlled by that agency and the third party, not by this Policy alone. 6. INTERNATIONAL PROCESSING Some service providers or integrations may process data outside the state or country where it was collected. We use contractual and technical safeguards and restrict transfers where applicable law or a government notification requires it. Agencies must ensure their configured integrations and travel operations satisfy any additional localisation or cross-border restrictions applicable to them. 7. RETENTION We retain personal data only for as long as reasonably necessary for the disclosed purpose, the subscription, security, dispute resolution and legal obligations. Retention depends on the data and context: • account, subscription, order, invoice and tax records are retained for the period required by applicable tax, accounting and limitation laws; • tenant Customer Data is retained during the subscription and for a limited post-termination export and recovery period, unless the agency requests earlier lawful deletion or a longer legal hold applies; • prospect and enquiry data is reviewed and deleted or anonymised when no longer needed for follow-up or legal records; • security, access and audit logs are retained for a proportionate period needed to investigate incidents, prevent abuse and demonstrate accountability; • support and legal communications are retained while the matter is active and for an appropriate limitation period; and • encrypted backups rotate on a controlled schedule, so deleted data may remain inaccessible in backups until overwritten and will not be restored except for disaster recovery. After retention ends, data is securely deleted or irreversibly anonymised, subject to technical limitations and legal requirements. Customers should export statutory business records before termination. 8. SECURITY We use safeguards appropriate to the nature and risk of data, including encrypted transport, password hashing, tenant and role controls, secure sessions, audit logging, protected storage, backups, security headers, restricted production access, dependency and vulnerability management, and incident-response procedures. Customers must use strong authentication, least-privilege roles, current devices and secure integrations. No internet or storage system is completely secure. If a personal-data breach occurs, we will investigate, contain and document it and notify affected customers, individuals and authorities where and within the time required by applicable law. Customers must promptly notify us of incidents involving their tenant. 9. INDIVIDUAL RIGHTS Subject to applicable law, an individual may request: • confirmation and information about personal data being processed; • access to a summary or copy of relevant personal data; • correction, completion or updating of inaccurate data; • erasure where retention is no longer necessary or legally required; • withdrawal of consent and cessation of optional marketing; • grievance redressal; • nomination of another individual to exercise rights in the event of death or incapacity, when that statutory right applies; and • information about significant processors or sharing where applicable. Send requests to support@humsafarsetu.com with the subject “Privacy Request”. We may verify identity, authority and tenant relationship and may ask the relevant agency to respond where it controls the data. We will acknowledge and resolve requests within the period required by applicable law and aim to respond within 30 days. We may retain or withhold data where required for legal obligations, another person’s rights, fraud prevention, security or legal claims and will explain the basis where permitted. Individuals should first use our grievance process. When the applicable provisions of the Digital Personal Data Protection Act, 2023 and Digital Personal Data Protection Rules, 2025 are in force for the relevant processing, eligible individuals may approach the Data Protection Board of India after exhausting available grievance redressal. Other statutory and consumer remedies remain available. 10. COMMUNICATIONS AND COOKIES Transactional messages about security, service, orders and accounts are necessary and cannot always be opted out of while an account remains active. Marketing messages include an unsubscribe method or may be stopped by emailing us. An agency is independently responsible for the legality of communications it sends to its customers through the Service. Essential cookies are used for login, session integrity, preferences, load protection and fraud prevention. If we introduce non-essential analytics or advertising technologies, we will provide the notices and consent choices required by law. Browser settings may block cookies but essential features may then fail. 11. CHANGES TO THIS POLICY We may update this Policy to reflect law, providers, security or Service changes. The updated effective date will be displayed. Material changes will be notified through the Service, website or registered email where reasonably practicable. We will request fresh consent if law requires it for a new purpose. 12. GRIEVANCE AND PRIVACY CONTACT Grievance and Privacy Officer HumsafarSetu Principal place of business: Ahmedabad, Gujarat, India Email: support@humsafarsetu.com Website: https://humsafarsetu.com Please include your name, relationship to the relevant agency, contact details, a clear description of the request and any relevant account or reference number. Do not email passwords, OTPs, full payment credentials or unnecessary identity documents. We aim to acknowledge grievances within 48 hours and resolve them within 30 days, subject to identity verification, complexity and any shorter mandatory period. This internal process does not restrict any non-waivable right to contact a regulator, Consumer Commission, court or law-enforcement authority.
← Back to HumsafarSetu