1. Introduction and Scope
1.1 This Privacy Policy describes how Launzr Private Limited, having its registered office at 5th Floor, Section-A, B-Hub Maurya Lok, Dak Bunglow, Patna, Bihar, India (“Company”, “We”, “Us”, “Our”), operating the platform Why Not Trips (whynottrips.com) and its associated applications (the “Platform”), collects, uses, shares, and protects personal data belonging to Travelers and Organizers who use the Platform.
1.2 This Policy is framed with reference to the Digital Personal Data Protection Act, 2023 and the rules made thereunder, the Information Technology Act, 2000, and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, to the extent they continue to apply during the phased implementation of India's data protection framework.
1.3 This Policy applies to all personal data collected through the Platform, whether from Travelers, individual Organizers, or business Organizers (including the personnel and authorized signatories of business Organizers). It should be read together with our Terms and Conditions.
2. Key Terms
- "Data Fiduciary" means the entity that determines the purpose and means of processing personal data — in respect of this Policy, Launzr Private Limited.
- "Data Principal" means the individual to whom the personal data relates (i.e., a Traveler, an individual Organizer, or an authorized representative of a business Organizer).
- "Personal Data" means any data about an individual who is identifiable by or in relation to such data.
- "Processing" means any operation performed on personal data, including collection, storage, use, sharing, and deletion.
- "Consent" means the free, specific, informed, unconditional, and unambiguous indication of a Data Principal's agreement to the processing of their personal data for a specified purpose.
3. Data Fiduciary and Contact Details
Launzr Private Limited is the Data Fiduciary in respect of personal data processed through the Platform.
Registered Office: Launzr Private Limited, 5th Floor, Section-A, B-Hub Maurya Lok, Dak Bunglow, Patna, Bihar, India
Email: privacy@whynottrips.com
Grievance Officer / Data Protection Contact: Mr. Aditya Jha, reachable at grievance@whynottrips.com, Monday to Friday, 10:00 AM to 6:00 PM (IST).
4. Personal Data We Collect
4.1 From Travelers, we collect: full name; contact details (email address and phone number); demographic information voluntarily provided; payment-related information necessary to process a Booking (tokenized/processed by our Payment Gateway Partner(s) — we do not store full card numbers); Booking and Trip history; preferences and inputs submitted to the AI Trip Planner (such as destinations, travel dates, budget, interests, and group composition); device and usage data; location data, where permission is granted; and reviews, ratings, or feedback submitted on the Platform.
4.2 From Organizers, we collect: for individual Organizers, identity and address proof, PAN details, bank account details, and Aadhaar-based verification data (processed as described in Clause 7); for business Organizers, incorporation/registration documents corresponding to their business structure, PAN, GST registration details (where applicable), authorized signatory identification, and bank account details; Trip listing content; and any data an Organizer chooses to input into the complimentary CRM about its own customers or leads.
4.3 We automatically collect certain technical data through use of the Platform, including cookies and similar technologies, log data, device identifiers, IP addresses, and analytics regarding how the Platform is used, as further described in Clause 12.
5. How We Use Personal Data
- To create and administer Traveler and Organizer accounts.
- To process Bookings, payments, and refunds, and to facilitate the contract between Travelers and Organizers.
- To verify Organizer identity and business credentials and to prevent fraud, as described in Clause 7.
- To provide the Organizer dashboard, complimentary CRM, QR-based check-in, automated notifications, and payment tracking.
- To generate itinerary suggestions through the AI Trip Planner based on Traveler inputs.
- To provide customer support and respond to grievances.
- To comply with Applicable Law, including tax, accounting, and regulatory record-keeping obligations.
- To send Booking-related and, where consented to, marketing communications (with an option to opt out).
- To maintain the security, integrity, and performance of the Platform, and to improve our services.
6. Legal Basis for Processing
6.1 We process personal data primarily on the basis of the Data Principal's consent, given at the time of registration, Booking, or use of a specific feature (such as the AI Trip Planner or Aadhaar-based verification). Where applicable, we may also process personal data for the “legitimate uses” recognized under the Digital Personal Data Protection Act, 2023, such as where a Data Principal has voluntarily provided data for a specified purpose and has not indicated an objection, or where processing is necessary to comply with Applicable Law.
6.2 We note that India's Digital Personal Data Protection framework is being implemented in phases following notification of the Digital Personal Data Protection Rules, 2025, and we will continue to update our practices as further provisions (including those relating to Consent Managers) come into force.
7. Aadhaar Data — Special Handling
7.1 Where an individual Organizer's Aadhaar number is used for identity verification, this is done exclusively through OTP-based Aadhaar authentication, carried out by UIDAI-licensed Aadhaar Authentication User Agencies / KYC User Agencies (Aadhaar aggregators), and only after obtaining the Organizer's explicit, informed consent for this specific purpose.
7.2 We do not store an Organizer's full Aadhaar number on our own servers. We retain only a masked reference (such as the last four digits) together with the verification success/failure status or reference token returned to us by the licensed aggregator. This data is used solely to confirm identity verification and is not used for any other purpose.
7.3 This data is retained only for as long as the Organizer's account remains active, plus a limited period thereafter as may be required to meet statutory audit, recordkeeping, or dispute-resolution obligations, after which it is securely deleted in accordance with our data retention schedule (Clause 10).
9. Cross-Border Data Transfer
9.1 Personal data collected through the Platform is primarily hosted on servers located in India. Where a sub-processor (for example, a cloud infrastructure or AI technology provider) processes data outside India, such transfer is undertaken in a manner consistent with Section 16 of the Digital Personal Data Protection Act, 2023, which permits transfers except to countries specifically restricted by the Central Government, and is subject to appropriate contractual safeguards.
10. Data Retention
- Traveler account, Booking, and payment history: retained for as long as the account remains active, and for a further period of up to seven years after the last transaction, to meet accounting and tax record-keeping obligations under Applicable Law, after which it is deleted or anonymized.
- Organizer KYC and business verification documents: retained for the duration of the Organizer's active engagement with the Platform, and for a further period of up to eight years thereafter for statutory audit and record-keeping purposes.
- Aadhaar verification reference/token: retained as described in Clause 7.3.
- AI Trip Planner input logs: retained for up to twelve months for service improvement and support purposes, unless linked to an active Booking, after which they are anonymized or deleted.
- Marketing consent records: retained until the Data Principal withdraws consent.
Where a Data Principal requests deletion of their account, we will delete or anonymize personal data except where retention is required to comply with a legal obligation, resolve a dispute, or enforce our agreements.
11. Your Rights as a Data Principal
Subject to the Digital Personal Data Protection Act, 2023 and its phased implementation, you have the right to:
- Access a summary of the personal data we hold about you and the processing activities undertaken.
- Request correction, completion, or updating of your personal data.
- Request erasure of personal data that is no longer necessary for the purpose for which it was collected, subject to our legal retention obligations.
- Withdraw consent at any time, without affecting the lawfulness of processing carried out prior to withdrawal.
- Nominate another individual to exercise these rights on your behalf in the event of death or incapacity.
- Raise a grievance regarding the processing of your personal data through our grievance redressal mechanism.
To exercise any of these rights, please write to us at privacy@whynottrips.com. We will respond within the timelines prescribed under Applicable Law.
13. Data Security
13.1 We implement reasonable security practices and procedures, including encryption of data in transit and at rest, access controls, tokenization of payment data by our Payment Gateway Partner(s), and confidentiality obligations for personnel, in line with Section 43A of the Information Technology Act, 2000, the rules made thereunder, and Section 8(5) of the Digital Personal Data Protection Act, 2023. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
14. Data Breach Notification
14.1 In the event of a personal data breach, we will notify affected Data Principals and the Data Protection Board of India, as applicable and required under the Digital Personal Data Protection Act, 2023 and the rules made thereunder, without undue delay.
15. Children's Data
15.1 The Platform is intended for use by individuals who are at least 18 years of age. We do not knowingly collect personal data from individuals under 18. Any Booking for a minor traveling as part of a group must be made and consented to by an accompanying adult.
16. Third-Party Links and Integrations
16.1 The Platform may contain links to, or integrations with, third-party websites or services (including Organizer websites, Instagram, and payment gateway pages). This Policy does not apply to such third parties, and we encourage you to review their respective privacy policies.
17. Updates to this Privacy Policy
17.1 We may update this Policy from time to time to reflect changes in our practices or Applicable Law. Material changes will be notified through the Platform or by email, and continued use of the Platform after such notice constitutes acceptance of the revised Policy.
18. Contact Us
For questions or grievances regarding this Privacy Policy or our data practices, please contact:
Launzr Private Limited (operating Why Not Trips)
Email: privacy@whynottrips.com
Grievance Officer: Mr. Aditya Jha — grievance@whynottrips.com
Address: Launzr Private Limited, 5th Floor, Section-A, B-Hub Maurya Lok, Dak Bunglow, Patna, Bihar, India
