Aerticket India – Privacy Policy
RAVIWO Aerticket Alliance India Private Limited (“Aerticket India”, “we”, “our”, or “us”) respects your privacy. This Privacy Policy explains how we collect, use, disclose, and protect personal information when you use our websites, mobile applications, APIs, platforms and related services (collectively, the “Services”). It also explains your choices and rights in relation to your personal information.
This Policy is intended for: (i) B2B users (e.g., travel agents, distributors, corporate travel managers and their staff); (ii) end customers whose bookings are processed through our platform by you or your travel provider; and (iii) visitors to our websites and apps.
If you are a corporate or travel agency using our Services on behalf of your customers, you are responsible for providing appropriate privacy notices to your customers and for obtaining all requisite permissions/consents to share their personal information with us to fulfill travel bookings.
Who we are and how to contact us
Data Fiduciary/Controller: Aerticket India Private Limited
Registered Office: MUMBAI
Email (general privacy queries): info@aerticket.in
Grievance Officer (India): +91 9967878700
Data Protection Officer: +91 9967878700
Scope
This Privacy Policy applies to personal information that we collect, generate or receive via the Services. It does not apply to third-party websites, applications, or services that are not under our control, even if accessed via the Services. Where you access third-party services (e.g., airline, hotel, rail, insurance, payment gateways), their privacy policies will apply.
Information we collect
We may collect and process the following categories of personal information. The examples are illustrative and may vary based on the booking and regulatory requirements of your destination:
- Identity details: title, name, date of birth/age, gender, nationality, photographs (e.g., for KYC where applicable), identification details (e.g., passport, visa, PAN as required), frequent-flyer/loyalty numbers.
- Contact details: postal address, email, phone numbers, emergency contact.
- Travel details: itineraries, PNR, ticket numbers, booking preferences, special requests (e.g., seat/meal preferences; accessibility assistance), travel history, co-traveller details.
- Government/official documentation: passport and visa information, known traveler ID, GST numbers (where applicable), other documents mandated by law or by travel suppliers (e.g., airlines/hotels) for ticketing and check-in.
- Payment and billing information: masked card information and limited payment instrument details, billing address, UPI/VPA (where applicable), transaction amounts and history.
- Account and usage data: usernames, log-in events, access times, device and browser information, IP address, app and website interactions, error logs, cookie identifiers and similar technologies (see Cookies below).
- Communications: queries, feedback, support tickets, call recordings (where permitted), emails/chats with us, and data you submit through forms or surveys.
- Job and corporate relationship data (B2B): agency or corporate name, employment role, authorization status, KYB/KYC documents, contract references.
- Sensitive data and special categories: In limited cases, we may process information that could be considered sensitive (e.g., health-related information for medical assistance, disability accommodations, or dietary preferences that may reveal religious beliefs). We only process such data where strictly necessary for your booking and as permitted by law and/or with your explicit consent.
- Children’s data: Our Services are not intended for minors without parental/guardian involvement. Where a booking involves a minor, information should be provided by a parent/guardian or an authorized adult.
How we collect personal information
- Directly from you when you create an account, request a quote, make a booking, communicate with us, or use our websites or apps.
- Through your organization or travel agent when they use our B2B platform to book on your behalf.
- From suppliers and partners (e.g., airlines, GDS/aggregators, hotels, rail, cruise, insurers, visa and immigration vendors, payment processors) to issue tickets, confirm reservations, or manage service disruptions.
- Automatically via cookies, SDKs and similar technologies when you browse or use the Services.
- From public/official sources and identity verification providers to comply with law, fraud prevention and security.
Purposes and legal grounds for processing
We process personal information for the purposes below and on the following legal grounds under applicable law (including the Digital Personal Data Protection Act, 2023 and allied rules, and IT Act/Intermediary and SPDI Rules, as applicable):
- Providing the Services – creating and managing accounts, facilitating searches, quotes, bookings, ticketing, itinerary changes/cancellations, check-in assistance, refunds, support, and service communications.
- Communicating with you – responding to queries, sending booking confirmations, travel alerts, disruptions, and service updates.
- Payments and fraud prevention – processing payments and refunds via secure gateways, preventing unauthorized transactions, chargebacks, misuse and security incidents.
- Compliance and public interest – KYC/KYB, tax/GST, accounting, audits, regulatory disclosures, law-enforcement requests, litigation, and risk management.
- Improving the Services and analytics – troubleshooting, product development, quality assurance, and aggregated/statistical analytics.
- Marketing and promotions – sending offers and travel content tailored to your preferences via email/SMS/app notifications; you may opt out at any time.
- Business operations – mergers, acquisitions, financing, or transfer of assets, subject to appropriate safeguards.
Cookies and similar technologies
We use cookies, pixels/SDKs and similar technologies to operate and improve the Services, remember preferences, keep you signed in, measure site/app performance, and personalize content. You can manage cookies via your browser or device settings. Certain cookies are essential; blocking them may impact functionality. See Annexure A – Cookie Notice for details and controls.
Disclosures of personal information
We share personal information only as described below, using appropriate contractual and organizational safeguards:
- Travel suppliers and enablers: airlines, GDS/aggregators, hotels, rail/cruise operators, car rental, activities/experiences providers, insurers, visa/immigration vendors and destination management companies, to issue and service bookings.
- Payment and fraud vendors: payment gateways, processors, banks, networks, fraud prevention and chargeback partners, and risk scoring vendors.
- Service providers (processors): IT hosting, cloud, customer support, analytics, communications, marketing (subject to your choices), document management and cybersecurity vendors.
- Group companies and business partners: where necessary to deliver cross-border inventory or integrated services, or to offer co-branded/partnered services you choose to use.
- Corporate clients and travel agencies (B2B): limited booking and reporting data for reconciliation, traveler tracking and duty-of-care, in accordance with our contract.
- Legal and compliance recipients: regulators, law enforcement, courts/tribunals, auditors, professional advisors, and as required to enforce our rights, protect users, or comply with law.
- Business transfers: in connection with reorganization, merger, acquisition or sale of assets, subject to continuity of protections under this Policy.
We do not sell personal data. We may share aggregated or de-identified information that does not identify you.
International data transfers
Because travel is inherently cross-border, personal information may be transferred to and processed in countries other than India (for example, where an airline, GDS, hotel, or cloud provider is located). Where required by law, we implement appropriate safeguards for such transfers, such as contractual protections and technical and organizational measures to protect the data.
Data retention
We retain personal information for as long as necessary to provide the Services, meet the purposes described in this Policy, and comply with our legal, accounting, tax, and regulatory obligations. Retention periods vary by data category, purpose, and applicable law. We may retain logs and de-identified/aggregated data for longer for security, analytics and product improvement.
Security
We implement reasonable technical and organizational measures designed to protect personal information, appropriate to the nature of the data and the risks of processing. These measures include access controls, encryption in transit and at rest where appropriate, network and application security, logging and monitoring, employee confidentiality obligations, and vendor due diligence. However, no system is entirely secure; please use strong passwords, enable multi-factor authentication where available, and notify us promptly of any suspected unauthorized access to your account.
Your choices and rights
Your rights will depend on applicable law. Subject to verification and legal exceptions, you may have the right to:
- Access personal information we hold about you;
- Correct/Update inaccurate or incomplete information;
- Delete/Erase information, where permitted;
- Withdraw consent at any time where processing is based on consent (this does not affect prior processing);
- Opt out of direct marketing communications;
- Grievance redressal by contacting our Grievance Officer; and
- Nominate an individual to exercise your rights on your behalf (where permitted by law).
We may ask you for information to verify your identity and authority to act. We will respond within timelines prescribed by law.
Communications and marketing preferences
We may send you service/transactional communications related to your bookings or account. For promotional emails/SMS/push notifications, you can opt out using the unsubscribe link or device settings, or by contacting us. Even if you opt out of marketing, we will continue to send essential service communications.
B2B accounts, corporate administrators and authorized users
If your account is provisioned by your employer or agency, your administrators may access, control, or terminate your access to the Services and view certain usage/booking data for reconciliation and duty-of-care purposes. Their own privacy notices and internal policies will govern how they use such information.
Third-party links and integrations
Our Services may include links to third-party sites, widgets, SDKs, and plugins (e.g., maps, chat tools, social sign-in). We do not control these third parties. Their privacy practices are governed by their own policies. Please review those policies before engaging.
Minors
The Services are not intended for independent use by individuals under the age of majority without involvement of a parent/guardian or a responsible adult traveler. We do not knowingly collect personal information from minors without appropriate authorization. If you believe a minor has provided personal information without proper authorization, please contact us and we will take appropriate steps.
Automated decision-making and profiling
We do not make decisions based solely on automated processing that have legal or similarly significant effects on individuals. We may use limited profiling to personalize content or offers; you can object to such use by contacting us.
Changes to this Privacy Policy
We may update this Policy from time to time. Material changes will be notified via the Services or by email (where feasible). The “Last Updated” date at the top of this Policy indicates when it was last revised. Your continued use of the Services after the effective date constitutes your acceptance of the revised Policy.
Annexure A – Cookie Notice
What are cookies? Cookies are small text files stored on your browser or device by websites/apps. They help websites remember you and your preferences and enable certain functionality.
Types of cookies we use
- Strictly necessary cookies – essential to operate the Services and enable secure log-in, search, and checkout.
- Functional cookies – remember choices such as language, currency, and recent searches.
- Performance/analytics cookies – help us understand usage and improve features and content.
- Advertising cookies/identifiers – used (with consent where required) to deliver relevant ads and measure campaign performance.
Managing cookies. Most browsers allow you to control cookies through settings. You can delete existing cookies and choose to block future cookies. Disabling certain cookies may limit site/app functionality. Mobile devices may include additional controls for app identifiers and push notifications.