Privacy Policy
What personal data we collect across our websites, client portal and travel bookings, why, and your rights.
1. Who we are & scope
This Privacy Policy explains how we collect, use, share and protect personal data when you browse our Platforms, create a client account, request an estimate, submit a project, contact us, or book travel through PravaasiGo. It is published in accordance with the Information Technology Act, 2000, the IT (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 and the Digital Personal Data Protection Act, 2023 (“DPDP Act”). For the purposes of the DPDP Act, Codetrays IT Pvt Ltd is the Data Fiduciary.
2. Personal data we collect
Account data
- Examples
- Name, email, phone, company name, password (stored only as a salted bcrypt hash)
- Source / Platform
- Client portal registration & profile
Project data
- Examples
- Project title, description, budget, reference links, selected features, messages exchanged with our team, quotes and timelines
- Source / Platform
- Client portal → My Account
Enquiry data
- Examples
- Name, email, phone, service of interest, budget range, message
- Source / Platform
- Contact forms, WhatsApp, email, calls
Traveller & booking data
- Examples
- Traveller names, age/date of birth, gender, contact details, passport/ID details where legally required by an airline, hotel or authority, travel dates, preferences, special requests
- Source / Platform
- PravaasiGo (pravaasigo.com) bookings, quotes and enquiries
Payment data
- Examples
- Transaction ID, amount, status, payment method type. Card/UPI/bank credentials are entered on and processed by our payment gateway — we do not store them
- Source / Platform
- Checkout via Cashfree Payments
Partner program data
- Examples
- Date of birth, address, skills & portfolio links, PAN, GSTIN (optional), bank account number, IFSC and/or UPI ID, verification results. PAN and account numbers are encrypted at rest (AES-256-GCM).
- Source / Platform
- Partner onboarding in My Account
Store purchases
- Examples
- Template purchased, chosen option (source code or deployment), domain and business details you share for deployment
- Source / Platform
- Ready-made website store
Technical data
- Examples
- IP address (used for security & rate-limiting), browser/device type, pages visited, timestamps, error logs
- Source / Platform
- All Platforms, automatically
Cookies
- Examples
- Session and preference cookies — see our Cookie Policy
- Source / Platform
- All Platforms
| Category | Examples | Source / Platform |
|---|---|---|
| Account data | Name, email, phone, company name, password (stored only as a salted bcrypt hash) | Client portal registration & profile |
| Project data | Project title, description, budget, reference links, selected features, messages exchanged with our team, quotes and timelines | Client portal → My Account |
| Enquiry data | Name, email, phone, service of interest, budget range, message | Contact forms, WhatsApp, email, calls |
| Traveller & booking data | Traveller names, age/date of birth, gender, contact details, passport/ID details where legally required by an airline, hotel or authority, travel dates, preferences, special requests | PravaasiGo (pravaasigo.com) bookings, quotes and enquiries |
| Payment data | Transaction ID, amount, status, payment method type. Card/UPI/bank credentials are entered on and processed by our payment gateway — we do not store them | Checkout via Cashfree Payments |
| Partner program data | Date of birth, address, skills & portfolio links, PAN, GSTIN (optional), bank account number, IFSC and/or UPI ID, verification results. PAN and account numbers are encrypted at rest (AES-256-GCM). | Partner onboarding in My Account |
| Store purchases | Template purchased, chosen option (source code or deployment), domain and business details you share for deployment | Ready-made website store |
| Technical data | IP address (used for security & rate-limiting), browser/device type, pages visited, timestamps, error logs | All Platforms, automatically |
| Cookies | Session and preference cookies — see our Cookie Policy | All Platforms |
We do not knowingly collect sensitive personal data such as health information, biometric data or financial account passwords. Passport/ID numbers are collected only when a travel supplier or law requires them for a specific booking.
3. How we use your data
- To create and secure your account and authenticate you (encrypted session tokens).
- To generate instant estimates, prepare fixed quotes and timelines, and deliver and support the services you engage us for.
- To process PravaasiGo travel enquiries and bookings, issue tickets/vouchers and share necessary details with airlines, hotels, transport and tour operators.
- To respond to enquiries, send project updates, invoices, receipts and service communications.
- To process payments, refunds and prevent fraud through our payment partners.
- To keep our Platforms secure — abuse detection, rate limiting, logging and incident response.
- To improve our websites, services and AI-assisted delivery workflows using aggregated or de-identified information.
- To send marketing communications only where you have opted in; you can opt out at any time.
- To comply with legal, tax, accounting and regulatory obligations.
Our legal grounds are your consent, performance of a contract with you, and legitimate uses permitted under Section 7 of the DPDP Act (including compliance with law).
4. AI-assisted work
We use AI tools to accelerate design, development, testing and content creation. Client project information may be processed by such tools only to the extent needed to perform the work, under confidentiality, and is reviewed by our team. We do not use your confidential project data or traveller data to train publicly available AI models.
6. How we protect your data
- Encryption in transit (HTTPS/TLS) across all Platforms.
- Passwords stored only as salted bcrypt hashes; never in plain text.
- Signed, HTTP-only, SameSite session cookies; separate, shorter-lived sessions for administrators.
- Role-based access — clients only see their own projects; admin areas are restricted and excluded from search engines.
- Rate limiting and input validation on login, registration, enquiry and project submission endpoints.
- Server-side recalculation of prices; client-side values are never trusted.
- Least-privilege access for staff and periodic review of access and logs.
No system is 100% secure. If a personal data breach occurs, we will notify affected users and the Data Protection Board of India as required by law.
7. How long we keep data
Client account & project records
- Retention
- For the duration of the account and up to 3 years after the last engagement, then deleted or anonymised
Enquiries / leads that did not convert
- Retention
- Up to 24 months
Travel booking records & invoices
- Retention
- 8 years, as required for tax and accounting laws
Security & access logs
- Retention
- Up to 180 days, or longer where required by law
Marketing preferences
- Retention
- Until you withdraw consent
| Data | Retention |
|---|---|
| Client account & project records | For the duration of the account and up to 3 years after the last engagement, then deleted or anonymised |
| Enquiries / leads that did not convert | Up to 24 months |
| Travel booking records & invoices | 8 years, as required for tax and accounting laws |
| Security & access logs | Up to 180 days, or longer where required by law |
| Marketing preferences | Until you withdraw consent |
8. Your rights
- Access a summary of the personal data we process about you.
- Correct, complete or update inaccurate data (most profile data can be edited directly in My Account → Profile).
- Request erasure of data that is no longer needed, subject to legal retention requirements.
- Withdraw consent at any time (this does not affect processing already carried out).
- Nominate another person to exercise your rights in case of death or incapacity.
- Raise a grievance with us, and thereafter with the Data Protection Board of India.
Send requests to our privacy contact. We will verify your identity and respond within 30 days.
9. Children
Our Platforms are not directed at children under 18. We do not knowingly create accounts for them. Travel bookings for minors must be made by a parent or legal guardian, who provides verifiable consent for the minor’s data.
10. International transfers
Some of our service providers may store or process data outside India. Such transfers are made only to countries not restricted by the Government of India and with appropriate safeguards.
11. Third-party sites & embedded previews
Our case studies may display live previews of websites in an embedded frame and link to external sites. Those sites are governed by their own privacy policies and may set their own cookies when loaded.
12. Changes to this policy
We may update this Policy to reflect changes in our services or the law. The “Effective date” above shows the latest version; material changes will be notified on the Platforms or by email.
13. Contact & grievance officer
Grievance Officer:
- Grievance Officer: Designated officer of the Company
© 2026 Codetrays IT Private Limited. Code Trays and PravaasiGo are brands of Codetrays IT Pvt Ltd.