Data Protection Policy
Security
Data encrypted at rest (AES-256) and in transit (TLS 1.2+). RBAC and audit logs. Payment via PCI-DSS compliant Razorpay; no card data stored. Retention: account data lifetime plus 7 years; KYC per regulations; booking data 7 years; chat messages 1 year post-booking. Rights under DPDP Act 2023: access, correct, delete. Breach notification within 72 hours as required by law. Contact: helo@gotripbroker.com
For questions about this policy, contact
helo@gotripbroker.com
GoTripBroker / GoTripBroker · gotripbroker.com