Roamaya ("we," "us," or "our") operates the website roamaya.inand associated mobile applications (the "Platform"). This Privacy Policy describes how we collect, use, disclose, and safeguard your information when you visit our Platform or use our services. By using the Platform, you consent to the data practices described in this policy.
1. Information We Collect
1.1 Information You Provide Directly
- Account Registration: Full name, email address, phone number (Indian mobile), password, and selected role (Traveler, Host, or Planner).
- Host/Planner Verification (KYC): Aadhaar number, PAN card number, Aadhaar document image, PAN document image, selfie photograph, Instagram username, website URL, bank account details (account holder name, account number, IFSC code, bank name, UPI ID).
- Booking Information: Full legal names of travelers, number of seats, selected trip dates, coupon codes applied.
- Payment Information: Payment transactions are processed through Razorpay. We store transaction references, payment status, and amounts. We do not store your full credit/debit card numbers or CVV.
- Cancellation & Refund Data: Bank account details (account holder name, account number, IFSC code, bank name) provided voluntarily for refund disbursement.
- Communications: Messages sent through our in-platform messaging system, support tickets, and any correspondence with our team.
- User-Generated Content: Trip reviews, ratings, profile bios, and uploaded images.
1.2 Information Collected Automatically
- Device & Browser Information: IP address, browser type, operating system, device type, screen resolution.
- Usage Data: Pages visited, time spent on pages, trip views, search queries, filters applied, booking funnel interactions.
- Cookies & Tracking Technologies: Authentication tokens (httpOnly cookies), session identifiers, Google Analytics tracking data. See our Cookie Policy for details.
- Location Data: Approximate geographic location inferred from IP address (we do not collect precise GPS data).
1.3 Information from Third Parties
- Google OAuth: When you sign in with Google, we receive your name, email address, and profile picture from Google.
- Razorpay: Payment confirmation status, transaction IDs, and payment method type (not full card details).
2. How We Use Your Information
- To create and manage your account and authenticate your identity.
- To process bookings, payments, and refunds.
- To verify Host and Planner identities (KYC compliance) and prevent fraud.
- To facilitate communication between Travelers and Hosts via our messaging system.
- To process Host payouts (commission calculation, TDS deduction, bank transfers).
- To send transactional notifications (booking confirmations, payment reminders, trip updates).
- To improve our Platform through analytics (trip recommendations, search optimization).
- To respond to support tickets and user inquiries.
- To enforce our Terms & Conditions and protect against misuse.
- To comply with legal obligations (tax reporting, regulatory requirements).
3. Legal Basis for Processing (India)
We process your personal data under the following legal bases as applicable under the Digital Personal Data Protection Act, 2023 (DPDP Act) and Information Technology Act, 2000:
- Consent: You provide consent at registration and when submitting KYC documents.
- Contract Performance: Processing necessary to fulfill booking and payment obligations.
- Legitimate Interest: Platform security, fraud prevention, and service improvement.
- Legal Obligation: Tax compliance (TDS deduction for Host payouts), regulatory reporting.
4. How We Share Your Information
We do not sell your personal data. We share information only in these circumstances:
- With Hosts/Planners: Booking details (traveler names, seats booked, contact for trip coordination) are shared with the respective Host or Planner for trip fulfillment.
- Payment Processors: Razorpay receives payment data necessary to process transactions.
- Cloud Infrastructure: Cloudinary (image storage), our hosting provider (for application data).
- Analytics: Google Analytics receives anonymized usage data.
- Legal Requirements: When required by law, court order, or government authority.
- Business Transfers: In the event of a merger, acquisition, or sale of assets, user data may be transferred to the successor entity.
5. Data Security
- All data transmission is encrypted via HTTPS/TLS.
- Authentication tokens are stored in httpOnly, Secure cookies with SameSite attributes.
- Passwords are hashed using industry-standard algorithms (never stored in plaintext).
- KYC documents are stored in access-controlled cloud storage.
- Role-based access control (RBAC) limits internal access to user data.
- Regular security audits and dependency vulnerability scans.
6. Data Retention
See our Data Storage & Retention Policy for detailed retention periods. In summary:
- Active account data: Retained while your account is active.
- Booking and transaction records: 8 years (tax and audit compliance).
- KYC documents: Retained during the Host/Planner's active period + 5 years post-deactivation.
- Support tickets: 3 years after resolution.
- Analytics data: Aggregated and anonymized after 26 months.
7. Your Rights
Under the DPDP Act 2023 and applicable laws, you have the right to:
- Access: Request a copy of the personal data we hold about you.
- Correction: Request correction of inaccurate or incomplete data.
- Erasure: Request deletion of your personal data (subject to legal retention requirements).
- Withdraw Consent: Withdraw previously given consent (may affect service availability).
- Grievance Redressal: Lodge a complaint with our Grievance Officer or the Data Protection Board of India.
- Nomination: Nominate an individual to exercise your data rights in case of death or incapacity.
8. Children's Privacy
Roamaya is not intended for individuals under 18 years of age. We do not knowingly collect personal data from minors. If we become aware that a user is under 18, we will promptly delete their account and associated data. If you believe a minor has provided us with personal data, please contact us immediately.
9. International Data Transfers
Your data is primarily stored on servers located in India. Some third-party services (Cloudinary, Google Analytics) may process data outside India. Where such transfers occur, we ensure appropriate safeguards are in place through contractual obligations with these service providers.
10. Grievance Officer
In accordance with the Information Technology Act, 2000 and DPDP Act, 2023:
- Name: Grievance Officer, Roamaya
- Email: roamayaofficial@gmail.com
- Response Time: Within 72 hours of receiving a complaint; resolution within 30 days.
11. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via email notification or a prominent notice on the Platform. Continued use after changes constitutes acceptance of the revised policy.