1. Introduction
This Privacy Policy explains how TravelPocket ("Company," "we," "us," or "our") collects, uses, discloses, and protects information in connection with the TravelPocket mobile application (the "App").
The App is a private, internal-use application developed exclusively for use by employees of TravelPocket and its authorized affiliates. It is not available to the general public, does not support customer bookings, and does not process any real financial transactions (no payments, refunds, or stored payment instruments are handled within the App).
By installing, accessing, or using the App, you (an authorized employee) agree to the terms of this Privacy Policy. If you do not agree, please do not use the App and contact your IT/HR administrator.
2. Scope
This Policy applies only to:
- Employees, contractors, and authorized personnel of TravelPocket who are issued credentials to use the App.
- Data processed within the App for internal travel coordination, itinerary management, booking requests routed to internal/approved vendors, expense pre-approval workflows, and related administrative functions.
This Policy does not apply to any public-facing website, customer booking platform, or third-party travel supplier systems operated separately by TravelPocket.
3. Information We Collect
3.1 Information You Provide
- Account/Identity Data: Full name, employee ID, work email address, department, designation, and work phone number.
- Travel-Related Data: Travel itineraries, destination preferences, dates of travel, purpose of trip, passport/ID number (if required for internal travel documentation), visa status, and emergency contact details.
- Communications: Messages, requests, approvals, or support queries submitted within the App.
3.2 Information Collected Automatically
- Device Information: Device model, operating system version, unique device identifiers, and mobile network information.
- Usage Data: App interaction logs, feature usage, crash reports, and diagnostic data.
- Log Data: IP address, access timestamps, and authentication logs for security purposes.
3.3 Information We Do NOT Collect
- We do not collect or store payment card details, bank account numbers, or any real transaction data, as the App does not facilitate actual payments or purchases.
- We do not access your personal contacts, photos, or files unless explicitly required and consented to for a specific internal function (e.g., attaching a document to a travel request).
4. How We Use Your Information
We use the information collected solely for legitimate internal business purposes, including to:
- Authenticate and manage employee accounts and access rights.
- Process and coordinate internal travel requests, approvals, and itineraries.
- Communicate updates regarding travel plans, approvals, or company travel policy.
- Maintain safety and duty-of-care records (e.g., knowing employee locations during business travel).
- Improve App performance, fix bugs, and enhance security.
- Comply with applicable labor, tax, audit, and legal record-keeping obligations.
- Investigate and prevent misuse, fraud, or unauthorized access.
We do not use employee data for advertising, marketing to third parties, or sale of personal data.
5. Legal Basis for Processing (Where Applicable)
Where required under applicable data protection laws (e.g., GDPR, India's DPDP Act, or similar), we process employee data based on:
- Performance of the employment contract / legitimate internal business operations.
- Compliance with legal obligations.
- Legitimate interests of the Company in managing safe and efficient business travel.
- Consent, where specifically required (e.g., optional location access).
6. Data Sharing and Disclosure
We do not sell, rent, or trade employee data. Information may be shared only in the following limited circumstances:
- Internal Teams: HR, Finance, Admin, and Travel Desk teams for approval and coordination purposes.
- Approved Vendors/Partners: Authorized travel service providers (e.g., hotels, airlines) strictly to fulfill booking arrangements on the Company's behalf — no payment data is shared, as transactions are settled outside the App through Company-managed corporate accounts.
- Service Providers: Cloud hosting, analytics, or IT support vendors bound by confidentiality and data protection agreements, acting only on our instructions.
- Legal Compliance: Where required by law, regulation, legal process, or governmental request.
- Corporate Transactions: In connection with a merger, acquisition, or restructuring, subject to continued confidentiality protections.
7. Data Storage and Security
- Data is stored on secure, access-controlled servers, which may include cloud infrastructure located in India.
- We implement industry-standard technical and organizational measures, including encryption in transit, role-based access controls, and regular security reviews, to protect data against unauthorized access, alteration, or loss.
- Access to the App is restricted to authorized employees via Company-issued credentials and, where applicable, single sign-on (SSO) or multi-factor authentication (MFA).
8. Data Retention
We retain employee data only for as long as necessary to fulfill the purposes outlined in this Policy, including:
- For the duration of your employment, plus a reasonable retention period thereafter for legal, tax, and audit purpose.
- Data is securely deleted or anonymized once retention periods expire, unless a longer period is required by law.
9. Your Rights
Subject to applicable law, you may have the right to:
- Access the personal data we hold about you.
- Request correction of inaccurate or incomplete data.
- Request deletion of data, subject to legal/employment record-keeping requirements.
- Withdraw consent for optional features (e.g., location access).
- Raise concerns or complaints regarding data handling.
To exercise these rights, contact us at info@travelpocket.in.
10. Children's Privacy
This Services do not address anyone under the age of 13. We do not knowingly collect personal identifiable information from children under 13. In the case we discover that a child under 13 has provided us with personal information, we immediately delete this from our servers. If you are a parent or guardian and you are aware that your child has provided us with personal information, please contact us so that we will be able to do necessary actions.
11. International Data Transfers
If data is transferred across borders (e.g., to cloud servers or vendors in other countries), we ensure appropriate safeguards are in place, such as standard contractual clauses or equivalent mechanisms, consistent with applicable data protection laws.
12. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. Material changes will be communicated to employees via the App, internal email, or Company intranet. Continued use of the App after such changes constitutes acceptance of the updated Policy.
13. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or your data, please contact: