Travel CRM

Terms & Conditions Privacy Policy Back to Login

Privacy Policy

Travel CRM

This document is maintained by the platform administrator and applies to use of the Travel CRM SaaS platform.

Travel CRM — Privacy Policy

Effective Date: [Effective Date]
Last Updated: [Last Updated]

This Privacy Policy explains how [Legal Entity Name] (“Tejas Delta”, “we”, “us”, or “our”) collects, uses, stores, processes and protects information in connection with Travel CRM.

Travel CRM is primarily provided to travel agencies, travel operators and similar businesses (“Customer”, “Agency”, or “you”) for managing their business operations.

This Privacy Policy should be read together with our Terms & Conditions.


1. Our Role

Travel CRM is a software platform provided to businesses.

When an Agency uses Travel CRM to store information about its customers, travellers, employees or other individuals, the Agency is responsible for determining:

  • what information it collects;
  • why it collects that information;
  • whether it has the necessary legal basis, permission or consent;
  • how that information is used; and
  • whether the information may be shared with third parties.

Tejas Delta provides the technology used by the Agency to manage that information.

We generally process Customer Data on behalf of the Agency to provide, maintain, secure and support Travel CRM.

The Agency remains responsible for the traveller/customer information it enters into the platform and for complying with laws applicable to its collection and use of that information.


2. Information We Collect

Depending on how Travel CRM is used, we may process several categories of information.

A. Agency and account information

This may include:

  • agency/business name;
  • legal/business information;
  • business contact information;
  • business address;
  • email address;
  • telephone number;
  • subscription information;
  • plan and contract information;
  • account status; and
  • administrator information.

B. User and staff information

Where an Agency creates staff accounts, we may process:

  • name;
  • email address;
  • telephone number;
  • login credentials in securely protected form;
  • user roles;
  • permissions;
  • account status;
  • authentication information;
  • OTP/challenge information;
  • login and security events; and
  • actions performed through the account.

C. Traveller and customer information

Depending on the Agency's use of Travel CRM, Customer Data may include:

  • names;
  • contact information;
  • traveller profiles;
  • travel preferences;
  • booking information;
  • itinerary information;
  • flight/train/bus information;
  • hotel information;
  • vendor information;
  • payment-related records;
  • identification information;
  • passport information;
  • travel documents;
  • visa-related information;
  • photographs or other uploaded material; and
  • other information entered by the Agency.

The exact information processed depends on what the Agency chooses to enter into the platform.


3. Traveller Documents

Travel CRM may support the management of traveller documents.

Depending on the Agency's configuration, traveller documents may be stored through the Agency's connected Google Drive account.

The Agency is responsible for ensuring that it has the necessary authority and legal basis to upload and process those documents.

We do not determine the purpose for which the Agency collects traveller documents.


4. Subscription and Payment Information

When an Agency subscribes to Travel CRM, we may process information relating to:

  • selected subscription plan;
  • billing cycle;
  • subscription duration;
  • invoice information;
  • payment status;
  • payment records;
  • renewal information;
  • AutoPay authorization status;
  • payment-provider identifiers;
  • payment-related events; and
  • subscription lifecycle information.

Payments and recurring billing may be processed through Razorpay.

We do not intend to store complete card credentials such as full card numbers or CVV information as part of ordinary Travel CRM subscription processing.

Payment information may be processed directly by the applicable payment provider under its own privacy practices and security controls.


5. Google Login

Travel CRM may allow users to authenticate using Google.

If a user chooses Google authentication, we may receive information made available through the authorized Google authentication process, such as:

  • name;
  • email address;
  • Google account identifier; and
  • profile information permitted by the applicable authorization.

Google authentication is optional where alternative authentication methods are available.


6. Google Drive Integration

Travel CRM may provide an optional Google Drive integration.

When an Agency connects Google Drive, the Agency authorizes Travel CRM to access the Google Drive resources necessary for the enabled functionality.

Depending on the functionality used, this may include:

  • creating files or folders;
  • uploading files;
  • reading files;
  • updating files;
  • deleting files where the Agency requests an applicable operation; and
  • retrieving files required to display or manage supported CRM content.

The Agency's connected Google Drive remains the Agency's account.

We do not use a shared platform Google Drive for storing each Agency's traveller documents.

The Agency can control the Google account it connects and may revoke the applicable authorization through Google's account controls.

Some document functionality may not be available without a connected Google Drive account.


7. WhatsApp and Meta Integrations

Travel CRM may provide optional WhatsApp-related functionality through Meta/WhatsApp services.

Where an Agency uses such functionality, information may be transmitted to the applicable Meta/WhatsApp service in order to send or manage messages requested by the Agency.

The Agency is responsible for ensuring that its communications with travellers and customers comply with applicable laws, messaging requirements and applicable Meta/WhatsApp policies.

We are not responsible for WhatsApp or Meta service availability, delivery decisions, account restrictions, policy enforcement or outages.


8. Email Communications

Travel CRM may send transactional communications such as:

  • welcome emails;
  • temporary login credentials;
  • password-related communications;
  • OTPs;
  • security notifications;
  • subscription notifications;
  • billing notifications;
  • payment-related notifications;
  • account notifications; and
  • other service-related communications.

The email address associated with an account may therefore be used to deliver necessary service and security communications.

The specific third-party email delivery provider may vary based on the production configuration of Travel CRM.


9. How We Use Information

We may use information to:

Provide Travel CRM

Including to:

  • create and maintain accounts;
  • authenticate users;
  • provide CRM functionality;
  • store and retrieve Customer Data;
  • manage subscriptions;
  • process payments;
  • provide integrations;
  • send notifications;
  • provide customer support; and
  • perform requested operations.

Maintain security

We may use information to:

  • detect unauthorized access;
  • prevent abuse;
  • investigate security events;
  • enforce access controls;
  • protect accounts;
  • prevent fraud; and
  • maintain platform security.

Maintain and improve the service

We may use technical and operational information to:

  • troubleshoot problems;
  • monitor system health;
  • improve performance;
  • develop features;
  • diagnose errors; and
  • maintain reliability.

Comply with law

We may process or disclose information where reasonably necessary to:

  • comply with legal obligations;
  • respond to lawful requests;
  • enforce our agreements;
  • protect our rights;
  • protect users or third parties; or
  • investigate unlawful activity.

10. Customer Data Is Not Used to Run the Agency's Business

Tejas Delta does not become the travel operator merely because an Agency uses Travel CRM.

We do not use the Agency's traveller/customer information to:

  • operate the Agency's travel business;
  • sell travel services to those travellers;
  • independently manage the Agency's customers; or
  • assume responsibility for the Agency's customer relationships.

Customer Data is processed primarily to provide the Travel CRM service and for the purposes described in this Privacy Policy and the applicable agreement.


11. When We Share Information

We may share or provide access to information with service providers where reasonably necessary to operate Travel CRM.

Depending on the functionality used, these may include:

  • payment providers such as Razorpay;
  • Google services;
  • Google Drive;
  • Meta/WhatsApp;
  • email delivery providers;
  • hosting and infrastructure providers;
  • database/storage providers;
  • security and operational service providers; and
  • other technology providers required to provide enabled functionality.

We do not sell Customer Data as a product.

We do not permit third-party providers to use Customer Data for unrelated purposes merely because the data passes through their systems.

Third-party providers may independently process information under their own terms and privacy policies where applicable.


12. Agency Responsibility for Third-Party Integrations

When an Agency enables an integration, the Agency is responsible for:

  • deciding whether to enable it;
  • reviewing applicable third-party terms;
  • reviewing applicable third-party privacy policies;
  • providing required authorization;
  • maintaining the connected account;
  • ensuring it has authority to share the relevant information; and
  • managing the integration appropriately.

For example, when an Agency connects its Google Drive account, the Agency controls that Google account and the files stored within it.


13. Data Retention

We generally retain Customer Data while the Customer maintains an account or while retention is otherwise reasonably necessary for the provision of the service.

Cancellation does not automatically result in immediate deletion of Customer Data.

Customer Data may remain retained after cancellation or account inactivity so that:

  • the account can potentially be reactivated;
  • the Customer can return to the service;
  • historical records can be maintained;
  • legal or accounting obligations can be satisfied;
  • security records can be maintained; or
  • other legitimate operational purposes can be fulfilled.

An Agency may submit an official request for deletion.

Deletion requests may be subject to:

  • legal retention requirements;
  • accounting or financial obligations;
  • legitimate security requirements;
  • unresolved disputes;
  • backup retention; or
  • other circumstances where retention is legally or operationally necessary.

14. Account Reactivation

Because Travel CRM may retain account information after cancellation, an Agency may be able to return to the service and reactivate its account in accordance with applicable commercial and technical conditions.

Reactivation may require:

  • payment of applicable subscription charges;
  • acceptance of current commercial terms;
  • verification of account ownership; or
  • other reasonable requirements.

15. Security

We implement reasonable technical and organizational safeguards intended to protect information against unauthorized access, misuse, alteration, loss and disclosure.

Depending on the information and functionality involved, security measures may include:

  • authentication controls;
  • password hashing;
  • authorization and permission controls;
  • OTP verification;
  • encrypted network communication;
  • access restrictions;
  • audit/security records;
  • secure configuration;
  • database access controls; and
  • operational backups.

However, no internet-connected system can be guaranteed to be completely secure.

The Agency is responsible for maintaining appropriate security on its own side, including protecting:

  • passwords;
  • email accounts;
  • Google accounts;
  • payment accounts;
  • employee devices;
  • connected third-party accounts; and
  • other credentials.

16. Backups

We may maintain backups of platform and Customer Data for operational, maintenance, security and recovery purposes.

Backups are not intended to create a permanent archival service for Customers.

We do not guarantee that every deleted, corrupted or unavailable item can always be recovered.

Customers should maintain independent copies of information that is critical to their business.


17. Cookies and Technical Information

Travel CRM may use cookies, sessions and similar technical mechanisms necessary to:

  • authenticate users;
  • maintain login sessions;
  • protect accounts;
  • remember appropriate settings;
  • maintain application functionality;
  • prevent security issues; and
  • understand basic technical operation of the application.

We may also collect technical information such as:

  • IP address;
  • browser type;
  • device information;
  • operating system;
  • login timestamps;
  • security events;
  • application activity;
  • error information; and
  • other technical information generated through normal use of the service.

This information is primarily used for operation, security, troubleshooting and service improvement.


18. Authentication and Security Challenges

Travel CRM may use authentication challenges such as one-time passwords for certain security-sensitive operations.

For example, a one-time email OTP may be required when an administrator is required to verify an initial mandatory password change.

OTP information may be:

  • generated;
  • securely stored in protected form;
  • subject to expiration;
  • limited by attempt controls; and
  • invalidated after successful use.

OTP information is used for authentication/security purposes and is not intended to be used as ordinary Customer Data.


19. Children's Information

Travel CRM is a business software platform intended for use by travel agencies and travel operators.

The platform is not directed toward children as individual account holders.

However, an Agency may enter information relating to a child traveller as part of a legitimate travel booking.

Where this occurs, the Agency is responsible for ensuring that it has the appropriate legal authority and permissions required to collect and process that information.


20. International and Third-Party Processing

Travel CRM may rely on infrastructure and third-party providers whose systems may be located in India or other jurisdictions.

Where information is processed through such providers, we take reasonable steps appropriate to the service and applicable legal requirements.

Third-party providers may also apply their own security, privacy and data-processing practices.


21. Data Deletion Requests

An Agency may request deletion of its account or Customer Data by contacting us through the official privacy/contact channel.

We may request sufficient information to verify the identity and authority of the requester.

Deletion may not be immediate where information must be retained for:

  • legal compliance;
  • financial records;
  • fraud/security prevention;
  • dispute resolution;
  • contractual obligations;
  • backup purposes; or
  • other legally permitted purposes.

Once applicable retention requirements have expired, information may be deleted, anonymized or otherwise disposed of through reasonable processes.


22. Data Access and Correction

Where technically and legally appropriate, Customers may request access to or correction of information associated with their account.

Customers should first use the available Travel CRM functionality to correct information that they control directly.

Where information cannot be corrected through the application, the Customer may contact us through the official support/privacy channel.


23. Security Incidents

If we become aware of a security incident affecting Customer Data, we will assess the incident and take reasonable steps appropriate to the circumstances, including investigation, containment, remediation and notification where required by applicable law.

The nature and timing of any notification may depend on:

  • the nature of the incident;
  • the information affected;
  • applicable legal requirements;
  • the scope of the incident; and
  • whether notification would interfere with legitimate investigation or security measures.

24. Third-Party Websites and Services

Travel CRM may provide links or integrations to third-party services.

Those third-party services are not controlled by Tejas Delta.

Their privacy practices are governed by their own policies.

We recommend that Customers review the applicable third-party privacy terms before enabling or using such services.


25. Google Services

Where Google services are used, including Google Login and Google Drive, Google's own privacy practices and terms may apply.

The Customer is responsible for reviewing Google's applicable policies and managing the permissions it grants to Travel CRM.

Travel CRM only requests and uses the Google access required for the applicable functionality.


26. Razorpay

Where Razorpay is used for Travel CRM subscriptions and payments, Razorpay may process payment-related information under its own privacy and security practices.

Travel CRM may receive information necessary to:

  • identify a payment;
  • confirm payment status;
  • manage subscription state;
  • reconcile payments;
  • process refunds where applicable;
  • manage recurring authorization; and
  • maintain billing records.

Travel CRM does not control Razorpay's internal payment-processing systems.


27. Meta and WhatsApp

Where Meta/WhatsApp functionality is enabled, information required to deliver the Customer's requested communication may be processed through Meta/WhatsApp infrastructure.

The Agency is responsible for ensuring that communications are lawful and appropriately authorized.

Meta/WhatsApp may independently apply its own policies and processing practices.


28. Email Service Providers

Travel CRM uses an email delivery mechanism to send transactional communications.

Depending on the production configuration, the applicable email provider may process information such as:

  • recipient email address;
  • sender information;
  • message content;
  • delivery information;
  • bounce information; and
  • security-related information.

The exact provider may change as infrastructure evolves.


29. No Sale of Customer Data

We do not sell Customer Data as a commercial data product.

We do not provide traveller/customer databases to unrelated third parties for their own marketing purposes merely because the information is processed through Travel CRM.

Information may nevertheless be shared with authorized service providers where required to operate the platform, provide requested functionality, comply with law, or protect legitimate rights and interests.


30. Confidentiality

We treat Customer Data as confidential business information except where disclosure is:

  • authorized by the Customer;
  • necessary to provide the service;
  • required by law;
  • necessary to protect security;
  • necessary to enforce our agreements; or
  • otherwise permitted by this Privacy Policy or applicable law.

31. Changes to This Privacy Policy

We may update this Privacy Policy when:

  • Travel CRM functionality changes;
  • integrations change;
  • legal requirements change;
  • our processing practices change;
  • security practices change; or
  • other legitimate business requirements arise.

The updated version will be published through the applicable website or Travel CRM interface.

The Effective Date and Last Updated dates will identify the current version.

Where legally required, we may provide additional notice or obtain additional consent for material changes.


32. Contact and Privacy Requests

For privacy questions, data requests, deletion requests or concerns regarding the processing of information, Customers may contact:

[Legal Entity Name]
Address: [From Super Admin Settings]
Privacy / Legal Email: [From Super Admin Settings]
Support Email: [From Super Admin Settings]
Website: [From Super Admin Settings]

We may request appropriate information to verify the identity and authority of a person making a privacy request.


33. Acceptance and Acknowledgement

By creating or using a Travel CRM account, the Customer acknowledges that it has reviewed this Privacy Policy.

Where explicit consent or acknowledgement is legally required for a particular processing activity, we may request it separately through the application.

The Customer remains responsible for providing any notices or obtaining any consents required from its own travellers, customers, employees or other individuals whose information it enters into Travel CRM.

Privacy Policy | Terms & Conditions | Sign in