Privacy Policy
Travel planning cannot happen without personal data — passports, dates of birth, dietary needs, card details. This page sets out exactly what we hold, why, who sees it and when we destroy it.
Last updated 21 July 2026
A plain-language summary before the detail
We collect what a trip actually requires and nothing more. We never sell traveller data. Identity documents get the strictest handling we apply to anything, and they are deleted once the legal retention window closes.
1. Who we are and what this policy covers
99Travels is a travel agency operated by Catalyst Web Trendz Pvt. Ltd., with its registered travel desk at D 29, 2nd Floor, Greater Kailash Enclave 2, Greater Kailash, New Delhi – 110048. For the purposes of the Digital Personal Data Protection Act, 2023 ("DPDP Act") we act as the Data Fiduciary for personal data you give us, and you are the Data Principal.
This policy covers www.99travelz.com, our enquiry and booking forms, email and WhatsApp correspondence with our consultants, and the traveller files we build to operate your journey. It does not cover the independent privacy practices of airlines, hotels, cruise lines, insurers, embassies or destination management companies, each of which controls the data it receives in its own right.
2. The categories of data we collect
We group personal data by why it exists rather than by where it came from, because that determines how long we keep it.
- Enquiry data — name, email, phone, country of residence, service required, budget band, preferred travel month, number of travellers and your free-text message.
- Identity and travel documents — passport bio-page scans, passport number and expiry, date and place of birth, nationality, photographs meeting embassy specifications, previous visa records and, for some missions, employment or bank statements.
- Booking and itinerary data — flight PNRs, hotel reservations, transfer details, loyalty numbers, seat and room preferences, and the emergency contact you nominate.
- Care and accessibility data — dietary requirements, mobility needs, allergies and any medical information you choose to disclose so that we can brief suppliers safely.
- Financial data — invoice records, GST details where you claim input credit, PAN where TCS reporting applies, and the last four digits and payment reference of the instrument used.
- Technical data — IP address, browser and device type, referring page and pages viewed, collected through the limited cookies described in section 9.
We do not ask for caste, religion, political opinion or biometric data. Where a destination's own entry rules force disclosure of health or religious information — pilgrimage permits and certain vaccination regimes are the common examples — we collect it only for that submission and delete it once the permit is issued.
3. Passports, visas and other identity documents
Identity documents are the most sensitive material we ever touch, and they are handled under a tighter standard than the rest of your file.
- We never ask for passport scans through the public enquiry form. They are collected only after a booking exists, over a link a consultant sends you, and never requested over an unsolicited call.
- Scans are stored encrypted at rest, access-controlled to the consultant and visa officer working your file, and logged on every open.
- Physical passports submitted for a visa are held in a locked cabinet, tracked on a register with your signature at handover and return, and never couriered without your written instruction.
- Supporting financial documents supplied for a visa file — bank statements, salary slips, income tax returns — are deleted within 30 days of the visa decision, whatever that decision is.
- Passport scans themselves are deleted within 12 months of the completion of the last trip they were used for, unless a longer period is compelled by a specific law or a live dispute.
We do not retain identity documents "for convenience on your next booking". If you travel with us again we will ask you for them again. That is deliberate.
4. Why we process your data, and on what basis
Under section 4 of the DPDP Act, personal data may be processed for a lawful purpose either with consent or for certain legitimate uses. Our purposes are:
- To answer your enquiry and prepare a quote — on the consent you give when you submit the form.
- To operate a confirmed booking — issuing tickets, registering you at hotels, filing visas, arranging transfers and insurance. Without this data the trip cannot exist.
- To meet statutory obligations — invoicing and GST records, TCS reporting on foreign remittances under the Liberalised Remittance Scheme, and record-keeping required of a travel agent.
- To respond to an on-trip emergency — including sharing your details with a hospital, insurer or Indian mission where necessary to protect life or safety.
- To send marketing — only where you have separately ticked the optional consent box, and never as a condition of booking.
5. Who we share your data with
A journey is delivered by a chain of independent businesses, and your details must travel down that chain for anything to work. We share the minimum each party needs.
- Airlines and global distribution systems — name exactly as printed on the passport, date of birth, gender marker, passport number and nationality, plus any special assistance code.
- Hotels and resorts — guest names, arrival and departure dates, bed and dietary preferences. Many jurisdictions additionally require passport details at check-in by law.
- Embassies, consulates and outsourced visa service providers — the complete application file they specify. We cannot reduce this set; the mission dictates it.
- Destination management companies and ground handlers — traveller names, contact number, arrival details and any accessibility or medical note relevant to their service.
- Insurers and payment gateways — the data required to issue a policy or process a transaction.
- Statutory authorities — tax authorities, and law enforcement where a lawful written demand is made under the Information Technology Act, 2000 or other applicable law.
We do not sell, rent or barter traveller data. We do not share your details with unrelated advertisers, lead-generation networks or data brokers. Our supplier contracts require that traveller data be used only to deliver the booked service.
6. Cross-border transfers
International travel is, by definition, a cross-border transfer of data. If you fly to Zurich and sleep in a hotel there, that hotel and that airline hold your details on servers outside India, and no policy we write can prevent it.
We transfer personal data outside India only where it is necessary to deliver a booked service or to file a visa application, and only to countries not restricted by the Central Government under section 16 of the DPDP Act. Where we appoint an overseas ground handler we contract for confidentiality, purpose limitation and deletion after the trip. Where the recipient is a sovereign authority such as an embassy, that authority applies its own national law, over which we have no control and can offer no assurance.
7. Payment data
We do not store complete card numbers, CVVs or net-banking credentials on our systems. Card payments are processed by RBI-authorised payment gateways under PCI-DSS, and what returns to us is a masked reference plus the transaction status. Bank transfers and UPI payments reach our current account directly.
What we do keep is the invoice trail: amount, date, instrument type, last four digits, GST computation and, where a foreign remittance triggers Tax Collected at Source under the Liberalised Remittance Scheme, your PAN and the TCS certificate. Tax records are retained for the period the Income-tax and GST legislation requires, currently eight financial years, and are not used for any other purpose. Nobody at 99Travels will ever ask you for a card CVV, an OTP or an internet-banking password — such a request is fraudulent, and you should report it to us immediately.
8. Marketing and your preferences
Marketing consent sits in a separate checkbox from booking consent, and unticking it costs you nothing. If you opt in, you receive seasonal fare alerts, new itineraries and occasional destination journals — roughly two emails a month, never daily.
Every email carries a working one-click unsubscribe, and withdrawal takes effect within seven days. Withdrawing marketing consent does not stop operational messages about a live booking: flight schedule changes, visa appointment confirmations and departure briefings will still reach you, because they are part of the service you paid for. WhatsApp is used for booking operations by default; promotional WhatsApp messages are sent only on separate explicit opt-in.
9. Cookies and site analytics
This site uses a deliberately small cookie set. Strictly necessary cookies keep the site functioning and remember your consent choice in your browser's local storage under the key vy99-consent. Preference cookies remember display choices such as recently viewed destinations. Analytics cookies, only set if you accept them on the banner, tell us in aggregate which destinations and pages people read, so we know what to write next.
We do not run third-party advertising pixels or cross-site retargeting tags. Declining analytics on the cookie banner leaves the site fully functional. You can additionally block or delete cookies in your browser settings; strictly necessary cookies removed this way may cause the consent banner to reappear on each visit.
10. Children and minors travelling with families
Our services are sold to adults. We do not knowingly collect data directly from anyone under 18, and the site is not directed at children.
Family bookings necessarily include minors' details, because airlines and hotels require them. In line with section 9 of the DPDP Act, that data is provided by the parent or lawful guardian making the booking, who confirms their authority to do so. Minors' data is used strictly to issue tickets, register accommodation and file visas — never for behavioural tracking, profiling or targeted advertising — and is deleted on the same schedule as the rest of the traveller file. If you believe a minor's data has reached us without guardian consent, write to the Grievance Officer and we will erase it.
11. How long we keep things
- Enquiries that never became bookings — 24 months, then erased. Ask sooner and we erase sooner.
- Passport scans and identity documents — 12 months after the last trip on which they were used.
- Visa supporting financials — 30 days after the decision.
- Itinerary and booking records — 3 years after travel, so we can answer questions and defend claims.
- Invoices and tax records — 8 financial years, as statute requires.
- Marketing list membership — until you unsubscribe, plus a suppression record so we do not re-add you by accident.
12. Security measures
We apply reasonable security safeguards as required by section 8(5) of the DPDP Act and rule 8 of the IT (Reasonable Security Practices) Rules, 2011: TLS on all site traffic, encryption at rest for document stores, role-based access so a consultant sees only their own travellers, mandatory multi-factor authentication on staff accounts, access logging on identity documents, and confidentiality undertakings signed by every employee and contractor.
No system is perfect. Should a personal data breach occur, we will notify the Data Protection Board of India and every affected Data Principal without undue delay, describing what happened, what data was involved and what you should do.
13. Your rights as a Data Principal
Under the DPDP Act you may exercise the following rights free of charge, and we will respond within 30 days:
- Access — a summary of the personal data we process about you and the parties it has been shared with.
- Correction and completion — important before ticketing, since a name mismatch against a passport can invalidate a ticket.
- Erasure — subject to records we are legally required to retain, such as tax invoices.
- Withdrawal of consent — as easily as it was given. Withdrawing consent needed to operate a confirmed booking may make that booking impossible to deliver, and cancellation terms would then apply.
- Grievance redressal — and, if we do not resolve it, the right to complain to the Data Protection Board of India.
- Nomination — to nominate another individual to exercise these rights in the event of your death or incapacity.
You also carry duties under section 15 of the Act, chiefly not to impersonate another person and not to file frivolous or false complaints.
14. Grievance Officer, governing law and changes
Complaints about how your data has been handled should be addressed to the Grievance Officer, 99Travels, appointed under the DPDP Act and rule 3(11) of the IT (Intermediary Guidelines) Rules. We acknowledge every grievance within 48 hours and resolve it within 30 days.
Grievance Officer — 99Travels
- info@catalystwebtrendz.com — subject line "DPDP Request" or "Privacy Grievance"
- +91-9953590779
- Catalyst Web Trendz Pvt. Ltd., D 29, 2nd Floor, Greater Kailash Enclave 2, Greater Kailash, New Delhi – 110048
- Monday – Friday, 10:00 AM – 7:00 PM IST
This policy is governed by the laws of India, and the courts at New Delhi have exclusive jurisdiction over any dispute arising from it. We review it at least annually and whenever the law or our supplier arrangements change materially. The "last updated" date at the top of this page always reflects the current version; material changes are additionally notified by email to travellers with a live booking.
Questions about this policy?
Ask a person rather than guessing. Write to info@catalystwebtrendz.com, call +91-9953590779 or message us on WhatsApp, Monday to Friday, 10:00 AM – 7:00 PM IST.