Privacy Policy

Version 2.0 · Effective July 3, 2026 · Last updated June 22, 2026

This Privacy Policy explains how Voyagea (a product of PTRI Innovations Private Limited) collects, uses, stores, discloses, and protects your personal data when you use our website, mobile applications, and related services (collectively, the “Service”). By using the Service, you confirm that you have read, understood, and agreed to this Privacy Policy.

We are committed to protecting your privacy and processing your personal data lawfully, fairly, and transparently in accordance with the Digital Personal Data Protection Act, 2023(“DPDP Act”), the Information Technology Act, 2000 and its rules, the Consumer Protection Act, 2019, and other applicable Indian laws.

1. Identity of the Data Fiduciary

For the purposes of the DPDP Act and this Policy, the “Data Fiduciary” is:

PTRI Innovations Private Limited

CIN: U62090GJ2026PTC176297

Registered Office: 706 Supath Complex, Vijay Cross Road, Ahmedabad, Gujarat 380009, India

Email: info@ptriinnovation.com

Product: Voyagea (voyagea.co)

References to “Voyagea”, “we”, “us”, or “our” in this Policy refer to PTRI Innovations Private Limited acting in its capacity as Data Fiduciary. References to “you” or “your” refer to the natural person whose personal data is being processed (the “Data Principal” under the DPDP Act).

2. Scope of this Policy

This Privacy Policy applies to all personal data we collect from or about you when you:

  • Visit our website voyagea.co or any subdomain;
  • Create or maintain a Voyagea account;
  • Use any feature of the Service (including but not limited to AI itinerary generation, the V-Passport, Trip Crew, shared trips, and the Voyagea Shop);
  • Subscribe to a paid plan or make any purchase;
  • Communicate with us via support channels, contact forms, email, or social media;
  • Participate in surveys, feedback, beta features, or any promotional activity organised by Voyagea.

This Policy does not apply to third-party websites, applications, or services that may be linked from the Service. We are not responsible for the privacy practices of third parties. We strongly encourage you to review the privacy policies of any third-party service you access through Voyagea.

3. Personal Data We Collect

We collect personal data only to the extent necessary to provide and improve the Service. The categories of personal data we may collect are described below.

3.1 Information You Provide Directly

  • Account credentials: Email address, password (hashed and salted, never stored in plaintext), and authentication tokens from third-party identity providers (Google, Apple).
  • Profile information: Display name, username, home city, preferred travel mode, travel preferences, visited countries and states, and any V-Passport identifier you create.
  • User-generated content: Trip queries and prompts you submit to our AI, generated itineraries, notes, saved places, shared trip links, crew/group member details you enter, and feedback you submit.
  • Communication data: Information you provide when contacting our support team, submitting bug reports, completing surveys, or participating in promotions.
  • Payment information: When you subscribe to a paid plan, our payment processor (Razorpay) collects your payment method details directly. We do not store or have access to your full card numbers, CVVs, UPI PINs, or banking credentials. We receive only a transaction reference, last 4 digits of the card (where applicable), payment method type, and transaction status.

3.2 Information We Collect Automatically

  • Device and technical data: Device type, operating system, browser type and version, screen resolution, timezone, language preferences, device identifiers, and IP address.
  • Usage data: Pages viewed, features used, time spent on pages, click paths, search queries, error events, session duration, and navigation patterns.
  • Session replays: We may capture an interactive replay of your session on the Service (mouse movements, clicks, scrolls, and DOM state) for product analytics and debugging. Sensitive form inputs (passwords, payment fields) and PII-sensitive pages (account settings, profile, V-Passport, billing) are masked. Cross-origin payment frames (e.g., Razorpay's checkout iframe) are technically inaccessible to our recording tools and are NOT recorded.
  • Cookies and similar technologies: See Section 12 (Cookies & Tracking Technologies).
  • Approximate location: We may infer your approximate location (city or country) from your IP address for analytics, currency display, and fraud prevention. We do not collect precise GPS location.

3.3 Information from Third Parties

  • Identity providers: If you sign in via Google or Apple, we receive your name, email address, profile picture (if any), and a unique provider identifier from that provider. We do not receive your password.
  • Payment processor: Razorpay shares with us transaction confirmations, refund and chargeback notifications, and subscription status updates necessary to fulfill your subscription.
  • Analytics providers: PostHog (our product analytics provider) and Vercel Analytics provide aggregated and individual session-level data on usage of the Service.

3.4 What We Do NOT Collect

  • We do not knowingly collect personal data of children under 18 years of age (see Section 11);
  • We do not collect biometric data, government-issued identification numbers (Aadhaar, PAN, etc.), or financial account credentials directly;
  • We do not collect data classified as “sensitive personal data” under the IT Rules 2011 (such as health records, sexual orientation, religious beliefs, political opinions) unless you voluntarily provide such information through your trip queries, in which case it is treated as user-generated content;
  • We do not access your contacts, photos, files, or other applications on your device unless you explicitly grant such permission.

4. Purposes for Which We Process Your Personal Data

We process your personal data for the following specific, explicit, and legitimate purposes:

4.1 Providing the Service

  • Creating, authenticating, and maintaining your account;
  • Generating AI-powered travel itineraries based on your queries;
  • Storing and displaying your trips, V-Passport, saved places, and travel history;
  • Enabling collaboration features such as Trip Crew, trip sharing, and invites;
  • Processing subscriptions, payments, refunds, and chargebacks via Razorpay;
  • Sending transactional emails (account confirmations, subscription receipts, security alerts, password resets, cancellation confirmations);
  • Providing customer support and responding to your inquiries.

4.2 Improving and Operating the Service

  • Analysing usage patterns, identifying bugs, debugging errors, and improving feature design;
  • Conducting A/B tests, surveys, and other research to improve product quality;
  • Personalising your experience based on stated preferences and inferred behaviour;
  • Training, fine-tuning, and evaluating our AI models using anonymised and aggregated query data (your individual trip queries are NOT used to train third-party AI models without your separate consent);
  • Detecting, preventing, and responding to fraud, abuse, spam, security incidents, and violations of our Terms of Service.

4.3 Legal and Compliance

  • Complying with applicable laws, regulations, and lawful requests from courts or government authorities in India;
  • Establishing, exercising, or defending legal claims;
  • Maintaining records of acceptance of these Terms, Privacy Policy, cookie preferences, and other consent events as required by the DPDP Act;
  • Conducting tax, accounting, and audit functions.

4.4 Marketing (with separate consent)

With your explicit and separately obtained consent, we may send you promotional emails about new features, special offers, or launch promotions (including the LAUNCH50 offer). You may withdraw this consent at any time by clicking the unsubscribe link in any marketing email or by writing to our Grievance Officer (Section 15).

Transactional emails (account, billing, security) are not subject to this consent — these are essential to providing the Service.

5. Legal Basis for Processing

Under the DPDP Act, we process your personal data based on the following grounds:

  • Consent: When you create an account, accept this Policy, or opt in to marketing communications, you provide consent that is free, specific, informed, and unambiguous, signified by clear affirmative action.
  • Performance of contract: Processing necessary to provide the Service you have subscribed to, including processing subscription payments, providing AI itineraries, and maintaining your account.
  • Legitimate uses (as defined in DPDP Section 7): Including responding to medical emergencies, complying with court orders, providing services under employment, and other purposes specifically permitted by the DPDP Act.
  • Compliance with law: Where processing is required to comply with applicable Indian law.

6. Sharing and Disclosure of Personal Data

We do not sell, rent, or trade your personal data to third parties. We may share your personal data only as described below:

6.1 Service Providers (Data Processors)

We engage trusted third-party service providers to perform specific functions on our behalf. These providers process personal data only as instructed by us and under contractual obligations of confidentiality and security. Current key providers include:

  • Supabase (database, authentication): Stores your account, profile, trips, and subscription data. Hosted on AWS infrastructure.
  • Vercel (web hosting): Hosts the Service's frontend and serverless functions. Processes request logs.
  • Google (AI services): Google Gemini processes your travel queries to generate itineraries. Queries are sent under Google's Cloud terms; Google does not use your queries to train its public models when accessed via API.
  • Razorpay (payment processing): Processes all subscription payments, refunds, and chargebacks. Razorpay is the data controller for payment instrument details and is regulated by the Reserve Bank of India.
  • PostHog (product analytics): Receives usage events, session replays, and anonymised analytics. Hosted in PostHog's EU region.
  • Resend (transactional email): Delivers account, security, and subscription emails. Receives your email address and message content.
  • Vercel Analytics: Receives anonymised page-view and performance metrics.
  • Google Maps Platform: Displays maps, geocodes locations, and provides Places data for your itineraries. Some queries may be transmitted to Google.

This list may be updated from time to time as we add or change providers. The current list is maintained on our public Trust page (where available) and we will update this Policy when materially new categories of providers are added.

6.2 Legal Compliance and Safety

We may disclose your personal data to courts, law enforcement, regulators, or other government authorities when we believe in good faith that disclosure is required to:

  • Comply with applicable Indian law, regulation, legal process, or a lawful government request;
  • Enforce our Terms of Service, including investigation of potential violations;
  • Detect, prevent, or address fraud, security incidents, or technical issues;
  • Protect against harm to the rights, property, or safety of Voyagea, our users, or the public as required or permitted by law.

6.3 Business Transfers

If PTRI Innovations Private Limited is involved in a merger, acquisition, asset sale, reorganisation, insolvency, or other change of control, your personal data may be transferred to the successor or acquiring entity as part of that transaction. We will notify you of any such transfer that materially affects your privacy rights, and the successor entity will be bound by this Privacy Policy (or a successor policy no less protective).

6.4 With Your Consent or at Your Direction

We may share personal data with third parties when you direct us to do so (for example, by sharing a trip link publicly or by inviting collaborators to your Trip Crew). Shared trip links are accessible to anyone with the link unless otherwise restricted by you.

7. Data Retention

We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected, subject to the following:

  • Account data: Retained while your account is active. If you delete your account, we initiate deletion within 90 days, subject to legal retention requirements.
  • Subscription and billing records: Retained for 8 years from the date of the transaction, as required by the Income Tax Act, GST law, and the Companies Act in India.
  • Communication records: Retained for 3 years from last contact.
  • Session replays: Automatically deleted after 30 days unless flagged for specific incident investigation.
  • Analytics events: Retained in aggregated and anonymised form for up to 24 months.
  • Server logs: Retained for 90 days for security and operational purposes.
  • Backup data: Encrypted backups may be retained for up to 35 days after primary deletion to enable disaster recovery.

We may retain certain data longer if required by law, to resolve disputes, prevent fraud, or enforce our agreements. Aggregated and anonymised data that cannot reasonably be linked to you may be retained indefinitely.

8. International Data Transfers

Voyagea is operated from India. However, some of our service providers (such as Supabase, Vercel, Google, PostHog) host infrastructure outside India, including in the United States and the European Union. By using the Service, you acknowledge and consent to the transfer of your personal data to jurisdictions outside India for processing and storage by our service providers.

We will not transfer your personal data to any country or territory in respect of which the Central Government of India has, by notification, restricted such transfer under Section 16 of the DPDP Act. Where transfers occur, we rely on standard contractual protections with our service providers and require them to maintain technical and organisational safeguards consistent with this Policy.

9. Your Rights as a Data Principal

Under the DPDP Act, you have the following rights with respect to your personal data:

9.1 Right to Access Information

You have the right to obtain a summary of the personal data we process about you, the processing activities undertaken, and the identities of Data Fiduciaries and Data Processors with whom your personal data has been shared.

9.2 Right to Correction and Erasure

You have the right to request the correction of inaccurate or misleading personal data, the completion of incomplete personal data, the updating of outdated data, and the erasure of personal data that is no longer necessary for the purposes for which it was collected. Many of these actions can be performed directly from your account settings.

9.3 Right of Grievance Redressal

You have the right to have a readily available means of grievance redressal provided by us. Please write to our Grievance Officer (Section 15) with your concern. We will acknowledge receipt within 72 hours and respond within 30 days, in accordance with the DPDP Act.

9.4 Right to Nominate

You have the right to nominate another individual to exercise these rights on your behalf in the event of your death or incapacity. To exercise this right, write to our Grievance Officer.

9.5 Right to Withdraw Consent

Where we rely on your consent, you may withdraw it at any time. Withdrawal does not affect the lawfulness of processing done before withdrawal, and does not affect processing that is necessary to fulfil our contractual obligations to you.

9.6 How to Exercise Your Rights

To exercise any of these rights, contact our Grievance Officer (Section 15) or use the in-product controls available in your account settings. We may need to verify your identity before processing your request. There is no fee for reasonable requests; we may refuse or charge a fee for manifestly unfounded, excessive, or repetitive requests, as permitted by the DPDP Act.

10. Data Security

We implement reasonable security practices and procedures to protect your personal data from unauthorised access, use, disclosure, alteration, or destruction. These include but are not limited to:

  • Encryption in transit (TLS 1.2 or higher) and at rest where supported by our hosting providers;
  • Hashed and salted password storage (we never store passwords in plaintext);
  • Role-based access controls restricting employee and contractor access to personal data on a need-to-know basis;
  • Multi-factor authentication for administrative access to our infrastructure;
  • Regular security reviews of code, dependencies, and configurations;
  • PCI-DSS-compliant payment processing handled entirely by Razorpay (we do not store payment instrument data);
  • Network firewalls, rate limiting, and intrusion detection at the infrastructure level via our hosting providers;
  • Logging and monitoring of access to production systems.

However, no method of electronic transmission or storage is completely secure. While we strive to protect your personal data, we cannot guarantee absolute security. In the event of a personal data breach affecting you, we will notify the Data Protection Board of India and you (where required) in accordance with the DPDP Act and applicable timelines.

11. Children's Privacy

The Service is not directed to or intended for use by individuals under the age of 18. We do not knowingly collect personal data from children under 18. If you are under 18, you may use the Service only with the consent and supervision of a parent or legal guardian.

Under the DPDP Act, processing of personal data of children (individuals below the age of 18) requires verifiable consent from a parent or legal guardian. We do not engage in tracking, behavioural monitoring, or targeted advertising directed at children.

If we become aware that we have collected personal data from a child under 18 without proper parental consent, we will delete that data promptly. If you are a parent or guardian and believe your child has provided us with personal data, please contact our Grievance Officer immediately.

12. Cookies and Tracking Technologies

We use cookies, similar storage technologies (such as localStorage, sessionStorage), and pixels (collectively, “Cookies”) to operate, secure, and improve the Service.

12.1 Categories of Cookies We Use

  • Strictly necessary cookies: Required for the Service to function (authentication, session management, security tokens, CSRF protection, language preference). These cannot be disabled.
  • Functional cookies: Remember your preferences (theme, recently used features, dismissed notifications) to improve your experience.
  • Analytics cookies: Help us understand how users interact with the Service so we can improve it (PostHog, Vercel Analytics).
  • Performance cookies: Collect anonymised performance data such as page load times.

12.2 Managing Cookies

You can manage non-essential cookies through our Cookie Consent banner (presented on your first visit and accessible thereafter via the “Cookie Preferences” link in our footer). You may also manage cookies through your browser settings, although disabling essential cookies will prevent the Service from functioning correctly.

12.3 Do Not Track

We do not currently respond to browser “Do Not Track” signals, as there is no industry consensus on how to interpret them. We respect your choices made via our Cookie Consent banner.

13. Third-Party Links and Services

The Service may contain links to third-party websites, applications, or services that are not operated by us (for example, booking sites referenced in itineraries, social media platforms, or external content). This Privacy Policy does not apply to those third parties. We are not responsible for the content, privacy policies, or practices of third-party services. We encourage you to review the privacy policy of any third-party service you visit.

14. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will:

  • Update the “Last updated” date at the top of this Policy;
  • Notify you by email (to the address associated with your account) and/or by prominent notice within the Service;
  • For changes that require renewed consent under the DPDP Act, request your acceptance before the changes take effect for you.

Your continued use of the Service after the effective date of any changes constitutes your acceptance of the revised Policy, unless renewed consent is required. We encourage you to review this Policy periodically.

15. Grievance Officer

In compliance with the DPDP Act, the Information Technology Act, 2000, and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, we have designated a Grievance Officer to address your concerns regarding personal data processing, privacy rights, or compliance with this Policy.

Grievance Officer

Name: Dev Shah

Designation: Director, PTRI Innovations Private Limited

Email: dev@ptriinnovation.com

Postal address: 706 Supath Complex, Vijay Cross Road, Ahmedabad, Gujarat 380009, India

Hours: Monday to Friday, 10:00 AM to 6:00 PM IST (excluding public holidays)

We will acknowledge receipt of your grievance within seventy-two (72) hours and provide a substantive response within thirty (30) days, unless the nature of the grievance requires a longer period (in which case we will inform you of the expected timeline).

16. Governing Law and Jurisdiction

This Privacy Policy and all matters relating to it are governed by the laws of India. The courts at Ahmedabad, Gujarat shall have exclusive jurisdiction to entertain and try all disputes arising out of or in connection with this Policy, to the exclusion of any other courts. You agree to submit to the personal jurisdiction of such courts.

17. Contact Us

For any questions, concerns, or requests regarding this Privacy Policy or our handling of your personal data, you may contact us at:

  • For privacy and data-protection matters: dev@ptriinnovation.com
  • For general inquiries: hello@voyagea.co
  • For business and partnership inquiries: info@ptriinnovation.com

This Privacy Policy is the current version effective from July 3, 2026. Previous versions are available upon request to the Grievance Officer. © 2026 PTRI Innovations Private Limited. All rights reserved.

AI DisclaimerVoyagea uses AI to generate travel information. Content on this page may contain errors or be out of date. Always verify visa requirements, prices, operating hours, and travel conditions with official sources before booking. Voyagea is not a licensed travel agency and accepts no liability for decisions made based on this content. Terms of Service