1Who controls your data
Gigglezen Technologies Pvt Ltd is the data fiduciary for TripGZIO under India's Digital Personal Data Protection Act. When you book, the property you booked also becomes a fiduciary for the details it needs to host you.
Questions about this policy, and every request described below, go to the grievance officer named on the Grievance officer page.
2What we collect
We collect what a reservation actually needs and what you choose to give us.
- Search context: the city, dates, room and guest counts you enter, and the filters you apply. Recently viewed properties are kept in your own browser, not on our servers.
- Account details: name, mobile number, email, and your language and currency preferences.
- Booking details: guest names, stay dates, room and rate plan, special requests, and any GST number and legal name you give for a business invoice.
- Payment status: the method used, the amount, and the gateway's reference. Card numbers, UPI PINs and bank credentials are entered on the gateway's own page and never reach TripGZIO.
- Co-traveller details you save: name and ID type only. We do not store ID numbers.
- Technical data: IP address, device and browser type, and self-hosted analytics events for funnel steps such as search, property view and booking confirmed.
3Why we use it
To take and confirm your reservation, to send the voucher and the updates that follow it, to collect payment and process refunds, to support you when something goes wrong, to publish reviews you choose to write, and to keep the accounting and tax records Indian law requires us to keep.
We do not sell your data, and we do not use it to build advertising profiles.
5How long we keep it
Booking and payment records are kept for eight years from the end of the financial year in which the stay took place, which is the retention Indian tax and company law requires. Account details are kept while your account is open. Analytics events are aggregated and stripped of identifiers after twelve months.
Deleting your account removes your profile, saved travellers, wishlist and preferences. Booking and payment records within the retention window remain, because we are not permitted to delete them.
6Your rights
Under the DPDP Act you can ask for a copy of your data, correct it, have it erased where we are not required to keep it, withdraw a consent you gave, and nominate someone to exercise these rights if you cannot.
Account settings has a data export and an account deletion control that does all of this without waiting for anyone. A request sent to the grievance officer instead is answered within thirty days.
7How it is protected
Traffic is encrypted in transit. Access to booking data is limited by role and every access is logged. Property staff see only their own property's guests, and a brand sees only its own properties.
If a breach affects your data, we notify you and the Data Protection Board as the Act requires.