BookmytravelFlights made premium
Back to BookMyTravel
Privacy and data

Your journey. Your data.

See what information we use to complete your travel, why we need it, how we protect it and the choices available to you.

Updated 23 January 202610 min read
Clear before you confirm

The important points are surfaced first. Use the section guide below whenever you need the complete policy.

Purpose-led collection

We collect information needed to search, book, support and secure your trip.

Responsible sharing

Travel data is shared only with relevant airlines, providers and authorities.

You remain in control

Access, correction, erasure and grievance options are explained clearly.

On this page

Privacy in plain language

We use traveller information to arrange and manage services you request. This page explains the full policy and how to exercise your privacy rights.

1. Preface

This Privacy Policy outlines the practices followed by BookMyTravel (hereinafter referred to as "BookMyTravel" or the "Company") with respect to the collection, processing, storage, sharing, and protection of your personal data when you use our platforms through our website (www.bookmytravel.com), mobile site, or mobile applications (iOS/Android).

This policy complies with applicable data protection laws, including the Information Technology Act, 2000, and specifically reflects our commitment to the principles, obligations, and rights outlined in the Digital Personal Data Protection Act, 2023 ("DPDP Act").

By using our platform, you, as a user ("User", "you", or "your"), consent to the terms of this Privacy Policy and acknowledge that your personal data may be processed in accordance with applicable laws, including the DPDP Act. If you do not agree with any terms herein, we advise you not to use the platform.

Please note that third-party platforms, business partners, or external links accessed through BookMyTravel may follow different data privacy practices. We encourage you to review their respective privacy policies independently.

Users outside the geographical limit of India

Please note that the data shared with BookMyTravel shall be primarily processed in India and such other jurisdictions where a third party engaged by BookMyTravel may process the data on its behalf. By agreeing to this policy, you are providing BookMyTravel with your explicit consent to process your personal information for the purpose(s) defined in this policy. The data protection regulations in India or such other jurisdictions mentioned above may differ from those of your country of residence.

If you have any concerns regarding the processing of your data and wish to withdraw your consent, you may do so by writing to the following email IDs: info@bookmytravel.com or support@bookmytravel.com.

However, if such processing of data is essential for us to be able to provide a service(s) to you, then we may not be able to serve or confirm your bookings after your withdrawal of consent. For instance, if you make a booking (flight or hotel), certain personal information of yours like contact details, gender, dietary preferences, choice of room with smoking facility, any medical condition which may require specific attention or facility etc. may have to be shared by us with our vendors, and they may further process this information for making suitable arrangements for you during your trip.

Data Fiduciary under DPDP Act

Under the DPDP Act, BookMyTravel acts as a "Data Fiduciary" with regard to the collection and processing of your personal data, and as such is committed to fulfilling all obligations therein, including obtaining valid consent, processing data for legitimate purposes, and enabling users to exercise their rights effectively.

Information We Collect: Categories and Legal Basis

We collect and process your personal data solely for lawful purposes, with your consent where applicable, or in accordance with other valid grounds specified under the DPDP Act. These purposes include the provision of services, compliance with legal requirements, and business operations in line with our Terms of Use.

The information detailed below is collected by us to be able to provide the services chosen by you and also to fulfill our legal obligations as well as our obligations towards third parties as per our Terms of Use.

Personal Information of the User shall include the information shared by the User and collected by us for the following purposes :

  • Registration on the Website: Information which you provide while subscribing to or registering on the Website, including but not limited to information about your personal identity such as name, gender, marital status, age, date of birth, passport details, profile picture, etc., and your contact details such as your email address, postal address, frequent flyer number, telephone (mobile or otherwise) and/or fax numbers. The information may also include banking details (including credit/debit card information), billing information, payment history, tax information, and any other information relating to your income and/or lifestyle, as shared by you.
  • Other Information: We may also collect additional information and documents, including but not limited to:
    • Transactional history (other than banking details) relating to your e-commerce activities and buying behaviour.
    • Your usernames, email addresses, and other security-related information used by you in relation to our Services.
    • Data either created by you or by a third party which you choose to store on our servers, such as image files, documents, or other digital content.
    • Data available in the public domain or received from third parties, including social media platforms, such as name, email address, friend list, profile pictures, or any other information permitted under your account settings.
    • Information relating to other traveler(s) for whom you make bookings through your registered account. You confirm that such traveler(s) have consented to the sharing of their information with us and relevant service providers.
    • If you request visa-related services, copies of passports, bank statements, completed application forms, photographs, and other information required by embassies or consulates for processing visa applications.
    • For international bookings, information required under the Liberalized Remittance Scheme (LRS) of the Reserve Bank of India or any other applicable law, including PAN or passport details. Such information shall be used strictly for lawful purposes and in compliance with applicable regulations.
    • In case of contactless hotel check-ins, copies of government-issued identification documents such as Aadhaar, driving license, voter ID, self-declaration forms, and other information required by hotels to honour bookings.

We may also collect transaction history, usage behaviour, social login identifiers, user-submitted content, and information provided for specific services (for example, visa processing). In all cases, we aim to collect only the minimum data necessary for the stated purpose.

Additional information (Information collected automatically)

When you use the Service, we use persistent and session cookies and other tracking technologies to: (a) store your username and authentication tokens; (b) analyse the usage of the Service; (c) customise the Service to your preferences; and (d) control the advertising displayed by the Service. You can manage or disable cookies via your browser settings, though some features may not function correctly if cookies are blocked.

Categories of Personal Data (as per DPDP Act)

  • Personal Data: Any data about an individual who is identifiable by or in relation to such data (e.g., name, email address, mobile number, identification documents).
  • Sensitive Personal Data: Financial information, Aadhaar/PAN, etc., which are collected and transmitted under explicit consent or as per lawful grounds as permitted by the DPDP Act.

Legal Justifications for Processing under DPDP

  • Consent: For marketing communications or optional features, we process data only after obtaining your clear and specific consent.
  • Performance of Contract: Processing necessary to provide services you requested (e.g., to complete a booking).
  • Legal Obligation: Processing to comply with regulatory obligations.
  • Legitimate Use: For security, fraud prevention, and analytics.

User Rights under DPDP Act

As a Data Principal under the DPDP Act, you have the following rights regarding your personal data:

  • Right to Access Know what data we collect and how it’s used.
  • Right to Correction Request correction of inaccurate or outdated information.
  • Right to erasure : Request deletion (subject to legal requirements).
  • Right of Grievance Redressal: File complaints related to unlawful processing or violation of your privacy rights.
  • Right to Nominate: Appoint a nominee in case of death or incapacitation (once rules are notified).

We provide mechanisms to exercise these rights through your account settings or by contacting our grievance officer at escalations@bookmytravel.com.

You may withdraw consent for optional processing activities at any time under Section 5(5) of the DPDP Act. Please note that some essential services (e.g., booking a flight, creating an account) may not be offered if the data required is no longer consented to. You can initiate withdrawal of consent by contacting us at:

Grievance Officer

In compliance with Section 13 of the Digital Personal Data Protection (DPDP) Act, we have appointed a Grievance Officer to address queries, concerns, or complaints regarding your personal data.

  • Designation: Grievance Officer
  • Email: escalations@bookmytravel.com
  • Address: BookMyTravel Pvt. Ltd., Second Floor, Veritas Building, Sector – 53, Golf Course Road, Gurugram – 122002, Haryana, India

Data Retention

We retain personal information only as long as necessary to fulfil the purposes for which it was collected, or as required under applicable laws. Once data is no longer required, we ensure deletion or archiving in a manner prescribed by law.

Security and Safeguards

We adopt reasonable technical and organisational security measures, including encryption and role-based access controls, to protect your personal information from unauthorised access, processing, loss, or destruction.

Data Breach Response

In the event of any personal data breach that negatively impacts your rights or raises significant risk, we will notify the Data Protection Board (when constituted under DPDP) and affected users, as required under the law.

Children’s Data

We do not knowingly collect personal information from children under the age of 18 without appropriate consent. Any processing of personal data of children will follow safeguards notified by the government, and we will obtain verifiable parental consent wherever necessary.

Updates to Policy

This Privacy Policy may be updated periodically to comply with new legal, business, or technological requirements. Upon revision, we will update the "Last updated" date and inform users via appropriate communication channels. Your continued use of the platform after changes to this policy constitutes your acceptance of the revised policy.

Contact Us

If you have any concerns or queries regarding this privacy policy, you may contact us at:

By integrating the principles of the Digital Personal Data Protection Act, 2023 into our privacy practices, we reaffirm our commitment to protecting your personal data and ensuring transparency, accountability, and user empowerment.

Related policies

Review the documents that work together with this policy.