Itiner (“we”, “us”, “our”) operates the Itiner platform accessible at itiner.in (“Service”). This Privacy Policy explains how we collect, use, store, and protect your personal data in accordance with the Digital Personal Data Protection Act, 2023 (DPDPA), the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (SPDI Rules), and the Information Technology Act, 2000.
1. Data Fiduciary
Under the DPDPA, 2023, the Data Fiduciary responsible for determining the purposes and means of processing your personal data is Daksh Bathla, an individual carrying on business as a sole proprietor under the name and style of “Navital Labs”. Itiner is the name of the service, not a separate company.
- Data Fiduciary: Daksh Bathla (sole proprietor, trading as Navital Labs)
- Principal place of business: Delhi/NCR, India
- Contact Email: [email protected]
- Grievance Officer: Daksh Bathla, details below
2. Personal Data We Collect
2.1 Data You Provide
- Account information: name, email address, password (hashed)
- Agency details: agency name, logo, contact information
- Trip content: itineraries, destination details, pricing, quotes, notes
- Client records you enter: traveller names, contact details, travel preferences, free-text notes about the client, the sales-pipeline stage you assign them, and any documents (such as passport or visa scans) you upload against a trip
- Payment-related information (processed by Razorpay, our payment processor; we do not store card numbers)
- Communications: support messages, feedback you send us
2.2 Data Collected Automatically
- Log data: IP address, browser type, pages visited, timestamps
- Device information: operating system, screen resolution
- Analytics: feature usage, session duration (via Google Analytics 4 and PostHog, loaded only if you accept analytics cookies)
- Activity log: a record of key actions taken in your workspace (for example a trip created, published, or deleted, or an AI generation run), with the team member who performed them and a timestamp, kept for security and troubleshooting
- Cookies and local storage tokens (see Cookie Policy)
2.3 Sensitive Personal Data (SPDI)
About you (the agency account holder): we do not ask for or intentionally collect Sensitive Personal Data or Information as defined under the SPDI Rules, 2011, such as financial account details, health data, or biometric data. Payment card details are handled entirely by our payment processor (see Section 4); we never receive or store them.
About your clients (Travellers): agencies use Itiner to store the traveller records they need to plan and book a trip. These may include identification documents such as passport or visa scans, and free-text fields (client notes, trip briefs) into which an agency may enter dietary, accessibility, health, or similar details. Where that happens, Itiner holds the data as a processor, on the agency's instructions, under our Data Processing Agreement; it is encrypted at rest and access is restricted as described in Section 8. The agency is the Data Fiduciary for that data and is responsible for having a lawful basis to collect it and for not entering more than the travel service requires.
3. Purpose and Legal Basis for Processing
The DPDPA, 2023 permits processing of personal data on the basis of consent or a defined set of legitimate uses. We rely on the following:
| Purpose | Legal Basis (DPDPA) |
|---|---|
| Creating your account, operating the Service, and sending transactional email (account alerts, receipts) | Consent, given when you sign up and ask us to provide the Service |
| Processing your subscription payments and refunds | Consent; retained payment records are then kept as a legal obligation under tax and accounting law |
| Sending product updates and marketing email | Separate consent, which you may withdraw at any time |
| Improving the Service through analytics | Consent, given through the cookie banner (analytics are off until you accept) |
| Keeping the Service secure and investigating fraud or abuse | Consent; and legal obligation under the Information Technology Act, 2000 |
| Responding to your support requests | Consent, given when you contact us |
| Meeting legal, regulatory, or court-ordered obligations | Compliance with applicable law |
4. Data Sharing and Disclosure
We do not sell, rent, or trade your personal data. We may share data only in the following circumstances:
- Service Providers: the following processors act only on our instructions and are contractually bound to protect the data they handle. Not all of them receive personal data. The purpose column says what each one is sent, and some receive only trip content or payment details:
- Supabase, Inc.: Database hosting, authentication, and encrypted file storage (including any identification documents an agency uploads) (Hosted on AWS in the region selected for the project).
- Amazon Web Services, Inc.: Encrypted daily database backups, kept for 30 days (Australia (Sydney)).
- Vercel, Inc.: Application hosting, CDN, and edge functions (USA; global edge network).
- Resend, Inc.: Transactional and notification email delivery (USA).
- NVIDIA Corporation: AI inference for itinerary drafting and supplier quote import. Receives the trip brief and any supplier document text the agent submits, which may include a traveller’s name or contact details (USA).
- Groq, Inc.: AI inference for reading pasted client enquiries, suggesting alternatives, and drafting client emails, and as the fallback for itinerary drafting and supplier quote import. Receives the text the agent submits to those features, which may include a traveller’s name or contact details (USA).
- Axonwise Private Limited (Sarvam AI): Speech-to-text transcription for the optional voice trip-brief feature. The recording may include the traveller’s name, contact details, or budget as spoken by the agent (India).
- PostHog, Inc.: Product analytics (after you accept analytics cookies), error tracking, and logs of AI requests for debugging and quality. The AI request logs include the prompt and response text, which may carry a traveller’s name or contact details (USA).
- Cloudflare, Inc.: Network proxy, DNS and the Turnstile human check on sign-up and sign-in forms. Traffic to Itiner passes through it, and it sees request metadata such as IP addresses (Global edge network).
- OpenStreetMap services (Nominatim, Overpass) and Open-Meteo: Destination search, real-place lookups and weather forecasts. They receive only destination names and coordinates, never traveller details (Europe).
- Razorpay Software Private Limited: Subscription payment processing and refunds. Receives the payer’s name, email, and payment instrument details; card numbers are not shared with us (India).
- Google LLC (Google Analytics 4, Google Tag Manager): Website and product analytics, loaded only after you accept analytics cookies (USA).
- Business Transfers: In the event of a merger, acquisition, or sale, personal data may be transferred as a business asset. We will provide notice before such transfer.
- Legal Requirements: We may disclose data to comply with applicable law, court orders, or lawful government requests under the IT Act, 2000 or other Indian law.
- AI assistants you connect: if you connect your Itiner account to an AI assistant such as ChatGPT or Claude, the itinerary data it asks for is sent to that assistant at your direction. See Section 9.
- With Your Consent: Any other sharing requires your explicit consent.
India’s criminal-law framework has changed and the IPC has been replaced by the Bharatiya Nyaya Sanhita (BNS). References in this Policy to offences or penalties under Indian criminal law should be read as references to the corresponding provisions of the BNS and other laws currently in force.
5. Cross-Border Data Transfers
Several of the processors listed in Section 4, including Vercel, Resend, NVIDIA, Groq, and Google, store or process data on servers outside India, primarily in the United States. Supabase hosts data in the region selected for our project. Razorpay processes payment data within India.
Where data is transferred outside India, we rely on contractual data-protection commitments with each processor, and we will comply with any restrictions the Central Government notifies under the DPDPA, 2023.
If you have concerns about cross-border transfers, contact our Grievance Officer.
6. Data Retention
- Account data: Retained while your account is active and for 90 days after deletion request, then permanently deleted.
- Trip content and client records: Retained while your account is active. Deleted upon account deletion.
- Activity log: Retained for up to 12 months, then deleted.
- AI assistant connections: The record of your approval and the access it grants last until you disconnect the assistant or delete your account (see Section 9).
- Log and analytics data: Retained for up to 12 months, then anonymised or deleted.
- Backup data: Encrypted backups retained for up to 30 days; deleted on rolling basis.
- Legal hold: Where we are required by law or ongoing legal proceedings to retain data, we will retain it for the mandated period.
7. Your Rights Under DPDPA, 2023
As a Data Principal under the DPDPA, 2023, you have the following rights:
- Right to Information (Section 11): You may request a summary of personal data we hold about you and how it has been processed.
- Right to Correction and Erasure (Section 12): You may request correction of inaccurate data and deletion of data that is no longer necessary for the purpose for which it was collected, subject to legal retention obligations.
- Right to Grievance Redressal (Section 13): You may file a grievance with our Grievance Officer. We will respond within 30 days. If unsatisfied, you may escalate to the Data Protection Board of India once constituted.
- Right to Nominate (Section 14): You may nominate an individual to exercise your rights in the event of your death or incapacity.
- Right to Withdraw Consent: Where processing is based on consent, you may withdraw it at any time. Withdrawal does not affect prior processing.
To exercise any of these rights, contact us with subject line “Data Rights Request”. We will respond within 30 days.
8. Data Security
We implement reasonable security practices as required under the SPDI Rules, 2011 (Rule 8) and DPDPA, 2023 (Section 8(5)), including:
- Encryption in transit using TLS 1.2+
- Encryption at rest for all database content
- Row-level security (RLS) policies on all database tables
- Uploaded files, including any identification documents, held in access-controlled storage and encrypted at rest
- Hashed password storage (never stored in plaintext)
- Access to production data limited to the proprietor, and not routinely exercised
- Daily automated backups
- Security monitoring and intrusion detection via Supabase infrastructure
In the event of a personal data breach, we will notify affected Data Principals and, once constituted, the Data Protection Board of India, in accordance with obligations under the DPDPA.
9. Connecting AI Assistants (ChatGPT, Claude and Others)
You can choose to connect your Itiner account to an AI assistant you already use, such as ChatGPT or Claude, so you can create and manage itineraries by chatting with it. This is optional and off until you turn it on. Nothing is shared with an assistant unless you connect it yourself.
9.1 How you connect
You add Itiner in the assistant's settings, sign in to Itiner, and approve the connection on an Itiner page that names the assistant and lists what it will be able to do. The assistant never receives your Itiner password. It receives an access token that lets it act on your account only for the actions listed below.
9.2 What a connected assistant can do
- See your agency's itineraries and their day-by-day plans
- Create itineraries and plan them with Itiner's AI planner (counted against your plan's limits, as in the app)
- Edit itineraries, including rewriting a day or re-planning a trip
- Publish or unpublish an itinerary's client link, and, only if you ask it to, have Itiner email that link to your client
It cannot delete trips, see billing or payment details, see your password or your team members, or open uploaded documents such as passport or visa scans. It acts with your own permissions, so it can never reach another agency's data.
9.3 What data is sent to the assistant
Only what the assistant asks for to do what you requested: itinerary titles, destinations, dates, the number of travellers, travel preferences, the day-by-day plan, the client's name as it appears on the trip, the trip's status, and its share link. We do not send your clients' email addresses or phone numbers, uploaded documents, quotes or prices, or your private notes.
Whatever you type to the assistant, and whatever Itiner returns to it, is then handled by the company that provides the assistant (for example OpenAI for ChatGPT, or Anthropic for Claude) under its own terms and privacy policy. That company is a recipient you choose, not a processor working for Itiner, and it is not listed in Section 4. If your itineraries contain details about your clients, you are responsible, as the Data Fiduciary for those clients, for deciding whether sharing them with that assistant is appropriate.
9.4 What Itiner keeps
- A record of the assistant you approved and when, and the tokens that keep it connected, held by our authentication provider (Supabase) until you disconnect
- Short-lived server logs of each request (which action, which assistant, when, and whether it succeeded), kept for security and troubleshooting. They do not record what you asked for or what was returned
- Changes the assistant makes are saved to your account like any change you make in the app. Creating, AI-planning, publishing and unpublishing an itinerary are recorded in your workspace's activity log, as they are when you do them yourself
9.5 Disconnecting
Disconnect an assistant at any time from Settings → AI assistants in Itiner, or by removing Itiner from the assistant's own connector settings. If you cannot do either, email us and we will revoke every assistant connection on your account. After that the assistant can no longer read or change anything in Itiner. Itineraries it created or edited stay in your account. Data already sent to the assistant is kept or deleted according to that company's policy, so delete those chats in the assistant if you want them gone.
10. Children's Privacy
The Service is not directed to children under the age of 18. We do not knowingly collect personal data from minors. Processing of personal data of children requires verifiable parental or guardian consent under the DPDPA. If you believe we have inadvertently collected data from a minor, contact us immediately for deletion.
11. Grievance Officer
Complaints about this Service, about content on it, or about how your personal data is handled go to the Grievance Officer named below, under the Information Technology Act, 2000 and Rules thereunder, the DPDPA, 2023, and the Consumer Protection (E-Commerce) Rules, 2020. Itiner is run by one person, so the Grievance Officer is the proprietor himself. There is no separate compliance team, and you are writing directly to the person who can act on the complaint.
- Name: Daksh Bathla
- Designation: Grievance Officer (Proprietor)
- Address: Delhi/NCR, India
- Email: [email protected]
- Acknowledgement: within 48 hours of receipt
- Resolution: within 30 days of receipt
If you are not satisfied with the outcome, you may escalate to the Data Protection Board of India (once constituted) for data-protection matters, or file a consumer complaint through the National Consumer Helpline or the e-Daakhil portal.
12. Changes to This Policy
We may update this Privacy Policy to reflect changes in our practices or applicable law. For existing users, material changes are notified by email or in-app notice at least 30 days before they take effect. The date at the top of this page is the current version's effective date. Continued use after that date constitutes acceptance.