Privacy Policy
Last updated: 28 June 2026
This Privacy Policy explains how EverywhereGO LLP ("EverywhereGO", "we", "us") — the Data Fiduciary— collects, uses, shares and protects your personal data when you use everywherego.in and our apps (the "Platform"). It is provided in accordance with India's Digital Personal Data Protection Act, 2023 ("DPDP Act"), the Information Technology Act, 2000 and rules made thereunder. By using the Platform you acknowledge this notice; where required, we process your data on the basis of your consent.
1. Data we collect
- Account & identity: name, email, phone, password (hashed), and Google sign-in identifier if you choose it.
- Traveller & booking: traveller names, date of birth, gender, nationality, and passport/visa details for international travel; itinerary, PNR and booking history; place of supply (state) for your GST invoice.
- Payment: payment status and metadata via our payment partner. We do not store full card numbers.
- Technical & usage: device, browser, IP address, cookies and interaction data used for security, fraud prevention and analytics.
- Support: communications you send us and records of your requests.
2. Why we use your data & legal basis
We process your data to: create and fulfil your Bookings with Suppliers; process payments and refunds; provide customer support; send transactional updates; prevent fraud and secure the Platform; comply with legal obligations (including tax); and, with your consent, send offers and marketing. Our lawful bases are your consent and the "legitimate uses" recognised under the DPDP Act (such as performing a service you requested and meeting legal obligations).
3. How we share your data
We share only the minimum data necessary with: Suppliers (airlines, hotels, hosts, insurers and consolidators such as TBO) to fulfil your Booking; our payment partner (e.g. Razorpay) to process payment; and vetted service providers (e.g. communications, analytics, cloud hosting) bound by confidentiality and processing obligations. We may also disclose data where required by law, court order or a lawful government request, or to protect our rights, users or the public. We do not sell your personal data.
4. Cross-border transfers
Some Suppliers and service providers may process your data outside India. Where this happens, we do so in accordance with the DPDP Act and apply appropriate safeguards. We do not transfer data to any country restricted by the Government of India.
5. Data retention
We retain your personal data only for as long as necessary for the purposes above or as required by law (for example, tax and accounting records). When no longer required, we delete or anonymise it.
6. Security
We protect your data with reasonable technical and organisational safeguards, including encryption in transit, access controls, hashed credentials and tokenised payments. No method of transmission or storage is completely secure, but we work to protect your information and to review our safeguards.
7. Your rights as a Data Principal
Subject to the DPDP Act, you have the right to:
- access a summary of the personal data we process about you;
- correct, complete or update your data;
- request erasure of your data where it is no longer required;
- nominate another individual to exercise your rights in the event of death or incapacity;
- grievance redressal — readily raise a complaint with our Officer (see below).
You can exercise most rights from your account or by contacting our Grievance / Data Protection Officer.
8. Withdrawing consent
You may withdraw your consent at any time — for example, opt out of marketing from your account or via the unsubscribe link. Withdrawal does not affect processing already carried out. If you withdraw consent necessary to provide a service (e.g. data needed to issue a ticket), we may be unable to provide that service.
9. Cookies & tracking
We use essential cookies for the Platform to function and, with your consent, analytics cookies to understand and improve it. You can manage cookies through your browser settings.
10. Children's data
The Platform is intended for users aged 18 and above. We do not knowingly process the personal data of children without verifiable parental or guardian consent, and we do not undertake tracking or targeted advertising directed at children. If you believe a child's data has been provided to us, please contact our Officer so we can address it.
11. Data breach
In the event of a personal data breach, we will take prompt remedial action and notify the Data Protection Board of India and affected users as required under the DPDP Act.
12. Grievance & Data Protection Officer
For any privacy question, request or complaint, contact our Grievance / Data Protection Officer at EverywhereGO LLP, 82, Srinivasa, Dee-Enclave, 4th Cross, Sahakaranagar, Bangalore 560092, Karnataka, India — details on our Contact & Grievance Redressal page. We acknowledge requests promptly and aim to resolve them within the timelines prescribed by law.
13. Changes to this policy
We may update this policy from time to time. The current version with its "last updated" date is always available on the Platform; continued use after changes constitutes acceptance.
