Your Data, Protected

Privacy Policy
We Protect What
Matters Most

At CoTrav, your data privacy is not an afterthought — it is a core commitment. This policy explains exactly what we collect, why we collect it, and how we keep it safe.

Effective Date: June 22, 2026
Last Updated: June 22, 2026
Governed under Indian Law

How We Put Your Privacy First

Six principles that govern every decision we make about your data.

Data Minimisation
We collect only the data absolutely necessary to deliver our services — nothing more. If we don't need it, we don't ask for it.
Encrypted Storage
All personal and corporate data is encrypted at rest and in transit using industry-standard AES-256 and TLS 1.3 protocols.
Full Transparency
We explain every data collection purpose in plain language — no legalese designed to obscure, no buried clauses.
No Selling of Data
We never sell, rent, or trade your personal or corporate data to third parties for marketing or commercial purposes. Ever.
Your Rights, Respected
You can access, correct, export, or request deletion of your data at any time — no friction, no red tape.
Regulatory Compliance
We comply with India's Digital Personal Data Protection Act (DPDPA) 2023 and applicable international data protection frameworks.
Section 01

Who We Are

This Privacy Policy is published by BAI Infosolutions Private Limited, trading as CoTrav ("CoTrav", "we", "our", or "us"). We are a corporate travel management company incorporated under the Companies Act 2013 and registered at Unit No. 4 & 5, Ground Floor, DLF Building 9B, DLF Cyber City, Phase 2, Sector 24, Gurugram 122002, Haryana, India.

CoTrav operates a corporate travel management platform accessible via our website, mobile application, and direct relationship manager channels. This policy applies to all personal data processed in connection with our platform and services.

Scope: This policy applies to employees of our corporate clients, their travel administrators, our direct website visitors, and any individual whose personal data we process in connection with the CoTrav platform.
Section 02

Data We Collect

We collect personal data through three primary channels: information you provide directly, information generated through your use of our platform, and information obtained from your employer (our corporate client) to facilitate your travel arrangements.

Identity & Contact
Full name, work email, phone number, employee ID, designation, date of birth (for bookings), and passport / government ID details for international travel.
Travel Details
Origin, destination, travel dates, seat preferences, meal preferences, loyalty programme numbers, booking history, and itinerary data.
Payment & Expense
Corporate billing details, GST information, expense reports, reimbursement requests, and cost-centre allocations. We do not store full card numbers.
Technical & Usage
IP address, browser type, device identifiers, pages visited, session duration, and platform interaction logs used for security and service improvement.

For VISA and FRRO services, we may additionally collect passport copies, visa application forms, invitation letters, and immigration documentation strictly as required by the relevant embassy or Indian immigration authority.

Section 03

How We Use Your Information

We use your data only for the purposes for which it was collected or for directly related purposes that you would reasonably expect.

Purpose Data Used Legal Basis
Processing flight, hotel, cab, train & bus bookings Identity, travel details, payment data Contract performance
VISA application facilitation Passport, identity, travel history Contract performance
FRRO / FRO registration & compliance Identity, immigration documents Legal obligation
Travel policy enforcement & approvals Booking data, employee grade, cost centre Legitimate interest (employer)
Expense reporting & GST invoicing Payment, booking, and company data Legal obligation / contract
24/7 support & relationship management Contact details, booking history Contract performance
Platform security & fraud prevention Technical and usage data Legitimate interest
Service improvement & analytics Anonymised usage data Legitimate interest
Marketing communications (opt-in only) Contact details, preferences Consent
Important: We will never use your personal travel data to profile you for advertising purposes or share it with third-party advertisers.
Section 04

Sharing & Disclosure

CoTrav does not sell your data. We share it only with the parties listed below, and only to the extent necessary to provide our services.

  • Airlines, hotels, and transport providers — your booking details are transmitted to the relevant provider to complete your reservation. These parties operate under their own privacy policies.
  • Your employer (our corporate client) — travel data, itinerary details, and expense information are shared with your company's designated travel administrators and finance teams as part of our managed travel service.
  • VISA and immigration authorities — passport, identity, and application documents are submitted to embassies, consulates, and FRRO / FRO offices solely to complete your application.
  • Payment processors — billing data is processed by PCI-DSS compliant payment gateways. CoTrav does not store full card numbers on its systems.
  • Technology sub-processors — cloud infrastructure, communication, and analytics tools we use to operate our platform. All sub-processors are bound by data processing agreements.
  • Legal and regulatory authorities — when required by applicable law, court order, or government regulation, we may disclose data as legally mandated.
Section 05

Cookies & Tracking Technologies

Our website and platform use cookies and similar tracking technologies to deliver a functional, secure, and personalised experience.

Essential Cookies
Required for platform login, session management, and security. Cannot be disabled without breaking core functionality.
Analytics Cookies
Help us understand how the platform is used so we can improve it. All data is anonymised before processing. Opt-out available.
Preference Cookies
Remember your language, region, and display preferences so you don't have to set them on every visit.
Marketing Cookies
Only activated with your explicit consent. Used to show relevant content about CoTrav services. You may withdraw consent at any time.

You can manage your cookie preferences through your browser settings or via the cookie preference centre accessible from the footer of our website. Disabling essential cookies may prevent certain platform features from functioning correctly.

Section 06

Data Retention

We retain your personal data only for as long as necessary to fulfil the purpose it was collected for, or as required by applicable law.

  • Travel booking records — retained for 7 years from the date of travel to satisfy GST and financial audit requirements under Indian law.
  • VISA and FRRO documents — retained for 5 years post-completion or as required by the relevant immigration authority.
  • Active account data — retained for the duration of your employer's contract with CoTrav, plus a 90-day grace period for data export.
  • Marketing preferences & consent records — retained until consent is withdrawn, plus 1 year for audit trail purposes.
  • Technical and usage logs — retained for 12 months in identifiable form; anonymised and aggregated thereafter for up to 3 years for service analytics.
Account termination: When your employer ends their CoTrav contract, we will provide a 90-day window for data export. After this period, personal data is securely deleted from our active systems, subject to legal retention obligations above.
Section 07

Security Measures

We take the security of your data seriously and implement technical and organisational measures proportionate to the risks involved in corporate travel management.

  • Encryption: All data in transit is protected with TLS 1.3. Data at rest is encrypted using AES-256. Sensitive documents (passports, VISA files) are stored in encrypted, access-controlled vaults.
  • Access controls: Role-based access control (RBAC) ensures that only authorised personnel can access personal data relevant to their function. All access is logged and audited.
  • Infrastructure security: Our platform is hosted on ISO 27001-certified cloud infrastructure with regular penetration testing, vulnerability scanning, and security patching.
  • Incident response: We maintain a documented incident response plan. In the event of a personal data breach affecting your rights and freedoms, we will notify affected individuals and, where required, the relevant authority within 72 hours of discovery.
  • Employee training: All CoTrav team members handling personal data complete mandatory data protection training and are bound by confidentiality obligations.
Section 08

Your Rights

Under India's Digital Personal Data Protection Act (DPDPA) 2023 and applicable data protection principles, you have the following rights with respect to your personal data.

  • Right to Access — request a copy of the personal data we hold about you and information about how we use it.
  • Right to Correction — request correction of inaccurate or incomplete personal data. You may also update many details directly through the CoTrav platform.
  • Right to Erasure — request deletion of your personal data where it is no longer necessary for the purpose it was collected, subject to our legal retention obligations.
  • Right to Data Portability — request your data in a structured, machine-readable format (CSV / JSON) to transfer to another service provider.
  • Right to Withdraw Consent — where processing is based on consent (e.g., marketing emails), you may withdraw it at any time without affecting prior processing.
  • Right to Grievance Redressal — raise a complaint with our Data Protection Officer. If unresolved, you may escalate to the Data Protection Board of India once it is operationally established.
How to exercise your rights: Email us at privacy@cotrav.co with the subject line "Data Rights Request". We will respond within 30 days. We may ask you to verify your identity before processing the request.

Please note: some rights apply to data processed on behalf of your employer. For such data, your employer is the data controller and may need to be involved in fulfilling your request.

Section 09

Children's Privacy

CoTrav is a B2B corporate travel management platform intended solely for business use by adults. Our services are not directed at individuals under the age of 18.

We do not knowingly collect personal data from minors. If we become aware that a minor's data has been submitted to our platform without appropriate authorisation, we will take immediate steps to delete it. If you believe we have inadvertently collected such data, please contact us at privacy@cotrav.co.

Section 10

Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our services, legal requirements, or data processing practices. When we make material changes, we will:

  • Update the "Last Updated" date at the top of this page.
  • Send an email notification to registered users and corporate account administrators.
  • Display a prominent notice within the CoTrav platform for 30 days following significant changes.

Your continued use of our platform after the effective date of changes constitutes acceptance of the updated policy. If you do not agree with the changes, you may request account closure by contacting us.

Previous versions: Archived versions of this policy are available upon request. Email privacy@cotrav.co with the subject "Previous Privacy Policy".
Section 11

Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or the way CoTrav handles your personal data, please contact our Data Protection team:

Email
privacy@cotrav.co
Response within 2 business days.
Phone
0124-423-4958
Monday–Friday, 9 AM – 6 PM IST
Registered Address
Data Protection Officer — BAI Infosolutions Private Limited
Unit No. 4 & 5, Ground Floor, DLF Building 9B,
DLF Cyber City, Phase 2, Sector 24, Gurugram 122002, Haryana, India

This Privacy Policy was last reviewed and approved by the CoTrav Legal and Compliance team on June 22, 2026. It is governed by the laws of India and subject to the exclusive jurisdiction of courts in Gurugram, Haryana.

Trusted Corporate Travel

Your Data. Your Trust. Our Responsibility.

Questions about how CoTrav handles your data? Our team is available 24/7 to address any privacy concern.