1. Scope
This policy applies to Tinglem's Travel's website, accounts, cab-booking services, contact forms and related online services.
2. Personal Data We Collect
- Account data: name, email address, phone number and authentication-related information.
- Verification data: OTP records and security metadata when phone verification is enabled.
- Profile data: profile photo and information you voluntarily add to your account.
- Booking data: pickup, destination, date, time, trip type, passenger information, vehicle and booking status.
- Messages: information you submit through contact/support forms.
- Security/technical data: IP address, browser/device data, timestamps and security logs where actually collected.
3. How We Use Personal Data
- Create and maintain your account.
- Verify phone numbers and reduce fraudulent or automated registrations.
- Receive, manage and communicate about bookings.
- Send necessary booking confirmations and service notifications.
- Respond to support and contact requests.
- Protect the website, investigate abuse and maintain security.
- Comply with applicable legal obligations and lawful requests.
4. Consent and Legal Basis
We process personal data only for lawful purposes. Where consent is the applicable basis, the website will provide a notice describing the personal data and purpose before requesting consent. India's DPDP Act requires notice and consent mechanisms, and the notified 2025 Rules provide requirements for clear, understandable notices and consent management. DPDP Rules 2025 .
Where consent is used, you may withdraw it through the method we provide, subject to processing that is otherwise permitted or required by law.
5. OTP Verification
If SMS OTP is enabled, your phone number is used to send and verify one-time codes. OTPs should expire, have attempt limits and be protected from unnecessary disclosure. An external SMS provider may process your phone number and necessary delivery metadata to send the message.
6. Booking Data
We use booking data to arrange your requested transportation, communicate with you, maintain booking records, and handle operational and safety matters.
Where necessary to provide a trip, limited booking information may be shared with the assigned driver/service personnel. Your private account information is not intentionally published publicly as part of normal booking use.
7. Sharing of Personal Data
We may share limited personal data with drivers/service personnel, technical service providers (such as hosting, email, SMS, CAPTCHA or storage providers), and authorities or professional advisers where required or permitted by law.
We do not sell your personal data for advertising purposes.
8. Retention
We retain information only for as long as reasonably necessary to provide services, maintain business and security records, resolve disputes, prevent fraud, or comply with legal obligations. Exact retention periods should be set in the business's internal retention schedule.
9. Security
We use reasonable technical and organisational safeguards appropriate to the data we handle. These may include password hashing, HTTPS, access controls, authentication security, rate limiting, CAPTCHA, OTP expiration, database controls and restricted administrative access.
No online service can promise absolute security. Where a security incident triggers a legal notification obligation, we will follow the applicable process.
10. Your Privacy Rights
Depending on the applicable provisions and their effective date, individuals may have rights concerning access to information about processing, correction of inaccurate data, erasure where applicable, grievance redressal and withdrawal of consent where consent is the processing basis. The DPDP Act and 2025 Rules provide the statutory framework and a phased commencement timeline.
To make a privacy request, contact us below. We may reasonably verify your identity before processing a request.
11. Children
We do not knowingly seek to collect children's personal data in circumstances where additional parental/guardian consent or other safeguards are legally required. Where the law requires additional safeguards, we will follow them.
12. Cookies and Similar Technologies
The website may use cookies or similar technologies necessary for login sessions, security and normal functionality. If we add non-essential analytics, advertising or tracking technologies, the applicable disclosures and controls will be provided.
13. Third-Party Services and Transfers
Some providers supporting the website may process data from locations outside your state or outside India. We will use applicable contractual, technical and legal safeguards required for the relevant service and law.
Third-party providers have their own terms and privacy policies where applicable.
14. Changes to This Policy
We may update this policy when our services, data practices, security measures or legal requirements change. The published version will show its version and effective date. Material changes will be communicated or presented through the required notice/consent mechanism.
15. Privacy Contact
Business: Tinglem's Travel
Operator: [YOUR FULL LEGAL NAME]
Privacy/Grievance Email: [YOUR OFFICIAL PRIVACY EMAIL]
Address: [YOUR BUSINESS ADDRESS, NAGALAND, INDIA]
Phone: [YOUR OFFICIAL PHONE]