New Offering
Power your travel business with WaapTravel.Explore White Label
Legal & Data Protection← All Policies

Privacy Policy

At WaapTravel, we are committed to safeguarding enterprise travel data, API telemetry, passenger records, and financial transaction history for our B2B travel partners.

Last Updated: August 2026 • Version 2.4 (Enterprise Standards)

1. Information We Collect

As a business-to-business (B2B) travel technology provider, WaapTravel collects data required to facilitate GDS reservations, API calls, wallet deposits, and agent account management:

  • Agency Profile Data: Company name, GSTIN, PAN, IATA code, registered address, business contact phone, and admin email credentials.
  • Passenger Booking Records (PII): Passenger names, birth dates, passport details, meal/seat preferences, and contact information passed via GDS or direct API endpoints for ticketing.
  • Financial & Ledger Records: Prepaid wallet balances, UPI/Bank deposit transaction hashes, markup rule configurations, and monthly GST invoices.
  • API Telemetry & Logs: Endpoint request headers, IP addresses, user-agent details, response latencies, and error logs for security monitoring.

2. How We Use Your Data

We process data strictly to provide, secure, and optimize our travel technology services:

GDS & Airline Sync
Issuing instant PNRs via Amadeus, Sabre, Travelport, and LCC direct APIs.
Wallet & Settlement
Automating 24/7 prepaid ledger deductions, TDS reporting, and invoice generation.
Fraud Prevention
Detecting unauthorized API access, bot attacks, and velocity abuse.
Customer Support
Resolving ticket void requests, schedule changes, and refund disputes.

3. Data Sharing & Third Parties

We do not sell, rent, or monetize agency or passenger data. Data is shared exclusively with necessary travel suppliers and infrastructure providers:

  • GDS Hosts & Airlines: Flight booking data passed directly to Amadeus, Sabre, IndiGo, Air India, Emirates, etc.
  • Hotel Bedbanks & Operators: Guest names and check-in details dispatched to contracted property suppliers.
  • Payment Gateways & Banks: Transaction data processed under PCI-DSS Tier 1 encrypted channels.
  • Statutory Compliance: Government tax authorities when mandated by Indian GST or aviation regulations.

4. Data Security & Retention

We employ bank-grade security protocols including 256-bit SSL encryption, IP whitelisting for REST APIs, role-based access control (RBAC), and automated database backups. Passenger records are retained as required by civil aviation guidelines and deleted or anonymized thereafter.

5. Contact Data Protection Desk

If you have queries regarding data deletion requests, audit logs, or privacy rights, reach out to our Compliance Office:

Email: privacy@waaptravel.com
Compliance Desk: WaapTravel Legal Office, Cyber City, Gurugram, India