FLYTRAVIO
Privacy Policy
How FlyTravio collects, uses, stores, transfers and discloses your personal information across the India (Fly Travio Pvt Ltd) and Australia (FlyTravio Pty Ltd) platforms.
Jump to a section
Choosing a market fades the clauses that apply only to the other market. Nothing is hidden: the whole Agreement remains in force and the complete text prints.
21Privacy, data protection and communications
Our collection, use, storage, transfer and disclosure of your Personal Information is governed by our Privacy Policy, which forms part of this Agreement, and by the privacy law of the country in which you contract with us: the IT Act and the DPDP Act in India, and the Privacy Act in Australia. This clause summarises the commitments that matter most to a Booking. Where the Privacy Policy gives you more information or more protection, the Privacy Policy applies.
21.1What we collect, and why
To provide the Platform we collect the Personal Information you give us and that is generated by your use of it: your name, date of birth, gender as required by airlines, nationality, contact details, passport or identity document details where a Service Provider or a government requires them, frequent-flyer and loyalty numbers, travel preferences, the details of the people you book for, payment details in the tokenised form described in clause 9, records of your Bookings and communications with us, and technical information about the device and connection you use. We collect special categories of information, such as a medical or mobility-assistance need or a meal preference that may indicate a religious belief, only where you choose to give them to us for the purpose of a specific Booking, and we use them only to pass your request to the Service Provider.
We use Personal Information to make and manage Bookings; to communicate with you about them; to provide customer support; to verify identity and prevent fraud; to comply with legal, tax, aviation-security and border-control obligations; to improve the Platform; and, only with your consent, to send you marketing. We do not sell Personal Information, and we do not use it for a purpose that is incompatible with the purpose for which it was collected without telling you and, where the law requires, obtaining your consent.
21.2Who we share it with
To fulfil a Booking we share the Personal Information the Booking requires with the Service Providers concerned and with the global distribution systems, consolidators and technology providers through which reservations are made; with our Payment Partners to process payment and prevent fraud; with insurers where you buy insurance; and with government, border, customs, immigration, aviation-security and law-enforcement authorities where the law requires. We also share Personal Information with the companies in our group that support the Platform, and with service providers that host our systems, send our communications and support our customers, in each case under written contracts that require them to protect it and to use it only on our instructions. We disclose Personal Information otherwise only with your consent or where a law, court order or regulator requires us to.
21.3Transfers between India, Australia and other countries
Because we operate across the India–Australia corridor, Personal Information collected on the India Platform may be processed in Australia by FlyTravio Pty Ltd, and Personal Information collected on the Australia Platform may be processed in India by Fly Travio Pvt Ltd and by the group's service companies, in each case for customer support, operations, fraud prevention and technology services. Personal Information is also disclosed to Service Providers in the countries you travel to, from and through. Every transfer is made subject to the requirements of the law described in clauses 21.9 and 21.10.
21.4Security
We protect Personal Information with technical and organisational measures appropriate to its sensitivity, including encryption in transit and at rest, tokenisation of payment data, role-based access controls, logging and monitoring of access, regular backups, staff training, and contractual security obligations on every service provider. Card data is handled only by PCI DSS-certified Payment Partners. No system is perfectly secure, and we ask you to protect your Account as described in clause 5.
21.5Retention
We keep Personal Information for as long as it is needed for the purpose for which it was collected and for the periods that tax, company, aviation, anti-fraud and other laws require us to keep records, after which we delete or de-identify it. Booking and payment records are retained for the statutory record-keeping period that applies to the contracting company, and access logs are retained for the period required by the security regulations that apply to it.
21.6Your rights and how to exercise them
Subject to Applicable Law, you may ask us for access to the Personal Information we hold about you, ask us to correct, complete or update it, ask us to erase it where we no longer need it for the purpose for which it was collected or for a legal obligation, withdraw a consent you have given, object to direct marketing, and complain about the way we handle your Personal Information. Requests may be made through your Account or by contacting us. We verify your identity before acting on a request, we respond within 30 days, and we do not charge a fee for a request unless the law permits it and the request is manifestly unreasonable. Withdrawing consent does not affect processing that took place before the withdrawal, and it may mean that we can no longer provide a service that depends on that consent, which we will tell you at the time.
21.7Communications and marketing consent
We send transactional and service communications about your Bookings by email, SMS, WhatsApp, in-app notification or telephone: booking confirmations, e-tickets, invoices, schedule changes, gate and boarding information, refund updates, security alerts and responses to your requests. These are operational messages, are sent to the contact details you gave for the Booking, and cannot be opted out of while a Booking is active or a request is open.
We send marketing communications only if you have given your separate, affirmative consent to receive them. Consent to marketing is never a condition of making a Booking, is never bundled with your acceptance of this Agreement, and is never obtained through a pre-ticked box. You may withdraw consent at any time using the unsubscribe link in any marketing email, by replying STOP to a marketing SMS, by updating the preferences in your Account, or by contacting us; we give effect to the withdrawal promptly and in any event within the time Applicable Law allows. Withdrawing marketing consent does not affect transactional messages. We never sell your contact details, and we do not send marketing on behalf of third parties without telling you who they are.
21.8Cookies and similar technologies
The Platform uses cookies and similar technologies as described in our Cookie Policy. Cookies that are strictly necessary for the Platform to work are used without consent; analytics, personalisation and advertising cookies are used only with the consent you give through the cookie preferences tool, which you may change at any time.
21.9Data protection on the India Platform
Law that applies now. Fly Travio Pvt Ltd is a body corporate that handles sensitive personal data or information within the meaning of section 43A of the IT Act and the SPDI Rules. In accordance with those Rules we publish a Privacy Policy; we collect sensitive personal data or information, such as payment details, passwords and any medical or health information you give us for a Booking, only with your consent and only for a lawful purpose connected with the Platform; we tell you the purpose of collection, the intended recipients and the contact details of the agency collecting and retaining it; we do not disclose sensitive personal data or information to a third party without your prior permission unless the disclosure is required by law; we give you the option not to provide information, and to withdraw consent, subject to the consequences of doing so; we implement reasonable security practices and procedures consistent with ISO/IEC 27001 or an equivalent documented standard; and we report cyber-security incidents to the Indian Computer Emergency Response Team (CERT-In) within the time its directions require. Disclosure of Personal Information in breach of a lawful contract is an offence under section 72A of the IT Act, and we bind our staff and service providers accordingly.
The Digital Personal Data Protection Act, 2023. The DPDP Act and the Digital Personal Data Protection Rules, 2025 are being brought into force in phases, and the substantive obligations of Data Fiduciaries are scheduled to commence in May 2027. Fly Travio Pvt Ltd will comply with each provision from the day it commences, and applies the following commitments now, as a matter of practice, on the India Platform: we give you a clear, standalone notice, in English and in the languages the Rules require, that itemises the personal data we collect, states the specified purpose for which each item is processed, and explains how to withdraw consent, exercise your rights and complain to the Data Protection Board of India; we process your personal data only for the specified purpose and only on the basis of your free, specific, informed, unconditional and unambiguous consent given by a clear affirmative action, or for a legitimate use that the DPDP Act permits, such as performing the Booking you have asked for or complying with a law; withdrawing consent is as easy as giving it, including through a registered Consent Manager where you choose to use one; you have the right to obtain a summary of the personal data we process and the identities of the Data Fiduciaries and Data Processors with which it has been shared, the right to correction, completion, updating and erasure, the right to grievance redressal within the period the Rules prescribe, and the right to nominate a person to exercise your rights in the event of your death or incapacity; we erase personal data once the specified purpose is no longer being served and retention is not required by law, after giving you the notice the Rules require; we process the personal data of a child only with the verifiable consent of the child's parent or lawful guardian, and we do not track, behaviourally monitor or target advertising at children; we implement the reasonable security safeguards the Rules specify, including encryption, access control, logging, monitoring and backup; in the event of a personal data breach we notify you and the Data Protection Board of India without delay, in the form and within the time the Rules prescribe; and we transfer personal data outside India only in compliance with any restriction that the Central Government notifies under the DPDP Act. Once the relevant provisions commence, you may complain to the Data Protection Board of India after first raising a grievance with us under clause 28.
Commercial communications. Promotional messages and calls on the India Platform are sent only in accordance with the Telecom Regulatory Authority of India's Telecom Commercial Communications Customer Preference Regulations, 2018. We send promotional communications only to Users who have given explicit consent recorded on the access provider's consent-registration platform, we honour preferences registered on the National Customer Preference Register (Do Not Disturb), and we use registered headers that identify our messages as promotional, service or transactional in accordance with those Regulations. Transactional and service messages relating to your Bookings, including one-time passcodes, are sent irrespective of a Do Not Disturb registration, as those Regulations permit.
21.10Data protection on the Australia Platform
The Privacy Act and the Australian Privacy Principles. FlyTravio Pty Ltd handles personal information in accordance with the Australian Privacy Principles, and treats itself as bound by the Privacy Act regardless of its annual turnover. In particular: we maintain a clearly expressed and up-to-date privacy policy (APP 1); we collect personal information only where it is reasonably necessary for our functions and activities, and sensitive information only with your consent (APP 3); at or before the time we collect personal information we notify you of the matters APP 5 requires, including the purposes of collection, the third parties to which it is usually disclosed, and whether it is likely to be disclosed to overseas recipients and in which countries; we use and disclose personal information only for the purpose for which it was collected, a related purpose you would reasonably expect, or with your consent (APP 6); we use personal information for direct marketing only where APP 7 permits it, and every marketing message includes a simple means of opting out; we take reasonable steps to protect personal information from misuse, interference, loss and unauthorised access, modification or disclosure, and we destroy or de-identify it when it is no longer needed for any purpose for which it may be used or disclosed (APP 11); and we give you access to, and correct, the personal information we hold about you on request, responding within 30 days (APPs 12 and 13).
Overseas disclosure (APP 8). Personal information collected on the Australia Platform is disclosed to overseas recipients, including Fly Travio Pvt Ltd and group service companies in India, Service Providers in the countries you travel to, and technology providers in the countries in which they host their systems. India, and the other countries concerned, are not prescribed as having laws or binding schemes substantially similar to the Australian Privacy Principles. Before we disclose personal information to an overseas recipient we take such steps as are reasonable in the circumstances to ensure that the recipient does not breach the Australian Privacy Principles in relation to it, including binding the recipient by written contract to handle the information in accordance with those Principles, and we remain accountable for the recipient's handling of it under section 16C of the Privacy Act. Where, for a particular disclosure, we instead ask for your consent under APP 8.2(b), we will tell you at the time, and you should understand now, that if you consent to that disclosure and the overseas recipient handles your personal information in breach of the Australian Privacy Principles, we will not be accountable under the Privacy Act for that breach and you will not be able to seek redress under the Privacy Act.
Data breaches. If we suspect that personal information has been accessed, disclosed or lost in a way that is likely to result in serious harm to you, we assess the incident expeditiously and in any event within 30 days, and, where the assessment confirms an eligible data breach, we notify the Office of the Australian Information Commissioner and the individuals affected as soon as practicable, in accordance with the Notifiable Data Breaches scheme in Part IIIC of the Privacy Act. Where a law requires us to report a cyber-security incident or a ransomware payment to the Australian Signals Directorate, we do so within the time the law requires.
Automated decisions. We use automated tools to screen transactions for fraud and to personalise search results and offers. From 10 December 2026, as the Privacy Act requires, our privacy policy will describe the kinds of personal information used in, and the kinds of decisions made by, computer programs that make or substantially assist decisions that could reasonably be expected to significantly affect your rights or interests. A decision of that kind is reviewed by a person before it is final, as described in clause 9.1, and you may ask us to reconsider it.
Marketing and telemarketing. We send commercial electronic messages only with your express or inferred consent, we identify ourselves and how to contact us in every message, and every message contains a functional unsubscribe facility that we honour within five business days, as the Spam Act 2003 (Cth) requires. We do not make telemarketing calls to a number listed on the Do Not Call Register unless the Do Not Call Register Act 2006 (Cth) permits it. Our handling of children's personal information will comply with the Children's Online Privacy Code once it is registered by the Information Commissioner.
Complaints. If you believe we have breached the Australian Privacy Principles, please complain first to our Privacy Officer. We acknowledge every privacy complaint, investigate it, and respond within 30 days. If you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner, which can investigate, conciliate and make determinations, including determinations that require us to compensate you. The Privacy Act also gives you a right to bring an action in court for a serious invasion of your privacy.
Your Session has expired !
If there is no activity on page for more than 16 minutes, or the internet connection was lost or reset.