Privacy Policy
This Privacy Policy explains how Tripa ("Tripa", "we", "us", "our") collects, uses, shares and protects personal data when you visit tripa.in or use our SaaS products, apps and APIs (the "Services"). It is written in line with the Information Technology Act, 2000, its rules, and the Digital Personal Data Protection Act, 2023 (DPDP Act). By using the Services, you agree to this Policy.
1. Our Role
- For account, billing and website data — Tripa decides how this data is used, and acts as the Data Fiduciary.
- For data our customers store in our software (e.g. their clients' names, phone numbers, invoices, bookings, inventory records) — the customer business is the Data Fiduciary and Tripa acts only as a Data Processor, processing it on their instructions. If you are the end-customer of a business using Tripa, please contact that business first about your data.
2. Data We Collect
a) Data you give us
- Account details: name, email, phone number, password (stored encrypted), business name, role
- Business & billing details: billing address, GSTIN, PAN (where needed for invoicing), plan and payment history
- Support & communication: messages, emails, call notes and feedback you send us
- Customer Data: content you upload or enter into the Services (processed on your behalf, see Section 1)
b) Data collected automatically
- IP address, device and browser type, operating system
- Log data: pages visited, features used, actions taken, date and time, errors
- Cookies and similar technologies (see Section 6)
- For mobile apps: device identifiers, app version, crash reports, and location only if you grant permission and the feature needs it
c) Data from third parties
- Payment status from our payment gateway (we do not receive or store full card numbers, CVV or UPI PIN)
- Basic profile data if you sign in with Google or another login provider
3. How We Use Your Data
- Create and manage your account, and provide the Services
- Process payments, subscriptions, renewals and issue GST invoices
- Provide customer support and respond to requests
- Send service messages: OTPs, receipts, renewal reminders, security alerts, product updates
- Monitor, secure and prevent fraud, abuse and unauthorised access
- Analyse usage to fix bugs and improve features (using aggregated or de-identified data where possible)
- Comply with legal, tax and accounting obligations
- Send marketing emails or messages, only where permitted and with an opt-out
We do not sell your personal data. We do not use Customer Data to train public AI models.
4. Legal Basis & Consent
We process personal data on the basis of your consent (given when you sign up or submit a form), to perform our contract with you, and for legitimate uses permitted under the DPDP Act such as complying with law. You may withdraw consent at any time by writing to us; this will not affect processing already done, but may mean we can no longer provide some or all of the Services.
5. Sharing & Processors
We share data only as needed to run the Services, with providers bound by confidentiality and security obligations:
| Category | Purpose |
|---|---|
| Cloud hosting & databases (e.g. AWS) | Store and run the Services |
| Payment gateways (e.g. Razorpay) | Process subscription payments |
| Email, SMS & WhatsApp providers | OTPs, notifications, receipts |
| Analytics & error monitoring | Usage insights, crash and bug reports |
| AI model providers | Power AI features, only with the data needed for that request |
We may also disclose data: to comply with law, court order or a lawful request from a government authority; to protect the rights, safety or property of Tripa, our users or others; or to a successor in case of a merger, acquisition or sale of assets (with this Policy continuing to apply).
6. Cookies & Analytics
- Essential cookies keep you logged in and secure your session. The Services will not work properly without them.
- Preference cookies remember settings such as language or theme.
- Analytics cookies help us understand how the website and product are used.
You can block or delete cookies in your browser settings, but some features may then stop working.
7. Data Retention
- Account data: kept while your account is active.
- Customer Data: kept during your subscription and up to 30 days after cancellation, then deleted (backups are overwritten in their normal cycle).
- Billing and invoice records: kept for the period required under tax and accounting laws (generally up to 8 years).
- Logs: kept for a limited period for security and debugging, typically up to 180 days, or longer where required by law.
8. Security
We use reasonable security practices, including HTTPS/TLS encryption in transit, encrypted password storage, role-based access controls, restricted staff access, regular backups and monitoring. No system is 100% secure; if a personal data breach occurs, we will notify affected users and the authorities as required by law. Please keep your password private and enable any extra security features we offer.
9. Storage & Transfers
Data is primarily stored on servers in India or with reputed cloud providers. Some service providers (e.g. email or AI providers) may process data outside India. Any such transfer will be made only to countries not restricted by the Government of India and with appropriate safeguards.
10. Your Rights
Subject to applicable law, you have the right to:
- Access a summary of the personal data we hold about you and how it is processed
- Correct, complete or update inaccurate data
- Request erasure of data that is no longer needed (subject to legal retention)
- Withdraw consent
- Nominate another person to exercise your rights in case of death or incapacity
- Raise a grievance with us, and if unresolved, with the Data Protection Board of India
Most account details can be edited in your settings. For other requests, email privacy@tripa.in. We may need to verify your identity before acting.
11. Children
The Services are meant for businesses and are not directed at anyone under 18. We do not knowingly collect personal data of children. If you believe a child has given us data, contact us and we will delete it.
12. Communications
We will send essential service messages (such as OTPs, invoices and security notices) as long as you have an account. You can unsubscribe from marketing emails anytime using the link in the email or by contacting us.
13. Changes to This Policy
We may update this Policy from time to time. The latest version will always be on this page with the "Last updated" date. For significant changes, we will notify you by email or in-app.
14. Grievance Officer & Contact
In accordance with the IT Act, 2000 and the DPDP Act, 2023, you may contact our Grievance Officer:
Tripa
Email: info@tripa.in
Website: tripa.in
Address: Dhadi tower, Bahuguna Colony, Ajabpur Khurd, Dehradun, Uttarakhand 248121
We will acknowledge your complaint within 24–48 hours and aim to resolve it within 30 days.