Skip to content
TripsToPahar

Privacy policy

Last updated 4 October 2026

Read the latest version online

This privacy policy explains how TripToPahar collects, uses, shares and protects personal data when you use triptopahar.com, the TripToPahar app, the TripToPahar Host app and the host dashboard (the "Service"). It covers travelers, hosts and visitors who do not have an account.

We follow the Digital Personal Data Protection Act, 2023 and its rules, and the Information Technology Act, 2000 and its rules. Under the DPDP Act, TripToPahar is the Data Fiduciary for the personal data described here.

1. Who we are

TripToPahar is a sole proprietorship owned and operated by Deep Saha, Ghogomali, Siliguri, West Bengal 734006, India. For any question about this policy or your data, write to [email protected] (see "Contact and Grievance Officer" below).

2. The short version

  • We collect what we need to run a homestay directory: your account details, the homestays you save and contact, your reviews and, for hosts, the listing, verification documents and billing details.
  • Travelers do not pay through TripToPahar, so we never see their payment details. Hosts' plan payments are handled by Razorpay, Apple or Google; we never store card numbers or UPI PINs.
  • When you send an inquiry, the host you chose receives your details so they can reply. Your email address and phone number are never shown publicly.
  • We do not sell your personal data and do not show third-party advertising.
  • You can see, correct and delete your data, and delete your account from inside the app or website.

3. What we collect

Everyone who uses the Service:

  • Device and usage information: IP address, device type and model, operating system, app version, browser, language, approximate location from IP, pages and screens viewed, taps and clicks, searches and the homestays you view, and crash and error reports.
  • Location: Your device's precise location, only if you allow it and choose "Near me" (traveler app) or place your homestay on the map (host app).
  • Messages to us: Your name, email, phone number and what you write when you use the contact form or open a support request, and any files you attach.

Travelers:

  • Account: Name, email address, password (stored only as a secure hash), optional mobile number and profile photo. If you sign in with Google or Apple, we receive your name, email address (or Apple's private relay address) and an account identifier from them.
  • Activity: Homestays you save, recent searches, inquiries you send (dates, number of guests, message, and the name, phone and email you enter), whether the host replied, reviews, ratings and review photos, and reports you make.
  • Review protection: When you post a review, we store a one-way coded form (hash) of your IP address and device identifier to detect fake and duplicate reviews. We cannot turn these back into the original values.

Hosts:

  • Account: Name, email address, mobile number, password (as a hash) or Google/Apple sign-in.
  • Listing: Homestay name, address, map location, booking phone, WhatsApp and alternate numbers, email, website and social links, rooms, prices, amenities, policies, photos, host name, bio, photo and languages.
  • Verification and claims: Documents you upload to prove ownership, identity, address, phone or location, such as Aadhaar (masked if you choose), PAN, a driving licence, utility bills or property records.
  • Billing: Plan, billing name, address, state and GSTIN, invoices, and payment and subscription references from Razorpay, Apple or Google. We do not receive or store full card numbers, CVVs, UPI PINs or bank passwords.
  • Performance: Listing views, inquiries received, notes you add to inquiries and your replies to reviews.

From other sources: sign-in details from Google or Apple, payment status from Razorpay, RevenueCat, Apple and Google, and, for listings we created before the host joined, a homestay's business name, location and business contact details from public sources such as OpenStreetMap and openly published directories.

4. App permissions

The apps ask for these permissions only when a feature needs them. You can refuse or turn them off in your device settings, and the rest of the app still works.

  • Location (while using the app): To show homestays near you, or to place your homestay on the map. Never collected in the background.
  • Camera and photos: To add a profile photo, review photos, homestay photos, support attachments or verification documents. Location data embedded in photos is removed when they are uploaded.
  • Notifications: To tell you about replies, inquiries, reviews, plan changes and support requests.

The apps do not access your contacts or microphone.

5. How we use your data

  • To create and run your account and keep you signed in.
  • To show homestays, search results and homestays near you, and to remember your saved homestays and recent searches.
  • To send your inquiry to the host you chose, and to show hosts the inquiries they received.
  • To publish and moderate reviews and listings, and to detect fake reviews, spam, fraud and abuse.
  • To review listings, process claims and verify hosts.
  • To run host plans: take payments, issue GST invoices, apply plan features and handle renewals and refunds.
  • To send service emails and notifications, such as email verification, password resets, replies, inquiry alerts, plan receipts and support replies.
  • To answer support requests and complaints.
  • To measure how the Service is used, fix errors and improve it, using analytics and crash reports.
  • To meet legal, tax and accounting duties and respond to lawful requests from authorities.

We process your data on the basis of the consent you give when you create an account, send an inquiry, list a homestay or allow a permission, and for the legitimate uses the DPDP Act allows, such as when you voluntarily give us data for a purpose, to comply with law or a court order, and to respond to emergencies. You can withdraw your consent at any time (see "Your rights"); this does not affect processing that already took place, but we may then be unable to provide parts of the Service.

We do not use your data for automated decisions that have legal or similarly significant effects on you, and we do not sell it or use it for third-party advertising.

6. What others can see

  • Public: Reviews show your name, rating, text and photos. Host listings show the homestay details listed in our Terms, including booking phone and WhatsApp numbers, host name, bio and photo.
  • The host you contact: Sees that you contacted them and, if you were signed in, your name. With the inquiry form, they also get the name, phone, email, dates, guests and message you entered. Once a host has your details, they handle them for your stay and are responsible for them.
  • Never public: Your email address, a traveler's phone number, passwords, verification documents and billing details.

7. Who we share data with

We share personal data only as follows:

  • Hosts: The details of inquiries you send them, as described above.
  • Service providers: Companies that process data for us under contract and only on our instructions:
  • PostHog: Product analytics, session recording (with text you type masked) and error tracking; servers in the United States.
  • Sentry: Crash and error reports; United States.
  • Expo, Apple and Google: Delivering push notifications to the apps.
  • Google and Apple: Sign in with Google and Sign in with Apple, if you use them.
  • Razorpay: Payments for host plans on the dashboard; your name, email and phone are passed to Razorpay to complete checkout.
  • RevenueCat, the App Store and Google Play: In-app plan purchases in the TripToPahar Host app. RevenueCat receives only an identifier for the homestay, not your name or email.
  • Email provider: Sending service emails.
  • OpenStreetMap and Nominatim: Map tiles and turning place names into map locations. Your browser contacts them directly to load maps.
  • Cloudflare and our hosting provider: Running and protecting the website, apps and API, and storing data.
  • Authorities: Government agencies, courts and law enforcement, when required by law, including requests under the IT Act, which we answer within the time the law sets.
  • Business transfer: A buyer or successor if TripToPahar is sold, merged or reorganised, who must keep protecting your data as this policy says.
  • With your consent: Anyone else, only when you ask us to or agree.

8. Cookies and similar technologies

  • Essential: A secure sign-in cookie on the website (kept for up to 30 days), and sign-in tokens kept in your browser's storage on the host dashboard and in the device's secure storage in the apps. The Service does not work without these.
  • Preferences: Your theme, chosen location, recent searches and form drafts, stored on your device.
  • Analytics: PostHog cookies and similar identifiers that help us understand how the Service is used and fix problems.

We do not use advertising cookies. You can block or delete cookies in your browser settings; if you block essential cookies you will not be able to sign in.

9. Where your data is processed

Our main database and uploaded files are stored on servers we control. Some of the service providers listed above, such as PostHog, Sentry, Expo, RevenueCat, Apple and Google, process data in the United States and other countries. We transfer data outside India only as the DPDP Act and any restrictions notified by the Government of India allow, and with providers that protect it with appropriate safeguards.

10. How long we keep data

  • Account and profile: While your account is open. When you delete your account, your name, email, phone, password and photo are erased at once; your reviews, review photos, saved homestays, notifications, Google/Apple links and analytics profile are deleted; and your past searches are no longer linked to you.
  • Inquiries: An inquiry you sent stays with the host who received it, as part of their records, and in our systems for up to 3 years for dispute handling, then it is deleted or anonymised.
  • Support and contact requests: Up to 3 years after the request is closed.
  • Sign-in sessions: Deleted 30 days after they expire or you sign out. Notification tokens are deleted after 90 days of not being used.
  • Search and usage logs: Up to 12 months, then deleted or aggregated so they no longer identify you.
  • Verification and claim documents: While your host account is open. They are deleted when you delete your host account, together with your host profile and billing details.
  • Invoices and payment records: For at least 8 years, as Indian tax and accounting laws require.
  • Removed content: Information about content removed for breaking our Terms is kept for 180 days, or longer if an investigation or the law requires it.

11. How we protect data

We use reasonable security practices, including encrypted connections (HTTPS), hashed passwords, private storage for verification documents and attachments that can only be opened through short-lived signed links, access limited to the staff who need it, and logs of staff actions. No system is completely secure. If a personal data breach affects you, we will tell you and the Data Protection Board of India as the law requires.

12. Your rights

Under the DPDP Act you have the right to:

  • Access: Get a summary of the personal data we process about you and how we use it, and the names of those we shared it with.
  • Correction and erasure: Correct, complete or update your data, and have it erased when it is no longer needed for the purpose it was collected for, unless the law requires us to keep it.
  • Withdraw consent: As easily as you gave it, for example by turning off a permission or deleting your account.
  • Grievance redressal: Complain to our Grievance Officer, who will respond within the time set below.
  • Nominate: Name a person to exercise your rights if you die or become unable to do so.

You can edit most of your data yourself in account settings. For anything else, email [email protected] from the email address on your account. We may need to confirm your identity first, and we reply within 30 days. If you are not satisfied with our response, you can complain to the Data Protection Board of India.

13. Deleting your account

  • TripToPahar app: Account → Delete account.
  • TripToPahar Host app: More → Delete account.
  • Website or host dashboard: Account settings → Delete account.

If you cannot sign in, email [email protected] from your account's email address and we will delete it for you. Deleting a host account also removes the homestay from search and stops dashboard plans from renewing; App Store and Google Play subscriptions must be cancelled in the store. Data we must keep is held only for the periods above.

14. Children

TripToPahar accounts are for people aged 18 or over. We do not knowingly collect personal data from children, track them or target them. If you believe a child has given us personal data, contact us and we will delete it.

15. Emails and notifications

We send service messages about your account, inquiries, reviews, plans and support requests; these are part of the Service. If we send newsletters or offers, each one has a way to unsubscribe. You can turn off push notifications in the app or in your device settings.

16. Changes to this policy

We may update this policy as the Service or the law changes. The date at the top shows the latest version. If a change materially affects you, we will tell you on the website, in the app or by email before it takes effect, and ask for your consent again where the law requires.

17. Contact and Grievance Officer

If you have a complaint about TripToPahar, a listing, a review, other content or how we handle your personal data, contact our Grievance Officer:

  • Name: Deep Saha
  • Email: [email protected]
  • Address: TripToPahar, Ghogomali, Siliguri, West Bengal 734006, India

We acknowledge every complaint within 24 hours and resolve it within 15 days of receiving it. Requests to remove content that exposes a person's private parts, shows them in a sexual act or impersonates them are acted on within 24 hours. Please include your name, contact details, the link to the listing or content concerned and what you would like us to do.

See also our terms of use and refund and cancellation policy, or contact us with any questions.