DPDP Act 2023 Compliant

Privacy Policy

We take your privacy seriously. This policy explains exactly what data we collect, why we collect it, who we share it with, and your rights under Indian law.

Last Updated: August 6, 2026 Governing Law: India (DPDP Act, 2023)

Regulatory Framework

This Privacy Policy is drafted in accordance with India's Digital Personal Data Protection (DPDP) Act, 2023 and DPDP Rules, 2025; the Information Technology Act, 2000; the Consumer Protection Act, 2019; and Meta's WhatsApp Business Policies. This is not legal advice — consult qualified Indian legal counsel for specific compliance needs.

1. Overview & Who We Are

Wandermatic ("we," "us," "our") is an AI-powered travel planning platform that connects travelers with curated itineraries and verified travel agency partners through WhatsApp and our web platform.

We act as the Data Fiduciary under the DPDP Act, 2023, meaning we determine the purpose and means of processing personal data collected through our platform. Our verified Agency Partners act as independent Data Fiduciaries in respect of Traveler data they receive via our lead dispatch system.

Registered Address: Wandermatic, India. | Contact: privacy@wandermatic.com

2. What Data We Collect

CategoryExamplesPurposeRetention
Identity & Contact DataWhatsApp phone number, display nameAccount identification, delivering WhatsApp chatbot responses24 months from last interaction
Travel Preference DataDestination, travel dates, budget per person, group size/type, departure city, meal preferences, special requestsAI itinerary generation, agency lead matching24 months
Conversation LogsFull WhatsApp chat history with our AIQuality assurance, AI model improvement (anonymized), dispute resolution24 months
Lead & Booking DataAgency-assigned lead records, lead score, itinerary, booking reference (PNR)Agency Dashboard, booking confirmation, AI concierge unlock7 years (financial regulation compliance)
Agency Partner DataBusiness name, GST number, bank account details, email, password (hashed), destinationsAgency verification, wallet transactions, lead dispatch7 years from account closure
Technical & Usage DataIP address, browser type, device OS, session storage keys (e.g. `wm_profile_prompted`), page viewsSecurity, fraud detection, platform analytics90 days

We practice data minimization — we only collect what is strictly necessary to provide the Service. We do NOT collect passport numbers, payment card details, or biometric data.

3. How We Use Your Data

We process your personal data exclusively for the following specific, stated purposes:

  • AI Itinerary Generation: Your travel preferences are sent to Google Gemini API to generate a personalized day-by-day itinerary.
  • Agency Lead Matching: Your destination, budget, and group details are used to match you with a geographically and thematically relevant verified Agency Partner.
  • WhatsApp Communication: Your phone number is used to deliver AI responses, itinerary updates, and agency connection prompts via WhatsApp.
  • Platform Security & Fraud Prevention: Technical logs and session data help us detect abuse, prevent unauthorized access, and maintain platform integrity.
  • AI Model Improvement: Aggregated, anonymized conversation patterns (never personally identifiable data) are used to improve our AI prompts and response quality.
  • Legal Compliance: We may process and retain certain data to comply with Indian tax laws, court orders, or regulatory requirements.

Purpose Limitation: We will NOT use your data for secondary purposes such as selling to advertisers, behavioral profiling for third-party marketing, or sharing with unrelated businesses without obtaining separate, explicit consent.

4. AI Processing Disclosure

In compliance with India's IT Rules (Intermediary Guidelines) Amendment, 2023 and responsible AI principles, we make the following disclosures:

Model UsedGoogle Gemini (via Google Cloud AI Platform API)
Data Sent to AITravel preferences, budget, destination, group type, and conversation history context
Data NOT Sent to AIRaw phone numbers, real names, or payment details are never included in Gemini API prompts
AI Output NatureAll itineraries are AI-generated suggestions. They do NOT constitute confirmed bookings or professional travel advice.
Human OversightAI outputs are not autonomously actioned — a human Agency Partner reviews and finalises all booking quotations.
Opt-Out of AIYou may stop the AI service at any time by sending 'STOP' on WhatsApp.

Google's use of data sent via their API is governed by the Google Cloud Data Processing Addendum. Google states they do not use API data to train their public models without explicit agreement.

5. WhatsApp Communication & Consent

We use Meta's official WhatsApp Business API (not unauthorized third-party tools) to deliver our AI concierge service.

Opt-In Mechanism: By initiating a conversation with our WhatsApp chatbot, you provide free, specific, and informed consent to receive AI itineraries, travel recommendations, and agency connection prompts. This is an affirmative user-initiated action.
Promotional Messages: We will NEVER send unsolicited promotional broadcast messages. All messages are in direct response to your enquiry or relevant to your active travel planning session.
TRAI Compliance: We comply with TRAI's Telecom Commercial Communications Customer Preference Regulations (TCCCPR) by maintaining a registered sender ID and not contacting users registered on the National Do Not Call Registry for commercial purposes.
Opt-Out: Send 'STOP' or 'Unsubscribe' to our WhatsApp number at any time. Your preference will be actioned within 24 hours. Essential service messages (e.g., data deletion confirmation) may still be sent.
Meta's Role: Messages are delivered through Meta's infrastructure. Meta's privacy policy governs their handling of metadata. We do not control Meta's data practices.

6. Third-Party Sub-Processors

The following third-party services process personal data on our behalf. We have reviewed their data processing practices and, where available, signed Data Processing Addendums (DPAs).

Meta Platforms (WhatsApp Business API)Messaging & Communication
Data SharedWhatsApp phone number, message content (travel preferences, destination, budget, itinerary text)
Processing LocationUSA (Meta Inc. global infrastructure)
Google LLC (Gemini AI / Google Cloud)AI Itinerary Generation & Cloud Infrastructure
Data SharedTravel preferences, destination, budget, group type, conversation context (anonymized prompts sent to Gemini API)
Processing LocationUSA / Global (Google Cloud)
Supabase Inc.Database Storage & Authentication
Data SharedWhatsApp phone, name, lead details, session data, conversation logs, agency profile, wallet transactions
Processing LocationAWS ap-south-1 (Mumbai, India)
Mem0.aiAI Memory & Personalization
Data SharedAnonymized travel preferences, past interaction summaries to personalize future AI responses
Processing LocationUSA
DPA / Privacy RefMem0 Privacy Policy
Google LLC (Firebase App Hosting & Analytics)Web Application Hosting, CDN & Analytics
Data SharedServer logs, IP addresses, browser metadata, page views, session duration, device/OS type, user behaviour events (Firebase Analytics)
Processing LocationGoogle Cloud (asia-south1, Mumbai for hosting; global for Analytics)
Meta Platforms Inc. (Meta Pixel)Advertising & Conversion Tracking
Data SharedHashed browser identifiers, page view events, button click events, IP address (hashed), device/browser metadata. No personally identifiable travel preference data is shared.
Processing LocationUSA (Meta Inc. global infrastructure)
DPA / Privacy RefMeta Business Tools Terms

We will notify users of any material changes to this sub-processor list via WhatsApp or email with at least 30 days' notice before the change takes effect.

7. Cookies & Session Storage

Our web platform uses minimal browser storage mechanisms:

Storage TypeKey / NamePurposeDuration
Session Storagewm_profile_promptedPrevents the Agency Profile completion modal from reappearing on every page refresh within the same browser sessionBrowser session only (cleared on tab close)
Supabase Auth Cookiesb-[project]-auth-tokenStores authenticated session token for Agency Dashboard login7 days (configurable)
Browser LocalStoragesupabase.auth.tokenPersists login session across browser restarts for authenticated Agency PartnersUntil explicit logout
Firebase Analytics Cookie_ga, _ga_*, _gidGoogle Firebase Analytics — tracks page views, session duration, and user flow for platform improvement. No personally identifiable data is linked.2 years (_ga), 24 hours (_gid)
Meta Pixel Cookie_fbp, _fbcMeta (Facebook) Pixel — tracks website visits and button click events for advertising campaign measurement and conversion tracking.90 days

Analytics & Advertising Cookies: We use Firebase Analytics (Google) to understand how users navigate our platform, and Meta Pixel to measure the effectiveness of our advertising campaigns. These cookies do not link to your WhatsApp identity or travel preference data.

Your Cookie Choices: You can opt out of Firebase Analytics via Google Analytics Opt-out and Meta Pixel via Facebook Ad Preferences. Clearing browser cookies will remove all stored tracking identifiers.

You can clear session storage and cookies at any time through your browser settings. Clearing Supabase auth cookies will log you out of the Agency Dashboard.

8. Cross-Border Data Transfers

Some of our sub-processors (Google, Meta) store and process data outside India. These cross-border transfers occur when:

  • Your travel preferences are sent to Google Gemini API for itinerary generation (Google Cloud, USA)
  • Your WhatsApp messages are transmitted through Meta's global infrastructure (USA)

Data Residency: Your primary database (Supabase) and web hosting (Firebase App Hosting) are both hosted in Mumbai, India (AWS ap-south-1 / Google Cloud asia-south1) — keeping your personal data within Indian borders wherever possible.

We rely on the following safeguards for cross-border transfers to the USA:

  • Contractual protections through Data Processing Addendums with each sub-processor
  • Sub-processors' compliance with applicable data protection frameworks
  • Organizational security measures including access controls and encryption in transit and at rest

DPDP Note: Cross-border data transfer rules under the DPDP Act, 2023 are subject to notification by the Government of India. We will update our practices to comply with any restrictions on data transfer to specific countries once notified.

9. Data Security

We implement industry-standard technical and organizational measures to protect your personal data:

Encryption in TransitAll data transmitted between your device, our servers, and sub-processors is encrypted via TLS 1.2+
Encryption at RestDatabase records in Supabase are encrypted at rest using AES-256 encryption
Access ControlsAgency Dashboard data is access-controlled via Row-Level Security (RLS) policies in Supabase — agencies can only view leads assigned to them
Password SecurityAgency Partner passwords are hashed using bcrypt. We never store plaintext passwords.
Breach NotificationIn the event of a personal data breach, we will notify affected users and the Data Protection Board of India within 72 hours as required by law
No Sensitive Data in AI PromptsWe strip phone numbers and real names from AI prompts before sending to Google Gemini API

10. Data Retention & Deletion

We retain personal data only for as long as necessary for the stated purpose, and not beyond the periods specified in Section 2 above.

Automatic Deletion: Traveler conversation data older than 24 months is automatically scheduled for deletion. Agency financial records are retained for 7 years as required under the Indian Companies Act and GST regulations.

On Request: Upon a valid Data Erasure Request (email: privacy@wandermatic.com), we will delete your personal data within 30 days unless we are legally obligated to retain it (e.g., for pending legal disputes or statutory compliance).

Upon Account Closure: When an Agency Partner closes their account, all personal data will be deleted within 60 days, except financial transaction records retained for 7 years under applicable law.

11. Your Rights Under the DPDP Act, 2023

Right to Access

You can request a copy of all personal data we hold about you.

Email privacy@wandermatic.com with subject: 'Data Access Request'

Right to Correction

You can request that we correct inaccurate or incomplete personal data.

Email privacy@wandermatic.com with subject: 'Data Correction Request'

Right to Erasure

You can request deletion of your personal data, subject to legal retention obligations.

Email privacy@wandermatic.com with subject: 'Data Deletion Request'

Right to Withdraw Consent

You can withdraw consent for WhatsApp communications at any time by sending 'STOP' to our WhatsApp number. Withdrawal does not affect prior processing.

Send 'STOP' on WhatsApp, or email privacy@wandermatic.com

Right to Nominate

Under the DPDP Act, 2023, you may nominate a person to exercise your data rights on your behalf in case of death or incapacity.

Email privacy@wandermatic.com with a written nomination

Right to Grievance Redressal

You may file a complaint with our Grievance Officer. If unresolved, you may escalate to the Data Protection Board of India.

Email privacy@wandermatic.com

Response Timeline:

We will acknowledge all Data Principal requests within 72 hours and fulfill them within 30 days. If we are unable to fulfill a request (e.g., due to legal obligations), we will explain the reason in writing. If you are unsatisfied with our response, you may escalate to the Data Protection Board of India once constituted under the DPDP Act.

12. Children's Privacy

Wandermatic is not intended for use by persons under the age of 18. We do not knowingly collect personal data from minors. If you believe a minor has provided data to our platform, please contact us immediately at privacy@wandermatic.com and we will delete the data promptly. Under the DPDP Act, 2023, processing of personal data of children requires verifiable parental consent, which our platform is not currently configured to obtain.

13. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or applicable law. When we make material changes, we will:

  • Update the "Last Updated" date at the top of this page
  • Send a notification via WhatsApp to active users at least 30 days before the change takes effect
  • For Agency Partners: send an email notification to the registered email address

Your continued use of the Service after the effective date of the revised Policy constitutes acceptance of the changes.

14. Contact & Grievance Officer

General Enquiries & Agency Supportcontact@wandermatic.comGeneral questions, agency partner queries, sub-processor/DPA questions
Privacy, Data Rights & DPDP Grievance Officerprivacy@wandermatic.comData access, correction, deletion requests, and formal DPDP complaints — acknowledged within 24 hours, resolved within 15 business days

Your Privacy in One Line

We use your travel preferences to generate AI itineraries and connect you with agencies. We share your data only with the sub-processors listed above, never sell it to advertisers, and you can delete it anytime.

This Privacy Policy was last updated on August 6, 2026 and is effective from the same date.