Privacy Policy
We take your privacy seriously. This policy explains exactly what data we collect, why we collect it, who we share it with, and your rights under Indian law.
Regulatory Framework
This Privacy Policy is drafted in accordance with India's Digital Personal Data Protection (DPDP) Act, 2023 and DPDP Rules, 2025; the Information Technology Act, 2000; the Consumer Protection Act, 2019; and Meta's WhatsApp Business Policies. This is not legal advice — consult qualified Indian legal counsel for specific compliance needs.
Quick Navigation
1. Overview & Who We Are
Wandermatic ("we," "us," "our") is an AI-powered travel planning platform that connects travelers with curated itineraries and verified travel agency partners through WhatsApp and our web platform.
We act as the Data Fiduciary under the DPDP Act, 2023, meaning we determine the purpose and means of processing personal data collected through our platform. Our verified Agency Partners act as independent Data Fiduciaries in respect of Traveler data they receive via our lead dispatch system.
Registered Address: Wandermatic, India. | Contact: privacy@wandermatic.com
2. What Data We Collect
| Category | Examples | Purpose | Retention |
|---|---|---|---|
| Identity & Contact Data | WhatsApp phone number, display name | Account identification, delivering WhatsApp chatbot responses | 24 months from last interaction |
| Travel Preference Data | Destination, travel dates, budget per person, group size/type, departure city, meal preferences, special requests | AI itinerary generation, agency lead matching | 24 months |
| Conversation Logs | Full WhatsApp chat history with our AI | Quality assurance, AI model improvement (anonymized), dispute resolution | 24 months |
| Lead & Booking Data | Agency-assigned lead records, lead score, itinerary, booking reference (PNR) | Agency Dashboard, booking confirmation, AI concierge unlock | 7 years (financial regulation compliance) |
| Agency Partner Data | Business name, GST number, bank account details, email, password (hashed), destinations | Agency verification, wallet transactions, lead dispatch | 7 years from account closure |
| Technical & Usage Data | IP address, browser type, device OS, session storage keys (e.g. `wm_profile_prompted`), page views | Security, fraud detection, platform analytics | 90 days |
We practice data minimization — we only collect what is strictly necessary to provide the Service. We do NOT collect passport numbers, payment card details, or biometric data.
3. How We Use Your Data
We process your personal data exclusively for the following specific, stated purposes:
- AI Itinerary Generation: Your travel preferences are sent to Google Gemini API to generate a personalized day-by-day itinerary.
- Agency Lead Matching: Your destination, budget, and group details are used to match you with a geographically and thematically relevant verified Agency Partner.
- WhatsApp Communication: Your phone number is used to deliver AI responses, itinerary updates, and agency connection prompts via WhatsApp.
- Platform Security & Fraud Prevention: Technical logs and session data help us detect abuse, prevent unauthorized access, and maintain platform integrity.
- AI Model Improvement: Aggregated, anonymized conversation patterns (never personally identifiable data) are used to improve our AI prompts and response quality.
- Legal Compliance: We may process and retain certain data to comply with Indian tax laws, court orders, or regulatory requirements.
Purpose Limitation: We will NOT use your data for secondary purposes such as selling to advertisers, behavioral profiling for third-party marketing, or sharing with unrelated businesses without obtaining separate, explicit consent.
4. AI Processing Disclosure
In compliance with India's IT Rules (Intermediary Guidelines) Amendment, 2023 and responsible AI principles, we make the following disclosures:
Google's use of data sent via their API is governed by the Google Cloud Data Processing Addendum. Google states they do not use API data to train their public models without explicit agreement.
5. WhatsApp Communication & Consent
We use Meta's official WhatsApp Business API (not unauthorized third-party tools) to deliver our AI concierge service.
6. Third-Party Sub-Processors
The following third-party services process personal data on our behalf. We have reviewed their data processing practices and, where available, signed Data Processing Addendums (DPAs).
We will notify users of any material changes to this sub-processor list via WhatsApp or email with at least 30 days' notice before the change takes effect.
8. Cross-Border Data Transfers
Some of our sub-processors (Google, Meta) store and process data outside India. These cross-border transfers occur when:
- Your travel preferences are sent to Google Gemini API for itinerary generation (Google Cloud, USA)
- Your WhatsApp messages are transmitted through Meta's global infrastructure (USA)
Data Residency: Your primary database (Supabase) and web hosting (Firebase App Hosting) are both hosted in Mumbai, India (AWS ap-south-1 / Google Cloud asia-south1) — keeping your personal data within Indian borders wherever possible.
We rely on the following safeguards for cross-border transfers to the USA:
- Contractual protections through Data Processing Addendums with each sub-processor
- Sub-processors' compliance with applicable data protection frameworks
- Organizational security measures including access controls and encryption in transit and at rest
DPDP Note: Cross-border data transfer rules under the DPDP Act, 2023 are subject to notification by the Government of India. We will update our practices to comply with any restrictions on data transfer to specific countries once notified.
9. Data Security
We implement industry-standard technical and organizational measures to protect your personal data:
10. Data Retention & Deletion
We retain personal data only for as long as necessary for the stated purpose, and not beyond the periods specified in Section 2 above.
Automatic Deletion: Traveler conversation data older than 24 months is automatically scheduled for deletion. Agency financial records are retained for 7 years as required under the Indian Companies Act and GST regulations.
On Request: Upon a valid Data Erasure Request (email: privacy@wandermatic.com), we will delete your personal data within 30 days unless we are legally obligated to retain it (e.g., for pending legal disputes or statutory compliance).
Upon Account Closure: When an Agency Partner closes their account, all personal data will be deleted within 60 days, except financial transaction records retained for 7 years under applicable law.
11. Your Rights Under the DPDP Act, 2023
You can request a copy of all personal data we hold about you.
→ Email privacy@wandermatic.com with subject: 'Data Access Request'
You can request that we correct inaccurate or incomplete personal data.
→ Email privacy@wandermatic.com with subject: 'Data Correction Request'
You can request deletion of your personal data, subject to legal retention obligations.
→ Email privacy@wandermatic.com with subject: 'Data Deletion Request'
You can withdraw consent for WhatsApp communications at any time by sending 'STOP' to our WhatsApp number. Withdrawal does not affect prior processing.
→ Send 'STOP' on WhatsApp, or email privacy@wandermatic.com
Under the DPDP Act, 2023, you may nominate a person to exercise your data rights on your behalf in case of death or incapacity.
→ Email privacy@wandermatic.com with a written nomination
You may file a complaint with our Grievance Officer. If unresolved, you may escalate to the Data Protection Board of India.
→ Email privacy@wandermatic.com
Response Timeline:
We will acknowledge all Data Principal requests within 72 hours and fulfill them within 30 days. If we are unable to fulfill a request (e.g., due to legal obligations), we will explain the reason in writing. If you are unsatisfied with our response, you may escalate to the Data Protection Board of India once constituted under the DPDP Act.12. Children's Privacy
Wandermatic is not intended for use by persons under the age of 18. We do not knowingly collect personal data from minors. If you believe a minor has provided data to our platform, please contact us immediately at privacy@wandermatic.com and we will delete the data promptly. Under the DPDP Act, 2023, processing of personal data of children requires verifiable parental consent, which our platform is not currently configured to obtain.
13. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or applicable law. When we make material changes, we will:
- Update the "Last Updated" date at the top of this page
- Send a notification via WhatsApp to active users at least 30 days before the change takes effect
- For Agency Partners: send an email notification to the registered email address
Your continued use of the Service after the effective date of the revised Policy constitutes acceptance of the changes.
14. Contact & Grievance Officer
Your Privacy in One Line
We use your travel preferences to generate AI itineraries and connect you with agencies. We share your data only with the sub-processors listed above, never sell it to advertisers, and you can delete it anytime.
This Privacy Policy was last updated on August 6, 2026 and is effective from the same date.
