Data Storage & Security Policy
At Go For Trip, we prioritize the security and privacy of your corporate travel data. Learn how we protect, store, and manage your information.
Cloud Storage
Secure Cloudflare R2 cloud storage with 99.999999999% durability
Encrypted Data
All data encrypted in transit (TLS 1.3) and at rest (AES-256)
Compliant
Adherent to DPDP Act 2023 and global data protection standards
Corporate Registration Data
- Company Name & Legal Entity Type
- GST Number & GST Certificate (for tax compliance)
- PAN Number & PAN Document (for identity verification)
- Business Email & Contact Information
Travel Booking Data
- Travel lead details & itineraries
- Booking confirmations & invoices
- Payment transaction records
- Service agreements & e-signatures
Secure Cloud Storage (Cloudflare R2)
All uploaded documents are stored in Cloudflare R2, an enterprise-grade cloud storage service with:
- • 99.999999999% (11 nines) data durability
- • Automatic data replication across multiple zones
- • Zero egress fees for data retrieval
- • S3-compatible API with proven reliability
Encryption Standards
We employ industry-standard encryption at every level:
- • In Transit: TLS 1.3 encryption for all API communications
- • At Rest: AES-256 encryption for stored documents
- • Passwords: Bcrypt hashing with salt for user credentials
- • Sessions: JWT tokens with secure signing
Access Control
Strict access controls ensure only authorized users can access data:
- • Role-based access control (Corporate Admin, Member, Staff)
- • Corporate users can only access their own company's data
- • Admin access is logged and audited
- • UUID-based file naming prevents URL guessing
| Data Type | Retention Period | Purpose |
|---|---|---|
| Registration Documents (GST, PAN) | Account duration + 7 years | Legal compliance & audit |
| Travel Bookings & Invoices | 7 years from transaction | Tax & financial records |
| OTP Verification Codes | 10 minutes | One-time verification |
| Session Data | 24 hours of inactivity | User authentication |
| Activity Logs | 90 days | Security monitoring |
Right to Access
Request a copy of all personal data we hold about your company
Right to Correction
Request correction of inaccurate or incomplete data
Right to Deletion
Request deletion of your data (subject to legal retention requirements)
Right to Grievance
Lodge complaints about data handling practices
To exercise your rights: Contact our Data Protection Officer at info@gofortrip.net with your registered corporate email. We will respond within 30 days.
Digital Personal Data Protection Act, 2023
- ✓ Explicit consent for data collection
- ✓ Purpose limitation for data usage
- ✓ Reasonable security safeguards
- ✓ Data principal rights honored
Industry Best Practices
- ✓ OWASP security guidelines
- ✓ PCI-DSS awareness for payments
- ✓ ISO 27001 aligned practices
- ✓ Regular security assessments
Questions About Your Data?
Our team is here to help with any data privacy concerns or requests.
Last Updated: January 2025 | Version 2.0
