Privacy Policy

Last updated [[ date ]]
Draft — not yet reviewed Generated from how Trip Munshi actually stores and uses data today. Fill in the highlighted fields and have it reviewed before you publish it or apply for a payment gateway.

This policy explains what Trip Munshi, operated by [[ legal entity name ]] ("we", "us"), collects, why, and what you can do about it. It covers the Trip Munshi website and application.

1. What we collect

We do not run advertising or third-party tracking on the application. [[ update this line if you add website analytics ]]

2. What we do not collect

We never see or store card, UPI PIN, or bank credentials. Payment is made directly by you through your own UPI or banking app; we only record the amount and reference you report so we can confirm it.

3. Why we use it

We do not sell your data, and we do not use your business records to train models or build products for anyone else.

4. Separation between customers

Each organisation's records are scoped to that organisation and are not visible to any other customer. Within your account, access is limited to the users you invite and the roles you give them.

5. Who else touches your data

We use a small number of service providers to run Trip Munshi — hosting, database, email delivery. They process data only on our instructions.

Current providers: [[ list your hosting, mail and backup providers ]]. Data is hosted in [[ region / country ]].

We may also disclose data where required by law or valid legal process.

6. How long we keep it

We keep your records for as long as your account is active. After cancellation: [[ retention window before deletion, e.g. 90 days ]]. Backups are retained for [[ backup retention, e.g. 30 days ]] and then overwritten. Security and billing logs may be kept longer where the law requires it.

7. Security

Access is protected by password authentication with email verification, per-organisation scoping, and role-based permissions. Traffic is served over HTTPS and passwords are stored hashed. No system is perfectly secure; if a breach affects your data we will notify you promptly. [[ add encryption-at-rest and backup specifics once confirmed ]]

8. Your choices

9. Cookies

We set only the cookies needed to run the application: a session cookie to keep you signed in and a CSRF token to protect forms. No advertising or cross-site tracking cookies are used.

10. Children

Trip Munshi is a business tool and is not directed at anyone under 18.

11. Changes

We may update this policy. Material changes will be notified by email or in the app before they take effect.

12. Contact

Questions, or a request about your data: tripmunshi@gmail.com, [[ registered address ]].