Skip to content
Lexi Trip

Lexi Trip Privacy Policy

Version 1.0 · Effective Date 01/08/2026 · Data Fiduciary: Bani Global Industries LLP

Data Fiduciary / Publisher
Bani Global Industries LLP (LLPIN ACI-6373; PAN ABDFB4019N; GSTIN 07ABDFB4019N1ZR), registered office at 2-A/3, Kundan Mansion, Asaf Ali Road, New Delhi – 110002 (parent group website: baniglobal.in).
Platform
Lexi Trip — lexitrip.in and the Lexi Trip mobile applications.
Language / Currency / Dates / Time
English (India) · INR (₹) · DD/MM/YYYY · IST, 12-hour
Grievance Officer / Data Protection Contact
Mr. Bani Pal Singh · banipal@lexitrip.in · Toll-free 1800-313-2005
Contents

1. Preamble and Scope

1.1 This privacy policy (“Privacy Policy”) governs the collection, use, storage, disclosure, transfer, retention and deletion of personal data by Bani Global Industries LLP (“Lexi Trip”, “we”, “us”, “our”) through the Platform. Lexi Trip operates the Platform as a full-service, multi-service, multi-supplier online travel aggregator (“OTA”) — a technology platform and travel booking portal facilitating bookings across hotels/accommodation, flights, packages/custom trips, visa assistance, transfers/cabs/buses, activities/experiences, cruises, travel insurance and future travel verticals (each an “Underlying Service”).

1.2 Lexi Trip is a Facilitator and, where expressly stated on a specific transaction, a Disclosed Agent of the upstream airline, hotel, cruise line, cab/bus/activity operator, insurer, embassy/consulate or immigration authority (each such upstream provider, a “Supplier”). Lexi Trip is not itself the airline, hotel, cruise line, cab/bus/activity operator, insurer, embassy/consulate or immigration authority. Lexi Trip is not a Payment Aggregator, Payment Gateway or Payment System Operator under the Payment and Settlement Systems Act, 2007 or the RBI (Regulation of Payment Aggregators) Directions, 2025; card and payment-instrument data are processed and stored solely by authorised payment service providers (“PSPs”) engaged by Lexi Trip.

1.3 For purposes of the Digital Personal Data Protection Act, 2023 (“DPDP Act”) and the Digital Personal Data Protection Rules, 2025 (“DPDP Rules”), Lexi Trip acts as a Data Fiduciary in respect of the personal data it determines the purpose and means of processing. For purposes of the Information Technology Act, 2000 (“IT Act”) and the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 (“Intermediary Rules”), Lexi Trip is an intermediary within the meaning of Section 2(w) of the IT Act.

1.4 This Privacy Policy applies to:

1.4.1 visitors browsing the Platform without registration;

1.4.2 registered users of the Platform;

1.4.3 persons who make a booking through the Platform (each, a “Customer”);

1.4.4 persons in respect of whom a booking is made — including where the Customer books for a third party (each such person, whether or not the Customer, a “Traveller”);

1.4.5 corporate, business, LLP, partnership, proprietorship and institutional Customers, and their authorised bookers and employees;

1.4.6 parents/lawful guardians consenting to the processing of a minor Traveller’s personal data; and

1.4.7 recipients of Lexi Trip communications, whether or not registered.

1.5 By accessing or using the Platform, or by permitting a booking to be made on your behalf, you acknowledge that you have read and understood this Privacy Policy. Where applicable, your specific, informed, free, unconditional and unambiguous consent will additionally be captured through in-Platform consent flows in the manner required by Section 6 of the DPDP Act.

2. Definitions

2.1 In this Privacy Policy, capitalised terms have the meanings set out below. Terms defined in the Lexi Trip Master Customer Terms & Conditions (the “Master Terms”) carry the same meaning here unless the context requires otherwise.

2.1.1 "Aggregator Partner"
means a wholesale, consolidator or bed-bank aggregator, GDS, XML/API distribution partner or inventory aggregator through which Lexi Trip sources Underlying Services.
2.1.2 "Booking"
means a confirmed reservation of an Underlying Service made through the Platform.
2.1.3 "Booking Legal Snapshot"
means the immutable per-Booking record capturing the notice served, consents captured, notice/policy version identifiers, IP address, device identifiers and timestamps at the point of Booking, retained as evidence of consent for the purposes of Section 6 of the DPDP Act.
2.1.4 "Consent Manager"
has the meaning given in Section 6(7) of the DPDP Act read with the DPDP Rules.
2.1.5 "Cookies"
means small text files, pixels, tags, SDK identifiers, local storage items and similar technologies used on the Platform.
2.1.6 "Data Fiduciary", "Data Principal" and "Data Processor"
have the meanings given in Section 2 of the DPDP Act.
2.1.7 "Device Data"
means IP address, device identifiers (IMEI, IDFA, GAID, MAC), operating system, browser type, mobile network, crash logs, referral URLs and similar telemetry.
2.1.8 "Fulfilment Partner"
means a ground-handling, meet-and-assist, visa lodgement, courier, KYC verification, call-centre or on-destination service partner engaged for delivery of an Underlying Service.
2.1.9 "Lexi Trip Fees"
means the service fees, convenience fees, mark-up, commission or margin retained by Lexi Trip in respect of a Booking, as more fully described in the Master Terms.
2.1.10 "Merchant of Record" and "Payment Collection Entity"
have the meanings given in the Master Terms.
2.1.11 "Personal Data"
means any data about an individual who is identifiable by or in relation to such data, as defined in Section 2(t) of the DPDP Act.
2.1.12 "PSP"
means a bank, payment aggregator, payment gateway, card network, UPI PSP or other regulated payment service provider engaged to process payments in connection with a Booking.
2.1.13 "Sensitive Personal Data or Information" or "SPDI"
has the meaning given in Rule 3 of the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 ("SPDI Rules"), and includes passwords, financial information, physical/physiological/mental-health condition, sexual orientation, medical records, and biometric information, to the extent applicable.
2.1.14 "Service Provider" and "Third-Party Service Provider"
have the meanings given in the Master Terms.
2.1.15 "Supplier"
has the meaning given in clause 1.2.
2.1.16 "Traveller"
has the meaning given in clause 1.4.4.
2.1.17 "User Content"
means reviews, ratings, photographs, chat messages, complaints and other content submitted by users to the Platform.

3. Categories of Personal Data Collected

3.1 Lexi Trip collects only such Personal Data as is necessary for the specified purposes set out in clause 5. The categories of Personal Data collected include:

3.1.1 Identity Data — full name, gender, date of birth, nationality, salutation, photograph (where required by a Supplier).

3.1.2 Contact Data — mobile number, alternate contact number, email address, postal/billing address, emergency contact.

3.1.3 KYC and Travel Document Data — Aadhaar (in masked form, where used for KYC), PAN, passport number, passport scan, visa documents, driving licence, OCI/PIO card, government-issued photo ID, PNR, ticket numbers.

3.1.4 Travel Preferences — meal preferences, seat preferences, room preferences, accessibility requirements, loyalty programme numbers, travel history.

3.1.5 Payment Metadata — transaction reference, order ID, amount, currency, payment mode, last-four digits of card, PSP token, refund/chargeback status. Lexi Trip does not collect or store the full card PAN, CVV, PIN, card expiry or full bank account credentials; these are collected and stored by the PSP under the RBI (Regulation of Payment Aggregators) Directions, 2025 and applicable card-network rules.

3.1.6 Device Data, Location Data and Analytics Data — Device Data as defined, IP address, precise or coarse location (with consent) for cabs, transfers and pick-up features, in-app clickstream, session recordings, app version, crash logs, and analytics identifiers.

3.1.7 Call Recordings and Communications — recorded voice calls with Lexi Trip customer support (with prior recorded notice and consent), chat transcripts, email correspondence, WhatsApp/SMS logs.

3.1.8 User Content — reviews, ratings, photographs, complaints and other content submitted by users.

3.1.9 Corporate/Business Customer Data — company name, GSTIN, PAN, registered address, authorised booker details, cost-centre codes, project codes.

3.1.10 Minor Traveller Data — name, date of birth, gender, passport/ID, medical/accessibility requirements — collected only through, and with the verifiable consent of, the parent/lawful guardian in accordance with Section 9 of the DPDP Act.

3.1.11 Sensitive/High-Risk Data — passport, visa, biometric data captured for e-visa purposes, health/medical information supplied for travel insurance underwriting or in-trip medical emergencies, dietary/religious restrictions where indicative of belief. Such data is subject to the heightened-safeguards track described in clause 4.5.

4. Non-Negotiable Data-Handling Architecture

4.1 Supplier identity non-disclosure. Lexi Trip does not name any upstream Supplier, Aggregator Partner, consolidator or Fulfilment Partner at the enquiry, quotation, checkout or Booking Confirmation stage. Data-sharing disclosures in this Privacy Policy are therefore phrased generically by category — namely, “Suppliers”, “Aggregator Partners”, “Fulfilment Partners”, “Payment Service Providers”, “Insurance Partners”, “Visa Partners”, “IT and Cloud Vendors”, “Analytics Providers”, and “Auditors and Advisors”. The only exceptions are:

  1. (a)the consumption-point operator whose identity is necessarily disclosed on the ticket, policy schedule or voucher (e.g., the operating airline on an e-ticket, the hotel on a voucher, the insurer on the policy schedule); and
  2. (b)disclosures required by a court, tribunal or governmental authority, or otherwise required by law, in the manner set out in Rule 6 of the SPDI Rules and Rule 3(7) of the Intermediary Rules, and Sections 7 and 17 of the DPDP Act.

4.2 Non-interference by Lexi Trip. Lexi Trip cannot and does not override any Supplier’s or Partner’s privacy or data-handling terms. Lexi Trip’s role is strictly limited to conveying and coordinating Personal Data as required for fulfilment of the Underlying Service. Once Personal Data is transmitted to a Supplier, that Supplier processes such data as an independent Data Fiduciary under its own privacy policy, and Lexi Trip is not responsible for that downstream processing.

4.3 Booking Legal Snapshot. For every Booking, Lexi Trip captures and preserves a Booking Legal Snapshot as the definitive record of the notice served, consents captured, versions of policies applicable, and timestamps. The Booking Legal Snapshot is treated as evidence of consent under Section 6 of the DPDP Act and will be produced on reasonable written request to the Data Principal, or to a court, tribunal or regulator, subject to lawful process.

4.4 Consent granularity. Lexi Trip captures consent in separate, uncoupled tracks. No consent track is a pre-condition for any other. No consent is captured through pre-ticked boxes. The tracks are:

4.4.1 booking/service fulfilment consent (necessary for the transaction);

4.4.2 payments and anti-fraud consent;

4.4.3 marketing and promotional communications consent;

4.4.4 analytics and personalisation consent (including Google Analytics, Google Ads, behavioural analytics and user-behaviour tracking as described in clause 10);

4.4.5 call-recording consent;

4.4.6 location/device data consent for cabs, transfers and app features;

4.4.7 sharing with insurers, visa authorities and other regulated entities.

4.5 Heightened-safeguards track. Sensitive/high-risk data — passport, visa documents, biometrics captured for e-visa, health information for insurance, minor-Traveller data, and payment-instrument data — is processed under a heightened-safeguards track: purpose-limited, minimally collected, encrypted in transit and at rest, restricted to a need-to-know internal role set, retained only for the visa, insurance or regulatory period required, and disclosed only to the destination-country visa authority, the licensed insurer or the PSP (as the case may be) with the Data Principal’s express consent.

5. Purposes of Processing

5.1 Lexi Trip processes Personal Data for the following purposes:

5.1.1 to create and administer user accounts and profiles on the Platform;

5.1.2 to receive, process, confirm, modify, cancel and refund Bookings;

5.1.3 to coordinate with Suppliers, Aggregator Partners and Fulfilment Partners for delivery of the Underlying Service;

5.1.4 to process payments, effect refunds to the original mode of payment, and prevent, detect and investigate fraud, money-laundering and chargebacks;

5.1.5 to provide pre-Booking, in-trip and post-Booking customer support;

5.1.6 to handle visa and passport-related work through Visa Partners;

5.1.7 to coordinate travel insurance issuance and claims with Insurance Partners;

5.1.8 to comply with statutory, regulatory, tax, aviation, immigration, foreign-exchange, anti-money-laundering, insurance and consumer-protection obligations;

5.1.9 to handle grievances, disputes, chargeback representations and legal proceedings;

5.1.10 to operate analytics, product improvement, A/B testing, security telemetry and Platform health monitoring;

5.1.11 to send marketing and promotional communications (only where separate consent has been obtained under clause 4.4.3);

5.1.12 to enforce the Master Terms, this Privacy Policy and other applicable policies, and to establish, exercise or defend legal claims;

5.1.13 to carry out security audits, information-security incident response and business-continuity operations; and

5.1.14 for such other purposes as are notified to the Data Principal at the point of collection, and to which the Data Principal has consented.

6. Legal Bases for Processing

6.1 Consent (Section 6, DPDP Act). The primary legal basis for processing Personal Data is the Data Principal’s specific, informed, free, unconditional and unambiguous consent, given by clear affirmative action for the purposes notified under Section 5 of the DPDP Act.

6.2 Legitimate uses (Section 7, DPDP Act). Lexi Trip additionally relies on the legitimate uses recognised in Section 7 of the DPDP Act, including:

6.2.1 processing for the specified purpose for which the Data Principal has voluntarily provided Personal Data and has not indicated non-consent;

6.2.2 processing for employment-related purposes in respect of Lexi Trip personnel;

6.2.3 processing to respond to a medical emergency involving a threat to the life or immediate health of any Data Principal or Traveller;

6.2.4 processing to provide medical treatment or health services during an epidemic, outbreak of disease or other threat to public health;

6.2.5 processing to ensure safety of, or provide assistance or services to, any individual during any disaster or breakdown of public order;

6.2.6 processing for compliance with any judgment, decree or order under Indian law, or for compliance with any law for the time being in force in India; and

6.2.7 such other legitimate uses as are notified by the Central Government from time to time.

6.3 SPDI Rules savings. To the extent still applicable pending phase-out by the DPDP Rules, Lexi Trip’s processing is also grounded on the lawful-purpose basis under Rules 5 and 6 of the SPDI Rules, and body-corporate compliance under Section 43-A of the IT Act.

6.4 Contractual necessity. Processing necessary to give effect to a contract for an Underlying Service, and any pre-contractual steps taken at the Data Principal’s request, is undertaken on that basis.

7. Sharing and Disclosure

7.1 Consistent with clause 4.1, disclosures of Personal Data are described by generic recipient category. Lexi Trip shares Personal Data with:

7.1.1 Suppliers — for delivery of the Underlying Service booked (e.g., airline PNR creation, hotel room allocation, cruise manifest);

7.1.2 Aggregator Partners — for inventory sourcing, distribution, mid-office coordination and reconciliation;

7.1.3 Fulfilment Partners — for meet-and-assist, ground handling, KYC verification, courier delivery of documents and on-destination coordination;

7.1.4 PSPs — limited to the data reasonably required for payment processing, refunds and anti-fraud checks under the RBI (Regulation of Payment Aggregators) Directions, 2025 and card-network rules;

7.1.5 Insurance Partners — for issuance, servicing and claims of travel insurance policies, where the Data Principal has opted in;

7.1.6 Visa Partners and destination-country embassies/consulates/immigration authorities — for lodgement and adjudication of visa applications, with the Data Principal’s express consent;

7.1.7 IT and Cloud Vendors — for hosting, storage, backup, disaster recovery, cybersecurity, CRM, ticketing and communication infrastructure;

7.1.8 Analytics Providers — including Google Analytics, Google Ads and similar behavioural-analytics platforms, subject to clause 10 and the analytics consent track;

7.1.9 Auditors, Legal Advisors and Consultants — for statutory audit, tax audit, internal audit, secretarial compliance, legal advice and litigation;

7.1.10 LLP Affiliates — being any entity that Controls, is Controlled by, or is under common Control with, Lexi Trip, subject to equivalent safeguards;

7.1.11 Successors — any acquirer, transferee or successor entity in the context of a merger, demerger, slump sale, asset transfer, restructuring or insolvency, subject to notice to Data Principals and applicable law; and

7.1.12 Lawful-order recipients — courts, tribunals, law-enforcement agencies, regulators and other governmental authorities, where disclosure is required by, or made in accordance with, applicable law.

7.2 Rule 6 SPDI / Rule 3(7) Intermediary Rules architecture. Where disclosure is not for the purposes of the Booking and is not otherwise covered by the Data Principal’s consent, Lexi Trip will disclose Personal Data only in accordance with Rule 6 of the SPDI Rules and Rule 3(7) of the Intermediary Rules — that is, on a lawful written order from a court or a government agency lawfully authorised for verification of identity or for prevention, detection, investigation, prosecution or punishment of offences — and, wherever the law so permits, will do so without prior notice to the Data Principal.

7.3 No sale of Personal Data. Lexi Trip does not sell Personal Data to third parties in exchange for monetary consideration.

8. Cross-Border Transfers

8.1 Certain Suppliers, Aggregator Partners, PSPs, Insurance Partners, Visa Partners, IT and Cloud Vendors and Analytics Providers may be located outside India. Personal Data may accordingly be transferred to, stored in and processed in jurisdictions outside India.

8.2 Such transfers are made in accordance with Section 16 of the DPDP Act. Lexi Trip may transfer Personal Data to any country or territory outside India, other than any country or territory that the Central Government notifies as restricted for such transfer.

8.3 Safeguards. For all cross-border transfers, Lexi Trip puts in place contractual safeguards with the overseas Supplier, Partner, PSP, insurer or visa authority requiring: (a) purpose limitation; (b) confidentiality; (c) implementation of reasonable security practices consistent with SPDI Rule 8; (d) restrictions on onward transfer; and (e) cooperation with data-breach response.

9. Cookies, Analytics, Device and Location Data

9.1 Categories of Cookies used.

9.1.1 Strictly necessary Cookies — for authentication, session management, load balancing and security. These are set without consent as they are essential for the Platform to function.

9.1.2 Preference Cookies — to remember language, currency and search preferences.

9.1.3 Analytics Cookies — including Google Analytics and similar analytics SDKs used to measure Platform usage, funnel drop-off, feature adoption, session paths, and to conduct A/B testing.

9.1.4 Advertising and Behavioural Cookies — including Google Ads, retargeting pixels and behavioural-tracking SDKs used to serve, measure and optimise advertising, including on third-party websites and apps.

9.2 Consent banner and controls. On first visit, Lexi Trip presents a granular consent banner that permits the Data Principal to accept, reject or configure Cookies by category. Analytics Cookies and Advertising and Behavioural Cookies are set only after affirmative opt-in. Consent may be withdrawn at any time through the “Cookie Preferences” link on the Platform footer.

9.3 Google Analytics, Google Ads and user-behaviour tracking. Lexi Trip uses Google Analytics, Google Ads and equivalent user-behaviour and product-analytics tools (including heatmapping, session-replay and event-analytics tools) to understand how visitors interact with the Platform, to improve the product, to measure marketing performance and to serve targeted advertisements on and off the Platform. IP addresses are anonymised or truncated where technically feasible, and data-sharing settings with Google are configured to the minimum necessary. Data Principals can opt out of Google Analytics through the Google Analytics Opt-out Browser Add-on, and can manage Google Ads personalisation through the Google Ads Settings page.

9.4 Location Data. Precise location is collected only where the Data Principal grants device-level permission, and only for cabs, transfers, airport pickups, in-trip features and fraud-prevention. Location permissions may be revoked at any time through the device settings.

9.5 Retention. Cookies and analytics identifiers are retained for the periods stated in Schedule B.

10. Payment Data

10.1 Lexi Trip does not store the full card PAN, CVV, PIN, card expiry, full bank account credentials or netbanking passwords. All such payment-instrument data is captured directly by the PSP within its PCI-DSS certified environment and under the RBI (Regulation of Payment Aggregators) Directions, 2025.

10.2 Lexi Trip receives from the PSP only payment metadata (transaction reference, order ID, amount, currency, payment mode, last-four digits of card, PSP token, refund/chargeback status) as necessary for reconciliation, refunds, dispute management, MDR display and anti-fraud.

10.3 Refund-to-original-mode default. Refunds are effected to the original mode of payment, save where such mode is no longer operative or where the Data Principal specifically instructs otherwise and identity is re-verified.

10.4 MDR/convenience-fee display. Where Lexi Trip levies a convenience fee, the same is displayed transparently on the checkout page.

11. Visa, Passport and Travel-Document Handling

11.1 Visa and passport-related Personal Data is processed under the heightened-safeguards track described in clause 4.5.

11.2 Such data is collected only for the purpose of the specific visa or travel-document application, and only where the Data Principal has opted in for Lexi Trip’s visa assistance service.

11.3 Disclosure is limited to:

  1. (a)the destination-country visa authority, embassy or consulate;
  2. (b)the Visa Partner engaged for lodgement; and
  3. (c)courier partners for physical movement of documents.

11.4 Retention is limited to the visa/travel-document processing period and the statutory record-keeping period thereafter. Post-purpose, documents are securely erased or, if required by law, retained under restricted access.

11.5 Lexi Trip is not the embassy, consulate or immigration authority and does not adjudicate visa applications. All final decisions rest with the sovereign authority of the destination country.

12. Travel Insurance Data

12.1 Lexi Trip acts as a Facilitator between the Data Principal and the licensed insurer or regulated insurance intermediary (each an “Insurance Partner”). The policy contract sits between the Data Principal and the Insurance Partner.

12.2 Health, medical and other insurance-relevant information is disclosed only to the Insurance Partner, and only for underwriting, policy issuance, servicing and claims coordination.

12.3 Lexi Trip does not decide claims and does not act as an insurer, TPA, surveyor or loss adjuster.

13. Minor Travellers

13.1 In accordance with Section 9 of the DPDP Act, Personal Data of a minor (a person who has not completed 18 years) is processed only with verifiable parental or lawful-guardian consent.

13.2 Lexi Trip does not undertake tracking, behavioural monitoring or targeted advertising directed at minors.

13.3 The parent/guardian consenting to the Booking warrants that they hold all necessary authority in respect of the minor Traveller.

14. Data Principal Rights

14.1 Subject to and in accordance with Sections 11 to 14 of the DPDP Act and the DPDP Rules, a Data Principal has the following rights:

14.1.1 Right to access — to obtain a summary of Personal Data processed and the processing activities undertaken;

14.1.2 Right to correction and updation — to have inaccurate or misleading Personal Data corrected, and incomplete Personal Data completed and updated;

14.1.3 Right to erasure — to have Personal Data erased where it is no longer necessary for the purpose, subject to statutory retention obligations;

14.1.4 Right of grievance redressal — to have grievances redressed through the mechanism in clause 17;

14.1.5 Right to nominate — to nominate another individual to exercise rights in the event of death or incapacity;

14.1.6 Right to withdraw consent — to withdraw consent at any time with the same ease with which it was given. Withdrawal of consent will not affect the lawfulness of processing carried out before withdrawal. Withdrawal of consent for booking/service fulfilment or payment/anti-fraud may render Lexi Trip unable to continue providing the relevant Underlying Service, and in such cases Lexi Trip may cancel the Booking subject to the cancellation provisions of the Master Terms.

14.2 Consent Manager route. Once a Consent Manager registered with the Data Protection Board of India is operationally available and integrated with the Platform, rights may additionally be exercised through such Consent Manager.

14.3 How to exercise rights. Rights may be exercised by writing to the Grievance Officer at the contact points in clause 21, or through the “Privacy & Consent” module in the user account. Lexi Trip will verify the identity of the requester (through OTP, registered-email challenge or such other means as are proportionate to the request) before actioning the request.

14.4 Timelines. Lexi Trip will acknowledge a rights request within 48 (forty-eight) hours and endeavour to close it within 30 (thirty) days, save where the request is complex, contested or requires third-party inputs, in which case an interim response will be provided.

14.5 Data Principal duties. In accordance with Section 15 of the DPDP Act, the Data Principal shall not:

  1. (a)impersonate another person;
  2. (b)suppress material information while providing Personal Data;
  3. (c)register a false or frivolous grievance; or
  4. (d)furnish false particulars in exercising rights.

15. Retention and Deletion

15.1 Personal Data is retained only for the period necessary for the purpose for which it was collected, or as required under applicable law, whichever is longer.

15.2 Illustrative retention periods:

15.2.1 Booking, payment and tax records — 8 (eight) years, in line with the Income-tax Act, 1961, GST law and PMLA record-keeping requirements;

15.2.2 KYC records — as required under PMLA and RBI KYC directions;

15.2.3 Visa and passport records — for the duration of the visa validity plus the statutory period required by the destination country and Indian law, subject to a maximum of To be confirmed: internal retention cap for visa/passport records;

15.2.4 Insurance records — for the policy period and any longer period required by the IRDAI regulations and the Insurance Partner;

15.2.5 Call recordings — retained for To be confirmed: internal period, typically 6–12 months for quality, training, dispute and regulatory purposes;

15.2.6 Marketing consent records — until withdrawal plus a reasonable evidentiary period;

15.2.7 Cookies and analytics identifiers — as per Schedule B.

15.3 Upon expiry of the applicable retention period or on valid erasure request, Personal Data is securely deleted or irreversibly anonymised. Anonymised, aggregated analytics data that no longer identifies any Data Principal may be retained indefinitely for statistical and product-improvement purposes.

16. Security Safeguards

16.1 Lexi Trip implements reasonable security practices and procedures within the meaning of Section 43-A of the IT Act and Rule 8 of the SPDI Rules, and safeguards proportionate to the risk under Section 8(5) of the DPDP Act. These include:

16.1.1 encryption in transit (TLS 1.2+) and at rest for sensitive fields;

16.1.2 role-based access control, least-privilege principles and multi-factor authentication for administrative access;

16.1.3 network segmentation, WAF, DDoS protection, intrusion detection and vulnerability management;

16.1.4 periodic VAPT, secure SDLC practices and code review;

16.1.5 vendor due diligence and contractual security obligations for Data Processors;

16.1.6 employee training, confidentiality obligations and background checks;

16.1.7 documented incident-response and business-continuity plans; and

16.1.8 an information-security management framework aligned with recognised standards.

16.2 Breach notification. In the event of a personal data breach, Lexi Trip will notify the Data Protection Board of India and each affected Data Principal in the manner and within the timelines prescribed under Section 8(6) of the DPDP Act and the DPDP Rules.

16.3 Significant Data Fiduciary self-assessment. Lexi Trip will self-assess whether it is a Significant Data Fiduciary under Section 10 of the DPDP Act on notification of the applicable thresholds and will comply with the additional obligations (DPIA, audit, DPO) applicable to Significant Data Fiduciaries as and when triggered.

17. Grievance Mechanism

17.1 The Grievance Officer for the Platform is:

Grievance Officer / Data Protection Contact

Mr. Bani Pal Singh

Email: banipal@lexitrip.in

Toll-free: 1800-313-2005

Address: 2-A/3, Kundan Mansion, Asaf Ali Road, New Delhi – 110002

Hours: 10:00 AM – 06:00 PM IST, Monday to Saturday (except public holidays)

17.2 Dual-clock resolution. In accordance with Rule 4(4)–(5) of the Consumer Protection (E-Commerce) Rules, 2020, Rule 3(2) of the Intermediary Rules, and Section 8(10) of the DPDP Act:

17.2.1 acknowledgement of every grievance within 48 (forty-eight) hours of receipt; and

17.2.2 resolution and disposal within 1 (one) month from the date of receipt.

17.3 Fast-track content take-down. Where a grievance concerns content of the nature specified in Rule 3(2)(b) of the Intermediary Rules (including content depicting an individual in the nude or in a sexual act, or artificially morphed images), Lexi Trip will act to remove or disable access to such content within 24 (twenty-four) hours of receipt.

17.4 Escalation to the Data Protection Board. Where a Data Principal is not satisfied with the response of the Grievance Officer, or has not received a response within the timelines above, the Data Principal may approach the Data Protection Board of India in the manner prescribed under the DPDP Act and the DPDP Rules.

17.5 Consumer Protection escalation. Nothing in this Privacy Policy restricts a Data Principal’s right to approach a Consumer Disputes Redressal Commission under the Consumer Protection Act, 2019, or the National Consumer Helpline.

18. Third-Party Links

18.1 The Platform may contain links to third-party websites, applications and services (including Supplier websites, PSP checkout pages, embassy portals and Insurance Partner portals). Such third-party properties are governed by their own privacy policies. Lexi Trip does not control, endorse or assume responsibility for the content, privacy practices or data-handling of such third parties.

19. Marketing Communications

19.1 Marketing and promotional communications (email, SMS, push, WhatsApp, RCS, in-app) are sent only where the Data Principal has opted in through the marketing consent track under clause 4.4.3.

19.2 Unsubscribe. Every marketing communication contains an easy opt-out link or keyword. Opt-out is honoured within 7 (seven) working days.

19.3 Call recording notice. Inbound and outbound customer-support calls are recorded for quality, training, dispute-resolution, fraud-prevention and regulatory purposes. A pre-call IVR notice announces the recording, and the caller may decline by disconnecting or by opting for chat/email support.

20. Changes to this Privacy Policy

20.1 Lexi Trip may revise this Privacy Policy from time to time. Revisions are notified through:

  1. (a)an in-app banner and/or pop-up on the Platform;
  2. (b)an email to registered users; and
  3. (c)a website notice.

20.2 Non-material changes — continued use of the Platform after the effective date of the revised Privacy Policy constitutes acceptance of such changes.

20.3 Material changes — including changes that expand the categories of Personal Data collected, purposes of processing, categories of recipients, retention periods, or cross-border transfer arrangements — will require click-through re-consent at the next login or Booking.

20.4 A version log is maintained at Schedule D. The Booking Legal Snapshot records the version of the Privacy Policy applicable to each Booking.

21. Governing Law, Jurisdiction and Dispute Resolution

21.1 This Privacy Policy is governed by, and construed in accordance with, the laws of the Republic of India.

21.2 Subject to the grievance mechanism in clause 17 and the jurisdiction of the Data Protection Board of India, the courts at New Delhi shall have exclusive jurisdiction over any dispute arising out of or in connection with this Privacy Policy.

21.3 Where the Master Terms provide for arbitration or a specific dispute-resolution mechanism (Part X of the Master Terms), that mechanism shall apply to the extent legally permissible and consistent with the DPDP Act.

22. Contact

Data Fiduciary: Bani Global Industries LLP (LLPIN: ACI-6373)

Platform: Lexi Trip (lexitrip.in)

Registered Office: 2-A/3, Kundan Mansion, Asaf Ali Road, New Delhi – 110002

Grievance Officer / Data Protection Contact: Mr. Bani Pal Singh

Email: banipal@lexitrip.in

Toll-Free: 1800-313-2005

Schedule A — Category-wise Data Processing Register

#Data CategoryPurposesLegal BasisRetentionRecipients (by category)
1Identity DataAccount creation, Booking, KYC, fulfilmentConsent (Sec. 6 DPDP); contractual necessityAccount life + 8 yearsSuppliers, Aggregator Partners, Fulfilment Partners, IT/Cloud Vendors
2Contact DataBooking confirmations, support, refunds, communicationsConsent; contractual necessityAccount life + 8 yearsSuppliers, Fulfilment Partners, PSPs, IT/Cloud Vendors
3KYC & Travel Document Data (Aadhaar-masked, PAN, passport, visa)KYC, visa, ticketing, statutory complianceConsent; Sec. 7 (legal obligation); PMLA/RBI KYCAs per PMLA/statute; visa: to be confirmedSuppliers, Visa Partners, Fulfilment Partners, Auditors
4Travel PreferencesPersonalisation, fulfilmentConsentAccount lifeSuppliers, Aggregator Partners
5Payment MetadataPayment, refund, reconciliation, anti-fraudConsent; contractual necessity; RBI PA Directions8 years (tax/PMLA)PSPs, banks, Auditors
6Device Data, Analytics DataPlatform operation, analytics, securityStrictly-necessary basis (essential); Consent (analytics)14–26 months (analytics); to be confirmed (logs)Analytics Providers (incl. Google Analytics, Google Ads), IT/Cloud Vendors
7Location DataCabs, transfers, pickup, fraudConsent (granular)Trip + 90 daysSuppliers (cab/transfer), Fulfilment Partners
8Call RecordingsSupport, QA, disputesConsent (pre-call notice)To be confirmed — 6–12 monthsIT/Cloud Vendors, Auditors, lawful-order recipients
9User ContentReviews, ratings, communityConsentUntil removal / account closurePublic (as displayed), IT/Cloud Vendors
10Corporate/GST DataB2B Bookings, invoicing, GST complianceConsent; legal obligation8 yearsSuppliers, Auditors, tax authorities
11Minor Traveller DataBooking, fulfilmentVerifiable guardian consent (Sec. 9 DPDP)Trip + statutory periodSuppliers, Fulfilment Partners
12Sensitive / High-Risk Data (biometrics, health, passport)Visa, insurance, medical emergencyExpress consent; Sec. 7(c) DPDP for emergenciesPurpose + statutory periodVisa Partners, Insurance Partners, medical Fulfilment Partners
13Marketing PreferencesPromotional communicationsSeparate consent (Sec. 6 DPDP)Until withdrawal + evidentiary periodIT/Cloud Vendors, marketing tools

Schedule B — Cookies and SDK Register

To be confirmed: populate at go-live with the final list of Cookies and SDKs deployed on lexitrip.in and the Lexi Trip mobile apps, including for each item: name, provider, category (strictly necessary / preference / analytics / advertising), purpose, first- or third-party, retention/expiry, and cross-border transfer note. Baseline entries anticipated: Google Analytics (GA4) — analytics; Google Ads / DoubleClick — advertising; Google Tag Manager — tag management; Meta Pixel — advertising; behavioural/heatmap tool To be confirmed: tool name; session-replay tool To be confirmed: tool name; CDN/security Cookies (Cloudflare/AWS) — strictly necessary; authentication Cookies — strictly necessary.

Schedule C — Vertical-Specific Data Notes

C.1 Hotels and Accommodation

Data shared with the property (as consumption-point operator disclosed on the voucher) and, upstream, with Aggregator Partners and bed-banks by category only. Special requests (accessibility, dietary, medical) shared to enable service.

C.2 Flights

Data shared with the operating and marketing carrier (disclosed on the e-ticket) via GDS/NDC channels. APIS/PNR data disclosed to destination immigration authorities as required by law of the country of arrival/departure.

C.3 Packages and Custom Trips

Data shared across multiple Suppliers and Fulfilment Partners as required for each component. Component-level Suppliers not named upstream, except at the consumption point.

C.4 Visa Assistance

Data (including biometrics for e-visa where applicable) shared with the Visa Partner and the destination-country visa authority. Lexi Trip does not adjudicate visa outcomes.

C.5 Cabs, Transfers and Buses

Precise location shared with the cab/transfer/bus Supplier for pickup, tracking and safety. Ride-time telemetry retained for safety and dispute purposes.

C.6 Activities and Experiences

Data shared with the activity operator (disclosed on the voucher). Health/fitness declarations, where collected for adventure activities, are shared with the operator only.

C.7 Cruises

Data shared with the cruise line for manifest, immigration and safety-of-life-at-sea compliance. Health screening data shared where required by the cruise line and port health authorities.

C.8 Travel Insurance

Data shared with the Insurance Partner (named on the policy schedule) for underwriting and claims. Health information handled under the heightened-safeguards track.

C.9 Future Verticals

On onboarding of any new vertical (e.g., rail, homestays, MICE, loyalty), this Schedule will be updated by way of a policy amendment under clause 20, and the incremental data-handling will be notified to affected Data Principals.

Schedule D — Version Log

VersionEffective DateNature of ChangeConsent Refresh Required
1.001/08/2026Initial publicationN/A — accepted at first Booking / login

Questions about a specific booking? See Contact us.