How OnArrivalhandles personal data.
How OnArrival processes personal data across APIs, embedded products and partner deployments.

In this document+
The short version
OnArrival is an API-first travel technology platform. The data role follows the customer relationship: we control data needed to run OnArrival directly, and process traveller data on a partner’s instructions when the partner owns the customer experience. We collect only what is needed to search, book, pay, service, secure and improve a trip; rights, retention and transfer safeguards continue after checkout.
Introduction and regulatory commitment
OnArrival Travel Technology Private Limited operates a modular travel platform across cloud SaaS, enterprise VPC or on-premise deployments, and white-label web and mobile experiences.
Business and data roles
The platform aggregates flights, hotels, activities, insurance, visa information and ancillary services for fintechs, banks, OTAs, TMCs, marketplaces and enterprises.
- Data controller for direct relationships through onarrival.com, business-partner administration, developer accounts and platform security.
- Data processor for end-consumer bookings and white-label deployments where an enterprise client controls the customer relationship.
- Technology intermediary and platform provider; not merchant of record in most jurisdictions.
Compliance framework
- EU General Data Protection Regulation (GDPR).
- India Digital Personal Data Protection Act 2023.
- California CCPA and CPRA; UK GDPR and other applicable regional laws.
- SOC 2 Type II and PCI DSS controls. ISO 27001 Stage 2 is scheduled.
Controller information
OnArrival Travel Technology Private Limited · CIN U63030KA2022PTC158524 · WeWork Salarpuria Symbiosis, Bannerghatta Road, Arekere, Bengaluru 560076, Karnataka, India. Privacy matters are handled by the Data Protection Officer, reachable at security@onarrival.com.
Scope and application
The policy follows the data, not only the browser session.
Where it applies
- Processing in the EU/EEA and processing relating to EU/EEA residents.
- Processing in India, California and other markets where the Services operate.
- Direct web and mobile products, APIs, SDKs, webhooks, embedded widgets, developer tools and corporate SSO.
Deployment boundaries
Partner-hosted and client-controlled deployments remain subject to their specific data processing agreements and regional residency requirements. BYOS supplier integrations retain the separate data flows described in the applicable integration agreement.
Definitions and data classification
Personal data includes both obvious identifiers and the technical signals that can identify or single out a person.
What counts as personal data
- Direct identifiers such as name, email, passport number and payment references.
- Indirect identifiers such as IP address, device ID, online identifiers, location and behavioural data.
- Special-category data such as health or accessibility needs, biometrics used for identification, and information that may reveal protected characteristics.
Sensitivity model
- Public: marketing preferences and public reviews.
- Internal: contact information and travel preferences.
- Confidential: financial information and government identifiers.
- Restricted: special-category and biometric data, subject to the tightest access and retention controls.
B2B2C allocation
Partners remain the primary controller for their end-customer relationship and consent notices. OnArrival processes those bookings under a DPA, while remaining controller for its own account administration, security monitoring and direct business communications. Joint-controller activity is documented where platform analytics or fraud prevention genuinely requires shared purpose.
Lawful bases for processing
Every processing purpose must map to a recognised legal basis.
Primary bases
- Contract performance for booking fulfilment, payment and customer service.
- Legitimate interests for fraud prevention, security, service improvement and proportionate business marketing.
- Legal obligation for regulatory, tax, sanctions, AML/KYC and audit records.
- Consent for optional analytics, marketing and special-category data where consent is required.
Special-category data
Dietary, accessibility, medical or biometric information is processed only where the published policy identifies explicit consent or another permitted public-interest basis, with additional safeguards and minimised retention.
Data we collect
The categories vary with the product, deployment and role OnArrival is performing.
Information provided directly
- Identity and traveller details: name, nationality, date of birth, passport information and loyalty identifiers.
- Contact, journey, preference, accessibility and special-service information.
- Business-partner profiles, company details, developer accounts and corporate SSO claims.
- Payment tokens and limited card metadata; the policy states that full PAN and CVV are not retained by OnArrival.
Collected automatically
- API, application and security logs, timestamps, request metadata and performance signals.
- Device, browser, operating-system, language, IP and security telemetry.
- Usage analytics, feature adoption, crash reporting and consent records where enabled.
Third-party and supplier sources
- Airlines, hotels, ground transport, insurance and activity providers required to fulfil and service bookings.
- Payment providers, banking partners, identity and fraud-screening services.
- Partner-owned BYOS connections and market or pricing intelligence used for product operations.
Why we process data
Data is used to complete the trip, keep the platform safe and communicate what the user or partner needs to know.
Travel and platform functions
- Search, price, reserve, issue, service, cancel and refund travel products.
- Process payments, supplier settlement, reconciliation and fraud review.
- Operate partner accounts, APIs, SDKs, webhooks, support and reporting.
- Maintain security, availability, audit trails and incident response.
Improvement and communication
The published policy permits product research, aggregated analytics, service messages, surveys and marketing where the appropriate legitimate-interest assessment or consent exists. Marketing choice can be withdrawn without stopping necessary booking and security messages.
Cookies and tracking technologies
Consent depends on what the technology does.
Cookie classes
- Strictly necessary cookies for authentication, security, load balancing, cart and checkout.
- Functional cookies for language, accessibility and user preferences.
- Analytics cookies subject to consent, IP protections and retention limits.
- Marketing cookies subject to granular opt-in and withdrawal controls.
Beyond cookies
Mobile SDK analytics, crash reporting, push-delivery signals, offline sync, server-side API monitoring and security logs are described separately. Consent records are intended to be timestamped and consistent across OnArrival properties.
Sharing and third-party disclosure
Only the data necessary for the relevant service or legal purpose is shared.
Recipients
- Travel suppliers that create, manage and service the reservation.
- Cloud, CDN, monitoring, analytics and security providers operating under contract.
- Payment gateways, banks, refund and currency-conversion providers.
- Auditors, professional advisers and regulators where disclosure is necessary.
Legal and business events
Information may be disclosed in response to valid legal process, safety needs, regulatory reporting or a business transfer. Due diligence is conducted under confidentiality, and successor organisations are expected to inherit the applicable privacy obligations.
International data transfers
Travel is cross-border; the legal transfer mechanism must travel with the data.
Transfer safeguards
- Adequacy decisions where available.
- EU Commission Standard Contractual Clauses for non-adequate destinations.
- Transfer Impact Assessments covering government access, remedies and practical enforceability.
- Supplementary encryption, access controls and data-minimisation measures.
Regional processing
The published policy references data clusters in India, the EU and the United States, and describes country-specific assessments for transfers involving markets such as Singapore, Australia, Japan and India.
Retention and lifecycle management
Data is kept for the stated purpose, legal requirements and dispute windows, then reduced, anonymised or deleted.
Published retention examples
- Travel booking and payment records: commonly seven years where financial or travel regulation requires it.
- Cancelled bookings: three years; customer-support cases: five years after closure.
- Application logs: 12 months; security incident logs: up to five years.
- Analytics: 24 months with pseudonymisation after 12 months.
- Health information: travel completion plus 30 days; biometrics: deletion after verification where used.
Lifecycle controls
Automated tagging, deletion schedules, legal holds, audit trails, quality checks and progressive data minimisation are used to enforce retention decisions.
Security safeguards
Privacy rests on technical and organisational controls.
Technical measures
- Encryption in transit and at rest; managed key rotation and protected key storage.
- Multi-factor authentication, role-based access, least privilege and privileged-access review.
- Session controls, security monitoring, vulnerability management and protected backups.
Organisational measures
- Background checks and confidentiality obligations for authorised personnel.
- Annual security and privacy training; quarterly access reviews.
- Vendor due diligence, contractual security requirements and audit support.
- Incident-response, business-continuity and recovery exercises.
Individual rights and controls
People can ask what OnArrival holds, correct it, move it, restrict it or have it erased where the law permits.
Core rights
- Access to personal data and processing information.
- Rectification of inaccurate or incomplete data.
- Erasure where no overriding legal ground requires retention.
- Portability in a structured, commonly used machine-readable format.
- Restriction or objection, including an absolute right to object to direct marketing.
Automated decisions and profiling
The policy describes controls for travel preferences, risk assessments and marketing segments, including review, correction, opt-out and non-discrimination safeguards where automated decisions may have a material effect.
How to exercise a right
Requests may be submitted through available account tools or by email to security@onarrival.com. Identity verification may be required. The published response target is 30 days, extendable where legally permitted for complex requests.
Children's privacy
The published policy applies enhanced controls to minors and family journeys.
Age and consent
- Primary Services state a minimum age of 16; direct marketing a minimum age of 18.
- Parental or guardian consent is required where a person cannot consent independently.
- No behavioural advertising is intended for users under 18.
- Data collected from minors is subject to stricter minimisation and deletion review.
Family and group travel
Guardian oversight, emergency-contact handling, family-level consent, unaccompanied-minor procedures and institutional consent for school or youth travel are described as enhanced safeguards.
Breach notification and incident response
Detection, containment, assessment, notification and recovery are treated as one operating process.
Response sequence
- Continuous monitoring and rapid internal escalation.
- Containment, forensic preservation and risk assessment based on sensitivity and likely harm.
- Regulatory notification within applicable deadlines, including the GDPR 72-hour framework where relevant.
- Direct notice to affected people without undue delay where the legal high-risk threshold is met.
- Root-cause review, remediation, training and response-plan testing.
Governance and accountability
Privacy ownership extends from product design through vendor review.
Programme structure
- Published Data Protection Officer and cross-functional privacy governance committee.
- Privacy-by-design reviews and Data Protection Impact Assessments for high-risk processing.
- Documented necessity, proportionality, risk and mitigation decisions.
- Vendor security assessment, contract controls, monitoring and incident obligations.
Transparency and reporting
The policy commits to measuring the privacy programme, not merely describing it.
Metrics and reporting
- Rights-request volume and response performance.
- Consent, withdrawal, minimisation and retention compliance.
- Training completion and incident trends.
- Aggregated reporting about government requests, rights activity and privacy investment.
Contact and complaints
Start with the privacy team; regulatory complaint rights remain available.
Published contact points
- Privacy requests and the Data Protection Officer: security@onarrival.com.
- Postal: Data Protection Office, OnArrival Travel Technology Private Limited, WeWork Salarpuria Symbiosis, Bannerghatta Road, Arekere, Bengaluru 560076, Karnataka, India.
Escalation
The published process targets an initial privacy-team investigation within five business days, DPO review within 15 business days for escalated matters, and a response describing the outcome and corrective action. Individuals may also complain to the relevant supervisory authority.
Policy updates
Material changes should arrive before they take effect.
Change management
- Thirty days’ advance notice is stated for material changes.
- Email, product notices and website banners may be used.
- Fresh consent is sought where a new purpose legally requires it.
- Historical versions and approval records are intended to remain available.
Language and accessibility
Privacy information should be available in a format people can actually use.
Published commitments
- English plus translated support described for Hindi, Kannada, Spanish and French.
- Screen-reader compatibility, large-print and alternative formats.
- Plain-language explanations, accessible communication support and accommodation for vulnerable individuals.
Effective date and legal validity
The published v3.0 policy states an effective date of June 1, 2025 at 00:01 IST.
Effect
The policy states that it supersedes previous privacy notices, applies to personal data already held where lawful, preserves existing consent and preferences, and is reviewed against Indian privacy law, GDPR, UK GDPR, CCPA/CPRA and other applicable rules. Invalid provisions are intended to be severable without affecting the remainder.
A right is useful only when it is reachable.
Use the published privacy channels for access, correction, deletion, portability, consent withdrawal or a complaint.