Privacy Policy

Last updated: 29 July 2026  ·  Compliant with the Digital Personal Data Protection (DPDP) Act, 2023

1. Personal Data We Collect

LayoverX Technologies Pvt. Ltd. collects the following categories of personal data when you use our platform:

  • Identity Data: Full name, phone number, email address.
  • Flight Data: Flight number, airline, arrival/departure timestamps, layover duration.
  • Travel Documents: Passport number or government-issued ID (required for CSMIA T2 entry verification only).
  • Payment Data: Tokenized payment information processed exclusively by Razorpay. LayoverX does not store card numbers.
  • Device & Usage Data: Browser type, IP address, pages viewed, referrer URL (for analytics and fraud prevention).

2. Purpose of Data Processing

We process your personal data strictly for the following purposes:

  • Booking & Voucher Generation: Creating QR-coded access passes, vendor dispatch alerts, and booking confirmations.
  • Flight Delay Alerts: WhatsApp and push notifications for real-time flight status changes and automatic slot window shifts.
  • Concierge Dispatch: Sharing confirmed booking details with verified ground operations partners at CSMIA T2 for meet-and-greet coordination.
  • Customer Support: Responding to inquiries, resolving disputes, and processing refund requests.
  • Platform Improvement: Anonymized analytics for service quality optimization and performance monitoring.

3. Third-Party Data Sharing

LayoverX shares personal data only with the following categories of verified partners, strictly on a need-to-know basis:

  • Service Vendors: Hotel operators, restaurant partners, spa providers, and transport operators for service fulfillment.
  • Payment Processors: Razorpay for secure payment processing (PCI-DSS Level 1 certified).
  • Flight Data Providers: AirLabs / AeroAPI for real-time flight tracking.
  • Communication Services: WhatsApp Business API and email services for booking notifications.

We do not sell, rent, or trade your personal data to third-party advertisers or data brokers under any circumstances.

4. Payment Security & PCI-DSS Compliance

All payment transactions are processed through Razorpay, which maintains PCI-DSS Level 1 certification — the highest level of security compliance in the payment card industry.

LayoverX uses tokenized payment references only. We never receive, store, or process your full credit/debit card number, CVV, or expiry date. Payment data is encrypted end-to-end between your browser and Razorpay's secure infrastructure.

5. Data Retention & Your Rights

We retain your personal data only for as long as reasonably necessary to fulfill the purposes for which it was collected, typically for a period of 12 months from the date of your last booking or interaction with the platform.

Under the DPDP Act, 2023, you have the right to:

  • Access, correct, or update your personal data.
  • Request complete erasure of your personal data.
  • Withdraw consent for specific processing activities.
  • Lodge a complaint with the Data Protection Board of India.

To exercise any of these rights, email us at privacy@layoverx.com. We will respond within 72 hours of receiving your request.

6. Data Protection Officer

Designated Grievance & Data Protection Officer
LayoverX Technologies Pvt. Ltd.
CSMIA Terminal 2, Exit Gate 2 Arrivals, Sahar, Mumbai 400099
Email: privacy@layoverx.com