Our role
For agency and team data: TraWe is the data fiduciary. For traveller data your agency uploads: your agency is the fiduciary, TraWe is the processor.
Rights we honour
- Right to access and copy your personal data.
- Right to correction, completion and updation.
- Right to erasure once the processing purpose is complete.
- Right to nominate another individual to exercise rights on your behalf.
- Right to grievance redressal — acknowledged in 48 hours, resolved within 30 days.
Requests: dpo@trawe.in. From the app: Settings → Privacy → Request my data.
Consent
We collect only what's needed. Optional processing (marketing, product analytics) is opt-out from Settings → Privacy.
Security safeguards
- TLS 1.2+ in transit, AES-256 at rest.
- Row-level security isolating every agency's data.
- Least-privilege role model; MFA for admin access.
- Daily encrypted backups, 30-day retention.
- Immutable audit log of every meaningful action.
Sub-processors
Minimum data shared with a small number of vetted providers. Changes are notified at least 15 days in advance.
Managed Postgres (India region)
Database, auth, storage
Mumbai, India
Cloudflare Workers
Application hosting, edge compute
India edge PoPs
Razorpay
Payment collection & reconciliation
India
Meta WhatsApp Cloud API
WhatsApp Business messaging
Global (Meta)
Google Gemini via AI Gateway
AI copilot & itinerary drafting
Global
Grievance officer (India)
TraWe Technologies Pvt. Ltd. · grievance@trawe.in · Acknowledgement 48h, resolution 30 days.
Data breach notification
We notify the Data Protection Board and affected principals as required, with facts, likely consequences, and mitigation applied.