Our Core Business: Travel Services
At Innoway Services LLP, we are first and foremost a travel business. Our comprehensive travel services —
including tour packages, flight bookings, hotel reservations, and bus tickets — form the core of our
operations. We complement these with financial services, including AEPS (Aadhaar Enabled Payment System)
banking and BBPS (Bharat Bill Payment System) bill payments, to provide complete solutions to our travel
partners and customers.
Travel Business Focus
Bank-Grade Security
AEPS Compliant
BBPS Certified
Data Protection
Regulatory Compliant
Innoway Services LLP ("we," "our," or "us") is committed to protecting
your privacy and securing your travel and financial data. This Privacy Policy explains how we collect, use,
disclose, and safeguard your information when you use our services including Travel Packages, Flight Bookings, Hotel Reservations, Bus Tickets, Money Transfer
Services, AEPS (Aadhaar Enabled Payment System) Banking Services, and BBPS (Bharat Bill Payment System)
Bill Payments.
01
Information We Collect
Travel Service Information:
- Travel Booking Details: Passenger names, contact information, passport details, visa
information, travel preferences, and itinerary details.
- Payment Information: Credit/debit card details, UPI information, and other payment
method details for travel bookings and financial transactions.
- Financial Service Information: Personal identification, Aadhaar number (for banking
services), PAN details, and identification documents as required by regulatory compliance.
- AEPS Transaction Data: Aadhaar-linked biometric authentication references, bank
account linkage details, and transaction records for balance inquiry, mini statement, and cash withdrawal
services.
- BBPS Payment Data: Biller information, consumer/account numbers, bill amounts, and
payment confirmation details for electricity, gas, water, insurance, loan and other bill payments made
through the Bharat Bill Payment System.
- Transaction Data: Travel booking records, money transfer details, banking transactions,
bill payments, and financial records.
- Technical Information: IP address, device information, browser type, operating system,
and cookies for security and analytics.
02
How We Use Your Information
- To process travel bookings including flights, hotels, tour packages, and bus tickets.
- To provide comprehensive travel services and manage customer itineraries.
- To process financial transactions including money transfers, AEPS banking services (balance inquiry,
mini statement, cash withdrawal), and BBPS bill payments.
- To verify identity and prevent fraud through KYC and Aadhaar-based biometric authentication processes
for AEPS services.
- To fetch biller details and confirm payment status for BBPS bill payment services.
- To provide customer support and resolve travel and transaction-related queries.
- To comply with regulatory requirements including RBI and NPCI guidelines for AEPS and BBPS financial
services.
- To improve our travel and financial services, develop new features, and enhance security measures.
03
Data Sharing and Disclosure
We do not sell your personal information. We may share data with:
- Travel Partners: Airlines, hotels, bus operators, and tour service providers to fulfill
your travel bookings.
- Banking Partners: For processing money transfer transactions and AEPS banking services,
including Aadhaar-based authentication with NPCI-approved switches.
- Billers and BBPS Partners: Electricity, gas, water, insurance, and other billers, along
with the Bharat Bill Payment System network, to process and confirm your bill payments.
- Regulatory Authorities: As required by RBI, NPCI, UIDAI, and other financial regulatory
bodies.
- Service Providers: Trusted partners involved in payment processing, technology
infrastructure, and customer support.
- Legal Requirements: When required by law, court order, or to protect our rights and
prevent fraud.
We implement robust security measures to protect your travel and financial data:
- 256-bit SSL encryption for all data transmissions
- Secure servers with bank-grade security protocols
- Regular security audits and vulnerability assessments
- Multi-factor authentication for sensitive operations
- Aadhaar biometric data used only for AEPS authentication and never stored beyond what is permitted by
UIDAI regulations
- Compliance with PCI DSS standards for payment processing
- Secure storage of travel documents and financial information
We retain personal data only as long as necessary for:
- Providing travel and financial services as requested, including AEPS and BBPS transactions
- Complying with legal and regulatory requirements (typically 5–10 years as per RBI/NPCI guidelines for
financial transactions)
- Resolving disputes and enforcing agreements
- Maintaining business records for audit purposes
- Improving our travel services and customer experience
You have the right to:
- Access and review your personal information
- Correct inaccurate or incomplete data
- Request deletion of your data (subject to legal requirements)
- Object to processing of your personal data
- Data portability for your travel and transaction history
- Withdraw consent for marketing communications
To exercise these rights, contact us at innowayservices@innowaypay.com.
Our website uses cookies to:
- Enhance user experience and site functionality
- Analyze website traffic and service usage patterns
- Remember your travel preferences and settings
- Prevent fraudulent activities and ensure security
- Provide personalized travel recommendations
You can control cookie settings through your browser preferences.
Our services may contain links to third-party websites, including travel partners, banking partners, AEPS
and BBPS payment gateways. We are not responsible for the privacy practices of these external sites and
encourage you to review their policies independently.
09
International Data Transfers
Your data is processed and stored primarily in India. AEPS and BBPS transactions are processed entirely
within India in line with RBI and NPCI data localization requirements. For international travel bookings,
necessary information may be shared with international travel partners. We ensure adequate protection
through standard contractual clauses and compliance with applicable laws.
Our services are not directed to individuals under 18 years of age. We do not knowingly collect personal
information from children. If you believe we have inadvertently collected such data, please contact us
immediately so we can take appropriate action.
We may update this Privacy Policy to reflect changes in our practices or legal requirements. We will notify
you of significant changes through our website or direct communication. Continued use of our services after
changes constitutes acceptance of the updated policy.
For privacy-related questions, concerns, or to exercise your rights, contact our Data Protection Officer:
Note: This Privacy Policy should be read in conjunction with our Terms of Service and
other applicable agreements. As a travel business first, we prioritize the security of your travel data
while ensuring comprehensive protection for all financial transactions, including our AEPS and BBPS
services.