Last updated: 17 April 2026
This policy is provided for transparency and customer trust. It is not a substitute for independent legal advice. If you are a business customer with bespoke data-processing requirements, ask us for additional documentation before signing agreements.
1. Who we are
Aai Shree Khodiyar Tour & Travels (“the Company”, “we”, “us”, “our”) operates the public website https://www.carhireinahmedabad.in (the “Site”), related marketing profiles, and offline booking channels. We are a transport and car-rental-with-driver service based in Ahmedabad, Gujarat, India.
- Registered / correspondence address: C/4/97 Indrajit society, Nikolgam road, Ahmedabad, Gujarat 382350, India
- Email (privacy & general): aaishreekhodiyartourism@gmail.com
- Phone: +91 99258 36647 (also used for WhatsApp Business messaging where enabled)
For the purpose of applicable data-protection law in India (including the Digital Personal Data Protection Act, 2023, where it applies), we are generally the data fiduciary in respect of personal data you provide to us for our own business purposes, unless a separate written agreement states otherwise (for example certain B2B arrangements).
2. Scope of this policy
This policy applies to:
- Visitors to the Site and users of our progressive web app (PWA) features, if installed;
- Anyone who contacts us by phone, SMS, WhatsApp, email, social media direct messages, or the Site contact form;
- Customers and passengers for whom a booking is made (including when a third party books on your behalf);
- Corporate contacts who request quotes or invoicing.
It does not govern third-party websites we link to (for example Google Maps, social networks, or payment gateways). Those services have their own privacy policies.
3. Categories of personal data
Depending on how you interact with us, we may process:
| Category | Examples |
|---|---|
| Identity & contact | Name, phone number, email address, company name (if provided). |
| Booking & trip details | Pickup/drop addresses or areas, dates and times, flight or train references (for transfers), itinerary notes, passenger count, luggage description, vehicle preference, special requests (e.g. child seat, extra stops). |
| Payment-related | Payment method used at our direction (e.g. UPI reference, partial card digits if shown by a provider), transaction timestamps, GST / invoice details for corporate billing. We avoid collecting full card numbers on the Site; if a payment link or gateway is used, that provider processes card data under its own policy. |
| Communications | Call logs, message content, email threads, and enquiry form submissions. |
| Technical & usage | IP address (may be truncated or aggregated), device type, browser, approximate region, pages viewed, referring URL, interaction events, and cookie identifiers where used. |
| Security & anti-abuse | reCAPTCHA tokens and risk signals processed by Google when you submit the contact form; basic server logs for fraud prevention and debugging. |
We do not intentionally collect sensitive personal data about you (such as health data) unless you voluntarily share it to help us assist you (for example mobility needs). Please only share what is necessary.
4. How and why we use personal data
We process personal data for purposes including:
- Providing services: quoting, confirming bookings, dispatching drivers and vehicles, customer support during trips, and follow-up on service quality.
- Legal and safety: complying with applicable laws (including tax, transport, and record-keeping where relevant), responding to lawful requests, and protecting rights, safety, and property.
- Improving the Site: analytics, performance measurement, debugging, and understanding which content helps travellers (for example popular routes or blog topics).
- Marketing (where permitted): sending occasional offers or updates similar to what you enquired about. You can opt out of promotional messages at any time by telling us on the same channel.
- Integrity of communications: preventing spam, bots, and abuse (including reCAPTCHA).
We do not sell personal data to data brokers. We do not use automated decision-making that produces legal or similarly significant effects solely without human review.
5. Legal bases and consent
Where Indian law requires a lawful basis, we rely on one or more of: your consent (for example marketing cookies where consent is required, or optional fields you choose to fill); performance of a contract or steps prior to booking; compliance with law; and legitimate interests that are not overridden by your rights (for example network security, aggregated analytics, or internal training), balanced against your reasonable expectations.
You may withdraw consent where processing is consent-based, subject to limitations (for example we may still need certain data to perform an active booking or meet legal obligations).
6. Cookies, analytics, and similar technologies
We and our vendors may use cookies, local storage, pixels, or SDKs to remember preferences, keep sessions secure, measure traffic, and improve conversion paths. Categories may include strictly necessary cookies, functional cookies, and analytics or performance cookies.
Where required, we will present a consent mechanism (for example a banner) for non-essential cookies and honour your choices. You can also clear or block cookies via your browser or device settings; some Site features may not work correctly if you do.
If we use Google Analytics or similar products, Google may process data as described in Google's policies. We configure such tools to reduce unnecessary collection where feasible (for example IP anonymisation if offered).
7. Google reCAPTCHA (contact form)
The Site contact form may use Google reCAPTCHA to reduce spam. When you submit the form, Google may analyse hardware and software data (such as device and application data and the results of integrity checks) according to Google's Privacy Policy and Terms of Use. Do not use the form if you do not accept that processing.
8. Sharing and subprocessors
We may share limited personal data with:
- Drivers and operational staff who need trip details to perform the service safely and punctually;
- Technology providers such as hosting, DNS, email delivery, analytics, form handling, or customer-relationship tools;
- Professional advisers (lawyers, accountants) where required and subject to confidentiality;
- Authorities when we believe in good faith that disclosure is required by law or to protect vital interests.
Some providers may process data outside India (for example in the United States or the European Economic Area). Where such transfers occur, we rely on appropriate contractual or statutory mechanisms offered by the provider and applicable law.
9. Retention
We retain personal data only as long as necessary for the purposes described in this policy, including:
- Active customer relationship: for the duration of quoting, booking, trip execution, and post-trip support;
- Legal, tax, and accounting: as required by applicable retention rules (for example invoices, GST records);
- Security logs: typically rotated on a shorter schedule unless needed for an investigation;
- Marketing: until you unsubscribe or we refresh consent where required.
When retention periods end, we delete, destroy, or irreversibly anonymise data where reasonable. Backup copies may persist for a limited technical period before automatic overwrite.
10. Security
We implement reasonable administrative, technical, and physical safeguards appropriate to the nature of our business (access controls, secure connections where HTTPS is used, vendor due diligence, staff instructions on handling customer data). No online system is perfectly secure; please use strong passwords on your own devices and avoid sending full payment card numbers in plain chat unless we have directed you to a verified secure payment flow.
11. Your rights and choices
Subject to applicable law and practical constraints, you may request access to, correction of, or erasure of personal data we hold; restriction or objection to certain processing; and a copy of your data in a portable format where technically feasible. You may also lodge a complaint with the Data Protection Board of India or other competent authority once fully operational and where you qualify.
To exercise rights, email aaishreekhodiyartourism@gmail.com with the subject line “Privacy request” and enough detail for us to verify your identity (for example phone number used to book). We will respond within a reasonable period (typically within 30 days unless law requires faster or allows longer for complex requests).
Children: our services are not directed at individuals under 18. If you believe a child has provided personal data without appropriate parental authority, contact us and we will take appropriate steps to delete it.
12. Breach notification
If we become aware of a personal data breach that is likely to cause harm and we are required to notify affected individuals or regulators, we will do so in accordance with applicable law, including describing the nature of the breach and mitigation steps where required.
13. Changes to this policy
We may update this policy to reflect legal, technical, or business changes. We will revise the “Last updated” date and, where appropriate, provide a short notice on the Site or by email for material changes affecting active customers.
14. Related documents
Please also read our Terms of Service for contractual terms governing bookings and Site use.