EzySeat (“we”) is the Data Fiduciary for personal data processed through the Service. This policy explains how we handle your personal data in line with the Digital Personal Data Protection Act, 2023 (DPDP Act) and the Information Technology Act, 2000.
What we collect
- Account: name, email, mobile number, password (stored only as a secure hash) or Google sign-in identifier, optional gender (used only for optional women-only matching).
- Trips: PNR, train or flight number, date, class, stations, and seat/berth details of passengers on the booking.
- Swaps: your preferences, offers, decisions, chat messages with swap partners, and ratings.
- Security & logs: IP address, device/browser type, sign-in events, and records of important actions.
- Diagnostics: when something goes wrong, technical error details (page address, browser type, error message) so we can find and fix bugs. Personal data such as PNRs and phone numbers is masked in these reports.
Why we use it
- To verify bookings, find compatible swaps, and let travellers who both agree coordinate the swap.
- To send service messages by email and SMS (matches, confirmations, cancellations, security codes).
- To keep the Service safe: prevent fraud and abuse, investigate reports, and meet legal obligations.
We process this data on the basis of your consent (given when you sign up and add a trip) and for legitimate uses permitted by the DPDP Act. We do not sell your personal data or use it for third-party advertising.
Your PNR is special
- Encrypted with AES-256-GCM as soon as you add it, and shown only in masked form (e.g. 45••••••78).
- Permanently deleted 48 hours after your journey ends. We keep your trip and swap history (train number, date, seats, outcomes) so you can see past swaps — without the PNR.
- Only a very small number of authorised staff can view a full PNR, and only while it still exists; every such view is logged.
What other travellers see
Your first name and last initial, your seat for the relevant trip, your rating and verification badges. Your email and phone number are never shown to other travellers.
Who we share with
Service providers who process data on our behalf under contract — hosting, email delivery, SMS delivery, and booking-status lookups — and authorities where required by law. Data is processed in India or other countries with adequate safeguards.
How long we keep data
- PNRs: 48 hours after the journey ends.
- Account, trip history, chats and ratings: until you delete your account.
- Security logs: up to 12 months, or longer where required by law. Error reports: 45 days.
Your rights
You can access and correct your data in Settings, withdraw consent, and delete your account at any time (Settings → Delete account). Deletion erases your personal details, PNRs and messages; past swaps remain in your partners' history as “Deleted user”. You may also nominate another person to exercise your rights in case of death or incapacity, and raise a grievance with us or the Data Protection Board of India.
Security
Encryption in transit and at rest for sensitive fields, hashed passwords, optional two-factor authentication, rate limiting, audit logs, and strict access control for staff.
Cookies
We use essential cookies to keep you signed in and protect forms. Analytics cookies (Google Analytics, and Microsoft Clarity if enabled) are set only if you accept them, and you can change your choice any time from “Cookie settings” in the footer. See our Cookie Policy.
Grievance Officer
Grievance Officer, EzySeat — grievance@ezyseats.com. We acknowledge grievances within 24 hours and aim to resolve them within 15 days. If you are not satisfied, you may approach the Data Protection Board of India.