This Privacy Policy explains what personal data Detour ("we", "us") collects when you use the Detour app and website (the "Service"), how we use it, and the choices and rights you have. It applies to Travellers and Guides. If you do not agree, please do not use the Service.
1. Scope
Detour connects international travellers on a Mumbai layover with local student guides. Because international travellers use the Service, we aim to align with global privacy expectations including the EU/UK GDPR and India's data-protection framework.
2. What we collect
- Account & profile: name, email, password (stored hashed by our auth provider), role, and optional avatar, gender, nationality, languages, and interests.
- Guide details: university, course, year, bio, photos, and payout identifier (UPI VPA).
- Booking & trip data: flight timings, itineraries, agreements, messages between Traveller and Guide, and emergency-contact details you choose to add.
- Website requests: when you request a Detour or a guide, we collect the form details you submit (such as name, email, arrival/departure details, flight numbers, and interests), the landing-page path, and limited campaign attribution. The request is stored as a structured Detour lead in Supabase.
- Location: your device location during an active trip and when you trigger SOS (see below).
- Payments: processed by Razorpay. We receive payment status and identifiers but not your full card details.
- Device & usage: app/version, push-notification tokens, and basic diagnostic and usage data. On the website, Google Analytics loads only after you choose “Allow analytics”. We send allowlisted page and conversion events, never names, email addresses, flight numbers, emergency details, or form text.
- Mobile trip draft: the mobile website stores your selected places, preparation checklist, preferences and unfinished inquiry in session storage in your browser tab, for up to 12 hours since your last edit. It is not sent to Detour until you submit. Contact and flight details are cleared after successful submission. Open “My places”, then “Start over” to remove the draft earlier.
- Website storage: we store your analytics preference so the site remembers it. With permission, first-touch UTM campaign fields may be kept in your browser for up to 90 days and last-touch fields for the browser session. Our tracker does not retain advertising click identifiers such as gclid, fbclid, or msclkid.
3. How we use it
- Operate the marketplace: match Travellers and Guides, manage bookings, payments, and payouts.
- Enable safety features, including live trip context and SOS.
- Send transactional messages and push notifications (e.g. agreement, balance-due, and trip updates).
- Respond to website requests and understand, in aggregate, which pages and campaigns lead to qualified requests, bookings, and completed trips.
- Prevent fraud and abuse, enforce our Terms, and comply with legal and tax obligations.
- Improve the Service.
Where GDPR applies, our legal bases are performance of a contract (providing the Service), our legitimate interests (safety, fraud prevention, product improvement), your consent (e.g. precise location, marketing where applicable), and compliance with legal obligations.
4. Location & SOS
We access your location only when the app is in use and only for trip features: showing your Guide's live position during an in-progress trip, and sharing your coordinates with our operations team when you trigger SOS so we can help.
SOS is not an emergency service. It notifies our operations team and shares your location so we can assist — it does not replace the emergency services. In a life-threatening emergency in India, call 112. You can control location access in your device settings.
5. Who we share with
- The other party to your trip: Travellers and Guides see each other's name, profile, messages, and — during an active trip — the safety information needed to meet and stay in contact.
- Service providers who process data on our behalf: Supabase (database, authentication, lead storage, and media), Razorpay (payments and payouts), Expo (push notifications), and Resend (transactional lead notifications and email delivery).
- Website measurement and fallback delivery: Google Analytics receives consented, PII-free measurement events. If our structured lead endpoint is unconfigured or temporarily unavailable, FormSubmit may receive the form fields and limited attribution as a temporary email-delivery fallback.
- Authorities where required by law, or to protect the safety and rights of users and the public.
We do not sell your personal data.
6. Retention
We keep personal data only while it is needed to provide the Service, resolve safety or payment issues, and meet legal obligations. For website requests, contact and flight details are scheduled for redaction 30 days after the request is closed or marked as spam, or 30 days after a linked booking reaches its terminal state. Non-identifying attribution aggregates may be retained for reporting.
Consented first-touch campaign data in your browser expires after 90 days; last-touch data expires with the browser session. You can remove both immediately by changing Analytics preferences to “Not now” or clearing site storage. When you delete an account, we revoke access and remove or de-identify personal information that is no longer required. Limited transaction, fraud-prevention, dispute, safety, tax, and accounting records may be retained for the period required by law or a legitimate claim.
7. Your rights & choices
- Delete your account any time from Profile → Delete account in the app.
- Access & correct your profile data in-app, or by emailing us.
- Depending on your location, you may have rights to access, correct, delete, restrict, or port your data, and to object to certain processing. Contact us to exercise these rights.
- Manage push notifications and location access from your device settings.
- Change optional website analytics and attribution storage at any time using the Analytics preferences control.
8. International transfers
Detour operates from India and uses service providers that may process data in other countries. Where we transfer personal data across borders, we take steps to ensure it is protected consistent with this policy and applicable law.
9. Security
We use industry-standard measures — encryption in transit, access controls, and row-level security on our database — to protect your data. No system is perfectly secure; please use a strong password and keep your device secure.
10. Children
The Service is not intended for anyone under 18, and we do not knowingly collect data from children. If you believe a minor has used the Service, contact us and we will take appropriate action.
11. Changes
We may update this policy from time to time. Material changes will be signalled by updating the "Last updated" date above and, where appropriate, an in-app notice.
For privacy questions or to exercise your rights, contact us at admin@detourtrips.com. We aim to respond to grievances within the timelines required by applicable law. See also our Terms of Service.