Privacy Policy
There are no accounts here and no passwords, so we hold very little about you. This page says exactly what we do hold, why, who else sees it, and how to make us delete it.
Last updated · DontPlanIt is run by Akshat Jain, sole proprietor, in India.
1. Who is responsible for your data
Akshat Jain, sole proprietor, trading as DontPlanIt, at b1-1006, DSR Highland Greenz, Chikkanayakanahalli, Bengaluru, Karnataka 560035. Under India’s Digital Personal Data Protection Act 2023 (the “DPDP Act”) that makes us the data fiduciary — the ones who decide what is collected and why, and who answer to you for it.
For anything about your data, write to grievance@dontplanit.com.
2. What we collect
Only these. Nothing else.
- Your trip inputs
- Where you want to go, roughly when, how many of you, your travel style and your constraints (for example a vegetarian or Jain diet, an elderly parent’s pace, no long drives). This is the brief we build from.
- Your email address — optional
- Only if you give it, and only so we can send you your plan link and tell you when the plan is ready. You can use the product without it.
- Your phone number — optional, and only after you pay
- We never ask for a number while you are planning. After a purchase you can add one if you would rather we replied on WhatsApp about your own plan. It is used for nothing else — no marketing, no reminders, never shared or sold — and leaving it blank changes nothing about what you get. It is deleted along with your email if you ask us to erase your data.
- Your travel group’s answers
- If you invite people with a guest link, we store the first name the organiser gave them and the trip preferences they choose. No sign-up, no passwords, no contact details required from guests.
- Expenses you type in
- What you spent, on what, and who owes whom. We do the arithmetic and hand you a UPI link. We never hold or move the money, and we do not see your bank account.
- Payment status
- Razorpay tells us whether a payment succeeded and gives us a payment reference so we can find your order and issue refunds. We never see or store your card number, UPI PIN, CVV or bank credentials.
- Anonymous usage analytics
- Which pages get opened and where people stop, with no name and no account attached, so we can see which parts of the product are confusing. We do not build advertising profiles and we do not track you across other websites.
We do not run accounts or passwords. We do not ask for your address, your date of birth, your ID documents or your location, and we do not collect sensitive categories of data.
3. Why we collect it, and on what basis
We collect it to do the one job you asked for: build your travel plan, deliver it, answer your questions and, if it comes to it, refund you.
Our lawful basis is your consent, given when you type something in and continue. The DPDP Act requires that consent to be free, specific, informed and withdrawable — so it is. If you paid, we also process what we need to complete that transaction and to keep the records the law requires us to keep.
You can withdraw consent at any time by emailing grievance@dontplanit.com. We will stop using your data and delete it, except anything we are legally required to retain (for example payment records for tax). Withdrawing does not undo processing already done.
4. If you were invited as a guest
Someone planning a trip added your first name and sent you a link. We did not get your details from anywhere else, and we do not email you unless you give us an address.
You can ask us to delete your name and your answers at any time — write to grievance@dontplanit.com and mention the trip link. We will remove them from the plan.
5. Who else sees your data
A short list, and each one only gets the part it needs to do its job. We do not sell, rent or trade your data to anyone, ever, and we do not share it for advertising.
- Razorpay — takes your payment. They receive your payment details directly; we receive only the result. Their own privacy policy applies to what they hold.
- Anthropic — generates the free auto-draft. Your trip inputs (destination, dates, party, style, constraints) are sent to their API to produce the draft. Your email address, your phone number, your payment details and your expense entries are not.
- Our hosting and infrastructure providers — run the website and store the data that makes it work.
- Analytics — receives anonymous page-level usage, not your inputs.
- Anyone you send your plan link to. The link is the key: whoever holds it can read the plan. That is your choice to make, and yours to control.
We will also disclose data if a law, a court or a government authority validly requires it.
Some of these providers process data outside India. The DPDP Act permits that, except to countries the Government has specifically restricted.
6. How long we keep it
- A delivered plan and its trip data: 12 months after delivery, so you can go back to your link during and after the trip. Then we delete it.
- Drafts nobody paid for: deleted once they go stale.
- Payment and tax records: kept as long as Indian tax and accounting law requires.
- If you ask us to delete sooner: we do, within 30 days.
7. Your rights
Under the DPDP Act you can ask us to:
- show you what we hold about you and who we have shared it with;
- correct anything wrong, incomplete or out of date;
- erase it, unless we are legally required to keep it;
- nominate someone to exercise these rights for you if you die or become incapacitated;
- complain, and get a real answer — see the next section.
Email grievance@dontplanit.com. There is no form and no fee. We answer within 30 days, usually much sooner. We may ask a question or two to check the request really comes from you.
8. Complaints, and how to escalate
Our grievance officer is Akshat Jain, reachable at grievance@dontplanit.com. We acknowledge every complaint within 48 hours and resolve it within 30 days.
If you are not satisfied with how we handle a data complaint, you can escalate to the Data Protection Board of India. The contact page has the full escalation path, including the consumer routes.
9. Cookies and analytics
We keep this deliberately boring. We use essential storage only — the bits a browser needs to remember your in-progress plan and keep the site working — plus anonymous usage analytics.
No advertising cookies. No third-party trackers following you around the internet. No selling of behavioural data. If we ever add anything beyond that, we will ask you first and say so here.
10. Security
We take reasonable safeguards: plan links are long and unguessable, data moves over encrypted connections, and access is limited to the people who need it (which, today, is one person). We never store card details — Razorpay handles those.
No system is perfectly secure. If a breach ever affects your data, we will tell you and the Data Protection Board, as the law requires.
11. Children
DontPlanIt is meant for adults. The DPDP Act requires verifiable parental consent before processing a child’s data, and we are not set up to obtain it — so please do not enter a child’s contact details or personal information. If a child is travelling with you, tell us only what the plan needs (“a six-year-old”, “a teenager”), never their contact details.
12. Changes to this policy
If we change what we collect or who we share it with, we update this page and change the “Last updated” date at the top. If the change is significant, we will say so clearly rather than hoping you re-read it.