Privacy policy
Last updated 9 October 2026
This policy explains what personal data Yippigo collects, why, who can see it, how long we keep it, and how you can use your rights under the Digital Personal Data Protection Act, 2023 and other Indian law. It covers the website yippigo.com and the Yippigo Partner app.
1. Who is responsible for your data
Augmetic Infinite LLP (LLPIN AAQ-0027), a limited liability partnership registered under the Limited Liability Partnership Act, 2008, with limited liability, runs Yippigo and decides how your personal data is used. It is the “data fiduciary” under the Digital Personal Data Protection Act, 2023. Based in: Gujarat, India.
For any question about your data, or to use your rights, contact Keyurkumar Maru, Designated Partner and Grievance Officer, at hello@kafilaa.com.
2. The short version
- We collect what we need to match group trips with operators and run the bookings.
- Operators invited to your trip see your name. The operator whose quote you accept, or to whom you send an enquiry, also gets your mobile number (and your email, for an enquiry). Your driver sees your name and number during the trip.
- We do not sell personal data.
- Analytics and advertising tools load only if you accept cookies.
- Our database is in Singapore, and some of our service providers are in the United States.
- You can download your data at any time, and delete your account yourself once any live booking is finished or cancelled.
3. What we collect and why
Your account
We collect your mobile number (checked with a one-time code), your name, your email if you give one, your preferred language, your password if you set one (stored only as a scrambled hash), and a record of each sign-in (time, IP address, browser or device).
We use these to create and protect your account, sign you in, stop misuse, contact you about your trips and show Yippigo in your language. An email address is needed to send an enquiry to an operator and to see operators' contact details.
Business details
For operators, agencies, companies, schools and other organisations: business name and legal name, GSTIN and GST type, city, contact, support, WhatsApp and emergency numbers, support hours, description, UPI ID and partner plan, and the names and mobile numbers of team members. For a personal account, the account's name is your own name.
We use these to show the business to the people it deals with, to run bookings and payments, to verify operators, and to keep tax and accounting records.
Trip requests
Pickup and destinations, dates, group size, vehicle types, budget and notes, plus answers that depend on the kind of trip: occasion, number of senior citizens, society, company, cost centre or PO number, institution name, number of students and staff, safety needs, event, guests, venues, pilgrimage circuit, halts and pickup points. We ask for numbers of passengers, not their names or ages.
We use these to find suitable operators, get you quotes and run the trip.
Quotes, bookings and payments
Quotes, booking details, amounts, the payments you mark and operators confirm (with any note you add), cancellations and their reasons, and refunds due. We never collect card or bank login details: you pay operators directly.
We use these to run the booking, keep one shared record of payments, help settle disputes and meet tax and accounting law.
Chat messages
Messages between customers and operators about a request or booking, who sent them, and when they were read. Until a booking is confirmed, phone numbers, emails, UPI IDs and WhatsApp or Telegram links are hidden from the other side. In chat messages, the hidden parts are removed before the message is saved. In trip notes, quote notes and itineraries, we keep what was typed but show the other side the hidden version until the booking is confirmed.
We use these so you can agree the details of the trip, and to look into a complaint or safety issue.
Reviews
The rating, tags and text of a review, and who wrote it. Reviews of operators are public on the operator's page with the reviewer's first name. We use reviews to help people choose operators and to keep quality up.
Enquiries from operator pages
Your name, verified mobile number, email, pickup, destination, date, number of days and travellers, vehicle, your message and your IP address. We send the enquiry, with your contact details, to that operator, confirm it to you, and use the IP address to prevent spam.
Vehicles, drivers and verification documents
From operators: vehicle registration number, make, model, year, seats, the expiry dates of permits, fitness, insurance and pollution certificates, and vehicle photos; drivers' names, mobile numbers, licence numbers and expiry, badge numbers, experience and languages; and documents for verification (registration, permits, fitness, insurance, pollution certificate, driving licences, badges, GST, PAN, Aadhaar of owners and drivers, shop licence) with their document numbers.
We use these to verify operators and drivers, to remind operators before papers expire, to let drivers sign in, and to tell customers who is driving them. Vehicle photos are public, with location data removed. We ask for masked Aadhaar only. Operators must tell their drivers and staff that they are sharing their details with us.
AI trip planner
Destination, starting city, days, start date, group size, kind of trip, stay level, budget per person, interests and travel style; the plan we produce; your account if you are signed in; and a scrambled form of your IP address. We use these to write and price the plan, apply daily limits, and reuse a plan when someone makes the same request.
Devices and technical data
IP address and browser. In the app: platform, device name (for example “Riya's iPhone”, or the phone model), app version, build and update number, and a push notification token. If you turn on browser notifications, your browser's push subscription. Error and crash reports (the error, the screen and the app version), which go to our own servers.
We use these to keep you signed in, show you where you are logged in, spot suspicious sign-ins, deliver notifications and fix problems.
Messages we send
A copy of each notification we send (who it went to and what it said, for example a driver's name and the trip start code). We keep these as a delivery record and to help with support.
Cookies and analytics
See cookies and analytics below.
4. Your consent, and how to withdraw it
- We use your personal data with your consent, which you give when you create an account, post a trip, send an enquiry, use the trip planner or accept cookies, and only for the purposes described above.
- Some uses are allowed by law without separate consent: using details you gave us for the purpose you gave them (for example, sending your trip to operators), meeting legal duties such as tax records and lawful orders, and responding to an emergency that threatens someone's life or safety.
- You can withdraw consent as easily as you gave it: change your choice under “Cookie settings” at the bottom of our public pages or in Account & security, turn notifications off in your browser, phone or Account & security, delete your account, or write to us. We then stop using the data within a reasonable time, unless the law requires us to keep it.
- Withdrawing consent does not affect what was done before, but we may no longer be able to provide the parts of Yippigo that need that data.
5. Who can see your data
Other people on Yippigo
- Operators invited to quote on your request see the trip details and your account name. Contact details in your notes and messages stay hidden until the booking is confirmed.
- When you accept a quote, that operator sees your name, mobile number and GSTIN (if you have one), and can message you on WhatsApp. This happens as soon as you accept, before any advance is paid.
- When you send an enquiry from an operator's page, that operator gets your name, mobile number and email straight away, in the app and by email.
- During a trip, the driver can see your name and mobile number.
- Customers who book an operator see the operator's UPI ID, contact and support numbers, GSTIN and trip manager, and, while the booking is confirmed or under way, the driver's name and mobile number.
- Anyone can see an operator's public page: business details, fleet (without registration numbers), vehicle photos, tours and recent reviews with the reviewer's first name. Signed-in visitors with an email also see the operator's contact details, unless the operator turns this off.
- An operator's owner, admins and dispatchers can see that business's documents, including its drivers' licences and Aadhaar.
- If you report an operator, we may share your complaint, with your name and booking reference, with that operator to get their side.
Our staff
Authorised staff of Augmetic Infinite LLP can see requests, bookings, chats, payments and documents to verify operators, support users and prevent fraud. What each person can see depends on their role, and staff actions on accounts and money are logged.
Service providers
These companies process data for us, only to provide their service to us:
- Neon: our database, including documents and photos (Singapore).
- Hostinger: website hosting and server logs (Mumbai, India).
- MSG91: login codes by SMS (India).
- Resend: email delivery (United States).
- Zoho: our email inbox at hello@kafilaa.com, which receives your messages, complaints and data requests (India).
- Razorpay: payments for paid partner plans. Card, UPI and bank details are entered with Razorpay and never reach us; we keep the payment reference, amount and status (India).
- Anthropic: the AI trip planner, which receives only the trip details you enter (United States).
- Google, Apple, Mozilla and Microsoft: delivery of the browser notifications you allow.
- Expo: updates for the Yippigo Partner app and, once we switch them on, delivery of the app notifications you allow (United States).
- Google Analytics, Microsoft Clarity and Meta: only if you accept cookies (see below).
When you tap a WhatsApp or Google Maps link, that app opens with the details in the link, and its own privacy policy applies. We also share data when the law requires it, for example with a court or a government authority. We do not sell personal data.
6. Data stored outside India
Our database is in Singapore. Anthropic, Resend and Expo are in the United States, and Google, Meta and Microsoft may process data in the United States and other countries. The law allows this transfer unless the Government of India restricts a country. We choose providers that commit to protecting the data.
7. How long we keep it
- Login codes: deleted 2 days after they expire (each code works for 10 minutes).
- Sign-ins: 30 days on the website, and up to a year in the app if you keep using it. Records of ended sign-ins are deleted 30 days later.
- Your account: while it is open. When you delete it, we remove or anonymise your details as described on delete your account.
- After you delete your account: as the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 require, a sealed copy of the name, mobile number and email you registered with, and your sign-ins from the last 180 days (time, IP address and device), for 180 days. We open it only for a lawful request, such as from the police or a court, and then erase it.
- Booking, payment and tax records: as long as tax and accounting law requires, generally up to 8 years.
- Sign-in history and security logs: at least one year while your account is open.
- Messages, reviews, enquiries, trip plans, copies of notifications and verification documents: while they are needed for the booking, for safety, to settle disputes or to meet legal duties. We are setting fixed periods for these and will publish them here.
8. Your rights, and how to use them
- Access: download a copy of your data under Account & security, Your data. It includes your profile, businesses you own, trips you posted, bookings, messages you sent, reviews you wrote, devices and sign-ins. For anything else, such as documents, enquiries or trip plans, or for a summary of how we use your data and who we shared it with, write to us.
- Correction and updating: change your name and email under Account & security, and business details under Settings. Write to us for anything else.
- Erasure: delete your account yourself on the website or in the app (how to delete), or write to us. Some records are kept as described in section 7.
- Withdrawing consent: see section 4.
- Nomination: you can name someone to use these rights for you if you die or become unable to. Write to us with their name and contact details.
- Grievances: see section 9.
To make a request, write to hello@kafilaa.com with the mobile number registered on your account. Before we act, we will ask you to confirm it is you, with a one-time code sent to that number or other proof that the account is yours. We acknowledge requests within 24 hours and reply within 7 days. It is free.
9. Complaints
Write first to our Grievance Officer, Keyurkumar Maru (Designated Partner), at hello@kafilaa.com. We acknowledge within 24 hours and resolve within 7 days. If you are not satisfied with our answer, you can complain to the Data Protection Board of India. More on our complaints process in the terms.
10. Children
Yippigo is for adults aged 18 and over. We do not knowingly collect personal data from children, and we do not track children or show them targeted ads. Trip forms ask for the number of students or passengers, not their names or ages. If you think a child has given us personal data, write to us and we will delete it.
11. Security
- Sign-in uses one-time codes with limits on attempts. Passwords, if you set one, are stored only as a strong hash, and accounts lock for a while after repeated wrong tries.
- Sessions are stored only as hashed tokens. In the app, your sign-in is kept in the phone's secure storage and renewed on every use.
- All traffic is encrypted with HTTPS. Our database provider encrypts stored data.
- Access is limited by role. Verification documents are private, and staff actions on accounts and money are logged.
- Uploaded photos are re-saved with location data removed.
If a breach affects your personal data, we will tell you without delay what happened, the likely effects, what we are doing about it and what you can do, and we will report it to the Data Protection Board of India and CERT-In as the law requires. If you suspect misuse of your account, tell us at once at hello@kafilaa.com.
12. Cookies and analytics
We need a few things in your browser for Yippigo to work:
- a cookie that keeps you logged in (30 days);
- a cookie that remembers your cookie choice (1 year); and
- browser storage for a trip request you have started but not sent, and for prompts you have dismissed.
With your consent (the cookie notice, or “Cookie settings” at the bottom of our public pages and in Account & security), we also use the tools below. They set their own cookies.
- Google Analytics to count visits and see which pages help people plan trips. It runs on every page, including your account, and is told when you sign up, post a trip or accept a quote, with the booking value.
- Microsoft Clarity to see where people get stuck (heatmaps and session recordings). It records public pages, including login, sign-up, the trip planner and operator enquiry forms. Recording is turned off inside your account and workspaces.
- Meta Pixel and Conversions API to measure our Facebook and Instagram ads. It runs on every page, including your account. When you sign up, post a trip or accept a quote, we tell Meta that it happened, with your account id, mobile number and email in hashed (scrambled) form so Meta can match them to its users without seeing them, plus your IP address and browser (which Meta needs to prevent fraud), Meta's own cookie ids, the page address, the booking value and the type of account. A short-lived cookie (5 minutes) holds the event until the next page reports it.
If you choose “Only necessary”, none of these load and nothing is sent to Meta. You can change your choice at any time.
13. The Yippigo Partner app
- The app uses the same account and data as the website, plus the device details listed in section 3.
- It has no analytics or advertising tools. Crash reports go only to our own servers. Saved screens are cleared when you sign out; your language choice is kept on the phone.
- The app checks for updates from Expo each time it opens.
- You can delete your account from inside the app.
14. Changes to this policy
We will update this policy when our service or the law changes, and show the date at the top. We will tell you about important changes by email or in the app before they take effect, and remind you of this policy at least once a year.