Privacy Policy
Last updated: August 2026
At MAPPIN (operated by Red Carpet Travel Services Private Limited), we take your privacy seriously. This policy explains what data we collect, how we use it, and the choices you have.
1. Information We Collect
We collect the minimum information needed to provide the MAPPIN service:
- Account data: email, name, company, and password (hashed)
- Usage data: API call logs, endpoints accessed, timestamps, IP addresses
- Billing data: handled by our payment processor (HDFC SmartGateway) — we don't store card details
- Cookies: essential session cookies for authentication
2. How We Use Your Information
- To provide, maintain, and improve the MAPPIN service
- To authenticate you and secure your account
- To send you product updates (if you've opted in)
- To comply with legal obligations
3. Data Sharing
We do not sell your data. We share data only with:
- Service providers (e.g., cloud hosting, payment processing) under strict confidentiality
- Legal authorities when required by law
4. Data Retention
We retain your account data for as long as your account is active. API logs are retained for 90 days for troubleshooting and analytics.
5. Your Rights
You have the right to:
- Access the data we hold about you
- Correct or delete your data
- Export your data
- Object to processing
To exercise any of these rights, email assist@rpconnect.travel.
6. Security
We implement industry-standard security measures including encryption in transit (TLS), hashed passwords, API key rotation, and rate limiting. See our Security page for details.
7. Changes to This Policy
We may update this policy from time to time. We'll notify you of significant changes via email.
8. Contact
Questions? Reach out to us at assist@rpconnect.travel.