Effective Date: July 2026
A. INTRODUCTION
GoroBus Premium Travel Networks (hereinafter referred to as "GoroBus", "Company", "we", "us", or "our") is dedicated to protecting the privacy of its users and maintaining absolute confidentiality of any information provided by its passengers as a responsible digital data controller. This Privacy Policy clarifies our specific processing operations for gathering, handling, and securing User data across our platform.
This Policy applies to any individual ("User", "you", or "your") who explores, registers, intends to book, or executes a reservation for bus tickets made available through GoroBus's direct digital touchpoints—including our web portal (gorobus.com), mobile-optimized site, mobile application interfaces, and customer care helpdesks (collectively referred to as "Sales Channels").
By using or logging into our Sales Channels, you explicitly authorize the processing conditions detailed within this Privacy Policy. If you do not agree with these privacy parameters, please instantly discontinue using our online services.
Please note that this document does not apply to external third-party software structures or web domains, even if their hyperlinks appear on our platform. The information protocols of external payment providers, marketing partners, or independent transport fleet suppliers (including the up17 operator network) are governed by their own legal frameworks. We recommend reviewing the specific privacy clauses of any external network you interact with.
B. DOMESTIC & INTERNATIONAL DATA HANDLING
All data transmitted to GoroBus is safely hosted and processed primarily on secured cloud infrastructure within India. By utilizing our systems, you grant explicit consent for GoroBus to manage your operational profiles within these domestic data storage frameworks.
You maintain full liberty to retract your processing consent at any point by submitting an email to privacy@gorobus.com. However, please note that if you withdraw consent for core transactional markers (such as passenger names, contact numbers, age, and gender registries required to synchronize layout maps), GoroBus will be unable to finalize your seat reservations, distribute active PNR credentials, or maintain your booking state.
C. CATEGORIES OF DATA WE TRACK
To run sub-1.5-second route queries and manage seamless checkouts, GoroBus collects the following user metrics:
- Direct Booking Records: Full names, age details, genders, active mobile numbers, and email accounts provided during guest checkout or profile registration.
- Financial Logging: Masked payment tokens, historical transaction statuses, and billing references. GoroBus operates as a secure intermediary and never captures, views, or logs unencrypted credit card numbers or raw banking passwords.
- System Logs & Interactions: Past booking sequences, custom seat layout logs, platform markup modifications, and demographic summaries permitted via standard social login nodes (such as Google or Meta authentications).
D. OPERATIONAL UTILITY OF INDIVIDUAL DATA
GoroBus channels your personal data exclusively into critical operational workflows:
- Reservation Syncing: Transmitting structural passenger lists to designated transport network operators to book live inventory.
- Automatic Notifications: Routing digital M-Tickets, automated PNR confirmations, and scheduling modifications to users via SMS, WhatsApp webhooks, and email streams.
- System Guardrails: Deploying active verification checkups via dynamic mobile OTP validation to mitigate malicious brute-force attempts, rate limits, or system abuse.
- UI Optimization: Reviewing user reviews, star-ratings, and multimedia coach feedback to dynamically upgrade our grid selection engines.
E. DATA RETENTION POLICY
GoroBus retains active personal records only as long as required to successfully fulfill the ticketing operations described in this policy, or to fulfill standard statutory mandates including national taxation audits, corporate ledger verifications, and defensive legal alignments.
F. SYSTEM COOKIES AND METRIC CAPTURE
- Cookies: GoroBus utilizes system cookies to refine your active session, automate secure dashboard log-ins, and analyze channel engagement rates. Users can control cookie acceptance via browser settings; however, disabling them may break interactive UI elements (such as our dynamic grid seat selection layout).
- Session Strings: Our firewalls automatically record technical metadata including user IP footprints, operating system versions, browser specifications, and navigation timestamps. This information is processed anonymously to debug connection anomalies (like transient 429 errors) and maintain site performance.
G. RESTRICTED DATA DISTRIBUTION
- Fulfillment Partners: Your passenger details are shared directly with the specific transport operator executing your selected trip. While GoroBus binds its inventory network to strict service limits, operators function as independent data controllers with unique external compliance frameworks.
- Zero Commercial Data Selling: GoroBus strictly enforces a zero-tolerance policy against renting, trading, or selling user contact directories to unauthorized marketing channels. Data transfers occur solely during corporate restructuring, mergers, or core system transitions under matching NDA clauses.
- Mandatory Disclosures: GoroBus will share necessary data files with official regulatory boards or law enforcement agencies if compelled by a formal court order, legal investigation, or corporate audit.
H. PAYMENT SECURITY ARCHITECTURE
All checkouts running across GoroBus components are shielded via standard Transport Layer Security (TLS) encryption. Our servers follow rigid security guidelines to protect your credentials from accidental alterations, unauthorized modifications, or external data intrusion.
I. DELETION RIGHTS AND MANAGEMENT
Users have the absolute right to view, modify, or permanently wipe their personal data portfolios. Account deletion requests can be initiated via email to privacy@gorobus.com. For transaction safety, we perform standard identity verifications, storing the verification proof for up to 21 days post-deletion. Fundamental billing and sales logs are archived separately to meet strict tax legislation.