This policy explains what VoyageSifter does with information about you — what we collect, why, who else sees it, how long we keep it, and what you can require us to do. It is written to be read, not to be skimmed past.
This policy applies to voyagesifter.com and to every page and feature served from it (the "Service"). In this policy "we", "us" and "our" mean the operator of VoyageSifter; "you" means anyone who visits or uses the Service.
Under the Digital Personal Data Protection Act, 2023 (India) we are a Data Fiduciary and you are a Data Principal. Under the EU and UK General Data Protection Regulation we are a Controller and you are a data subject. Under the California Consumer Privacy Act we are a business. Different laws use different words for the same idea: we decide what happens to your data, and we are answerable for it.
We also observe the Information Technology Act, 2000 and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, and the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, which is why we publish a Grievance Officer in section 13.
This policy does not cover any third-party site you reach from ours. Those have their own policies and we do not control them.
We collect the following, and nothing beyond it:
We use personal data only for the purposes below. Where more than one legal basis could apply, we have stated the primary one.
| Purpose | Legal basis |
|---|---|
| To provide the Service you asked for | Performance of a contract with you; the "legitimate use" of a purpose for which you voluntarily provided your data (DPDP Act, s.7(a)) |
| To keep the Service secure, prevent abuse and investigate misuse | Our legitimate interests in protecting our infrastructure and our users |
| To measure and improve how the Service performs | Our legitimate interests; your consent where an analytics cookie requires it |
| To show advertising and to fund the Service | Your consent where required by law; otherwise our legitimate interests |
| To answer your enquiries and provide support | Performance of a contract; our legitimate interests in responding to you |
| To comply with law, court orders and lawful requests from authorities | Compliance with a legal obligation |
We do not use your personal data for automated decision-making that produces legal effects about you, and we do not sell it for money.
VoyageSifter is a comparison site. We do not sell tickets or rooms, we do not take payment, and we do not issue confirmations. When you choose a result you leave our site for the airline, hotel or booking site that actually sells it. From that point their privacy policy governs — including the passenger names, dates of birth, passport details and payment details you give them. We never see those.
If you book after clicking through, the partner may pay us a referral commission. That commission does not change the price you pay and does not move a result up our list. Where a result is a paid placement rather than an organic one, it is labelled.
Fares and rates change constantly and are held by the supplier, not by us. What we show is the most recent figure our partners returned; it can move between your search and your booking. Section 12 of our Terms and Conditions addresses this.
A cookie is a small file a site stores in your browser. We and our partners also use local storage, session storage and pixels, which do comparable jobs. We use four kinds:
| Kind | What it does | Can you refuse it? |
|---|---|---|
| Strictly necessary | Keeps your session working, balances load, and protects against cross-site request forgery | No — the Service will not function without these |
| Preference | Remembers your language, region, theme and tool settings | Yes |
| Analytics | Tells us which pages are used and where errors occur, in aggregate | Yes |
| Advertising | Set by our advertising partners to select and measure the recommendations you see | Yes — see section 6 |
You can delete or block cookies in your browser settings. Blocking strictly necessary cookies will break parts of the Service. Where the law in your country requires consent before a non-essential cookie is set, we ask for it before setting one.
VoyageSifter is free to use, and advertising is what pays for it. We work with Taboola, a content recommendation and advertising network, and may work with other advertising partners.
Taboola acts as an independent controller of the data it collects through its units. We do not receive, and cannot access, the profile it builds. Their privacy policy is at taboola.com/policies/privacy-policy.
Opting out stops advertising being personalised to you. It does not remove advertising, and the Service remains free either way.
We do not exchange your personal information for money. However, "sale" and "share" are defined broadly under the California Consumer Privacy Act as amended by the CPRA, and the disclosure of identifiers to an advertising partner for cross-context behavioural advertising may fall within those definitions. Section 11 explains how a California resident can opt out.
We do not sell your personal data. We disclose it only in these situations:
We are based in India and our infrastructure and service providers may be located in India, the European Union, the United Kingdom, Singapore or the United States. Using the Service may therefore involve your data crossing a border.
You can ask us for details of the safeguards applied to a specific transfer by writing to privacy@voyagesifter.com.
We keep personal data only as long as it is needed for the purpose it was collected for, or as long as the law requires.
| Category | Retention |
|---|---|
| Search parameters | Up to 90 days in identifiable form, then aggregated |
| Referral and click records | Up to 24 months, because partner commission is reconciled in arrears |
| Approximate location from IP | Not stored beyond the session, except in aggregate |
| Server and security logs | Up to 180 days |
| Support correspondence | Up to 3 years from the last message |
After these periods data is deleted or irreversibly aggregated so it can no longer identify you. Data may persist in encrypted backups for a further 90 days before those backups age out on their normal cycle.
We maintain reasonable security practices and procedures within the meaning of section 43A of the Information Technology Act, 2000 and the rules made under it, proportionate to the data we hold. In practice:
No system is perfectly secure, and we cannot guarantee that a determined attack will never succeed. If a personal data breach occurs we will notify the Data Protection Board of India and affected Data Principals as section 8(6) of the DPDP Act requires, and any other supervisory authority — including under Articles 33 and 34 of the GDPR, within 72 hours where feasible — to the extent those laws apply.
Your rights depend on where you are. We apply the strongest applicable standard rather than the minimum we could get away with.
You also have duties under section 15 of the Act, including not raising a false or frivolous grievance and not furnishing false particulars.
Residents of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana and other states with comprehensive privacy statutes have broadly equivalent rights of access, correction, deletion, portability and opt-out of targeted advertising. Use the same contact route and tell us which state you are in.
Email privacy@voyagesifter.com. We will acknowledge within 72 hours and respond substantively within 30 days, extendable once by a further 30 days where a request is complex — we will tell you if that happens. There is no charge unless a request is manifestly unfounded or excessive, in which case we will tell you the fee before doing the work.
We must be able to identify you before acting, particularly on a deletion request. We will ask for enough information to establish that the request is genuinely yours, and no more. An authorised agent acting for you must provide written proof of authority.
Section 9 of the Digital Personal Data Protection Act, 2023 treats anyone under 18 as a child. Processing a child's personal data requires verifiable consent from a parent or lawful guardian, and the Act specifically prohibits tracking, behavioural monitoring and targeted advertising directed at children.
In the United States, the Children's Online Privacy Protection Act applies to children under 13.
VoyageSifter is not directed at children, and is not intended for use by anyone under 18 without the involvement of a parent or guardian. We do not knowingly collect personal data from a child.
If you believe a child has provided us with personal data, write to privacy@voyagesifter.com and we will delete it promptly.
In accordance with the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 and section 13 of the Digital Personal Data Protection Act, 2023, we publish a Grievance Officer.
Complaints about the Service, content, or any contravention of these policies or of applicable law.
Acknowledged within 24 hours; resolved within 15 days.
Access, correction, erasure, consent withdrawal and other rights under section 11 above.
Acknowledged within 72 hours; resolved within 30 days.
Please include your name, how to contact you, a clear description of the issue, and the URL of the page concerned. It helps us resolve things quickly and it is what the Rules require.
We may update this policy as the Service or the law changes. The "last updated" date at the top always reflects the current version.
Where a change materially reduces your rights or materially expands how we use your data, we will give prominent notice on the Service before it takes effect, and — where the law requires consent — we will ask for it rather than assume it. Continuing to use the Service after a change takes effect means you accept the updated policy.
For anything in this policy:
© 2026 VoyageSifter. This Privacy Policy is published at https://voyagesifter.com/privacy-policy and should be read together with our Terms and Conditions.