Lexi Trip Cookies & Tracking Technologies Policy
Effective Date 01/08/2026 · Last Updated 01/08/2026 · Operated by Bani Global Industries LLP
- Publisher / Data Fiduciary
- Bani Global Industries LLP (LLPIN ACI-6373; PAN ABDFB4019N; GSTIN 07ABDFB4019N1ZR), registered office at 2-A/3, Kundan Mansion, Asaf Ali Road, New Delhi – 110002 (parent group website: baniglobal.in).
- Platform
- Lexi Trip — lexitrip.in and the Lexi Trip mobile applications.
- Grievance Officer / Data Protection Contact
- Mr. Bani Pal Singh · banipal@lexitrip.in · Toll-free 1800-313-2005
- Registered Office
- 2-A/3, Kundan Mansion, Asaf Ali Road, New Delhi – 110002
Contents
1. Preamble
1.1 This Cookies & Tracking Technologies Policy (the “Policy”) explains how the Publisher, acting as Data Fiduciary under the Digital Personal Data Protection Act, 2023 (the “DPDP Act”), and as an intermediary and e-commerce entity under the Information Technology Act, 2000 (the “IT Act”) and the Consumer Protection (E-Commerce) Rules, 2020 (the “E-Commerce Rules”), deploys cookies, software development kits (“SDKs”), pixels, tags and similar tracking technologies on the Platform.
1.2 This Policy applies to every visitor, user, guest or registered account holder who accesses or uses the Platform (each, a “Customer” or “Data Principal”), and applies to Lexi Trip’s role as Facilitator, Disclosed Agent, Merchant of Record or Payment Collection Entity as the case may be, and to the operation of every Underlying Service procured through Suppliers, Aggregator Partners, Fulfilment Partners, Service Providers and Third-Party Service Providers.
1.3 No banner, automated deployment model. Lexi Trip does not display a cookie consent banner or interstitial. Cookies, SDKs, pixels and similar tracking technologies deploy automatically on access to and use of the Platform, calibrated by category as set out in Section 3 below. This design has been adopted to avoid dark patterns, to keep disclosure prominent and controls one-click, and to align with the legal-basis architecture in the DPDP Act, the SPDI Rules, 2011 and the E-Commerce Rules.
1.4 The four-category legal-basis architecture is:
1.4.1 Strictly Necessary and Functional cookies/SDKs — deploy automatically on the basis that they are essential to deliver the requested service, aligned with Section 7 (Legitimate Uses) of the DPDP Act and the operational-necessity carve-out.
1.4.2 Analytics cookies/SDKs — deploy automatically only in aggregated, pseudonymised form, calibrated to service improvement and integrity, cross-referenced with the purpose stack in the Lexi Trip Privacy Policy, with an in-account opt-out.
1.4.3 Marketing / Advertising / Cross-Context Behavioural Profiling / Third-Party Ad-Network cookies and SDKs — do not deploy automatically; they deploy only if the Customer affirmatively opts in within the Lexi Trip account Cookie & Tracking Preferences panel, satisfying Rule 4(9) of the E-Commerce Rules and Section 6 (Consent) of the DPDP Act.
1.4.4 Sensitive Personal Data or Information as defined in Rule 3 of the SPDI Rules, 2011 (“SPDI”) is never collected via cookies/SDKs without express, unambiguous consent.
1.5 The primary consent-withdrawal / control routes available to a Customer are:
- (a)browser-level cookie controls;
- (b)device-level controls (iOS Limit Ad Tracking; Android opt-out of ads personalisation);
- (c)the Lexi Trip in-account Cookie & Tracking Preferences panel (Schedule CK-2); and
- (d)the DPDP Data Principal rights channel via the Grievance Officer.
1.6 Read this Policy together with the Lexi Trip Privacy Policy and the Lexi Trip Master Terms & Conditions. Where a conflict arises on cookie/tracking-related operational disclosure, this Policy prevails; on Data Principal rights, the Privacy Policy prevails.
2. Definitions
For the purposes of this Policy, capitalised terms carry the meanings given in the Master Terms & Conditions and the Privacy Policy. In addition:
- 2.1 “Cookie”
- means a small text file placed on a Customer’s device by a web server for storage and later retrieval.
- 2.2 “First-Party Cookie”
- means a Cookie set by the domain the Customer is visiting (i.e., a lexitrip.in or Lexi Trip-app-owned domain).
- 2.3 “Third-Party Cookie”
- means a Cookie set by a domain other than the one the Customer is visiting.
- 2.4 “Session Cookie”
- means a Cookie that is deleted when the browser or app session ends.
- 2.5 “Persistent Cookie”
- means a Cookie that remains on the device for a defined lifetime or until manually deleted.
- 2.6 “Local Storage”
- means browser-side storage mechanisms (including localStorage, sessionStorage and IndexedDB) used for functional persistence.
- 2.7 “SDK”
- means a software development kit embedded in the Lexi Trip mobile applications for analytics, attribution, crash/telemetry, push notifications or similar operational functions.
- 2.8 “Pixel / Web Beacon”
- means a transparent image or code snippet used to record page load, event or conversion signals.
- 2.9 “Server-side Tag Manager”
- means a container-based tagging architecture executed on Lexi Trip-controlled servers rather than the Customer’s browser.
- 2.10 “Fingerprinting”
- means the technique of combining device, browser or network attributes to derive a probabilistic identifier without setting a Cookie.
- 2.11 “Device Identifier”
- means an identifier such as IDFA, GAID, Android Advertising ID or an equivalent OS-issued identifier.
- 2.12 “Cross-Context Behavioural Profiling”
- means the tracking of a Customer’s activity across multiple websites, apps or services to build an advertising or behavioural profile.
- 2.13 “Data Principal” and “Data Fiduciary”
- carry the meaning given to them in the DPDP Act.
- 2.14 “Sensitive Personal Data or Information” or “SPDI”
- carries the meaning given to it in Rule 3 of the SPDI Rules, 2011.
- 2.15 “Booking Legal Snapshot”
- means the evidentiary record captured by Lexi Trip at the time of a Booking, which includes (among other items) the state of the Customer’s Cookie & Tracking Preferences at that moment.
3. Categories of Cookies and Tracking Technologies used by Lexi Trip
3.0 Lexi Trip uses a four-tier structure. The named vendor register lives in Schedule CK-1.
Tier (a) — Strictly Necessary
3.1.1 Purpose. To deliver the service the Customer has requested and to keep the Platform secure and reliable.
3.1.2 Examples. Session identifiers; authentication tokens; load-balancing cookies; CSRF and XSS-mitigation tokens; anti-fraud and anti-abuse cookies; bot-mitigation cookies (via the CDN and bot-mitigation provider); checkout-state cookies; payment-redirect return-URL cookies (within the PA/PG boundary).
3.1.3 Deployment. Automatic and cannot be disabled; if disabled at the browser level, core Platform functionality (including sign-in, Booking and checkout) will not work.
3.1.4 Legal basis. Section 7 of the DPDP Act (legitimate uses — service requested by the Data Principal, and safety/security of the Data Fiduciary and the Platform).
Tier (b) — Functional
3.2.1 Purpose. To remember Customer choices that improve the experience.
3.2.2 Examples. Language, currency, itinerary preferences, recently-viewed cities/hotels/flights, accessibility settings, remembered form fields (non-sensitive).
3.2.3 Deployment. Automatic; a Customer may switch these off through the Cookie & Tracking Preferences panel, at the cost of losing personalisation.
3.2.4 Legal basis. Section 7 of the DPDP Act (legitimate uses — service delivery and improvement).
Tier (c) — Analytics
3.3.1 Purpose. To measure use of the Platform, diagnose faults, and improve product and content.
3.3.2 How calibrated. Data is processed in aggregated, pseudonymised form; IP addresses are truncated where the vendor’s configuration supports it; no cross-site behavioural profile is built; no unhashed personal identifier is transmitted to a third-party analytics vendor.
3.3.3 Examples of tools deployed (by category, not by name). Web analytics provider; crash and telemetry SDK; performance-monitoring SDK; session replay / heatmap tool (subject to Section 8 below); server-side tag manager for measurement.
3.3.4 Deployment. Automatic; opt-out available through the Cookie & Tracking Preferences panel.
3.3.5 Legal basis. Section 8 of the DPDP Act (obligations of the Data Fiduciary) read with Section 7 (legitimate uses — internal analytics and integrity), and Rule 5 of the SPDI Rules where applicable.
Tier (d) — Marketing / Advertising / Cross-Context Behavioural Profiling
3.4.1 Purpose. To deliver personalised offers on- and off-Platform, measure marketing campaigns, and support re-marketing.
3.4.2 Examples of tools deployed (by category, not by name). Third-party ad-network cookies; attribution SDK; conversion pixel; re-marketing tag; cross-context behavioural profiling identifier; hashed CRM identifier for measurement (see Section 7).
3.4.3 Deployment. Off by default. These deploy only if the Customer affirmatively opts in through the Cookie & Tracking Preferences panel. There is no auto-check, no soft nudge and no re-prompting cadence beyond one confirmatory prompt per material change to this tier.
3.4.4 Legal basis. Section 6 of the DPDP Act (specific, informed, unambiguous consent) and Rule 4(9) of the E-Commerce Rules.
3.4.5 Children. This tier is disabled irrespective of any opt-in signal where Lexi Trip has actual knowledge that the Data Principal is a minor (Section 9, DPDP Act).
4. How Lexi Trip deploys cookies without a banner
4.1 A cookie banner is not the only lawful way to notify a Data Principal. Under Section 5 of the DPDP Act, the notice obligation is discharged if a clear, accessible notice is made available at or before the point of collection. Lexi Trip discharges this obligation by:
- (a)publishing this Policy prominently in the footer of every page of the Platform and in the Legal section of the mobile applications;
- (b)flagging this Policy at first sign-in and again at first checkout, with a link to the Cookie & Tracking Preferences panel;
- (c)restricting automatic deployment to Tiers (a), (b) and pseudonymised (c), each of which has an independent lawful basis under the DPDP Act; and
- (d)gating Tier (d) behind an explicit, in-account, off-by-default opt-in.
4.2 Browser-level and device-level controls are treated as authoritative consent-withdrawal channels. Where the Customer’s browser or device signals that Cookies (or a particular class of Cookies) are refused, Lexi Trip will not attempt to override that signal through fingerprinting or equivalent technical circumvention.
4.3 The Booking Legal Snapshot captures the state of the Cookie & Tracking Preferences at the moment of Booking, and is the evidentiary record of the Customer’s consent posture at that moment.
5. Legal basis for each category
| Category | Legal basis |
|---|---|
| (a) Strictly Necessary | Section 7, DPDP Act (legitimate uses — service requested; safety and security). |
| (b) Functional | Section 7, DPDP Act (legitimate uses — service delivery and continuity). |
| (c) Analytics | Section 8, DPDP Act (calibrated, pseudonymised processing) with in-settings opt-out; SPDI Rule 5 where applicable. |
| (d) Marketing / Advertising / Behavioural Profiling | Section 6, DPDP Act (specific, informed, unambiguous consent); Rule 4(9), E-Commerce Rules (affirmative consent). |
6. Third-party cookies, SDKs and pixels
6.1 Lexi Trip works with third-party service providers described in this Policy body by category only, including: web analytics provider; crash/telemetry SDK; attribution SDK; session replay / heatmap tool; server-side tag manager; CDN and bot-mitigation provider; email and communications delivery provider; ad-network / re-marketing provider; and conversion measurement provider.
6.2 The named vendor register — including vendor name, first- or third-party classification, category, purpose, retention period, cross-border host region and opt-out route — is set out in Schedule CK-1. Schedule CK-1 is producible under Rule 6 of the SPDI Rules and the DPDP disclosure duties on request, and to courts and regulators under Rule 3(7) of the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 (the “Intermediary Rules”).
6.3 Non-override / non-interference. Lexi Trip cannot override a vendor’s own cookie/SDK behaviour beyond the configuration options that the vendor exposes to Lexi Trip. Controls offered to Customers are configuration-level, not vendor-substitution-level.
6.4 Lexi Trip conducts vendor due diligence and executes data processing agreements or equivalent contractual safeguards with every vendor in Tier (c) and Tier (d).
7. Server-side tagging, container tags and hashed identifiers
7.1 Lexi Trip uses (or may use) a server-side tag manager to route measurement events through a Lexi Trip-controlled endpoint before onward transmission to a vendor. This design reduces the surface area of data shared with third parties.
7.2 Lexi Trip may transmit hashed CRM identifiers (e.g., SHA-256 hashes of an email address) to measurement partners solely for conversion attribution and audience measurement, and only for Customers in Tier (d) who have opted in.
7.3 Lexi Trip commits that no unhashed personally identifiable information will be transmitted to third-party ad networks. Where a vendor’s implementation compels transmission of raw identifiers, Lexi Trip will disable that integration.
8. Session replay, heatmaps and form analytics
8.1 If deployed, session replay, heatmap or form-analytics tools are configured with default masking of sensitive fields, including payment fields, PAN/CVV, passport numbers, government identifiers, date of birth and OTPs.
8.2 These tools are not enabled on logged-in visa, insurance or KYC flows.
8.3 A Customer may switch off Tier (c) tools, including session replay, through the Cookie & Tracking Preferences panel.
9. Mobile SDKs and app permissions
9.1 The Lexi Trip mobile applications may incorporate SDKs for:
9.1.1 attribution and deferred deep-linking (Tier (c) for aggregated measurement; Tier (d) for user-level attribution — opt-in only);
9.1.2 crash reporting and telemetry (Tier (a)/(c));
9.1.3 push notification tokens (Tier (b), governed by OS-level permission); and
9.1.4 map and location services (governed by OS-level permission).
9.2 A Customer may opt out through: the OS-level advertising identifier controls (iOS Limit Ad Tracking; Android opt-out of ads personalisation); OS-level push and location permissions; and the in-app Cookie & Tracking Preferences panel.
10. Cross-border transfers
10.1 Certain vendors listed in Schedule CK-1 host their services outside India. Personal data associated with cookies/SDKs may therefore be transferred to and processed in jurisdictions outside India, in accordance with Section 16 of the DPDP Act as notified by the Central Government from time to time.
10.2 Categories of destination jurisdictions include analytics vendor hosting regions, crash-telemetry vendor hosting regions and ad-network hosting regions — To be confirmed: exact categories to be populated at go-live from the completed Schedule CK-1 vendor register.
10.3 Lexi Trip implements contractual safeguards (including data processing addenda), technical safeguards (including encryption in transit and, where feasible, at rest) and organisational safeguards for every such transfer.
11. Retention
11.1 Session Cookies are deleted when the browser is closed or the app session ends.
11.2 Persistent Cookies, SDK identifiers and equivalent trackers have per-cookie/per-SDK maximum lifetimes set out in Schedule CK-1, subject to the following ceilings:
11.2.1 Tier (a) and (b): duration necessary for the operational purpose, refreshed each session — To be confirmed: exact refresh/expiry rule to be confirmed at go-live;
11.2.2 Tier (c) Analytics: capped at To be confirmed: maximum retention period to be confirmed at go-live (source suggests around 13 months);
11.2.3 Tier (d) Marketing: capped at To be confirmed: maximum retention period to be confirmed at go-live (source suggests around 6 months).
11.3 At expiry, identifiers are deleted or rotated, and any linked pseudonymised profile is dissociated in accordance with Lexi Trip’s retention schedule under the Privacy Policy.
12. Children — Section 9 DPDP Act
12.1 Lexi Trip does not deploy behavioural, targeted or profiling cookies or SDKs where it has actual knowledge that the Data Principal is a minor.
12.2 The Marketing tier (Tier (d)) is disabled for such Data Principals irrespective of any opt-in signal.
12.3 Analytics processing continues only in aggregated, pseudonymised form and only to the extent necessary for service integrity.
13. Do-Not-Track, Global Privacy Control and browser signals
13.1 Lexi Trip treats the following signals as a withdrawal of consent to Tier (d) for the browser or device sending the signal:
13.1.1 the Global Privacy Control (GPC) header, where technically detected;
13.1.2 the Do-Not-Track (DNT) header, where technically detected; and
13.1.3 OS-level advertising-identifier opt-out signals (iOS/Android).
13.2 These signals do not affect Tier (a), Tier (b) or pseudonymised Tier (c) processing, each of which rests on a distinct lawful basis.
14. Interaction with the Lexi Trip Privacy Policy and Master T&Cs
14.1 This Policy is a companion document to the Lexi Trip Privacy Policy and the Lexi Trip Master Terms & Conditions.
14.2 In the event of a conflict on operational cookie/tracking disclosure, this Policy prevails.
14.3 In the event of a conflict on Data Principal rights, the Privacy Policy prevails.
14.4 In the event of a conflict on commercial terms of the Booking or the Underlying Service (including the roles of Facilitator, Merchant of Record, Disclosed Agent, Payment Collection Entity, Lexi Trip Fees, Supplier, Aggregator Partner, Fulfilment Partner, Service Provider or Third-Party Service Provider), the Master Terms prevail.
15. Data Principal rights specific to cookies and tracking
15.1 A Customer has the right to:
15.1.1 access the current state of the Cookie & Tracking Preferences and the categories of trackers deployed;
15.1.2 correct or update those preferences;
15.1.3 erase tracker-linked identifiers associated with the Customer’s account, subject to lawful retention exceptions;
15.1.4 withdraw consent to Tier (d) at any time, with the same ease as it was given;
15.1.5 nominate another individual under Section 14 of the DPDP Act; and
15.1.6 raise a grievance with the Grievance Officer.
15.2 A request is processed after reasonable identity verification (typically confirmation from the registered email address and/or in-account challenge). Timelines are aligned with the DPDP Rules, 2025 and, in any case, the outer limit specified in Section 16 below.
15.3 A Customer may exercise these rights by writing to the Grievance Officer (see Section 21) or through the Lexi Trip account.
16. Security safeguards
16.1 Lexi Trip implements reasonable security practices and procedures under Section 43-A of the IT Act and Rule 8 of the SPDI Rules, including:
16.1.1 encryption in transit (TLS) and, where feasible, at rest;
16.1.2 pseudonymisation of tracker-linked identifiers;
16.1.3 role-based access controls and access logging;
16.1.4 audit trails for changes to the tag inventory and to vendor configurations;
16.1.5 vendor due diligence and data-processing agreements; and
16.1.6 breach detection, containment and notification consistent with Section 8(6) of the DPDP Act and the CERT-In directions.
17. Grievance mechanism
17.1 A Customer may raise a grievance concerning cookies or tracking with the Grievance Officer:
Mr. Bani Pal Singh
Email: banipal@lexitrip.in
Toll-free: 1800-313-2005
Postal: 2-A/3, Kundan Mansion, Asaf Ali Road, New Delhi – 110002
17.2 Dual clock. The Grievance Officer will:
17.2.1 acknowledge the grievance within forty-eight (48) hours of receipt; and
17.2.2 resolve the grievance within one (1) month of receipt,
as required by Rule 4(4)–(5) of the E-Commerce Rules, read with Rule 3(2) of the Intermediary Rules and Section 8(10) of the DPDP Act.
17.3 A Customer may escalate an unresolved grievance to the Data Protection Board of India in the manner prescribed under the DPDP Act and the DPDP Rules, 2025.
18. Changes to this Policy
18.1 Lexi Trip may amend this Policy from time to time. Notice of an amendment will be given through:
18.1.1 a version update in the footer of the Platform;
18.1.2 an in-app notification; and/or
18.1.3 email to the registered email address, where the amendment is material.
18.2 Continued use of the Platform after a non-material change constitutes acceptance of that change.
18.3 For a material change to Tier (d) (Marketing / Advertising / Behavioural Profiling), Lexi Trip will present a fresh in-account prompt for affirmative opt-in.
19. Governing law, jurisdiction and dispute resolution
19.1 This Policy is governed by, and construed in accordance with, the laws of India.
19.2 Subject to the DPDP Act’s grievance and adjudication architecture, the courts at New Delhi shall have exclusive jurisdiction over any dispute arising out of or in connection with this Policy.
19.3 The dispute resolution provisions in Part X of the Lexi Trip Master Terms & Conditions apply mutatis mutandis to disputes arising under this Policy, save that nothing in this Policy displaces the statutory rights of a Data Principal under the DPDP Act or the statutory rights of a consumer under the Consumer Protection Act, 2019.
20. PA/PG boundary note
20.1 Consistent with the RBI Payment Aggregator Directions, 2025 as applicable, cookies and pixels deployed in the checkout flow that touch PSP-side data sit strictly within the PA/PG boundary. Lexi Trip does not deploy cookies, pixels or SDKs to capture PAN, CVV or full-card data.
21. Contact block
Grievance Officer / Data Protection Contact
Mr. Bani Pal Singh
Email: banipal@lexitrip.in
Toll-free: 1800-313-2005
Registered Office
Bani Global Industries LLP
2-A/3, Kundan Mansion, Asaf Ali Road, New Delhi – 110002
Schedule CK-1 — Named Cookie and SDK Register
To be confirmed: populate at go-live from the live Tag Audit — final list of named Cookies and SDKs deployed on lexitrip.in and the Lexi Trip mobile apps, including for each item: vendor name, first- or third-party classification, category, purpose, retention period, cross-border host region and opt-out route. Producible under Rule 6 of the SPDI Rules and the DPDP disclosure duties on request, and refreshed on each tag-inventory change.
Schedule CK-2 — Browser, Device and In-Account Control Paths
| Environment | Path to Cookie / Tracking Controls |
|---|---|
| Google Chrome (desktop / Android) | Settings → Privacy and security → Cookies and other site data → Block third-party cookies or Send a "Do Not Track" request. |
| Apple Safari (macOS) | Safari → Settings → Privacy → Prevent cross-site tracking; Block all cookies. |
| Apple Safari (iOS/iPadOS) | Settings → Safari → Privacy & Security → Prevent Cross-Site Tracking; Block All Cookies. |
| Mozilla Firefox | Settings → Privacy & Security → Enhanced Tracking Protection → Strict; enable Global Privacy Control. |
| Microsoft Edge | Settings → Privacy, search, and services → Tracking prevention: Strict; Send "Do Not Track" requests. |
| iOS (device-level ad tracking) | Settings → Privacy & Security → Tracking → Allow Apps to Request to Track (off); Settings → Privacy & Security → Apple Advertising → Personalised Ads (off). |
| Android (device-level ad tracking) | Settings → Google → Ads → Delete advertising ID; or Opt out of Ads Personalisation. |
| In-account | Lexi Trip account → Privacy & Security → Cookie & Tracking Preferences (Schedule CK-2). |
Questions about a specific booking? See Contact us.