White-Label Partner Programme
D2W-WL-POLWhite-Label Partner Policies
Privacy, KYC, bookings and refunds, wallet and settlement, acceptable use, brand, security, service levels and grievance redressal, in one handbook for partners and their agents.
| Document code | D2W-WL-POL |
| Version | 1.1 |
| Effective date | 24 September 2026 |
| Supersedes | Version 1.0, effective 15 September 2026 |
| Issued by | D2W Mobility (Dash2Wheel), Indore |
| Applies to | White-label Partners, their Agents and every user of a Partner-branded Desk |
Document control
| Version and status | Version 1.1 — reissued in full |
| Owner | D2W Mobility (Dash2Wheel), B-9, Neha Apartment, Near Collector Office, Indore – 452001 |
| Related documents | D2W-WL-TC White-Label Partner Terms & Conditions v1.1 · D2W-WL-AGR White-Label Partner Agreement v1.1 |
| Sharing | Any Part may be shared on its own with Agents and staff. This document is not marked confidential for that reason. |
What changed in version 1.1. A.7 now states where the Platform is hosted, and A.13 lists the sub-processors by name. Part D is rewritten: D.2 and D.3 say who an agency actually pays and who is answerable for that money where a Partner funds its own Agents. G.5 states the backup, recovery-point and recovery-time objectives. B.4 requires a document for a change of legal name.
Contents
Introduction
These Policies form part of the White-Label Partner Terms & Conditions (D2W-WL-TC) and of every White-Label Partner Agreement that refers to them. Capitalised words have the meanings given in the Terms. Where a Policy and a signed Agreement conflict, the Agreement prevails.
The Policies are grouped into ten parts. Each part can be shared on its own with Agents or staff, but all of them apply together.
Part A — Privacy & Data Protection Policy
A.1
Purpose. This part explains how Personal Data is handled on a Partner-branded Desk. It covers who is responsible for the data, what is collected, why, who receives it, where it is kept and for how long. It is written to meet the Digital Personal Data Protection Act, 2023 ("DPDP Act"), the Information Technology Act, 2000 and the rules made under them.
A.2
Roles.
- Customer data. For the Personal Data of travellers and Customers entered on the Desk, the Partner or the Agent that collected it is the Data Fiduciary, and D2W acts as its Data Processor. D2W processes that data only to provide the Platform and on documented instructions, which include the configuration and use of the Desk.
- Account and business data. For the Personal Data of the Partner's and Agents' users, and for the data used for KYC, billing, security and fraud prevention, D2W is the Data Fiduciary.
A.3
Data collected.
- Business and user details: business name, constitution, address, city, GSTIN, PAN, registration documents, bank account for payouts, owner and user names, email addresses and phone numbers.
- Login and security data: password hashes (never readable passwords), two-factor settings, session tokens, IP address, device and browser details, audit logs.
- Acceptance records: the document and version accepted, the name and role typed, the time, the IP address and the browser reported.
- Customer and traveller details entered for a quotation or Booking: name, contact details, dates of birth, nationality, passport or identity document details where a Supplier requires them, meal and seat preferences, and special-assistance notes.
- Transaction data: quotations, Bookings, Supplier references, PNRs, Wallet movements, invoices, payouts and refunds.
- Communications: support tickets, emails and messages sent through the Platform.
A.4
Purposes. Personal Data is used to create and secure Accounts; verify businesses; search, quote and book travel with Suppliers; issue documents and invoices; process Wallet top-ups, refunds and payouts; provide support; detect and prevent fraud and abuse; meet tax, accounting and legal obligations; and improve the Platform using aggregated or de-identified information.
A.5
Payment cards. D2W does not store card numbers, CVVs, UPI PINs or net-banking credentials. Online payments, where offered, are processed by a PCI-DSS compliant payment gateway, which shares only the transaction outcome with D2W.
A.6
Sharing. Personal Data is shared only:
- with Suppliers, to the extent a search or Booking requires;
- with the sub-processors listed in A.13, acting on D2W's instructions and under confidentiality and security obligations;
- with the Partner, in respect of its own Agents' Accounts and activity on the Desk;
- with authorities, where the law, a court order or a lawful request requires, or to establish, exercise or defend legal claims.
A.7
Where the data is held, and transfers outside India. The Platform, its database and its backups are hosted on virtual servers provided by Contabo GmbH, presently in its European Union region (Lauterbourg, France). Personal Data entered on the Desk is therefore stored and processed outside India. Several Suppliers and service providers — airlines, international hotels, and the providers listed in A.13 — also operate outside India, and Personal Data is transferred to them to fulfil a Booking or to run the Platform. D2W does not host or transfer Personal Data to any country or territory that the Central Government has restricted under the DPDP Act. D2W will give Partners at least 30 days' notice before moving the hosting region, and will update this Part when it does.
A.8
Notice and consent. Before entering a Customer's Personal Data on the Desk, the Partner and its Agents must give the Customer the notices required by law, including the fact that the data is processed on infrastructure outside India, and obtain any consent the law requires. They are responsible for recording that consent and for honouring its withdrawal.
A.9
Retention.
- Account, Booking, invoice and Wallet records: for the life of the Account and then for as long as tax and other law requires, generally 8 years for financial records.
- Acceptance records under clause 1.6 of the Terms: for the life of the Account and 8 years afterwards.
- KYC documents: for the life of the relationship and 5 years after it ends, or longer where the law requires.
- Unconverted Enquiries: up to 24 months.
- Security logs: a rolling window sufficient for security investigation, normally up to 180 days.
A.10
Rights of Data Principals. Individuals may ask for access to, correction of, or erasure of their Personal Data, may withdraw consent, and may nominate another person. A request about Customer data received by D2W is forwarded to the relevant Partner or Agent within 5 Business Days. D2W helps the Partner answer such requests. A request about account data is answered by D2W within 30 days.
A.11
Personal Data breach. If D2W becomes aware of a Personal Data breach affecting Customer data on a Partner's Desk, it notifies the Partner without undue delay, and in any case within 48 hours. It will describe what is known, the likely consequences and the steps taken, and will cooperate with the notifications the DPDP Act requires.
A.12
Children. The Platform is for businesses and is not directed at children. Children's data is entered only as a traveller on a Booking made by an adult. Verifiable consent from a parent or guardian is obtained by the Partner or Agent where the law requires it.
A.13
Sub-processors. D2W engages the following, each under written obligations that protect the data. This list is kept current, and D2W notifies Partners at least 30 days before adding a sub-processor that will process Customer Personal Data.
| Sub-processor | What it does | Where |
|---|---|---|
| Contabo GmbH | Server hosting, database and backups | European Union |
| Google (Gemini API) | AI itineraries, quotations and message drafting | Outside India |
| Groq, Inc. | AI processing, as a fallback provider | Outside India |
| Resend, Inc. | Transactional email delivery | Outside India |
| Razorpay Software Private Limited | Online payments, where offered | India |
| Duffel Technology Limited | Flight search, booking and ticketing | Outside India |
| Hotelbeds / HBX Group | Hotel search and booking | Outside India |
| Tek Travels Pvt. Ltd. (TBO) | Flight and hotel search and booking | India |
| LiteAPI | Hotel search and booking | Outside India |
Part B — KYC & Anti-Fraud Policy
B.1
Purpose. Travel is a high-value, fraud-prone trade. This part sets out the verification D2W requires before an account can trade, and the controls used to stop fraudulent Bookings.
B.2
Documents required from the Partner.
| Document | Required for |
|---|---|
| PAN of the business (or of the proprietor) | All Partners |
| Certificate of Incorporation, LLP certificate, partnership deed or Udyam/shop-establishment registration | Company, LLP, partnership or proprietorship respectively |
| GST registration certificate, or a declaration of non-registration | All Partners |
| Proof of business address (utility bill, rent agreement or registration) | All Partners |
| Identity proof of the owner, directors or partners and of the authorised signatory | All Partners |
| Cancelled cheque or bank letter for the payout account, in the business's own name | Commission payouts and Wallet withdrawals |
| Board resolution or authority letter for the signatory | Companies and LLPs |
B.3
Agents. The Partner collects equivalent documents from each Agent before activating it for Bookings, keeps them, and produces them to D2W within 3 Business Days of a request. D2W may require an Agent to complete verification directly with D2W before it can issue tickets or withdraw funds.
B.4
Re-verification. Changes to legal name, address, city, GSTIN, PAN or bank account are submitted through the Desk and take effect only after D2W approves them. A change of legal name must identify the document on which the new name appears — its type and number, and a copy or link where available — and D2W records what it was shown. D2W may re-verify an account at any time.
B.5
Red flags. D2W may hold, verify or decline a Booking, top-up or payout that shows signs of fraud. Signs include:
- a payment from a third party whose name does not match the agency, or from a card or account flagged by a payment network;
- same-day or next-day international tickets bought with newly added funds for unrelated passengers;
- repeated failed payments, unusual booking velocity, or many bookings from one device or IP address across different agencies;
- mismatched or reused passenger and contact details;
- a request to refund to an account other than the source of funds.
B.6
Consequences. Where fraud is reasonably suspected, D2W may cancel unticketed Bookings, freeze the Wallet balance connected with the suspected fraud, suspend Accounts, recover losses from the Partner, and report to Suppliers, payment networks, banks and law-enforcement agencies. The Partner must cooperate fully with any investigation.
B.7
Sanctions. Bookings must not be made for, or on behalf of, persons or entities under sanctions that apply in India. Nor may they be made in breach of a Supplier's sanctions rules.
Part C — Booking, Cancellation & Refund Policy
C.1
Enquiries. An Enquiry has no fare commitment and no charge. Nothing is payable, and nothing is refundable, until a Booking is confirmed.
C.2
Confirmation. A Booking is confirmed only when the Platform shows a PNR, Supplier reference or confirmation number. Travel documents such as e-tickets, hotel vouchers and package confirmations are issued on the Desk.
C.3
Flights.
- Cancellation, date change and name change are governed by the airline's fare rules. Non-refundable fares return only the refundable taxes and fees, where the airline allows.
- A no-show may forfeit the fare and the onward and return sectors, under the airline's rules.
- Cancellations must be made on the Desk before the airline's cut-off, which is normally at least 3 hours before departure for domestic flights and 4 hours for international flights, or earlier if the fare rules require. A request after the cut-off is treated as a no-show.
- Where the airline cancels a flight or makes a significant schedule change, D2W passes on the options the airline offers, such as rebooking, a credit shell or a refund. The Partner or Agent must act on them within the time the airline allows.
C.4
Hotels. Cancellation deadlines and charges are those shown on the rate at the time of booking. Rates marked non-refundable cannot be refunded. A no-show is charged under the hotel's policy. Early check-out may not be refundable.
C.5
Holiday packages. Package cancellations are charged according to the slabs stated in the package quotation or confirmation. Where no slabs are stated, the actual non-recoverable costs incurred with Suppliers are charged, plus the service fee.
C.6
Service fees. Platform or service fees charged by D2W on a Booking are non-refundable once the Booking is confirmed, unless D2W or the Supplier caused the cancellation.
C.7
Refund process.
- Refunds are requested through the Desk against the Booking reference.
- D2W submits the request to the Supplier within 1 Business Day.
- D2W credits the amount it actually receives from the Supplier, less applicable charges, to the booking agency's Wallet within 7 Business Days of receiving it. Where the Booking was paid through a payment gateway, the refund goes back to the original payment source.
- Supplier refund timelines are outside D2W's control, and some airlines take 30 to 90 days. D2W shows the refund status on the Desk and follows up with the Supplier.
C.8
Refunds to Customers. The Partner or Agent is responsible for refunding its own Customer, under its contract with that Customer, and for handling any consumer complaint relating to that contract.
C.9
Errors by D2W. If a Booking fails, is duplicated or is mispriced because of a fault in the Platform, D2W corrects it or refunds the affected amount in full.
Part D — Wallet, Payments & Settlement Policy
D.1
Nature of the Wallet. The Wallet is a closed-loop advance held against Bookings and Fees on the Platform. It is not a bank deposit, a stored-value instrument or an investment. It earns no interest, and cannot be used outside the Platform or transferred between agencies, except as D.3 describes between a Partner and its own Agent.
D.2
Who you pay. The Desk shows each agency the account its top-ups must go to, and the name of the party that will confirm them. There are two cases, and the Desk always says which one applies.
- Paying D2W. For D2W's own direct agencies, and for a Partner's own balance, funds are paid by bank transfer (NEFT, RTGS or IMPS) or UPI, from an account in the name of the agency or its owner, to the D2W account shown on the Desk. The agency submits a top-up request with the amount and the UTR or transaction reference. D2W verifies receipt and credits the Wallet, normally within 1 Business Day of the funds arriving.
- Paying your Partner. Where a Partner has switched on its own agent funding, its Agents pay the Partner's account, shown on the Desk with the Partner's name, and the Partner confirms receipt. D2W is not a party to that payment and never receives those funds.
- Cash deposits and third-party payments are not accepted in either case. Any such amount received is returned to its source, less bank charges.
D.3
Who is answerable for the money.
- D2W holds, verifies and settles funds only for (i) its own direct agencies and (ii) a Partner's own balance. D2W is answerable for those balances and no others.
- Where a Partner funds its own Agents, that Partner is solely answerable to each such Agent for money received from it, for crediting it on the Platform, for any delay, for any refund, and for returning any balance. A claim by such an Agent in respect of money it paid its Partner lies against that Partner, not against D2W.
- Confirming an Agent's top-up moves the amount out of the Partner's own balance into the Agent's, in a single transaction, and is refused if the Partner's balance does not cover it. No balance is created: the Platform never holds more than what has actually reached D2W.
- A withdrawal by such an Agent returns its Platform balance to its Partner, and the Partner pays the Agent from its own bank account.
- The Partner sets and is responsible for its own Agents' credit, limits, pricing and collections. D2W does not bill a Partner's Agents for subscriptions unless the Agreement says otherwise.
D.4
Withdrawals from D2W. An agency that pays D2W directly may request withdrawal of its available balance through the Desk. The balance excludes amounts held for pending Bookings, disputes or suspected fraud. Withdrawals are paid only to the verified bank account held in the agency's own name, within 7 Business Days of approval.
D.5
Negative balance. Supplier charges, ADMs, chargebacks or penalties may result in a negative balance. The agency must restore it within 7 days of notice. D2W may recover a negative balance from the Partner's commission balance, and a Partner may recover its Agent's negative balance from that Agent.
D.6
Statements. A running statement of every credit and debit is available on the Desk, on both sides of a transfer between a Partner and its Agent. Discrepancies must be reported within 30 days of the transaction. After that, the statement is treated as accepted, except in the case of manifest error.
D.7
Commission payouts.
- The Override Commission accrues on confirmed Bookings.
- Payout requests submitted by the 5th day of a month are settled by the 15th day of that month, for commission on Bookings whose travel or cancellation window closed in the previous month.
- Payouts are made net of applicable TDS, and TDS certificates are issued as the law requires.
- The Partner must issue a valid GST tax invoice for the commission where it is GST-registered.
D.8
Taxes. GST, TCS on overseas tour packages, and other taxes are applied as required by the law in force on the date of the transaction.
Part E — Acceptable Use & Communications Policy
E.1
The Platform must be used only for genuine travel business, in line with the Acceptable Use clause of the Terms.
E.2
Customer communications. Emails, WhatsApp messages, SMS and calls to Customers must be sent only to people who have a relationship with the sender or have consented. They must comply with the rules on unsolicited commercial communications, and must include a way to opt out where the law requires.
E.3
AI features. AI outputs must be reviewed before use. The Partner and its Agents must not use AI features to create misleading offers, fake reviews, impersonation, or content that infringes the rights of others.
E.4
Automation. Only the APIs and integrations D2W provides may be used. Scraping, credential sharing and robotic booking tools are prohibited.
E.5
Fair use. Search volumes must bear a reasonable relationship to actual Bookings. D2W may apply rate limits, or charge for excessive look-to-book ratios where a Supplier charges D2W for them, after notice.
Part F — Brand & Marketing Guidelines
F.1
Partner Brand. The Desk shows the Partner Brand configured in Schedule D of the Agreement. The Partner supplies logos in the specified formats, and is responsible for their accuracy and its right to use them.
F.2
D2W marks. The names Dash2Wheel, D2W, D2W Travel AI, the D2W logo and related marks belong to D2W. They may be used only with D2W's written permission, and only in the form D2W approves.
F.3
Honest marketing. Advertised fares and packages must state what is included, what is excluded and whether taxes are included. They must be available on the terms advertised. Claims of accreditation, recognition, awards or "lowest price" must be true and verifiable.
F.4
Offers on the Desk. Offers that D2W publishes on the Desk are subject to the conditions and validity stated with them. The Partner may present them to its Agents, but may not change their terms.
F.5
Takedown. D2W may require the Partner to withdraw any marketing that breaches this part, or that misrepresents D2W, a Supplier or a fare, within 2 Business Days of notice.
Part G — Information Security Policy
G.1
D2W's controls. D2W maintains safeguards appropriate to the nature of the data, including:
- encryption of traffic in transit using TLS;
- one-way hashing of passwords with Argon2;
- short-lived, rotating session tokens and optional two-factor authentication;
- role-based access and permissions for users within each agency;
- logical separation of each agency's data;
- audit logging of administrative, payment and account-change events;
- restricted, logged access to production systems for authorised D2W personnel only;
- regular backups of production databases.
G.2
Partner and Agent obligations.
- One named login per person; no shared credentials.
- Strong, unique passwords, and two-factor authentication for owners and finance users.
- Access removed within 24 hours when a user leaves or changes role.
- Devices used for the Desk kept updated and protected against malware.
- Customer documents downloaded from the Desk stored securely and deleted when no longer needed.
- Suspected compromise reported to D2W within 24 hours.
G.3
Incident handling. D2W investigates security incidents, contains them, informs affected Partners as described in Part A, and records what was learned. The Partner must cooperate and preserve relevant records.
G.4
Testing. Security testing of the Platform, including penetration tests and vulnerability scans, may be carried out only with D2W's prior written permission. Vulnerabilities should be reported responsibly to info@dash2wheel.com.
G.5
Backups and recovery. The production database is backed up daily, and backups are retained for 30 days. D2W's objectives in a disaster are a recovery point of 24 hours (at most one day's transactions lost) and a recovery time of 8 business hours to restore the Desk's core functions. These are objectives, not guarantees, and restoring a Supplier's own systems is outside D2W's control. D2W tests a restore at least once every 6 months and records the result.
Part H — Service Levels & Support Policy
H.1
Availability target. D2W targets 99.5% monthly availability for the Desk's core functions of sign-in, search, quotation, booking and Wallet.
H.2
Exclusions. The availability target excludes:
- planned maintenance notified in advance;
- outages of Suppliers, airline or hotel systems, payment gateways or other third-party services;
- problems with the Partner Domain's DNS or registrar;
- force majeure;
- beta features;
- suspension under the Terms;
- issues caused by the Partner's or its Agents' systems, networks or misuse.
H.3
Support channels. Support is provided by email at info@dash2wheel.com and by phone on +91 70002 93640, Monday to Saturday, 10:00 AM to 8:00 PM IST. The Partner provides first-line support to its Agents and escalates to D2W any issue it cannot resolve, with the Agency Code, Booking reference, screenshots and steps to reproduce.
H.4
Severity and response.
First response times are measured within support hours.
| Severity | Meaning | First response | Target resolution or workaround |
|---|---|---|---|
| P1 — Critical | Desk down, or no user can sign in, search or book | 1 hour | 8 business hours |
| P2 — High | A core function is failing for many users; no workaround | 4 hours | 2 Business Days |
| P3 — Medium | A function is impaired, or a workaround exists | 1 Business Day | 5 Business Days |
| P4 — Low | Questions, cosmetic issues, feature requests | 2 Business Days | Planned release |
H.5
Escalation.
- Level 1: Support desk — info@dash2wheel.com, +91 70002 93640.
- Level 2: Account management — +91 89825 98676.
- Level 3: Management — +91 731-4397522, by written escalation referring to the ticket.
H.6
Service credits. Service credits, if any, are those stated in Schedule C of the signed Agreement. Where none are stated, the remedies in this part are the Partner's sole remedy for a failure to meet service levels.
Part I — Grievance Redressal Policy
I.1
Raising a grievance. A Partner, Agent, user or Customer with a complaint about the Platform, or about D2W's handling of Personal Data, can write to the Grievance Officer. The complaint should give the Agency Code or Booking reference, a description, and copies of any documents.
I.2
Grievance Officer. Grievance Officer, D2W Mobility (Dash2Wheel), B-9, Neha Apartment, Near Collector Office, Indore – 452001, Madhya Pradesh, India. Email: info@dash2wheel.com. Phone: +91 731-4397522. Hours: Monday to Saturday, 10:00 AM to 8:00 PM IST.
I.3
Timelines. A grievance is acknowledged within 24 hours and resolved within 15 days of receipt. Where a matter needs information from a Supplier or a longer investigation, D2W gives an interim update and the expected date.
I.4
Complaints about a Partner or Agent. A complaint that concerns a Partner's or Agent's own service to a Customer, or money an Agent paid its Partner, is forwarded to that Partner or Agent, who must respond within the same timelines. D2W may ask for evidence of the resolution.
I.5
Escalation. If the grievance is not resolved to the complainant's satisfaction, the dispute-resolution clause of the Terms or the Agreement applies. This does not limit any right a Customer has under consumer protection law, or to approach the Data Protection Board of India.
Part J — Changes to these Policies
J.1
D2W may update these Policies to reflect changes in law, Supplier rules, security practice or the Platform. Material changes are notified to Partners by email or through the Desk at least 30 days before they take effect, unless a shorter period is required by law, a Supplier or a security need.
J.2
A new version is put to each account owner for acceptance on the Desk when it takes effect, as clause 1.6 of the Terms describes.
J.3
The version number and effective date on the cover identify the current version. Earlier versions are available from D2W on request.