Security Policy
On this page
1. Security Overview and Commitment
At OntaTrip, including all our corporate entities, global branches, and regional offices ("OntaTrip"), protecting customer personal information and financial transaction security is an essential commitment. This Security Policy outlines the technical measures, administrative safeguards, and online standards enforced across ontatrip.com to maintain a safe booking environment.
2. Data Encryption Standards (SSL/TLS)
All interaction and data transmission between your internet browser and ontatrip.com web servers is protected using standard Secure Sockets Layer (SSL) and Transport Layer Security (TLS) cryptographic protocols:
Transport Encryption: 256-bit encryption protocols automatically scramble sensitive data, including passenger names, passport numbers, email addresses, and payment details, before transmission across the internet.
Digital Server Verification: Valid SSL digital certificates issued by recognized Certificate Authorities confirm website authenticity, ensuring that users connect securely with genuine OntaTrip servers.
3. Payment Card Data Safeguards (PCI-DSS)
Online payment transactions on ontatrip.com are processed through accredited payment gateways operating under strict global security standards:
| Security Domain | Protective Standard Enforced |
|---|---|
| Card Data Storage | OntaTrip does not save raw payment card numbers, debit PINs, or CVV/CVC codes on local web servers or internal databases. |
| Gateway Integration | Checkout payments are routed through encrypted APIs to certified payment gateway platforms complying with PCI-DSS Level 1 standards. |
| Multi-Factor Authentication | Financial transactions support 3D Secure verification, One-Time Passwords (OTP), or bank authorization codes issued by your payment card issuer. |
| Masked Receipt Display | Payment confirmations and account transaction records display truncated, masked card numbers (for example, showing only the first four and last four digits). |
Card Data Storage
OntaTrip does not save raw payment card numbers, debit PINs, or CVV/CVC codes on local web servers or internal databases.
Gateway Integration
Checkout payments are routed through encrypted APIs to certified payment gateway platforms complying with PCI-DSS Level 1 standards.
Multi-Factor Authentication
Financial transactions support 3D Secure verification, One-Time Passwords (OTP), or bank authorization codes issued by your payment card issuer.
Masked Receipt Display
Payment confirmations and account transaction records display truncated, masked card numbers (for example, showing only the first four and last four digits).
4. Infrastructure and Network Security
Our server architecture and cloud hosting environments are protected by defense-in-depth network controls:
Firewall Monitoring: Enterprise Web Application Firewalls (WAF) inspect incoming web traffic, filter malicious requests, and guard against unauthorized system access.
Vulnerability Reviews: Automated security scanners conduct regular security checks across system perimeters and booking application code.
Regular Patching: Operating systems, database engines, and server software are regularly updated with vendor security patches.
5. Staff Administrative Controls
OntaTrip maintains internal administrative protocols to govern data handling:
Role-Restricted Access: Customer records are accessible solely to authorized ticketing officers, visa specialists, and support team members who require data access for service duties.
Authentication Credentials: Internal access requires unique multi-factor authentication credentials and strong password parameters.
Confidentiality Commitments: All OntaTrip team members sign formal non-disclosure and confidentiality agreements prohibiting unapproved information sharing.
6. Friendly User Security Recommendations
We kindly encourage travelers to observe basic security practices for a safe browsing experience:
Password Hygiene: We kindly ask users to choose unique passwords for their OntaTrip account and to avoid sharing OTP codes or passwords with anyone.
Address Bar Verification: Please feel free to verify that your browser address bar shows https://ontatrip.com with an active padlock icon before entering checkout details.
Unsecured Networks: We kindly suggest avoiding financial payments over open public Wi-Fi networks unless connected through a trusted Virtual Private Network (VPN).
7. Security Assistance and Reporting
If you ever notice unexpected account activity, discover a potential vulnerability, or receive a suspicious communication claiming to represent OntaTrip, we warmly invite you to inform our technical security team at cs@ontatrip.com or contact your local OntaTrip branch.
OntaTrip Global Support and Contact
If you have any questions, polite requests, or need assistance regarding this document or your travel reservations, you are warmly invited to contact our team. This policy applies universally across all OntaTrip companies, branches, and regional operations.
Central Email Support
cs@ontatrip.comOfficial Website
ontatrip.comBranch Network
Please feel free to reach out to your local OntaTrip branch or regional office directly.
