Privacy Policy

Preface

This policy governs how Journey DMC collects and processes personal data of travelers booking trips across India, in line with India's Digital Personal Data Protection Act, 2023 (DPDPA), and applicable rules issued under the Information Technology Act, 2000. As your data fiduciary for Indian bookings, we outline below the purposes, safeguards, and choices available to you.

1. Categories of Personal Data Collected

Category Examples
Identity data Name, passport number, e-Visa/visa copy, date of birth
Contact data Email, phone number, mailing address
Travel data Itinerary preferences, hotel/train/flight bookings, past trips with us
Financial data Card details, billing address, GST invoicing information
Sensitive personal data Health conditions relevant to travel (e.g., for Himalayan or wildlife itineraries), dietary/religious preferences
Technical data IP address, device type, cookies, website interaction logs

2. Purposes of Processing

We process your data to:

  • Confirm hotel, train (including tourist-quota rail bookings), domestic flight, and vehicle reservations across Indian states
  • Support your Indian e-Visa or visa-on-arrival documentation where relevant
  • Issue GST-compliant tax invoices as required under Indian law
  • Arrange wildlife safari permits (e.g., for national parks such as Ranthambore or Kaziranga) where advance government booking is mandatory
  • Coordinate with local guides, drivers, and heritage-site ticketing systems
  • Respond to service requests and complaints
  • Send trip updates, weather advisories, or safety notices during your journey
  • Send marketing communications about Indian destinations, only where you've opted in

3. Legal Basis and Consent

Under the DPDPA, we process your data primarily on the basis of your consent, given at the time of booking or website use, and in limited cases for "legitimate uses" such as fulfilling a contract or complying with legal obligations (e.g., reporting requirements to Indian tourism or immigration authorities). You may withdraw consent for non-essential processing (such as marketing) at any time without affecting service delivery already contracted.

4. Sharing of Data

Your data may be shared with:

  • Hotels, homestays, and heritage properties across India
  • Domestic airlines, Indian Railways/IRCTC-linked booking agents, and car rental partners
  • Forest department authorities for national park and wildlife permits
  • Licensed local guides and Archaeological Survey of India-regulated monument ticketing systems, where applicable
  • Payment processors compliant with RBI (Reserve Bank of India) data localisation norms for payment data
  • Government bodies, where mandated by law (e.g., Foreigner Regional Registration Office reporting for extended stays)

We require every data processor we engage in India to commit contractually to data protection standards consistent with the DPDPA.

5. Cross-Border Considerations

Where your data is transferred outside India (for example, to our regional booking systems), we take steps to ensure the receiving country is not one restricted by the Indian government, consistent with DPDPA requirements on cross-border data transfer.

6. Cookies and Website Tracking

Our India-facing website pages use cookies for session management, analytics, and remembering your preferred itinerary filters. You can manage cookie settings through your browser; disabling them may limit trip customization tools.

7. Security Measures

We maintain reasonable security practices and procedures as contemplated under Indian IT law, including encryption in transit, access controls, and regular internal audits of systems holding traveler data.

8. Data Retention

We retain your data only as long as necessary for the purposes above, or as required under Indian tax (GST), foreign exchange, or immigration record-keeping rules, after which it is deleted or anonymised.

9. Your Rights as a Data Principal

Under the DPDPA, you may:

  • Request a summary of the personal data we hold and how it's processed
  • Correct or update inaccurate data
  • Request erasure of data no longer needed
  • Withdraw consent for optional processing
  • Nominate another individual to exercise your rights in the event of death or incapacity
  • Lodge a grievance with us, and if unresolved, escalate to the Data Protection Board of India

10. Children's Data

Where a booking includes travelers under 18, we treat their data with additional care and process it only with verifiable consent from a parent or lawful guardian, consistent with DPDPA requirements for children's data.

11. Updates to This Policy

We will revise this policy as Indian data protection rules and guidance evolve, particularly as DPDPA implementation rules are finalized. Updates will be posted here with a revised date.

12. Grievance Officer / Contact

Journey DMC — India Desk Website: https://india.journeydmc.com/ For data protection grievances specific to Indian operations, please reference "India DPDPA Enquiry" in your message so it reaches our designated grievance contact.