v1.0
Privacy Policy
Last updated: September 19, 2025
This Privacy Policy explains how Next Step Destinations (Insert Legal Entity Name) ("we", "us", "our") collects, uses, discloses, and safeguards your information when you use our website, make enquiries, or book our travel services. By accessing our services, you consent to this Policy.
1) Scope & Data Controller
This Policy applies to our website, enquiry forms, WhatsApp/phone communications, and booking services. The Data Controller/Data Fiduciary is Next Step Destinations (Insert Legal Entity Name) at the address below.
2) Data We Collect
- Contact & Identity: name, email, phone, address, date of birth, nationality; guest details as per passports/IDs.
- Booking Details: destination preferences, dates, hotel/room choice, special assistance, meal/bed preferences.
- Documents: passport, visa, travel insurance proof (where required). Stored securely and only as long as necessary.
- Payment: method, status, transaction reference (we do not store full card/UPI details; handled by payment gateways).
- Technical: IP, device/browser, pages visited, referral source, cookies & analytics identifiers.
- Communications: emails, calls, WhatsApp messages, chat transcripts, feedback, reviews.
3) How We Use Data
- Respond to enquiries, prepare quotations/itineraries, and fulfil bookings.
- Issue vouchers/tickets, coordinate with airlines/hotels/transporters/ground handlers.
- Process payments and invoices, comply with tax and accounting requirements.
- Provide customer support, resolve complaints, and improve our services and website.
- Send service communications (booking updates, alerts). Marketing emails/WhatsApp only with consent and opt‑out option.
- Detect, prevent, and address fraud, abuse, or security incidents.
4) Consent & Legal Bases
- Consent: for optional marketing, cookies, or when required by law. You may withdraw consent anytime.
- Contractual necessity: to take pre‑contract steps and perform your booking contract.
- Legal obligation: KYC, taxation, and regulatory compliance.
- Legitimate interests: service improvement, analytics, and security—balanced against your rights.
7) Payments & Security
- Online payments are processed by third‑party gateways using industry‑standard encryption. We do not store full card numbers, CVV, or UPI PINs on our servers.
- Always verify payment links originate from our official domain or authorised providers before paying.
8) International Transfers
Your data may be processed outside India when bookings involve foreign suppliers or global cloud services. We take reasonable steps to ensure an adequate level of protection and share only what is necessary for fulfilment.
9) Data Retention
We keep personal data only as long as needed for the purposes stated, including legal/accounting requirements. Typical retention: enquiries (12–24 months), booking records (7–10 years), passport/visa copies (until completion plus a short archival period unless law requires longer).
10) Your Rights (DPDP 2023/GDPR)
- Right to access and obtain a copy of your personal data.
- Right to correction/rectification and updating of inaccurate data.
- Right to deletion/erasure where applicable and not conflicting with legal obligations.
- Right to withdraw consent for optional processing (e.g., marketing).
- Right to grievance redressal and to nominate a person to exercise your rights under DPDP 2023.
To exercise rights, email us from your registered email ID with proof of identity. We acknowledge within 7 working days and endeavour to resolve within 30 days.
11) Children’s Privacy
We do not knowingly collect personal data from children without parental/guardian consent. If you believe a child has provided data without consent, please contact us to remove it.
12) Security Measures
- Industry‑standard technical and organisational measures: HTTPS, access controls, encryption in transit, and need‑to‑know access.
- No method of transmission or storage is 100% secure. We will notify you and regulators of significant breaches as required by law.
13) Do‑Not‑Track
Some browsers offer “Do‑Not‑Track” (DNT). We do not currently respond to DNT signals due to lack of a consistent industry standard.
14) Third‑Party Links
Our website may contain links to third‑party websites/apps. Their privacy practices are governed by their own policies. Please review them before sharing any data.
15) Changes to this Policy
We may update this Policy from time to time. The version and date above indicate the latest revision. Continued use of our services after changes constitutes acceptance of the updated Policy.
16) Contact & Grievance Redressal
Next Step Destinations (Insert Legal Entity Name)
Your Registered Address, City, State, PIN, India
Phone: +91-XXXXXXXXXX
Email: support@nextstepdestinations.in
Website: https://www.nextstepdestinations.in
Grievance Officer
Grievance Officer Name
Email: grievance@nextstepdestinations.in
Phone: +91-XXXXXXXXXX
Address: Registered Office Address, City, State, PIN, India
Acknowledgement within 7 working days; resolution target within 30 days.