v1.0

Privacy Policy

Last updated: September 19, 2025

This Privacy Policy explains how Next Step Destinations (Insert Legal Entity Name) ("we", "us", "our") collects, uses, discloses, and safeguards your information when you use our website, make enquiries, or book our travel services. By accessing our services, you consent to this Policy.

1) Scope & Data Controller

This Policy applies to our website, enquiry forms, WhatsApp/phone communications, and booking services. The Data Controller/Data Fiduciary is Next Step Destinations (Insert Legal Entity Name) at the address below.

2) Data We Collect

  • Contact & Identity: name, email, phone, address, date of birth, nationality; guest details as per passports/IDs.
  • Booking Details: destination preferences, dates, hotel/room choice, special assistance, meal/bed preferences.
  • Documents: passport, visa, travel insurance proof (where required). Stored securely and only as long as necessary.
  • Payment: method, status, transaction reference (we do not store full card/UPI details; handled by payment gateways).
  • Technical: IP, device/browser, pages visited, referral source, cookies & analytics identifiers.
  • Communications: emails, calls, WhatsApp messages, chat transcripts, feedback, reviews.

3) How We Use Data

  • Respond to enquiries, prepare quotations/itineraries, and fulfil bookings.
  • Issue vouchers/tickets, coordinate with airlines/hotels/transporters/ground handlers.
  • Process payments and invoices, comply with tax and accounting requirements.
  • Provide customer support, resolve complaints, and improve our services and website.
  • Send service communications (booking updates, alerts). Marketing emails/WhatsApp only with consent and opt‑out option.
  • Detect, prevent, and address fraud, abuse, or security incidents.

5) Cookies & Analytics

  • We use essential cookies for core site functionality and preference cookies to remember settings.
  • We may use analytics (e.g., Google Analytics) and advertising cookies (e.g., Meta/Google Ads) to measure performance and personalise ads.
  • You can manage cookies via your browser settings or a cookie banner (if implemented). Blocking some cookies may impact site functionality.

6) Data Sharing & Third Parties

  • Suppliers: airlines, hotels, DMCs, transport companies, activity operators—to fulfil your bookings.
  • Payment processors: banks, UPI providers, payment gateways—card/UPI details are handled by them.
  • Technology vendors: hosting, email/SMS/WhatsApp service providers, analytics and support tools.
  • Legal & compliance: where required by law, court orders, or to protect rights, safety, and property.

7) Payments & Security

  • Online payments are processed by third‑party gateways using industry‑standard encryption. We do not store full card numbers, CVV, or UPI PINs on our servers.
  • Always verify payment links originate from our official domain or authorised providers before paying.

8) International Transfers

Your data may be processed outside India when bookings involve foreign suppliers or global cloud services. We take reasonable steps to ensure an adequate level of protection and share only what is necessary for fulfilment.

9) Data Retention

We keep personal data only as long as needed for the purposes stated, including legal/accounting requirements. Typical retention: enquiries (12–24 months), booking records (7–10 years), passport/visa copies (until completion plus a short archival period unless law requires longer).

10) Your Rights (DPDP 2023/GDPR)

  • Right to access and obtain a copy of your personal data.
  • Right to correction/rectification and updating of inaccurate data.
  • Right to deletion/erasure where applicable and not conflicting with legal obligations.
  • Right to withdraw consent for optional processing (e.g., marketing).
  • Right to grievance redressal and to nominate a person to exercise your rights under DPDP 2023.

To exercise rights, email us from your registered email ID with proof of identity. We acknowledge within 7 working days and endeavour to resolve within 30 days.

11) Children’s Privacy

We do not knowingly collect personal data from children without parental/guardian consent. If you believe a child has provided data without consent, please contact us to remove it.

12) Security Measures

  • Industry‑standard technical and organisational measures: HTTPS, access controls, encryption in transit, and need‑to‑know access.
  • No method of transmission or storage is 100% secure. We will notify you and regulators of significant breaches as required by law.

13) Do‑Not‑Track

Some browsers offer “Do‑Not‑Track” (DNT). We do not currently respond to DNT signals due to lack of a consistent industry standard.

15) Changes to this Policy

We may update this Policy from time to time. The version and date above indicate the latest revision. Continued use of our services after changes constitutes acceptance of the updated Policy.

16) Contact & Grievance Redressal

Next Step Destinations (Insert Legal Entity Name)

Your Registered Address, City, State, PIN, India

Phone: +91-XXXXXXXXXX

Email: support@nextstepdestinations.in

Website: https://www.nextstepdestinations.in

Grievance Officer

Grievance Officer Name

Email: grievance@nextstepdestinations.in

Phone: +91-XXXXXXXXXX

Address: Registered Office Address, City, State, PIN, India

Acknowledgement within 7 working days; resolution target within 30 days.

© 2025 Next Step Destinations. All rights reserved.