Home · Privacy Policy
Privacy Policy
Komorebi Travel LLP · Last updated: 29 June 2026 · Effective: 29 June 2026
This Privacy Policy explains how Komorebi Travel LLP (“the Company,” “we,” “us,” or “our”) collects, uses, shares, and protects personal data when you enquire about, book, or travel on our journeys, or browse our website and social channels. We design slow, place-conscious travel across India and selected international destinations, and we treat the data you share with the same care.
We act as the data fiduciary (under India’s Digital Personal Data Protection Act, 2023) and, where applicable, as the data controller (under the EU/UK GDPR) for the personal data described below. By sharing your data with us, you confirm you have read and understood this Policy.
1. Who this Policy applies to
This Policy applies to travelers, enquirers, and website visitors located in India and abroad, including travelers from the European Economic Area and the United Kingdom who book journeys with us. Because we arrange international journeys, your data may be processed in, and travel to, countries other than your own (see Section 9).
2. Data we collect
2.1 Data you give us
| Category | Examples and purpose |
|---|---|
| Identity | Name, age, gender, and government ID (Aadhaar, Passport, PAN, or Voter ID) where required for permits, hotel check-in, flights, or visas. |
| Contact | Phone number, email, WhatsApp number, postal address. |
| Booking | Trip selected, traveler count, room preferences, dietary needs, special requests. |
| Health | Pre-existing conditions, allergies, mobility needs, relevant only to high-altitude or remote journeys, shared voluntarily to keep you safe. |
| Emergency contact | Name and phone number of a person to reach in an emergency. |
| Payment | Transaction reference, UPI handle, or bank details for refunds. We do not store full card numbers (see Section 6). |
| Reviews and media | Reviews, ratings, comments, and photos you submit to us or post on our channels. |
2.2 Data we collect automatically
- Website and analytics data: device type, browser, approximate location, pages viewed, and referral source, collected through cookies and similar technologies (see our Cookie section below and Section 7).
- Communication records: copies of your enquiries and our correspondence over email and WhatsApp, kept to service your booking.
2.3 Sensitive personal data
Health information and government ID are sensitive. We collect them only where genuinely needed, ask for your explicit consent at the point of collection, and limit access to staff who need it for your trip.
3. How we use your data, and our legal basis
We use your data only for the purposes below, each supported by a lawful basis:
| Purpose | Lawful basis |
|---|---|
| Process bookings, issue itineraries, arrange permits, accommodation, and transport | Performance of your booking contract |
| Procure restricted-area permits (e.g. Arunachal Pradesh) and complete check-ins | Legal obligation and your consent |
| Keep you safe on high-altitude and remote journeys | Your explicit consent and vital interests |
| Send trip updates, payment reminders, and service messages | Performance of contract |
| Send marketing about future journeys | Your consent, which you may withdraw at any time |
| Use trip photos and video for promotion | Your consent (see Section 5) |
| Issue GST invoices and meet tax and accounting duties | Legal obligation |
| Improve our website and understand traffic | Our legitimate interests, balanced against your rights |
We will not use your data for a new, unrelated purpose without telling you and, where the law requires, obtaining fresh consent.
4. Sharing your data
We share data only as far as needed to deliver your journey, and never sell, rent, or trade it.
- Travel service providers: hotels, homestays, destination management companies, bus and cab operators, airlines, and activity vendors, in India and abroad, who need your details to deliver booked services.
- Government and regulatory authorities: for permits, identity verification, visas, taxation, or where disclosure is required by law or to protect the safety of any person.
- Professional and operational partners: our chartered accountant, payment processors (PayU and our banking partners), IT and communication tools, bound by confidentiality and processing only on our instructions.
Where a partner processes your data on our behalf, we put a written agreement in place requiring appropriate security and limiting use to our instructions.
5. Photographs and video
We sometimes capture photos and video during journeys for our website and social channels. We rely on your consent for this. You may decline at the start of any trip, or ask us later to remove media where you are the main subject, by writing to us at the contact in Section 13. We will honour reasonable requests promptly, though we cannot always recall content already reshared by third parties.
6. Payment data security
Payments are handled by PayU and by direct bank transfer or UPI. Card and account credentials are entered on the gateway’s secure, PCI-DSS-compliant environment, not stored by us. We retain only the transaction reference and the details needed to issue invoices and process any refund.
7. Cookies and tracking
Our website uses cookies and similar technologies to run the site, remember preferences, and measure traffic. Non-essential cookies, including analytics and advertising cookies, are set only with your consent through our cookie banner. You can withdraw consent or adjust your browser settings at any time, though some features may then not work as intended. Where we run advertising on Meta or other platforms, those providers may process limited data as independent controllers under their own policies.
8. Data retention
We keep personal data only as long as needed for the purpose collected, then delete or anonymise it.
| Data | Retention |
|---|---|
| Booking and trip records | Up to 8 years, to meet tax, accounting, and legal claim periods |
| GST and financial records | As required under Indian tax law |
| Health and emergency data | Deleted shortly after the journey ends, unless a claim is pending |
| Website analytics | Per the retention set in our analytics tools |
9. International transfers
Because we arrange journeys abroad, your data may be shared with service providers located outside India, including in countries whose laws may differ from your own. Where we transfer data internationally, including any transfer of EEA or UK data, we use lawful transfer mechanisms and require appropriate safeguards so your data stays protected. You may ask us for details of the safeguards in place.
10. Your rights
Subject to applicable law, you may:
- access the personal data we hold about you and ask for a copy;
- correct or update inaccurate or incomplete data;
- withdraw consent at any time, without affecting processing already carried out;
- ask us to erase data we no longer need, subject to our legal retention duties;
- nominate another person to exercise your rights in the event of death or incapacity (under the DPDP Act);
- for EEA/UK travelers, additionally object to or restrict certain processing, request portability, and lodge a complaint with your supervisory authority.
To exercise any right, contact us using Section 13. We will respond within the timeframes set by applicable law and may need to verify your identity first.
11. Children
Our booking services are intended for adults aged 18 and over. Minors may travel only under the responsibility of a booking adult, who confirms they are authorised to share the minor’s data. We do not knowingly collect data directly from children. If you believe a child’s data has been shared with us without authority, contact us and we will delete it.
12. Security, and third-party links
We apply reasonable technical and organisational measures to protect your data against unauthorised access, alteration, or loss, and review them periodically. No method of transmission is fully secure, so we cannot guarantee absolute security. Our website may link to third-party sites and our partners run their own systems; we are not responsible for their privacy practices and encourage you to read their policies.
If a personal data breach is likely to cause you harm, we will notify you and the relevant authority as required by the DPDP Act and other applicable law.
13. Contact, grievances, and changes
For any privacy question, request, or complaint, contact our Grievance Officer:
Grievance Officer: Udisha Raghuvanshi
Email: journeys@komorebitravel.com
We may update this Policy from time to time. When we make material changes, we will revise the “Last updated” date and, where appropriate, notify you. The current version always governs. All privacy matters are subject to the laws of India and the exclusive jurisdiction of the courts in Delhi, without prejudice to any non-waivable rights you hold under your local law.