Ghumo Phiro iconGhumo Phiro Travel

Privacy Policy

Effective and last updated: 18 August 2026

Your Privacy Matters: This Policy explains what personal information we collect, why we use it, who may receive it, how long we keep it, and the choices available to you.

By using the Platform, you acknowledge that you have read this Policy. Where consent is required, we will request it separately through a clear affirmative action.

1. Who We Are

Ghumo Phiro Travel is a sole proprietorship owned and operated by Akash Aggarwal, with its principal place of business at Amit Gram, NH-34 Haridwar-Rishikesh Road, near Hotel Yog Nagri, Dudhupani, Malviya Nagar, Gumaniwala, Rishikesh, Uttarakhand 249204, India.

Ghumo Phiro operates an online travel marketplace that connects customers with selected independent activity operators, tour providers, trek organisers, accommodation providers, transport providers, destination management companies and training organisations (collectively, “Operators”).

For personal data for which Ghumo Phiro determines the purpose and means of processing, Ghumo Phiro is the Data Fiduciary under applicable Indian data-protection law. An Operator may be a separate Data Fiduciary for information it collects directly or uses for its own lawful purposes.

2. Scope of This Policy

This Policy applies to www.ghumophirotravel.com, its mobile version, our account and booking systems, official email, phone and WhatsApp channels, and any future application operated under the Ghumo Phiro Travel brand (collectively, the “Platform”).

It does not govern an independent Operator’s website, payment account, premises, application or separate data practices. Where an Operator collects information directly, you should also review that Operator’s privacy notice.

3. Personal Information We Collect

We collect only information reasonably connected with a stated purpose. The categories may include the following.

Information You Provide

Identity and contact details: Name, email address, mobile number, city or address where needed, and other contact information you choose to provide.

Account information: Email address, encrypted or securely handled authentication credentials, account preferences and profile information. Current login methods may include email and password, password-free email OTP and Google Sign-In.

Booking information: Selected destination, activity, tour, trek, course or stay; dates; reporting details; participant count; price; booking status; special requests; coupon or referral information; and names or contact details of participants.

Eligibility and safety information: Age, date of birth, height, weight, swimming ability, prior experience, relevant medical disclosure, emergency contact or another activity-specific detail, but only where reasonably required for eligibility, safety or Operator rules.

Documents: Most adventure activities do not require you to show an identity document. For a Service that requires an ID, permit, medical certificate, passport or other document, the requirement will be communicated before participation. Unless expressly stated, documents are normally shown directly to the relevant Operator rather than stored by Ghumo Phiro.

Payment and transaction information: Amount, currency, payment status, transaction or gateway reference, refund status, payment method type and limited masked details made available by the payment processor. We do not collect or store complete card numbers, CVV numbers, UPI PINs or online-banking passwords.

Communications and support: Messages, emails, call or WhatsApp details, feedback, complaints, refund requests and information you provide when seeking assistance.

Optional content: Reviews, ratings, photographs, videos, testimonials or other content you deliberately submit through a Platform feature or provide with permission. Merely tagging Ghumo Phiro on social media does not, by itself, permit us to use that content in advertising.

Partner information: Business, professional, social-media, tax, payment and contact information submitted by an applicant for an agent, affiliate, creator, Operator or other partnership.

Information Collected Automatically

When you use the Platform, we or our service providers may automatically receive an IP address, browser and device type, operating system, language, referring page, pages viewed, approximate location derived from the IP address, dates and times of access, error logs, security events and cookie or similar-technology identifiers. We do not collect precise device location unless a feature clearly requests it and you permit it.

Information Received From Other Sources

We may receive limited information from Google when you use Google Sign-In, from Razorpay or another authorised payment provider when a transaction is attempted, from an Operator concerning booking delivery or safety, and from a referral partner where you use that partner’s link or code. The information received depends on your settings, the relevant service and the permissions you provide.

4. Guest Bookings and Information About Other Participants

You may book as a guest or through an account. An account is optional unless a particular feature clearly requires one.

If you book for another person, you must be authorised to provide their information and must share relevant parts of this Policy with them. For a minor, a parent or lawful guardian must make or approve the booking and provide any required information.

5. How We Use Personal Information

Depending on the circumstances, we may use personal information to:

  • Create, authenticate, secure and manage an account.
  • Process, confirm, modify, reschedule or cancel a booking and issue vouchers or booking communications.
  • Share necessary booking information with the relevant Operator so the Service can be delivered.
  • Process payments, tokens, advances, refunds and related financial records.
  • Check activity eligibility and communicate safety, reporting or document requirements.
  • Respond to questions, complaints, support requests and grievances.
  • Detect and prevent fraud, misuse, unauthorised access, payment abuse and security incidents.
  • Maintain, troubleshoot, analyse and improve the Platform and customer experience.
  • Send promotional communications where you have consented or another lawful basis applies.
  • Maintain accounting, tax, audit and legal records and comply with lawful requests or obligations.
  • Establish, exercise or defend legal claims and enforce our Terms & Conditions.

6. Lawful Processing and Consent

We process digital personal data only for a lawful purpose and in accordance with applicable law, including the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025 as their relevant provisions come into force.

Depending on the purpose, processing may be based on your consent, on information you voluntarily provide for a specific requested purpose, on compliance with law, on responding to an emergency or safety situation, or on another use permitted by applicable law.

Where consent is the basis, the request will be presented separately in clear language and limited to information reasonably necessary for the stated purpose. You may withdraw consent through the method offered on the Platform or by contacting us. Withdrawal does not affect processing already lawfully completed and may prevent us from providing a feature that requires the relevant information.

7. Payment Information

Online payments may be processed by Razorpay or another payment processor identified at checkout. Payment credentials are entered into the processor’s environment and are processed under that provider’s terms and privacy practices.

For information about Razorpay’s data practices, see the Razorpay Privacy Policy.

For some bookings, only a token or advance is paid online and the remaining balance is paid directly to the Operator through cash, UPI or another method communicated for that Service. Information collected by the Operator during that direct payment is controlled by the Operator.

8. When and With Whom We Share Information

We do not sell or rent personal information. We may share only what is reasonably necessary with:

  • Operators and travel providers: activity companies, guides, tour operators, trek organisers, accommodation providers, transport providers, destination management companies and training organisations responsible for the booked Service.
  • Payment providers: Razorpay, banks, card networks, UPI participants and other providers involved in a payment, refund, dispute or fraud check.
  • Account and technology providers: authentication providers such as Google, and providers supporting hosting, databases, cloud storage, security, error monitoring and website operations.
  • Communication providers: services used to deliver email, SMS, telephone, WhatsApp, confirmations, reminders and customer-support communications.
  • Analytics and marketing providers: only as described in Section 9 and subject to applicable consent and controls.
  • Professional advisers: accountants, auditors, insurers and legal advisers where access is necessary and subject to appropriate confidentiality duties.
  • Government and legal authorities: where disclosure is required or permitted by law, a lawful order, fraud or cyber-incident investigation, or the protection of rights and safety.
  • Business successors: a buyer, investor, successor or reorganised entity in connection with a genuine business transfer, subject to Section 20.

Booking information shared with an Operator may include names, mobile numbers, participant count, date, reporting details and any eligibility or safety information needed for that Service. We expect service providers processing information on our behalf to use it only for authorised purposes and under appropriate contractual or legal duties.

9. Cookies, Analytics and Similar Technologies

The Platform may use cookies, pixels, local storage and similar technologies. Necessary technologies support core functions such as security, account access, booking flow, cart or preference memory. Analytics technologies help us understand traffic and improve performance. Marketing technologies may measure campaigns or help present relevant offers.

Tools may include Google Analytics, Google Tag Manager and Meta Pixel when they are actually enabled. Non-essential analytics or marketing technologies will be used subject to applicable consent requirements. You may manage them through any cookie-preference tool made available on the Platform and through your browser settings. Blocking necessary cookies may prevent parts of the Platform from functioning correctly.

A browser’s ‘Do Not Track’ signal may not be recognised uniformly. We will honour any legally required browser or device-based privacy control that applies to the Platform.

10. Service and Promotional Communications

We may use email, SMS, telephone or WhatsApp to send essential booking communications such as confirmation, payment updates, reporting instructions, schedule changes, reminders, support responses, safety messages and refund updates. These messages are necessary to manage a requested Service and may continue even if you opt out of marketing.

Promotional emails or messages will be sent only where consent has been obtained or another lawful basis applies. You may opt out using an unsubscribe link, a communication preference setting, or by contacting us. We may retain a minimal suppression record so that we can respect the opt-out.

11. Children’s and Minors’ Information

Under the Digital Personal Data Protection Act, 2023, a child is an individual under 18 years of age. A parent or lawful guardian must make or approve a booking for a minor and provide any required information on the minor’s behalf.

Where applicable law requires verifiable parental or guardian consent before processing a child’s personal data, we will obtain it before that processing. We do not knowingly conduct tracking or behavioural monitoring of children or direct targeted advertising at children.

If you believe a child has provided personal information without appropriate authorisation, contact us so that we can review and take appropriate action.

12. Data Accuracy and Minimisation

We seek to collect only information reasonably necessary for the stated purpose. Customers must provide accurate and complete information, particularly where it affects identification, eligibility, safety, booking delivery or legal compliance.

You may correct account details through available account features or by contacting us. Where information will be used to make a decision affecting you or shared for Service delivery, we will take reasonable steps to keep it complete, accurate and consistent.

13. Data Retention

We retain personal information only for as long as reasonably necessary for the purpose for which it was collected, to comply with accounting, tax, consumer, payment and other legal requirements, to resolve disputes, prevent fraud, maintain security and enforce agreements.

  • Account information: Generally retained while the account remains active and for a reasonable period after closure where needed for security, backup, dispute or legal purposes.
  • Booking and transaction records: Retained for the period required to provide support and meet accounting, tax, audit, chargeback, consumer and legal requirements.
  • Support and grievance records: Retained until the matter is resolved and for a reasonable period afterwards to document the outcome and address repeat issues.
  • Marketing preferences: Retained until consent is withdrawn or you opt out, with a minimal suppression record retained where necessary to honour the request.
  • Analytics information: Retained according to the configured settings of the relevant tool and applicable law, and aggregated or anonymised where appropriate.

When information is no longer required, we will delete, anonymise or securely isolate it, subject to lawful retention, backup cycles and technical limitations.

14. Security and Personal Data Breaches

We use reasonable administrative, technical and organisational safeguards designed to protect personal information against unauthorised access, alteration, disclosure, loss or misuse. Measures may include access controls, secure authentication, encryption in transit where supported, restricted staff access, monitoring, backups and service-provider reviews.

No internet transmission, device, provider or storage system can be guaranteed to be completely secure. You are responsible for protecting your account credentials and should contact us promptly if you suspect unauthorised account use.

If a personal data breach occurs, we will investigate, take reasonable containment and remediation measures, and notify affected individuals and the Data Protection Board of India or another authority where and when applicable law requires.

15. Processing and Storage Outside India

Some technology, authentication, communication, analytics or cloud providers may process or store information in India or other countries. Where personal data is processed outside India, we will take reasonable steps to use providers and arrangements consistent with applicable Indian law and any notified transfer restrictions.

16. Your Privacy Rights

Subject to applicable law and any valid exception, you may have the right to:

  • Obtain a summary of the personal data being processed and the processing activities undertaken.
  • Receive information about other Data Fiduciaries or Data Processors with whom personal data has been shared, where applicable.
  • Correct inaccurate or misleading information and complete or update incomplete information.
  • Request erasure of information that is no longer necessary, unless retention remains required for a stated purpose or by law.
  • Withdraw consent at any time where consent is the basis of processing, with comparable ease to giving consent.
  • Opt out of promotional communications.
  • Use our grievance-redressal process for an act or omission concerning personal data or the exercise of a privacy right.
  • Nominate another individual to exercise applicable rights in the event of death or incapacity, in the manner provided by law.

17. How to Exercise a Privacy Right

Send a request to support@ghumophirotravel.com with the subject ‘Privacy Request’ and describe the right you wish to exercise. You may also contact us using the phone number in Section 23.

We may request information reasonably necessary to verify your identity, confirm your authority to act for another person, locate the relevant records and protect personal information from unauthorised disclosure. We will not ask for more verification information than is reasonably necessary.

We will respond within the period required by applicable law. If a request cannot be completed, we will explain the reason where legally permitted. Rights may be limited where retention or processing is required for a booking already placed, legal compliance, fraud prevention, security, claims or another lawful purpose.

18. Complaints and Privacy Grievances

Please contact us first if you have a complaint about how personal information is handled. We will acknowledge a privacy grievance within 48 hours and seek to resolve it within one month from receipt, subject to the nature and complexity of the matter.

Grievance Officer: Akash Aggarwal, Proprietor and Grievance Officer

Email: support@ghumophirotravel.com

Phone: +91 97600 09709

Address: Ghumo Phiro Travel, Amit Gram, NH-34 Haridwar-Rishikesh Road, near Hotel Yog Nagri, Dudhupani, Malviya Nagar, Gumaniwala, Rishikesh, Uttarakhand 249204, India

Where the applicable provisions are in force, you may approach the Data Protection Board of India after first using the grievance opportunity available through Ghumo Phiro, as required by law.

19. Third-Party Websites and Services

The Platform may link to an Operator, map, social network, payment provider or other third-party website or service. Their privacy practices are governed by their own notices. We are not responsible for the content or independent privacy practices of a third party, except to the extent responsibility cannot lawfully be excluded.

20. Business Changes

If Ghumo Phiro undergoes a genuine sale, investment, merger, reorganisation, conversion of legal form or transfer of all or part of the business, relevant personal information may be disclosed or transferred as part of that process. The recipient must use it consistently with this Policy and applicable law, unless a new notice or consent is required.

21. Changes to This Policy

We may update this Policy to reflect changes in law, technology, service providers, Platform features or business operations. The revised version will be published on the Platform with a new effective date.

Material changes will be communicated through the Platform, email or another reasonable method. Where required by law, we will provide a new notice or obtain fresh consent before using personal information for a materially different purpose.

22. Relationship With Other Policies

This Policy should be read with the Terms & Conditions and the product-specific information shown before payment. If a product-specific privacy notice is provided for a particular feature, it applies to that feature together with this Policy.

23. Contact Us

For privacy questions, requests or complaints, contact:

Business: Ghumo Phiro Travel

Authorised privacy contact: Akash Aggarwal, Proprietor and Grievance Officer

Email: support@ghumophirotravel.com

Phone: +91 97600 09709

Address: Amit Gram, NH-34 Haridwar-Rishikesh Road, near Hotel Yog Nagri, Dudhupani, Malviya Nagar, Gumaniwala, Rishikesh, Uttarakhand 249204, India