Privacy Policy
Version 1.2 · Last updated 6 September 2026
This Policy explains how EdenRoute Travels (“we”), a business established in India, handles personal data when you use our website and services. It is written to meet India’s Digital Personal Data Protection Act, 2023 (“DPDP Act”) and, where it applies to you, the EU/UK General Data Protection Regulation (“GDPR”).
1. Who is responsible for your data
EdenRoute Travels is the data fiduciary / controller for the processing described here. We are a Micro enterprise registered as a travel agency in India (Udyam Registration No. UDYAM-WB-06-0072077), with a registered address at Godamdhura, Ging Tea Garden, Lebong, Sadar, Darjeeling, West Bengal – 734105, India.
Contact us about privacy at [email protected]. Our Grievance Officer under the DPDP Act is Nabin Pokhrel; how to raise a complaint and our response timelines are set out on the Grievance Redressal page. Where required, our EU representative (GDPR Article 27) will be named here once appointed.
2. What we collect
- Account data — name, email, password (stored only as a hash), role.
- Booking data — stays booked, dates, guest counts, amounts, messages.
- Payment data — handled by Razorpay; we receive confirmation and reference identifiers, not full card numbers.
- Host verification (KYC) — government identity document number and type, phone, email, and settlement bank details. This is sensitive data and is access- controlled and logged.
- Content — reviews, ratings, trip stories, photos you upload.
- Technical data — IP address and basic device/browser information in security and audit logs.
- Consent records — which version of these documents you accepted, and when.
3. Why we use it and our legal basis
- To provide the service (create your account, take bookings, process payments) — performance of a contract.
- Host verification and fraud prevention — legal obligation and legitimate interests.
- Security, audit logging, and abuse handling — legitimate interests.
- Service emails (verification, booking confirmations, KYC outcome) — contract / legitimate interests.
- Improving the service and support — legitimate interests.
- Where we rely on consent (for example any future marketing or analytics), you can withdraw it at any time without affecting prior processing.
4. Who we share it with
We share personal data only with service providers that help us run the Platform:
- Razorpay — payment processing and refunds.
- Resend — transactional email delivery.
- Render — application and database hosting.
- Vercel — website hosting and delivery.
We also share data where required by law, to enforce our Terms, or to protect the rights and safety of users. We do not sell personal data.
5. International transfers
Our providers may process data outside your country, including in the EU, the UK, and the United States. Where GDPR applies, such transfers are made under an adequacy decision or Standard Contractual Clauses with additional safeguards. The specific transfer mechanism for each provider is being finalised and will be listed here.
6. How long we keep it
Account and content data: while your account is active and for a reasonable period after closure. Booking and payment records: retained as long as needed for tax, accounting, and dispute purposes. Audit and security logs: a limited retention period. KYC records: retained for the period required by applicable law after the Host relationship ends, then deleted or anonymised. Messages between a guest and a Host are tied to that booking and are automatically deleted from our servers two months after the stay's check-out date. A detailed retention schedule is being finalised.
7. Your rights
Subject to the applicable law, you can ask us to:
- access a copy of your personal data;
- correct inaccurate or incomplete data;
- delete your data (“right to be forgotten” / erasure);
- receive your data in a portable format;
- restrict or object to certain processing;
- withdraw consent where processing is based on consent;
- nominate another person to exercise your rights (DPDP Act).
To exercise any of these, email [email protected]. We may need to verify your identity. Where you have transacted, some records (bookings, payments) are kept even after an erasure request, with your identifying details removed. You also have the right to complain to your data-protection authority — the Data Protection Board of India, or your local supervisory authority in the EU/UK.
8. Security
Passwords are hashed. Access to KYC and other sensitive data is restricted by role and every access is written to an audit log. We use encryption in transit and apply administrative and technical safeguards appropriate to the risk. No system is perfectly secure; if a breach affects you we will notify you and the relevant authority as required by law.
9. Children
The Platform is not intended for anyone under 18, and we do not knowingly collect their data. If you believe a child has given us personal data, contact us and we will delete it.
10. Changes
We will post updates here with a new version number and date and, for material changes, give advance notice by email or in-product.
Questions about this document or your personal data: [email protected]