Legal
Privacy Notice
Last updated November 15, 2025
This Privacy Notice explains how StayKedarnath.in ("StayKedarnath","we","us","our") collects, uses, shares, stores, and protects personal data when you use our website (www.staykedarnath.in), mobile interfaces, or our services (together, the"Platform"). It also explains the rights you have in respect of your personal data and how to exercise them.
This Notice is written for travelers and visitors who browse our Platform, create accounts, make bookings, contact customer support, or otherwise use our services. It is intended to be comprehensive and practical — similar in scope to privacy notices used by leading travel platforms — but tailored for a regional operator focused on the Kedarnath Yatra.
If you do not agree with this Notice, please do not use the Platform or provide personal data to us.
Table of Contents (quick links)
1. Key terms we use
- Platform: www.staykedarnath.in, our mobile interfaces, APIs, and related services.
- You / User / Traveler: anyone using or visiting the Platform (with or without an account).
- Service Provider / Trip Provider: independent accommodation owners, transport operators, guides, or other third parties providing Travel Experiences listed on the Platform.
- Booking: a reservation confirmed by a Booking Voucher or confirmation message.
2. Personal data we collect and how we collect it
We collect personal data about you in three main ways: (a) data you provide directly to us, (b) data we collect automatically when you use the Platform, and (c) data we receive from third parties.
2.1. Data you provide directly
When you interact with the Platform or our customer service, you may provide:
- Contact information: name, email address, phone number, postal address.
- Booking details: travel dates, party size, room preferences, special requests, and any guest details required by Service Providers.
- Identity documents: passport, Aadhaar, voter ID, driver's license or other ID when required for regulatory checks or verification (only when necessary).
- Payment & billing information: payment status, last four digits of card (for records), UPI transaction references. We do not store full payment card numbers, CVV, or UPI PINs.
- Communications: messages sent to us via email, chat, WhatsApp, or phone, including any attachments you provide.
- User-generated content: reviews, photos, and ratings you post about properties or services.
- Support and verification inputs: selfies or identity photos where you consent to verification for trust/badge programs.
2.2. Data collected automatically
When you browse or use the Platform we automatically collect:
- Technical data: IP address, device identifiers, browser type/version, operating system, screen resolution.
- Usage data: pages viewed, search queries, timestamps, clickstreams, and error logs.
- Location data: approximate location derived from IP; precise GPS location only if you allow it in the mobile app.
- Cookies and similar identifiers: session cookies, persistent cookies, and local storage identifiers.
2.3. Data from third parties
We may receive data about you from:
- Service Providers: confirmation details, property check-in requirements, and communications related to your stay.
- Payment processors: transaction status, refunds, chargebacks, and limited payment metadata.
- Verification partners: identity and property verification results.
- Advertising and analytics providers: aggregated or pseudonymized performance data.
- Public & regulatory sources: law enforcement or government authorities when required.
3. How and why we process your personal data (purposes)
We process personal data to operate and improve the Platform, to fulfil bookings, and to comply with legal obligations. Key purposes include:
3.1. Providing and administering bookings
- Create, confirm, modify, and cancel Bookings; issue Booking Vouchers and receipts; pass necessary information to Service Providers to deliver the Travel Experience.
- Send transactional messages (booking confirmations, reminders, check-in instructions).
3.2. Customer support and dispute resolution
Respond to support requests, investigate complaints, and mediate disputes between travelers and Service Providers.
3.3. Payments, refunds & fraud prevention
- Initiate and verify payments, process refunds (see our Refund Policy), and investigate suspicious transactions or chargebacks.
- Detect, prevent, and mitigate fraud and security risks (including automated fraud scoring and manual review).
3.4. Safety, verification & trust
- Verify identities where necessary for safety, guest verification badges, or regulatory compliance (e.g., Char Dham Yatra checks).
- Share essential details with Service Providers to ensure guest identification and safety at check-in.
3.5. Personalization & marketing (where permitted)
Personalize property recommendations and promotional messages based on your preferences and past booking behavior (you can opt out of marketing).
3.6. Analytics & product improvement
Aggregate and analyze data to improve search, UI, performance, and services; test features and measure engagement.
3.7. Legal compliance & recordkeeping
Maintain records to comply with accounting, tax, and regulatory requirements; respond to lawful requests from authorities.
4. Legal bases for processing
Under applicable data protection laws (including Indian law and, where relevant, other jurisdictions), we rely on one or more of the following legal bases:
- Contractual necessity: processing required to perform a booking contract or to take steps at your request prior to entering a contract (e.g., confirming bookings).
- Consent: where you have given consent (for example, to marketing communications or optional identity verification).
- Legitimate interests: for platform security, fraud prevention, service improvement, and enforcing our Terms of Service — balanced against your rights and freedoms.
- Legal obligation: where processing is required by law, such as tax or government-issued checks for the Yatra.
When we rely on legitimate interests, we will never use your data in ways that meaningfully harm your interests without clear justification.
6. International transfers and safeguards
We are based in India and process personal data in India. We may also transfer personal data to recipients outside India (e.g., cloud providers, payment processors, analytics partners). When transferring data internationally we implement adequate safeguards such as:
- Contractual agreements with recipients including data processing clauses,
- Where needed, standard contractual clauses or other legal mechanisms, and
- Practical technical measures such as pseudonymization and encryption.
If you are located in a jurisdiction that requires additional protections for international transfers (for example, the EEA or UK), contact us for details of the safeguards in place.
8. Automated decision-making, AI & profiling
We may use automated systems and machine learning models to support fraud detection, personalize content, and improve user experience. Where such processing has a legal or similarly significant effect on you, we will provide suitable safeguards including human review and an explanation of the rationale upon request.
Examples:
- Fraud scoring: transactions may be automatically scored for risk; high-risk transactions are reviewed by humans before action is taken.
- Personalization: search rankings, property suggestions, and marketing may be influenced by automated models trained on anonymized and pseudonymized data.
We do not currently use fully automated decision-making that produces legal or similarly significant effects without human intervention.
9. Retention of personal data
We retain personal data only as long as necessary for the purposes stated and to meet legal and regulatory obligations. Typical retention periods:
- Booking records & tax records: up to 7 years (or as required by law).
- Customer support communications: 1–3 years depending on the case.
- Authentication & account data: for the lifetime of the account plus a period for recovery and legal compliance.
- Analytics data: aggregated or pseudonymized; raw logs retained up to 24 months unless otherwise needed.
- Identity verification documents: retained only as long as necessary to complete verification and for fraud prevention obligations; then securely deleted unless law requires otherwise.
Where retention is based on legitimate interests, we document and periodically review the need for keeping the data.
10. Data security and breach response
We apply industry-standard technical and organizational measures to protect personal data, including:
- Transport-layer encryption (TLS/HTTPS),
- Pseudonymization and encryption of sensitive records where feasible,
- Access control and least-privilege principles,
- Regular security audits and vulnerability assessments,
- Secure backups and disaster recovery plans.
In the event of a data breach, we will follow our incident response plan, notify affected individuals and regulators as required by law, and take steps to remediate and prevent reoccurrence.
11. Your rights and how to exercise them
Subject to applicable law, you may have the following rights:
- Access: request a copy of personal data we hold about you.
- Correction: ask us to correct inaccurate or incomplete data.
- Erasure: request deletion of data where legal grounds permit.
- Restriction: ask for limitation of processing in certain circumstances.
- Portability: receive a machine-readable copy of data you provided.
- Objection: object to processing based on legitimate interests or direct marketing.
- Withdraw consent: where processing is based on consent.
To exercise these rights, contact us at info@staykedarnath.in with subject"Data Subject Request". We will verify your identity and respond within the timelines required by applicable law. If you remain unsatisfied, you may lodge a complaint with a supervisory authority.
12. Children's data
The Platform is not intended for children under 13. We do not knowingly collect data from children. If a parent or guardian believes we have collected data about a child in error, please contact us and we will delete it.
13. Specific market or product notes
- Ground transport & car hires: additional identity or driving licence information may be required for bookings; these are shared with the relevant Service Provider.
- Insurance products: if offered, insurance providers will be separate controllers for insurance-specific data and will process it according to their policies.
- Local/regulatory checks: for the Kedarnath Yatra, local authorities or Service Providers may require identity data; when necessary, we will disclose such data to comply with local rules.
14. Changes to this Notice
We may update this Privacy Notice to reflect changes in our practices or legal requirements. The"Last Updated" date at the top will indicate when the Notice was last revised. Material changes will be communicated where appropriate.
15. Contact, grievance officer & supervisory authorities
If you have questions, requests, or complaints about this Privacy Notice or our data practices, contact us:
We aim to acknowledge data subject requests within 48–72 hours and resolve them promptly. If you are not satisfied with our response, you can raise a complaint with the relevant data protection supervisory authority in your country.
End of Privacy Notice — StayKedarnath.in