1. Who we are
GoMandir (“we”, “us”) is operated by [REGISTERED COMPANY NAME PVT. LTD.], registered in India (CIN: [CIN TO BE INSERTED]; GSTIN: [GSTIN TO BE INSERTED]). We are the Data Fiduciary for personal data processed through the GoMandir website and related services, under the Digital Personal Data Protection Act, 2023 (“DPDP Act”) and applicable rules.
Contact (privacy): privacy@gomandir.in
Registered address: [Registered Office Address, City, State, PIN — India]
2. Personal data we collect
We may collect:
- Identity & contact: name, email, phone, city/state, date of birth (if provided)
- Account & trip data: trip plans, itineraries, favourites, reviews, preferences
- Booking & payment metadata: booking references, amounts, GST invoice numbers, payment status (card/UPI details are processed by licensed payment aggregators; we do not store full card numbers)
- Technical data: device/browser type, IP address (hashed where feasible), cookies and similar technologies (see our Cookie Policy)
- Communications: support tickets, grievance filings, feedback
We do not knowingly collect personal data of children under 18. Accounts require confirmation that the user is at least 18 years of age.
3. Purpose of processing
We process personal data for these purposes (and not beyond them without fresh consent or law):
- Account creation, authentication, and security
- Trip planning, temple discovery, itinerary management
- Facilitating travel/stay bookings via licensed partners
- Customer support, grievance redressal, and service communications
- Legal compliance (tax/GST records, law-enforcement requests with due process)
- Product improvement and analytics (with cookie/analytics consent where required)
- Marketing only where you have given separate, withdrawable consent
4. Legal basis / consent
Under the DPDP Act, we rely primarily on your free, specific, informed, unconditional and clear consent for specified purposes, and on processing necessary for employment of contracts you enter with us (e.g., providing the service you requested). You may withdraw consent for non-essential processing via Profile → Privacy & Data Rights or by emailing privacy@gomandir.in. Withdrawal does not affect processing already lawfully completed.
5. Sharing with third parties
We may share data with:
- Infrastructure providers (e.g., hosting, auth/database) under contractual safeguards
- Travel, stay, and map partners solely to fulfil bookings or navigation you request
- RBI-authorised payment aggregators for payment processing
- Professional advisors and authorities where required by Indian law
We do not sell personal data. Cross-border transfers, if any, will follow DPDP Act requirements and government notifications on restricted territories.
6. Retention
- Booking and tax-related records: up to 8 years (or longer if required by tax/company law)
- Inactive accounts: reviewed after 3 years of inactivity, then deleted or anonymised unless legal retention applies
- Consent logs: retained as evidence of compliance
7. Your rights (Data Principal)
Subject to the DPDP Act and exceptions, you may:
- Seek confirmation and a summary of personal data we hold (access)
- Request correction or updating of inaccurate data
- Request erasure of personal data no longer needed for the stated purpose
- Withdraw consent for processing based on consent
- Nominate another individual (where rules provide) for rights in case of death/incapacity
Submit requests in-app at Privacy & Data Rights or email privacy@gomandir.in. We aim to respond within timelines prescribed under applicable rules.
8. Security
We use industry-standard safeguards including encrypted transport (HTTPS), access controls, and Row Level Security on user data stores. No method of transmission is 100% secure; please use a strong unique password and enable available account protections.
9. User-generated content
Reviews and public comments may be moderated or removed to comply with the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, including unlawful content takedown requests.
10. Grievance redressal
For privacy or platform grievances, see our Grievance Redressal page. Escalation to the Data Protection Board of India may be available under the DPDP Act once operational for the relevant category of complaint.
11. Changes
We may update this policy. Material changes will be notified in-app or by email, with an updated effective date and version. Continued use after notice may constitute acceptance where permitted by law; for material new purposes we will seek fresh consent.