IMPORTANT LEGAL NOTICE:
This Privacy Policy forms an integral part of, and must be read harmoniously alongside, the Trek Break & More Terms & Conditions, Cancellation and Refund Policy, Participation Waivers, and Itinerary-Specific Advisories. It is engineered for full compliance with the Digital Personal Data Protection (DPDP) Act, 2023 (India).
Effective Date: 27 June 2026
01. PREAMBLE & BINDING NATURE
This Privacy Policy (“Policy”) outlines the structural and lawful practices of Trek Break & More (“the Company”, “we”, “our”, or “us”) regarding the collection, storage, processing, deployment, security matrix, cross-border transfer, and ultimate erasure of Personal Data and Digital Personal Data belonging to its Customers, Clients, Users, and Participants (“Data Principal”, “you”, or “your”).
By registering for, inquiring about, purchasing, accessing, or continuing to utilize any Travel Services, Adventure Activities, digital booking platforms, mobile suites, or websites provided or facilitated by the Company, you explicitly provide unconditional, free, specific, informed, and unambiguous consent to the processing of your Personal Data as detailed in this instrument. If you do not agree with any terms or clauses within this legal framework, you must immediately cease accessing our services, digital interfaces, or booking platforms.
02. STATUTORY DEFINITIONS
All capitalized terms used but not explicitly defined in this Policy shall carry the legal meanings ascribed to them under the Digital Personal Data Protection (DPDP) Act, 2023, or the Company’s primary General Terms & Conditions document.
“Data Principal” refers to the individual to whom the personal data relates. In the context of our operations, this includes any customer, trekker, tour participant, website user, or corporate client representative.
“Data Fiduciary” means Trek Break & More, which alone or in conjunction with others determines the purpose and specific technical means of processing personal data.
“Data Processor” means any person, entity, contractor, or automated software module that processes personal data on behalf of the Data Fiduciary under a structured service agreement.
“Digital Personal Data” means personal data in digital form or data collected entirely offline and subsequently digitized for backend management, ticketing, or permitting.
“Personal Data” means any data about an individual who is directly or indirectly identifiable by or in relation to such data.
03. LEGAL BASIS FOR PROCESSING & MATERIAL CONSENT
The Company processes Digital Personal Data strictly under valid legal frameworks as mandated by Section 4 of the DPDP Act, 2023. Processing is executed under the following distinct conditions:
- Explicit Consent: The primary framework relies on a clear, affirmative action by the Data Principal (such as checking a digital consent box, submitting a formal booking form, or transmitting documentation via authorized WhatsApp/Email channels). This consent is entirely revocable at any time, subject to legal, regulatory, and operational limitations.
- Certain Legitimate Uses: In compliance with statutory exemptions, the Company reserves the absolute right to process Personal Data without explicit fresh consent for specialized scenarios, including:
- Fulfilling a voluntary obligation, structural contract, or specific travel service requested by the Data Principal (e.g., executing a live booking reservation).
- Responding to urgent medical emergencies or providing immediate care involving a definitive threat to the life, safety, or immediate health of the Data Principal or any companion during an Adventure Activity, remote expedition, or tour.
- Complying with any prevailing law, judicial order, statutory audit, state-mandated border security protocol, or law enforcement requisition.
04. EXPLICIT CATEGORIES OF DATA COLLECTED
We enforce strict data minimization principles, collecting only the specific information required to execute travel bookings safely, comply with regulatory bodies, and deliver high-quality travel products.
- Data Provided Directly by the Principal:
- Identity Details: Full legal name, verified date of birth, age, gender, nationality, and physical photographs.
- Contact Infrastructure: Direct email address, permanent and current physical residence addresses, mobile telephone coordinates, and WhatsApp unique identifiers.
- Official Documentation: Government-issued Passports, Aadhaar cards, Voter IDs, PAN cards, active visas, or restricted area inner line permits required by civil or military border authorities for route clearances.
- Medical & Physical Fitness Matrix: Self-disclosed medical conditions, prescription history, chronic allergies, physical limitations, dietary specifications, and emergency contact lists. This highly sensitive operational data is mandatory for high-altitude treks, extreme topography tours, and remote outdoor deployments.
- Data Collected Automatically via Digital Interaction:
- Technical Identifiers: Internet Protocol (IP) addresses, browser architectures, operating system versions, device fingerprints, and explicit geolocation coordinates.
- Usage Metadata: Micro-level navigation maps, specific pages visited, duration of stay on our platform, link selection histories, digital conversion paths, and localized search engine queries within our booking engine.
05. COOKIE POLICY & ADVANCED DIGITAL TRACKING INTEGRATION
The Company’s digital ecosystem utilizes cookies, tracking pixels, scripts, and local browser storage mechanisms to enhance system optimization, monitor marketing efficacy, and maintain platform security integrity.
- Operational & Core Session Cookies: Essential for handling fundamental system architecture, secure customer user account logins, and ensuring items match your designated digital booking engine cart.
- Google Analytics Integration: Utilized to map completely anonymous, aggregate demographic behaviors, geographic traffic variations, and overall user interaction profiles.
- Meta Pixel & Google Ads Tracking: Deployed to measure conversion returns on external marketing investments and serve highly relevant informational, logistical, or promotional content to individuals who have engaged with our itineraries.
- Principal Autonomy & Controls: You retain the absolute right to configure your browser parameters to reject, filter, or erase cookies entirely. However, disabling technical cookies may degrade operational functionality, causing loss of state or forcing repetitive data inputs during active digital checkouts.
06. PURPOSES OF DATA PROCESSING
Your Digital Personal Data is processed exclusively for explicit, specified, and legally sustainable commercial and logistical purposes:
- Booking Execution & Delivery: Validating user registrations, executing airline/rail ticketing, reserving accommodation inventories, securing mandatory environmental permits, and compiling manifest rosters for local guides and field operatives.
- Operational Communication: Disseminating itinerary updates, invoice statements, payment links, mandatory health advisories, weather adjustments, or pre-departure packing checklists via Email, SMS, WhatsApp, or direct voice telephony.
- Safety Coordination: Providing ground leaders, expedition medics, and rescue teams immediate access to essential medical declarations to prevent or mitigate health crises in remote, off-grid topographies.
- Marketing & Brand Operations: Supplying curated travel newsletters, seasonal discounts, and details on upcoming itineraries via Mailchimp and WhatsApp, executed only where explicit opt-in parameters have been met.
- Regulatory Compliance: Fulfilling strict financial auditing rules, tax computations (GST), foreign exchange reporting (LRS where applicable), or responding to official requests from law enforcement agencies.
07. VENDOR, PROCESSOR, AND THIRD-PARTY OBLIGATIONS
To fulfill bookings and maintain digital systems, the Company shares your data with specific categories of external entities under clear accountability parameters.
- Third-Party Service Providers (Operational Vendors): Data must be shared with independent airlines, hotels, transport operators, local mountain guides, expedition coordinators, and visa consultants. These independent entities handle your information subject to their own statutory obligations and separate privacy practices. In line with our General Terms & Conditions, the Company is not responsible for deficiencies or privacy breaches occurring within their standalone systems.
- Data Processors (Technical Ecosystems): We execute clear, binding contracts with all technology vendors, including secure integrated payment gateways to manage digital invoicing without retaining raw card credentials locally, and marketing engines including Mailchimp and WhatsApp Business.
- Compliance Under Section 8: Under Section 8 of the DPDP Act, 2023, the Company ensures that all contracted Data Processors maintain equal or higher technical safeguards, process data strictly on our documented instructions, and erase data immediately once the contractual purpose concludes.
08. INTERNATIONAL DATA TRANSFERS
When you book international tours, trans-boundary expeditions, or itineraries requiring cross-border logistics, your Personal Data (including identity proofs, visas, and health declarations) may be transferred to service providers situated outside India.
The Company guarantees that any such cross-border transfer will comply strictly with Section 16 of the DPDP Act, 2023. Data will not be transferred to any country or territory explicitly blacklisted or restricted by the Central Government of India. By completing a booking for an international destination, you acknowledge and authorize this operational cross-border transmission.
09. CHILDREN’S DATA PROVISIONS
Trek Break & More does not intentionally collect, process, or track data from individuals under eighteen (18) years of age without explicit, verifiable consent from a parent or legal guardian.
In compliance with Section 9 of the DPDP Act, 2023:
- The Company will not process any personal data of a child that is likely to cause an adverse effect on the well-being of the child.
- We strictly prohibit tracking, behavioral monitoring, or targeted advertising directed at children through our website or digital systems.
- Any registration or booking for a minor participant must be executed entirely by a legal guardian, who thereby consents to the processing of the minor's data for travel logistics.
10. STATUTORY RIGHTS OF THE DATA PRINCIPAL
Under Chapter III of the DPDP Act, 2023, you possess robust statutory rights regarding your Digital Personal Data. You may exercise these rights by submitting a formal request to our designated Grievance Officer:
- Right to Information and Access: The right to obtain a summary of your personal data currently being processed, along with a description of the identities of all third parties with whom it has been shared.
- Right to Correction and Erasure: The right to correct inaccuracies, update incomplete profiles, or request the permanent erasure of your data when it is no longer necessary for the operational or legal purposes for which it was collected.
- Right to Grievance Redressal: The right to register a formal complaint regarding any perceived deficiency or non-compliance by the Company before escalating the issue to the Data Protection Board of India.
- Right to Nominate: The right to nominate another individual to exercise your rights under this Act in the event of your death or systemic incapacity.
- Right to Withdraw Consent: The right to withdraw your processing consent at any time. Withdrawal will not operate retroactively, and it immediately releases the Company from any active obligation to continue providing the corresponding Travel Services or maintaining the active Booking.
11. DATA SECURITY & BREACH NOTIFICATION MATRIX
The Company employs commercially reasonable administrative, technical, and physical security measures, including transport-layer encryption (SSL/TLS), firewalls, and restricted database access privileges, to secure your information.
However, no digital system is entirely foolproof. In the event of an actual or suspected personal data breach, the Company will fulfill its obligations under Section 8(5) of the DPDP Act, 2023. We will immediately notify the Data Protection Board of India (DPBI) along with the affected Data Principals. This notification will include a comprehensive description of the breach, the categories of data compromised, potential real-world consequences, and the immediate remedial steps implemented by our technical team.
12. DATA RETENTION & MANDATORY ERASURE
The Company retains personal data only as long as necessary to satisfy the commercial, operational, and contractual purposes outlined in this Policy, or as required by applicable laws.
- Transaction and Financial Records: Retained for the statutory periods mandated under Indian tax laws (e.g., GST filings, income tax compliance, and financial audits).
- Operational Roster Data: Retained for reasonable post-trip periods to handle customer feedback, coordinate loyalty updates, or manage potential liability claims as governed by our Limitation of Liability clauses in our Terms & Conditions.
- Ultimate Destruction: When data is no longer required for legal, regulatory, or business continuity purposes, it is securely destroyed, overwritten, or rendered completely anonymous.
13. GRIEVANCE REDRESSAL MECHANISM & CONTACT INFRASTRUCTURE
If you have questions, require clarification, wish to invoke your Data Principal rights, or intend to file a formal complaint regarding data processing, you may contact our designated Grievance Officer directly:
- Legal Entity: Trek Break & More
- Attention: Designated Grievance Officer
- Email Channel: contact@trekbreakandmore.com
- Telephone Support: +91 87774 95581 (Available 10 AM – 7 PM, Monday through Saturday, excluding National/State Holidays)
- Corporate Portal: www.trekbreakandmore.com
The Grievance Officer will investigate your issue and respond within the statutory timelines prescribed under the DPDP Act, 2023.
14. AMENDMENTS & UPDATES
The Company reserves the right to modify, amend, or rewrite this Privacy Policy at any time to reflect structural changes in our operations, technical infrastructure, or evolving legal frameworks. Any updated version becomes legally effective immediately upon its publication on the website or via direct digital communication to your registered coordinates. Your continued use of our platforms or services after an update constitutes an unconditional acceptance of the revised terms.