DEVGAMAN

Legal · Privacy

Privacy Policy

आपकी निजता

We are a small travel company in Jaipur, not a data business. This page says exactly what we hold, why we hold it, who else can see it, and how to make us delete it — in the same plain English we use everywhere else on this site.

Last updated
Collected by this website
Nothing
Sold to anyone, ever
Nothing

The short version

01
  • This website collects nothing about you. No account, no login, no analytics, no advertising pixel, no tag manager, no embedded map, no social widget, no third-party script of any kind.
  • The only cookie it can set is the one that records your answer to the consent banner. Everything else it keeps in your browser stays in your browser.
  • We learn about you only when you choose to write to us — on WhatsApp, on Telegram or by email — and we use what you write to plan, quote and book your trip.
  • We do not sell, rent or trade your information, and we run no advertising.
  • You can ask us to delete everything we hold about you at any time. Write to hello@devgaman.com and we will do it.

Who we are

02

DEVGAMAN is the trading name of Devgaman Tours & Travels, a tours and travels company based in Jaipur, Rajasthan, India. Under India’s Digital Personal Data Protection Act 2023 we are the Data Fiduciary for the information described here, and you are the Data Principal. Under the EU and UK GDPR we are the controller.

  • Postal address: Devgaman Tours & Travels, C-Scheme, Jaipur, Rajasthan 302001, India.
  • Email: hello@devgaman.com
  • WhatsApp and phone: +91 77328 98891

A person reads that inbox. There is no ticketing system, no outsourced desk and no chatbot standing between you and an answer.

What this website collects

03

Nothing, automatically. Every page you can reach here is a static file that was built in advance and is served from our own origin. There is no form on this site that posts to a server of ours, because we have no server that receives one, and there is no database behind these pages to write you into.

Specifically, and checkably:

  • No analytics of any kind — no Google Analytics, no tag manager, no self-hosted counter.
  • No advertising or remarketing pixel, and no ad network.
  • No embedded third-party frames. The Jaipur map on our contact page is drawn by hand in SVG rather than embedded, and the photographs are stored on this site’s own server, not fetched from someone else’s.
  • No web fonts loaded from another company. The four typefaces are built into this site and served from here.
  • No third-party cookies, and no first-party cookie either — except the one that remembers your consent choice, described in full in our Cookie & Storage Policy.

Three small things are kept in your browser, on your device, and are never transmitted to us: a draft of your answers in the trip planner, so a half-finished plan survives a reload; your best score in the little driving game on /play; and a note that the opening animation has already played this session. Every one of them is listed by name, lifetime and purpose on the Cookie & Storage Policy page, and clearing your browser data removes them.

One honest exception, because it is true of every website on earth: the machine that serves these pages keeps ordinary web-server logs — an IP address, a timestamp, the page requested and the browser string. Our hosting provider holds them, we use them only to keep the site running and to spot abuse, we do not build a profile from them, and we do not connect them to any message you send us. If you would like to know who hosts the site, ask and we will tell you.

What you send us, and why

04

Everything we hold about you, you gave us on purpose. When you write to us on WhatsApp, Telegram or email — including when the planner or the enquiry form on the contact page drafts the message for you, which it does entirely inside your browser before handing it to your own app — we receive whatever you chose to put in it. Typically that is:

  • your name, and the phone number, Telegram handle or email address you wrote from;
  • the dates or the month you are thinking of, and how many days you have;
  • who is travelling — how many people, and often their ages;
  • the places, themes or festivals you care about, and a budget range if you offer one;
  • anything else you decide to tell us: a bad knee, altitude sickness two years ago, a vegetarian household, a wheelchair, a proposal you are planning to spring on someone in Udaipur.

We use it for one thing: to plan a trip for you, quote it, book it, and be reachable while you are on the road. Health, dietary and mobility notes are sensitive, and we ask for them only where they change the plan — a hotel with a lift, a slower ascent to Leh, a Jain thali. Tell us as much or as little as you like; the less you tell us, the more generic the plan has to be.

If a trip is confirmed, we will also need identity details that the Indian system genuinely requires: passport particulars for train tickets, hotel registration and permits such as Inner Line Permits. We ask for those only after you have decided to travel, only by email, and never on a chat thread.

We will never ask you for a card number, a CVV, an OTP or a UPI PIN — not in a message, not on a call, not on this website. If anyone claiming to be us does, it is not us. Tell us straight away.

Where your message then lives

05

In our inbox, on our phone, and in the ordinary business record we keep of your trip. We do not have a customer database, a CRM or a marketing platform, so your enquiry does not get copied into one.

The messaging companies you chose to reach us through also hold the conversation, on their own terms and under their own privacy policies, which we do not control:

  • WhatsApp — operated by Meta. A WhatsApp message is end-to-end encrypted in transit, but Meta still handles the metadata around it and both phones keep a copy.
  • Telegram — operated by Telegram Messenger. Ordinary Telegram chats sit on their servers.
  • Email — our mail provider, and yours, each hold the message the way they hold all of your mail.
  • Our hosting provider — serves these pages and keeps the server logs described above.

Once you are actually travelling, the parts of your details that a booking requires go to the suppliers who need them, and no further: the hotel or homestay you are sleeping in, the airline or railway you are ticketed on, the driver meeting your train, the guide walking you round a fort, the office issuing a permit. We give each of them the minimum that makes the booking work.

We are in India, so your information is stored and handled in India. Nothing about you is transferred to anyone for their own commercial purposes.

How long we keep it

06
  • An enquiry that never becomes a trip. We delete the thread within twelve months, or sooner if you ask. If you say “next year, not this one”, we keep it until then, because that is the point.
  • A trip we actually planned and booked. The invoice and the booking record are kept as long as Indian tax and accounting law requires us to keep our books — currently up to eight financial years. That is a legal obligation, not a preference.
  • Passport and identity copies. Deleted within ninety days of your trip ending, unless a permit or a tax rule specifically requires us to hold them longer.
  • Server logs. Held briefly by our hosting provider for operations and security, then rotated away.

How to make us delete it

07

Write to hello@devgaman.com from the address you wrote from, or send us a WhatsApp message from the same number, and say what you want: a copy of what we hold, a correction, or deletion. You do not need to give a reason and you do not need to phrase it legally — “please delete my data” is enough.

We will do it and confirm, normally within a few days and in any case within thirty. Two honest limits: we cannot delete the copy of the conversation sitting on your own phone, and we cannot delete records that tax law obliges us to keep for a booked trip — we will tell you plainly if that applies to you and delete everything else.

What we never do

08
  • We do not sell, rent, trade or broker your information. There is no version of this we would do.
  • We do not run advertising, retargeting or lookalike audiences, here or anywhere else.
  • We do not buy contact lists, and we do not cold-message people who have not written to us.
  • We do not add you to a mailing list because you enquired. If we ever start a newsletter you will have to ask for it, and one click will end it.
  • We do not profile you, score you or make automated decisions about you.

If analytics is ever switched on

09

Today there is none, and the consent banner you may have seen is telling the truth when it says so. We may one day want to know which journeys people actually read about. If that day comes:

  • this page and the cookie page will name the tool, and what it stores, before it goes live;
  • nothing will load until you say yes. The banner does not decorate the page — it is the switch, and the measurement script is only fetched after a positive choice;
  • “No” is remembered exactly as firmly as “yes”, and you can change it later;
  • we would use it to count pages, not to follow people, and never to build advertising audiences.

Your rights in India

10

The Digital Personal Data Protection Act 2023 gives you rights over what we hold, and we honour them whether or not you cite the Act:

  • To know. A summary of what we hold about you, what we are doing with it, and who else has received it.
  • To correct, complete, update and erase. Wrong spelling, changed number, a plan you would rather we forgot.
  • To withdraw consent as easily as you gave it — one message. We stop processing, except where the law still requires us to keep a booking record.
  • To nominate someone to exercise these rights on your behalf if you die or become unable to.
  • To be heard. A grievance channel that answers, described below, before you ever need to involve a regulator.

The Act also lets you manage consent through a registered Consent Manager — an intermediary through which you can give, review and withdraw consent for many companies in one place. We do not use one today. If we ever do, we will name it here, and you will still be able to write to us directly.

The Act entitles you to this notice in English or in any language listed in the Eighth Schedule to the Constitution. Ask us and we will send you a Hindi copy.

If you are in the EU or the UK

11

The GDPR and the UK GDPR give you the rights of access, rectification, erasure, restriction of processing, data portability, objection to processing, and withdrawal of consent at any time. Use the same address and you will get the same answer.

What we rely on to process your information at all:

  • Steps taken at your request before a contract (Article 6(1)(b)) — planning, quoting and then delivering the trip you asked for.
  • Your consent (Article 6(1)(a)) — for anything optional, including analytics if it is ever enabled. Special-category details such as health or mobility rest on your explicit consent, given by the act of telling us (Article 9(2)(a)).
  • Legal obligation (Article 6(1)(c)) — the accounting and tax records we must keep.
  • Our legitimate interests (Article 6(1)(f)) — keeping the website up, keeping our own record of what we agreed with you, and preventing fraud.

Where the data goes. We are in India, which does not have an EU adequacy decision. When you write to us and ask us to plan a trip, the transfer is necessary for the performance of that contract with you, and for the pre-contract steps you asked for (Article 49(1)(b)), and it is also covered by the explicit consent you give by sending it (Article 49(1)(a)). We hold it in India and nowhere else.

Complaints. You can complain to your national supervisory authority, or to the Information Commissioner’s Office in the UK. We would much rather you told us first.

We are a small Indian company with no establishment in the EU or the UK. If we are required to appoint a representative under Article 27, we will name them on this page.

Grievances and complaints

12

Under the DPDP Act every Data Fiduciary must publish a way to raise a grievance and must answer it. Ours:

  • Nirankar Singh — Grievance Officer, DEVGAMAN
  • Email: hello@devgaman.com — put “Grievance” in the subject line so it is not read as a trip enquiry.
  • Post: Grievance Officer, Devgaman Tours & Travels, C-Scheme, Jaipur, Rajasthan 302001, India.
  • Phone and WhatsApp: +91 77328 98891

We acknowledge within seven working days and resolve within thirty. If we have not sorted it out, you may complain to the Data Protection Board of India, and visitors from the EU or the UK may go to their own supervisory authority instead.

Children

13

This site is not aimed at children, and we do not knowingly plan a trip with someone under eighteen acting on their own. Bookings are made by adults. Where children travel with you, we hold only what the booking genuinely needs — usually a first name and an age for a hotel room or a train berth — and you give us that as their parent or guardian.

Under the DPDP Act, processing a child’s personal data needs verifiable parental consent, and neither tracking nor targeted advertising at children is permitted. We run neither, at any age. If you believe a child has sent us something they should not have, write to us and we will delete it.

Keeping it safe

14

The best security measure here is how little there is to take: no accounts, no passwords of yours, no database, no card details, nothing stored on this website at all. The pages are served over HTTPS, and the build has no third-party script that could be tampered with upstream.

What does exist is our inbox and our phone, and those are protected the way they should be — strong unique passwords, two-factor authentication, screen locks, and access limited to the people who are actually planning your trip. If we ever have a breach that is likely to affect you, we will tell you and the regulator, as the law requires.

No one can honestly promise perfect security, so we will not. We can promise a small attack surface.

Changes to this policy

15

When this policy changes, the date at the top of the page changes with it, and we will say here what moved. If the change is material — a new tool, a new category of data, a new recipient — we will flag it visibly on the site for at least thirty days before it takes effect, and if it involves anything that needs your consent, we will ask again rather than assume.

Version 1 · · first publication