1. About this policy
This policy explains how we handle personal data when you use this website, make a booking, or contact us. It is written to meet our obligations under the Digital Personal Data Protection Act, 2023 and the rules made under it, and under the Information Technology Act, 2000.
We have tried to write it in plain English rather than in the language of a compliance form, because a privacy notice you cannot read protects nobody.
2. Who is responsible for your data
[registered legal name — to be completed], trading as YavaTrip, of [full registered address with PIN code — to be completed], is the Data Fiduciary responsible for the personal data described here. In this policy that is "we" and "us"; you are the Data Principal.
You can reach us about anything in this policy at hello@yavatrip.com or +91 73076 98635.
3. The information we collect
We collect only what we need to sell you a trip, run it, take payment for it and account for it.
| What | Why we have it |
|---|---|
| Your name, mobile number and email address | To identify you, sign you in, send your confirmation, boarding details and invoice, and reach you if a departure changes. |
| Booking details — boat, date, time, party size, and any note or request you add | To run your trip. Notes may include information you choose to give us about mobility, health or dietary needs. |
| Lead-traveller contact details for the party | So the crew can reach the person responsible for the group on the day. |
| Payment records — amount, date, status and the reference issued by our payment gateway | To confirm the booking, issue invoices and credit notes, process refunds and keep our accounts. |
| Correspondence — emails, messages and notes of calls with you | To answer you and to keep a record of what was agreed. |
| Technical records — IP address, browser or device identification, and the time of significant actions on your account | For security, fraud prevention, and to be able to reconstruct what happened if a booking or payment is disputed. |
If you give us information about other people in your party, you must have their agreement to do so, and you should show them this policy.
4. What we do not collect
We think it is as important to say what we do not do.
- We do not run advertising trackers, third-party analytics or social-media pixels on this website. We do not build a behavioural profile of you and we do not follow you around the internet.
- We never see or store your card number, CVV, UPI PIN or net-banking credentials. Those are entered on our payment gateway's own secure page and never reach our servers.
- We do not sell, rent or trade your personal data to anybody, for any purpose. We do not share it with data brokers or advertising networks.
- We do not ask for your government identity numbers to make a booking. Crew may inspect photo identity at boarding, but we do not record or retain a copy.
5. Why we use it, and on what basis
We use your personal data for the following purposes and no others:
- To perform our contract with you — creating and holding your booking, taking payment, issuing invoices, running the trip, handling changes, cancellations and refunds.
- Because you asked us to — answering an enquiry, calling you back, or sending you marketing you have opted in to.
- To meet a legal obligation — GST invoicing and tax records, company accounting records, and responding to a lawful request from an authority.
- To keep the service safe — preventing fraudulent bookings and payment abuse, protecting accounts, and investigating incidents.
Where the law requires your consent, we ask for it clearly and separately, and you may withdraw it at any time. Withdrawing consent does not affect anything we did lawfully before you withdrew it, and it does not remove records we are legally obliged to keep.
7. Messages we send you
There are two kinds, and they are treated differently.
- Transactional messages — your one-time password, booking confirmation, boarding details, payment receipt, invoice, balance reminder and cancellation notice. These are part of the service. You cannot opt out of them while you hold a live booking, because you need them.
- Marketing messages — offers, seasonal departures and news. We send these only if you opt in, and every one carries a way to stop. You can also just reply and tell us, or write to hello@yavatrip.com.
Our SMS goes through a licensed Indian gateway using message templates registered under the TRAI DLT framework, as required for commercial messaging in India. Your number is provided to that gateway solely to deliver the message.
9. Where your data is stored
We store personal data on servers located in [state the hosting region, e.g. India (Mumbai) — to be completed]. Some of the service providers listed above may process limited data outside India in the course of delivering a message or a payment. Where that happens, it is done under contractual protections and in accordance with Indian law.
10. How long we keep it
- Booking, invoice and payment records: at least eight years from the end of the financial year they relate to, because tax and company law require it.
- Your account and contact details: for as long as your account is open, and for a reasonable period afterwards in case you return or a question arises about a past trip.
- Security and audit records: for as long as needed to investigate incidents and defend claims.
- Marketing consent records: for as long as you remain opted in, and a record of your opt-out afterwards so that we do not contact you again by mistake.
When we no longer need something, we delete it or render it anonymous. Where a record must be preserved for tax purposes, we restrict it so it is used for nothing else.
11. Your rights
Under the Digital Personal Data Protection Act, 2023 you have the right to:
- obtain a summary of the personal data we hold about you and what we do with it;
- have inaccurate or incomplete data corrected, updated or completed;
- have data erased where we no longer need it and are not required to keep it;
- withdraw a consent you previously gave;
- nominate another person to exercise these rights on your behalf if you die or become incapable of doing so; and
- have a grievance addressed by us, and to complain to the Data Protection Board of India if we do not deal with it properly.
Exercising these rights is free and will never affect the service you get from us.
12. How to exercise your rights
Write to us at hello@yavatrip.com, or call +91 73076 98635. Tell us what you want and give us enough detail to find your records — the mobile number or email on your account, and a booking reference if you have one.
We will verify that the request really comes from you, usually by sending a one-time password to the number or address on the account. This protects you: without it, anyone who knows your email address could ask for your data.
We will respond as soon as we can, and in any case within the period the law allows. If we cannot do what you have asked — for example, erase an invoice we are legally required to keep — we will tell you why.
13. Children
This website is not intended for children, and a booking must be made by an adult of 18 or over. Where a booking includes children, we hold only what the trip requires — that they are travelling, and their age where a child fare applies.
We do not knowingly collect personal data directly from a child, we do not track children, and we never direct advertising at them. If you believe a child has given us personal data, tell us and we will delete it.
14. How we protect your information
- Traffic between your browser and our servers is encrypted in transit.
- Sign-in is by one-time password. We do not store passwords, so there is no password database to steal.
- Sign-in tokens are short-lived and rotate; a stolen one stops working quickly.
- Access to customer records by our staff is restricted to those who need it, and significant actions are recorded in an audit trail with the account and time.
- Invoices and other documents shared by link use expiring, single-purpose links that can be switched off, rather than public web addresses that anyone could guess.
- Uploaded files are validated by inspecting the file itself, not by trusting its name.
No system is perfectly secure, and we do not pretend otherwise. What we can promise is that we hold as little as we can, for as short a time as we can.
15. If something goes wrong
If a personal data breach occurs, we will notify the Data Protection Board of India and every affected person in the manner and within the time the law requires, and we will tell you plainly what happened, what it means for you and what we are doing about it.
16. Grievance Officer
Our Grievance Officer for the purposes of the Digital Personal Data Protection Act, 2023 and the Information Technology Act, 2000 is [name and designation of the grievance officer — to be completed].
| hello@yavatrip.com | |
| Phone | +91 73076 98635 |
| Post | [full registered address with PIN code — to be completed] |
We will acknowledge a grievance within 48 hours and aim to resolve it within one month. If you are not satisfied with our response, you may complain to the Data Protection Board of India.
17. Other websites
Our pages may link to other websites — a payment gateway, a map, a review site. We are not responsible for their privacy practices, and you should read their notices before giving them your data.
18. Changes to this policy
We will update this policy when our practices change, and the version published here is always the current one, with its revision date at the top. If a change materially affects how we use your data, we will tell you directly rather than relying on you to notice.
This policy should be read with our Terms & Conditions.