Home / Privacy Policy
Privacy Policy
escapes.asia — by Earthly Hospitality Services Private Limited
1. Introduction
This Privacy Policy explains how Earthly Hospitality Services Private Limited (CIN U55101UR2022PTC013829), operating under the brand "escapes.asia" ("we", "us", "the Company"), collects, uses, discloses, retains, and protects your personal data when you visit our website, make an enquiry, or book travel with us. We are the data fiduciary for the personal data described here. This policy is published in compliance with the Information Technology Act, 2000 and its rules, and the Digital Personal Data Protection Act, 2023 (as and when brought into force).
By using our website or booking with us, you consent to the practices described in this policy. If you do not agree, please do not use the website or submit your information.
2. Information we collect
2.1 Information you give us
- Contact and identity — name, email address, phone number, and postal address.
- Traveller details — the names, ages, and government-ID details of travellers where required for bookings, permits, or Char Dham / yatra registration.
- Booking details — your itinerary, dates, preferences, and correspondence with us.
- Billing details — billing name, address, and GSTIN (where you request a GST invoice).
2.2 Information we collect automatically
We run our own analytics on our own servers. We do not use Google Analytics, advertising pixels, or any other third-party tracking, and no visit data is sent to another company.
- Usage data — the pages you view, the page that referred you, and any campaign tags in the link you followed.
- Device data — browser, operating system, and device type, derived from the information your browser sends with every request.
- Engagement — how far down a page you scrolled, roughly how long you stayed, and which links you followed away from the site.
- Approximate location — country, region, city, and the approximate coordinates of that city, looked up from your IP address against a database held on our own servers. Your IP address is not sent anywhere to do this.
- IP address — shortened before it is stored, so that the last part of the address is discarded and the stored value points at a block of addresses rather than yours.
By default we do not store anything that identifies you across days. Visitors are counted using a code derived from the shortened IP address and browser, and the method of deriving it changes every night, so we do not link yesterday's visits to today's. If you choose "Allow" on the cookie banner, we store a random identifier in a cookie instead, which lets us recognise a returning visitor. See Section 5.
2.3 Payment information
Payments are processed by our third-party payment gateway. Card numbers, CVV, UPI credentials, and net-banking passwords are entered on the gateway's PCI-DSS-compliant systems — we do not collect or store your full card or banking credentials. We receive only the transaction status, a payment reference, and the amount.
3. How we use your information
- To respond to enquiries and prepare itineraries and quotes.
- To confirm, manage, and deliver your booking, including with the vendors and authorities named in Section 4.
- To issue invoices, receipts, and GST documents, and to process refunds.
- To provide customer support and handle grievances.
- To send booking-related and, where you have opted in, promotional communications by email, phone, SMS, or WhatsApp. You can opt out of promotional messages at any time.
- To comply with legal, tax, and regulatory obligations and to prevent fraud.
4. How we share your information
We do not sell your personal data. We share it only as needed to deliver your trip and meet legal duties, with:
- Travel service providers — hotels and homestays, transport operators, guides, airlines, Indian Railways / IRCTC, and helicopter operators, so your services can be booked.
- Government and permit authorities — for Char Dham / Hemkund Sahib registration, national-park entry, and inner-line permits, where the trip requires them.
- Payment gateway and banking partners — to process payments and refunds.
- Professional advisers and regulators — accountants, auditors, and tax or law-enforcement authorities, where required by law.
- Service vendors — hosting and communications providers that process data on our behalf under confidentiality obligations. Analytics is not on this list: we process it ourselves and share none of it.
5. Cookies
We use cookies to keep the site working, to keep you signed in where that applies, and to remember your answer to the banner below. Most browsers let you refuse or delete cookies; disabling essential cookies may affect how parts of the site function.
The analytics cookie is optional. When you first visit, we ask:
- Allow — we store a random identifier for two years so we can tell that a returning visitor is the same person. The identifier is a random value; it holds nothing about you.
- Decline — no analytics cookie is stored. We still count the visit, using the daily-changing code described in Section 2.2, which cannot be linked to you or to your other visits.
You can change your mind by clearing this site's cookies, which brings the banner back.
6. Data retention
We keep personal data only for as long as needed for the purposes above and to meet legal and tax obligations. Booking, invoice, and tax records are retained for the period required under the applicable tax and company law (generally up to eight years), after which they are deleted or anonymised.
Analytics records are deleted on a fixed schedule: individual page-view records after 90 days, and visit records after 400 days. What remains after that is daily totals — how many visits came from a country or a campaign on a given day — which contain no record of any individual visit. Those daily totals are kept indefinitely.
7. Data security
We apply reasonable security practices and procedures to protect your data against unauthorised access, alteration, disclosure, or destruction, consistent with the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
8. Your rights
Subject to applicable law, you may:
- request access to the personal data we hold about you;
- ask us to correct or update inaccurate or incomplete data;
- request erasure of your data where it is no longer required and we are not legally obliged to keep it;
- withdraw consent for promotional communications; and
- raise a grievance about how your data is handled.
To exercise any of these, contact our Grievance Officer using the details in Section 11. We may need to verify your identity before acting on a request.
9. Children's data
Our services are intended for adults. Where a booking includes minors, their details are provided and consented to by a parent or guardian. We do not knowingly collect data directly from children.
10. Changes to this policy
We may update this policy from time to time by publishing the revised version on escapes.asia. The version in force on the date of your booking applies to that booking. Please review this page periodically.
11. Grievance Officer & contact
In compliance with the Information Technology Act, 2000 and the Consumer Protection (E-Commerce) Rules, 2020, you may contact our Grievance Officer:
Grievance Officer: Dev, Earthly Hospitality Services Private Limited
Email: info@earthlygroup.in · Phone: +91 99901 19989
Hours: Monday to Saturday, 10:00 to 18:00 IST
Complaints are acknowledged within 48 hours and resolved within 30 days. See also our Contact Us page.
This product includes GeoLite2 data created by MaxMind, available from https://www.maxmind.com.
Earthly Hospitality Services Private Limited · operating as escapes.asia
CIN U55101UR2022PTC013829 · GSTIN 05AAGCE9827L1Z6 · Registered in Uttarakhand, India