Legal
Privacy Policy
How we collect, use, and protect your personal data. Compliant with the Digital Personal Data Protection Act, 2023.
- Data Fiduciary
- Bytechakra (trading as Satmarg)
- Udyam No.
- UDYAM-UP-75-0177698
- Contact
- [email protected] • +91 77680 98790
- Compliance
- DPDP Act 2023, IT Act 2000
1. Introduction
Satmarg respects your privacy and is committed to protecting the personal data you share with us. This Privacy Policy ("Policy") explains what personal data we collect, why we collect it, how we process and protect it, who we share it with, how long we retain it, what rights you have under Indian law, and how to contact us for questions or grievances.
This Policy applies to all users of the Platform — Guests, prospective Guests, enquirers, visitors, and partners — and to all personal data collected on or after the Effective Date.
By using the Platform or submitting any data to us, you acknowledge that you have read, understood, and consented to this Policy, to the extent your personal data is processed on the basis of consent under the DPDP Act.
2. Who We Are
Satmarg is an Indian pilgrimage travel and coordination service based in Varanasi. We design, coordinate, and deliver pilgrimage packages, day tours, heritage walks, festival tours, and related travel services across Varanasi, Sarnath, Bodhgaya, Ayodhya, Prayagraj, and associated holy sites.
As the entity determining the purposes and means of processing your personal data, we are the Data Fiduciary under the Digital Personal Data Protection Act, 2023.
3. Personal Data We Collect
3.1 Identity and Contact Data
Full name, age/date of birth, gender (if voluntarily provided), nationality, photograph (on request for reservations where required), passport number (for international guests or temple-entry bookings that require it), Aadhaar or other government-issued ID (only if expressly required by temple trust or transport operator; never stored beyond the transaction).
3.2 Communication Data
Email address, mobile/WhatsApp number, landline (if provided), postal address (when invoicing or document delivery required), messaging platform identifiers (WhatsApp, Telegram — only if you initiate contact).
3.3 Booking and Travel Data
Enquiry details (dates, group size, preferences, dietary requirements, special needs), Package selection history, hotel preferences and room type, dietary notes, travel companion information (names and ages for room allocation), check-in/check-out timing, pick-up and drop location.
3.4 Health and Sensitive Data
Where expressly provided by you for safety reasons (e.g., medical conditions, pregnancy, mobility limitations, allergy to specific food or medication), we process this information solely for Guest safety and itinerary adjustment. Such data is treated with elevated protection. We do not seek unsolicited health data and do not process it beyond what is strictly necessary.
3.5 Payment Data
We do not store your full credit or debit card details or bank account numbers. Payment processing is handled by authorised payment gateways (Razorpay, PayU, Cashfree, or equivalent), who are independently liable as Data Fiduciaries for the data they collect. We retain: transaction ID and timestamp, amount, last 4 digits of card (for dispute/reconciliation), UPI ID masked (for same purpose).
3.6 Technical Data
When you use the Platform, we automatically collect: IP address and approximate location, browser type and version, operating system, referring page, date and time of access, pages viewed, session duration, interactions, cookies and similar tracking.
3.7 Communication Records
Emails, WhatsApp conversation transcripts, call records (where calls are recorded — you will be notified at call start), feedback, reviews, testimonials submitted by you.
3.8 Third-Party-Sourced Data
We may receive data from social login providers (Google, Apple) where you use such sign-in, partner referrers, and publicly-available directories.
4. Purposes of Processing
We process personal data for the following lawful purposes, based on performance of contract (for Guests), legitimate interest (for prospective Guests), legal obligation, or your consent:
| Purpose | Legal Basis |
|---|---|
| Processing bookings and delivering Packages | Contract |
| Communicating with you before, during, after the trip | Contract / Legitimate interest |
| Coordinating with Suppliers (hotels, transport, temples) | Contract |
| Processing payments and refunds | Contract / Legal obligation |
| Invoicing, tax compliance, government reporting | Legal obligation (Income Tax Act, IT Act) |
| Responding to enquiries and grievances | Contract / Legal obligation |
| Customising Package recommendations | Legitimate interest |
| Fraud prevention and security monitoring | Legitimate interest |
| Marketing communications (transactional) | Contract / Legitimate interest |
| Marketing communications (promotional) | Consent (opt-out anytime) |
| Analytics and Platform improvement | Legitimate interest (anonymised where possible) |
| Compliance with court or regulatory orders | Legal obligation |
| Defence of legal claims | Legitimate interest |
| User-generated content (reviews, photos submitted) | Consent |
We will not process your data for any purpose that is materially different from the purposes disclosed here without obtaining your consent.
6. International Data Transfers
Some of our service providers (e.g., cloud hosting, email delivery, analytics) are based outside India. Where personal data is transferred outside India, transfers are made only to countries not restricted by notification of the Central Government under the DPDP Act. We rely on standard contractual clauses or equivalent safeguards. Data remains subject to this Policy. We do not transfer sensitive personal data outside India without additional legal safeguards.
7. Data Retention
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by applicable law.
| Data Category | Retention Period | Basis |
|---|---|---|
| Booking records | 7 years from trip completion | IT Act / Companies Act |
| Tax invoices and receipts | 8 years from financial year | Income Tax Act |
| Payment records | 7 years | RBI / FEMA guidelines |
| Communications (email, WhatsApp) | 3 years from last interaction | Contract and dispute defence |
| Enquiries without booking | 18 months | Legitimate interest |
| Marketing-consented email list | Until opt-out or 24 months inactive | Consent |
| Website analytics (anonymised) | 26 months | Legitimate interest |
| Testimonials / reviews published | Until Guest withdraws consent | Consent |
| Legal holds | As long as required | Legal obligation |
Upon expiry of the retention period, data is deleted or anonymised through secure procedures.
8. Your Rights Under the DPDP Act
As a Data Principal under the Digital Personal Data Protection Act, 2023, you have the following rights:
- Right to Access — request a summary of the personal data we hold about you and the purposes for which it is being processed;
- Right to Correction — request correction of inaccurate or outdated personal data;
- Right to Erasure — request deletion, subject to legal retention obligations, ongoing booking fulfilment, and defence of legal claims;
- Right to Nominate — nominate a successor Data Principal in the event of death or incapacity;
- Right to Grievance — raise a grievance with our Grievance Officer (Section 11);
- Right to Withdraw Consent — where processing is based on consent (marketing, non-essential cookies, testimonials), you may withdraw at any time. Withdrawal does not affect lawfulness of processing prior to withdrawal.
To exercise rights, send a written request to [email protected] with your full name and registered email/phone, the right you wish to exercise, and reasonable identification to verify your identity. We shall respond within thirty (30) days, extendable by an additional thirty (30) days on written notice. Reasonable fees may be levied for repeated or manifestly excessive requests, as permitted under the DPDP Act.
10. Security Measures
We implement reasonable security practices consistent with the IT (Reasonable Security Practices) Rules, 2011: HTTPS/TLS encryption for all Platform traffic; database encryption at rest; role-based access controls; strong password requirements and multi-factor authentication for admin access; regular vulnerability scanning and patching; employee confidentiality obligations; incident response plan; background checks for employees with data access; data processing agreements with all third-party processors.
Despite these measures, no system is perfectly secure. In the unlikely event of a personal data breach, we shall notify affected Data Principals and the Data Protection Board as required under the DPDP Act.
11. Grievance Officer
Under the DPDP Act and the IT (Intermediary Guidelines) Rules, 2021:
- For: Bytechakra (trading as Satmarg)
- Role: Grievance Officer / Data Protection Contact
- Email: [email protected]
- Phone / WhatsApp: +91 77680 98790
- Working hours: Monday to Saturday, 10:00–19:00 IST (excluding national and regional holidays)
Complaints shall be acknowledged within forty-eight (48) hours, resolved within thirty (30) days. In case of non-resolution or dissatisfaction, escalated to the Data Protection Board of India.
12. Children
The Platform is not intended for users below eighteen (18) years of age. We do not knowingly collect personal data from children without verifiable parental consent.
Where children travel as part of a family booking, the booking parent/guardian provides information on behalf of the child. We process such data only to the extent necessary for Package delivery (room assignment, meal preference, safety). We do not profile children, track their behaviour across services, or direct advertisements at children.
13. Third-Party Links
The Platform may contain links to third-party websites (Google Maps, payment gateways, hotel websites, news articles). Once you leave our Platform, the third party's privacy policy applies. We are not responsible for the content or privacy practices of third-party sites.
15. Changes to This Policy
We may revise this Policy from time to time. Revisions shall be published on the Platform with the updated "Effective Date". For material changes, we shall notify registered Guests by email at least fifteen (15) days before effect. Continued use of the Platform after the effective date constitutes acceptance of the revised Policy.
16. Applicable Law and Jurisdiction
This Policy is governed by the laws of the Republic of India. Any dispute arising shall be subject to the exclusive jurisdiction of the Courts at Varanasi, Uttar Pradesh, notwithstanding where the Data Principal resides.
17. Contact
- Data Fiduciary: Bytechakra, sole proprietorship firm trading as Satmarg
- Grievance Officer: [email protected]
- General enquiries: [email protected]
- Phone / WhatsApp: +91 77680 98790
- Udyam Registration: UDYAM-UP-75-0177698
- Website: https://satmarg.com
18. DPDP Act Contact (Data Protection Board)
If your grievance is not resolved by the Grievance Officer, you may approach:
- Data Protection Board of India
- Address: (as notified by the Central Government under the DPDP Act, 2023)
For Bytechakra (trading as Satmarg)
Effective from: 17 April 2026
Related legal documents
14. Social Media Integration
Where we embed or link to social media (Facebook, Instagram, YouTube, WhatsApp), those platforms may collect data about your visit. Their privacy policies apply to such data.