Privacy Policy for SoulPlanners.com
Effective Date: Januray 1, 2025
Your privacy is critically important to us at Soul Planners. This Privacy Policy outlines how SoulPlanners.com (referred to as “we”, “us”, or “our”) collects, uses, processes, and protects your personal data when you visit our website, use our services, or interact with us.
As the Data Fiduciary for the personal data collected on this website, we are committed to being transparent about our practices and safeguarding your information in compliance with applicable data protection laws, including the Digital Personal Data Protection Act, 2023 (DPDPA), the General Data Protection Regulation (GDPR), and the California Consumer Privacy Act (CCPA) / California Privacy Rights Act (CPRA), where relevant.
1. Introduction and Scope
This Privacy Policy applies to all information collected through our website SoulPlanners.com, and any related services, sales, marketing, or events.
2. What Personal Data Do We Collect?
We collect various types of personal data to provide you with our services, improve your experience, and for legitimate business purposes. We only collect data that is necessary and relevant for the purposes outlined in this policy.
- Data You Provide to Us Directly:
- Contact Information: Name, email address, phone number, postal address.
- Booking Information: Dates of travel, number of travelers, accommodation preferences, flight preferences, dietary restrictions, special requests.
- Payment Information: (Processed securely via third-party payment gateways; we do not store full payment card details on our servers). Billing address.
- Communication Data: Information you provide when you communicate with us via email, phone, chat, or contact forms.
- Feedback and Surveys: Your responses to surveys, reviews, and feedback forms.
- Data Collected Automatically:
- Usage Data: Information about how you interact with our website, including pages viewed, time spent on pages, links clicked, and navigation paths.
- Device Information: IP address, browser type, operating system, device identifiers.
- Location Data: General location derived from your IP address.
- Cookies and Tracking Technologies: Information collected through cookies, web beacons, and similar technologies.
- Sensitive Personal Data:
We generally do not seek to collect sensitive personal data unless it is necessary for providing you with a specific service that you have explicitly requested (e.g., dietary restrictions related to allergies, accessibility requirements for travel). In such cases, we will obtain your explicit consent and provide specific disclosures about enhanced security measures.
3. How and Why Do We Use Your Personal Data? (Purposes and Legal Bases)
We use your personal data for various purposes, relying on different legal bases depending on the context of the data collection:
- To Provide and Manage Our Services:
- Facilitate bookings and reservations: Performance of a contract with you.
- Communicate about your bookings: Performance of a contract with you.
- Provide customer support: Performance of a contract with you; Legitimate interests (to address your inquiries).
- To Improve Our Website and Services:
- Analyze website usage and trends: Legitimate interests (to understand how our website is used and improve its functionality and user experience); Consent (for certain cookies and tracking technologies, as per your cookie preferences).
- Personalize your experience: Legitimate interests (to show you relevant content and offers).
- Develop new features: Legitimate interests (to enhance our service offerings).
- For Marketing and Promotional Purposes:
- Send newsletters and promotional offers: Consent (where required by law, e.g., for direct marketing emails); Legitimate interests (for existing customers in certain jurisdictions).
- Run targeted advertisements: Consent (for certain advertising cookies); Legitimate interests (to promote our services).
- For Legal and Security Reasons:
- Detecting and preventing fraud: Legal obligation; Legitimate interests (to protect our business and users).
- Comply with legal obligations: Legal obligation (e.g., tax, reporting requirements).
- Enforce our terms and conditions: Legitimate interests (to protect our rights and operations).
- Respond to legal requests: Legal obligation.
4. How Do We Share Your Personal Data?
We may share your personal data with third parties only when necessary for the purposes outlined in this Privacy Policy, and always with appropriate safeguards.
- With Service Providers:
We engage trusted third-party service providers to perform functions on our behalf. These include:
- Accommodation Providers: Hotels, resorts, guesthouses.
- Airline and Transportation Providers: Airlines, taxi services, car rental companies.
- Activity and Tour Operators: Providers of excursions, tours, and experiences.
- Payment Gateways: Securely process your payments (e.g., Razorpay, Stripe, PayPal). We do not store your full payment card details.
- IT and System Providers: Hosting services, data analytics providers, CRM systems, email service providers.
- Marketing and Advertising Partners: For analytics and targeted advertising (where consent is obtained).
These third parties are contractually obligated to protect your data and only use it for the purposes for which it was shared. We advise you to review the privacy policies of these third-party service providers directly, as they operate under their own privacy frameworks.
- For Legal Reasons:
We may disclose your personal data if required to do so by law, in response to a court order, subpoena, or other legal process, or if we believe in good faith that such action is necessary to:
- Comply with a legal obligation.
- Protect and defend the rights or property of SoulPlanners.com.
- Prevent or investigate possible wrongdoing in connection with the services.
- Protect the personal safety of users of the services or the public.
- Business Transfers:
In the event of a merger, acquisition, or sale of all or a portion of our assets, your personal data may be transferred as part of that transaction. We will notify you via email and/or a prominent notice on our website of any such change in ownership or control of your personal data.
- With Your Consent:
We may share your data with other third parties when we have your explicit consent to do so.
5. Cross-Border Data Transfers
As we operate globally and may use service providers located in different countries, your personal data may be transferred to, and processed in, countries other than India.
When your data is transferred outside of India (or the European Economic Area for GDPR purposes, or California for CCPA/CPRA purposes), we ensure that appropriate safeguards are in place to protect your data, such as:
- Standard Contractual Clauses (SCCs) approved by relevant authorities.
- Ensuring the recipient country has been deemed to provide an adequate level of data protection.
- Obtaining your explicit consent for the transfer after informing you of the possible risks.
6. Data Retention
We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected, including for the purposes of satisfying any legal, accounting, or reporting requirements.
To determine the appropriate retention period for personal data, we consider the amount, nature, and sensitivity of the personal data, the potential risk of harm from unauthorized use or disclosure of your personal data, the purposes for which we process your personal data and whether we can achieve those purposes through other means, and the applicable legal requirements.
Generally:
- Booking and Transaction Data: Retained for a period required by tax and accounting laws (e.g., 7-10 years).
- Account Data: Retained as long as your account is active. If your account is inactive for a prolonged period, we may delete it.
- Marketing Consent: Retained until you withdraw consent.
- Customer Service Communications: Retained for a reasonable period to manage inquiries and disputes.
When your personal data is no longer required, we will securely delete or anonymize it.
7. Your Data Protection Rights
You have significant rights regarding your personal data. We are committed to facilitating the exercise of these rights. The specific rights available to you may vary depending on your location and applicable data protection laws (DPDPA, GDPR, CCPA/CPRA).
- Rights under DPDPA, 2023 (for Data Principals in India):
- Right to Confirmation and Access: To confirm whether your personal data is being processed and to access a summary and copies of your personal data.
- Right to Correction and Erasure: To correct inaccurate or incomplete personal data and to erase personal data that is no longer necessary.
- Right of Grievance Redressal: To have grievances addressed by the Data Fiduciary.
- Right to Nominate: To nominate another individual to exercise your rights in case of death or incapacity.
- Right to Withdraw Consent: To withdraw consent at any time, where processing is based on consent, without affecting the lawfulness of processing before such withdrawal.
- Rights under GDPR (for Data Subjects in the EEA/UK):
- Right to be Informed: About how your data is processed.
- Right of Access: To obtain confirmation and access to your personal data.
- Right to Rectification: To have inaccurate personal data corrected.
- Right to Erasure (“Right to be Forgotten”): To request deletion of your personal data under certain circumstances.
- Right to Restriction of Processing: To limit how your data is processed under certain circumstances.
- Right to Data Portability: To receive your personal data in a structured, commonly used, and machine-readable format.
- Right to Object: To processing based on legitimate interests or for direct marketing.
- Rights in relation to automated decision-making and profiling: To not be subject to decisions based solely on automated processing, including profiling, which produce legal effects concerning you or similarly significantly affect you.
- Rights under CCPA/CPRA (for California Residents):
- Right to Know: To request information about the categories and specific pieces of personal information we have collected, used, disclosed, and sold/shared.
- Right to Delete: To request the deletion of your personal information, subject to certain exceptions.
- Right to Opt-Out of Sale/Sharing: To opt-out of the “sale” or “sharing” of your personal information (as defined by CCPA/CPRA).
- Right to Correct Inaccurate Personal Information: To request correction of inaccurate personal information.
- Right to Limit Use and Disclosure of Sensitive Personal Information: To limit the use and disclosure of sensitive personal information to that necessary to perform the services or provide the goods reasonably expected by an average consumer.
- Right to Non-Discrimination: Not to be discriminated against for exercising your CCPA/CPRA rights.
How to Exercise Your Rights:
To exercise any of your rights, please contact our Privacy Contact Person using the details provided in Section 9. We may need to request specific information from you to help us confirm your identity and ensure your right to access your personal data (or to exercise any of your other rights). This is a security measure to ensure that personal data is not disclosed to any person who has no right to receive it. We may also contact you to ask for further information in relation to your request to speed up our response.
We will respond to legitimate requests within the timeframes required by applicable law (e.g., 30 days under DPDPA, 30 days under GDPR, 45 days under CCPA/CPRA, with possible extensions).
8. Cookie Policy and Consent Management
We use cookies and similar tracking technologies to track the activity on our Service and hold certain information. Cookies are filed with a small amount of data which may include an anonymous unique identifier.
- Essential Cookies: Necessary for the website to function.
- Analytical/Performance Cookies: Help us understand how visitors interact with our website.
- Functional Cookies: Remember your preferences and choices.
- Targeting/Advertising Cookies: Used to deliver relevant advertisements.
We utilize a Consent Management Platform (CMP) to manage your cookie preferences. When you visit our website for the first time, you will be presented with a cookie banner allowing you to accept or decline different categories of cookies, or to customize your preferences. You can change your cookie preferences at any time by clicking on the “Cookie Settings” or “Manage Consent” link, typically found in the footer of our website.
9. Data Security
We have implemented appropriate technical and organizational measures to protect your personal data from unauthorized access, accidental loss, destruction, alteration, or disclosure. These measures include:
- Encryption: Using SSL/TLS encryption for data in transit (e.g., on our website forms).
- Access Controls: Restricting access to personal data to authorized personnel on a need-to-know basis.
- Data Minimization: Collecting only the data necessary for the stated purposes.
- Regular Security Audits: Performing regular assessments of our systems.
- Employee Training: Training our staff on data privacy and security best practices.
While we strive to protect your personal data, no method of transmission over the Internet or method of electronic storage is 100% secure. Therefore, we cannot guarantee its absolute security.
10. Privacy Contact Person and Grievance Redressal
For any questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact our Privacy Contact Person:
Name: Frankie
Email: privacy@soulplanners.com
We will endeavor to respond to your inquiries promptly and address any grievances you may have in accordance with applicable law.
11. Links to Other Websites
Our website may contain links to other websites that are not operated by us. If you click on a third-party link, you will be directed to that third party’s site. We strongly advise you to review the Privacy Policy of every site you visit. We have no control over and assume no responsibility for the content, privacy policies, or practices of any third-party sites or services.
12. Children’s Privacy
Our services are not intended for individuals under the age of [18 for DPDPA, 16 for GDPR, or as applicable by law]. We do not knowingly collect personal data from children without verifiable parental consent. If we become aware that we have collected personal data from a child without parental consent, we will take steps to remove that information from our servers.
13. Changes to This Privacy Policy
We may update our Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the “Effective Date” at the top of this Privacy Policy. We encourage you to review this Privacy Policy periodically for any changes. Material changes will be communicated more prominently, for example, via email or a notice on our website.