Privacy Policy
Last updated: 8 September 2026
This Privacy Policy explains how Ambraoleia Hospitality Private Limited, operating BookMyDestination.com (“BookMyDestination”, “we”, “us”, or “our”), collects, uses, shares, stores and protects personal data when you use BookMyDestination.com, our travel search, booking and enquiry services, our communications channels, and approved integrations with platforms such as Google, Meta and OpenAI.
Data Controller / Data Fiduciary: Ambraoleia Hospitality Private Limited
Website: BookMyDestination.com
Address: FF 32, Wave Silver Corporate Tower, Sector 18, Noida, Uttar Pradesh 201301, India
Email for privacy requests: info@bookmydestination.com
Phone: +91-9650179451
1. Scope of this Policy
This Policy applies to BookMyDestination.com and to personal data processed through our website, booking systems, enquiry services, customer-support channels, advertising, analytics, product catalogues, travel-distribution services and approved AI integrations.
BookMyDestination currently offers or may offer travel services including holiday packages, tours and activities, hotels and other accommodation, and may introduce additional travel services such as visas, travel insurance, cruises, airport transfers, cabs, transport, flights, rail services, eSIMs, rentals and other related travel services.
The inclusion of a service category in this Privacy Policy does not necessarily mean that every service is currently available in every location, through every BookMyDestination channel, or through the BookMyDestination ChatGPT/OpenAI integration.
Third-party travel suppliers and technology platforms may also process information under their own privacy policies and terms.
This Policy is intended to follow applicable data-protection requirements and platform rules, including the principles of transparency, purpose limitation, data minimisation, security, retention limitation and user control. Where a platform-specific rule is stricter for information processed through that platform, we apply the stricter requirement to that integration.
2. Personal Data We May Collect
2.1 Information you provide directly
- Identity and contact information: name, email address, telephone number, WhatsApp number, billing/contact address and account details.
- General travel information: destination, travel dates, number and type of travellers, travel preferences, package selections, accommodation requirements, departure information, pickup information and special requests.
- Tour and activity information: selected tour or activity, preferred date/time, participant count, adult/child categories, participant ages where relevant, pickup point, meeting point, language preferences and other information required by the activity operator.
- Hotel and accommodation information: destination, selected property, check-in and check-out dates, number of rooms, number of adults and children, children’s ages where required for pricing, room configuration, meal plan, guest names, nationality where required, accommodation preferences and special requests.
- Traveller information required to fulfil a booked service: age or date of birth, gender where required by the supplier, nationality and, where strictly required for airline, cruise, visa, insurance, hotel, border-control or other regulated travel fulfilment, passport or other government-document information.
- Visa-related information: where BookMyDestination provides or facilitates visa services, this may include nationality, passport information, photographs, travel itinerary, accommodation details, employment or financial supporting documents, application forms and other documents specifically required by the relevant government, embassy, consulate, visa-processing provider or authorised service provider.
- Travel-insurance information: selected insurance product, destination, travel dates, traveller ages, nationality, trip value and other information required to obtain a quotation or policy. Where an insurance product, underwriting process or claim specifically requires health or medical information, such information will be processed only where necessary and under an appropriate legal basis, consent or insurer workflow.
- Cruise information: cruise selection, sailing date, embarkation/disembarkation port, cabin preference, passenger names, ages/date of birth, nationality and passport information where required by the cruise line or immigration authorities.
- Cab, transfer and transport information: pickup and drop-off locations, pickup date/time, passenger count, contact number, flight/train details where relevant, luggage requirements and other information necessary to arrange transportation.
- eSIM information: destination, selected plan, email/contact information, device type or compatibility information and activation or fulfilment information required by the eSIM provider. We do not require access to unrelated content stored on your device.
- Transaction information: order number, booking number, amount, currency, payment status, refund status and payment-provider reference. Full payment-card details are handled by the applicable authorised payment processor and are not intended to be stored on BookMyDestination servers.
- Communications: enquiries, booking requests, support requests, feedback, reviews and correspondence by email, telephone, WhatsApp, forms or other support channels.
- Marketing preferences: subscription status, consent choices, campaign preferences and opt-out requests.
2.2 Information collected automatically
- Device and network information: IP address, browser type, device type, operating system, language, approximate region and security-related request information.
- Website activity: pages viewed, searches, clicks, referral source, campaign parameters, cart/checkout activity and interaction with website features.
- Cookies and similar technologies: identifiers used for essential site operation, preferences, analytics, measurement, fraud prevention and, where permitted, advertising.
- Advertising and attribution data: campaign source, medium, campaign identifiers, ad/click identifiers, conversion events and related measurement information.
2.3 Information received from travel suppliers and service providers
Where necessary to operate or fulfil a travel service, we may receive information from hotels, tour/activity operators, transport providers, cruise companies, visa providers, insurers, eSIM providers, payment processors, travel inventory providers and other authorised partners.
This may include booking confirmation numbers, availability information, room confirmation, vouchers, cancellation status, refund information, service changes, supplier messages, visa-processing status, insurance-policy references, transfer allocation, eSIM activation status and other information necessary to provide or support the service requested by you.
3. How We Use Personal Data
We process personal data only for defined purposes, including:
- providing travel search, availability, quotation, booking, enquiry and customer-support services;
- searching and booking holiday packages, tours, activities, hotels and other accommodation;
- providing or facilitating visas, insurance, cruises, transfers, cabs, eSIMs and other travel services where available;
- creating and managing accounts, carts, bookings, reservations, orders, vouchers, invoices, cancellations and refunds;
- communicating confirmations, service information, reminders, itinerary changes and other information relating to a requested travel service;
- sharing the minimum necessary information with authorised suppliers and travel partners so they can fulfil the requested service;
- operating, securing, debugging, maintaining and improving our website and integrations;
- measuring website, catalogue, booking and advertising performance;
- sending marketing communications where you have consented or where otherwise permitted by applicable law, with an opt-out available;
- creating or using matched/custom audiences only where permitted by applicable law and applicable platform rules;
- preventing fraud, abuse, unauthorised access, chargebacks and security incidents;
- meeting accounting, tax, legal, regulatory and dispute-resolution obligations.
4. Service-Specific Data Processing
4.1 Tours, holiday packages and activities
When you search for or book a holiday package, sightseeing tour, excursion, attraction, guided experience or other activity, we may process destination, travel date, participant count, adult/child classification, ages where relevant, selected option, meeting/pickup information, traveller/contact details and other information required by the applicable operator.
Information necessary to fulfil the service may be shared with the relevant tour operator, activity provider, destination-management company, guide, transport provider or other supplier involved in the booking.
4.2 Hotels and accommodation
When you search for or book hotels or other accommodation through BookMyDestination.com, we may process your destination, selected property, check-in and check-out dates, number of rooms, number of adults and children, children’s ages, room and meal preferences, guest names, contact information, nationality where required, special requests, booking references, payment status, cancellations and refund information.
We use this information to search accommodation inventory and rates, display room options, create and manage reservations, provide confirmations, service booking modifications, communicate with the property, process applicable payments or deposits, provide customer support and process eligible cancellations or refunds.
Information necessary to fulfil a hotel reservation may be shared with the selected hotel or accommodation provider, hotel inventory or connectivity providers, booking technology providers, payment processors and other service providers involved in completing or servicing the reservation.
Passport information, payment-card credentials and other sensitive booking information are not used for advertising audience creation.
4.3 Visa services
Where BookMyDestination offers visa assistance or processing, we may collect information specifically required for the relevant visa application, such as passport details, photographs, nationality, date of birth, itinerary, accommodation information and supporting documentation.
Visa information is used only for processing, supporting or administering the requested visa service, communicating with the traveller and complying with applicable legal requirements.
Visa documentation may be shared with authorised visa-processing providers, embassies, consulates, government authorities or service partners only where necessary for the requested service.
Passport information and visa documents are not used for advertising, custom audiences or behavioural profiling.
4.4 Travel insurance
Where travel insurance is offered, we may process information needed to obtain quotations, issue policies or facilitate service, including traveller age, destination, travel period, nationality and trip value.
If an insurer or regulated process requires additional sensitive information, including limited health or medical declarations, such information will be requested only where necessary and processed under an appropriate legal basis, consent or insurer-controlled workflow.
Health information and insurance claim information are not used for advertising audiences or behavioural advertising.
4.5 Cruises
Where cruise booking is available, we may process cruise itinerary, sailing dates, selected cabin, embarkation/disembarkation points, passenger information, nationality, date of birth and passport details where required by the cruise operator or border authorities.
Necessary information may be shared with the cruise operator and authorised booking or fulfilment partners.
4.6 Cabs, airport transfers and ground transportation
Where cab or transfer services are available, we may process pickup and drop-off locations, travel date/time, passenger count, mobile/contact information, flight or train number where relevant, luggage information and special assistance requirements.
We may share the minimum required booking information with the relevant cab operator, driver, transfer company or transport provider.
BookMyDestination does not continuously track a user’s precise device location unless a specific service requires location functionality, that functionality is clearly disclosed, and the user has enabled or authorised it.
4.7 eSIM services
Where BookMyDestination offers eSIM services, we may process destination, selected plan, email/contact information, order information, device compatibility information and activation/fulfilment identifiers required by the selected provider.
This information is used to deliver, activate, support or troubleshoot the purchased eSIM service.
We do not use eSIM activation identifiers or device-specific fulfilment information for advertising audience creation.
4.8 Future travel services
BookMyDestination may introduce additional travel-related services in the future. We will apply the same principles of purpose limitation, data minimisation, security, appropriate sharing, retention limitation and user control.
If a new service materially changes the types of personal data we collect or how personal data is used, this Privacy Policy will be updated before or when the new processing begins.
5. BookMyDestination.com ChatGPT / OpenAI Plugin and MCP Connector
BookMyDestination.com provides an approved MCP-backed integration for ChatGPT/OpenAI.
The capabilities available through the integration depend on the tools currently enabled. The availability of a travel service on BookMyDestination.com does not automatically mean that the same service, booking functionality or customer data is accessible through ChatGPT/OpenAI.
The current V1 integration is read-only and information-only. It searches and returns supported published BookMyDestination.com travel catalogue information. It does not create a booking, reserve inventory, take payment, create an enquiry, modify a customer account or access private customer order records.
5.1 Data the current V1 tools may receive
- Search: a task-specific search keyword, destination, optional minimum/maximum price, sort order and pagination values.
- Travel product details: a BookMyDestination catalogue product/package identifier.
- Itinerary: a BookMyDestination catalogue product/package identifier.
- Departures/date check: a BookMyDestination catalogue product/package identifier and, if requested by the user, a travel date in YYYY-MM-DD format.
The current V1 tool schema does not request a user’s name, email address, telephone number, postal address, payment-card data, password, API key, passport/government identifier, visa documents, insurance or health information, hotel guest identity, OpenAI account identifier, precise GPS location, eSIM activation information or full ChatGPT conversation history.
5.2 Data the current V1 tools may return
Tool responses contain first-party BookMyDestination catalogue information relevant to the user’s request, such as product identifiers, title, summary or description, destination/category, duration, departure city, price/currency, configured or selectable travel dates, itinerary/day details, overnight stays, meals, inclusions, exclusions, tags, image/link information, listing status and BookMyDestination booking-rule or internal-capacity fields.
Supplier-confirmed external inventory is not represented as guaranteed live availability unless it has been specifically verified through a supported live inventory or booking service.
5.3 Future AI booking capabilities
If BookMyDestination introduces additional OpenAI/ChatGPT tools in the future for live hotel booking, activities, visa services, insurance, cruises, cabs, eSIMs or other transactions, we will limit each tool to the minimum information necessary for its stated purpose.
Where a future AI-enabled service requires personal information, its tool description, schema, user experience and this Privacy Policy will be updated as required before or when that processing becomes available.
Sensitive information such as passport data, health information or payment credentials will not be collected through a general search tool and will only be processed through an appropriate secure transactional workflow where specifically necessary.
5.4 Chat content and data boundaries
Our current MCP server operates only on the specific tool arguments that ChatGPT chooses to send for the requested task. It does not request or reconstruct the user’s full chat history.
We do not place raw ChatGPT conversation text into package URLs, booking links or UTM campaign parameters.
5.5 Attribution when a user opens a BookMyDestination link
Links returned through the integration may contain limited UTM source, medium or campaign parameters, for example to identify that a visit originated from ChatGPT.
If a user chooses to open the link, BookMyDestination may use those parameters together with the user’s website cookie/consent choices for attribution, analytics and conversion measurement.
The UTM parameters do not contain the user’s raw ChatGPT conversation.
5.6 Security and short-lived rate limiting
The connector uses server-to-server authentication.
The BookMyDestination WordPress connector may process the source network IP address for abuse prevention and rate limiting by hashing it with a short-lived time bucket. That rate-limit record expires after approximately 90 seconds.
We do not use this rate-limit mechanism for behavioural advertising or user profiling.
5.7 OpenAI as a separate platform
OpenAI separately controls how ChatGPT conversations, accounts and platform-level information are processed under OpenAI’s own terms, privacy policy and user settings.
Disconnecting or disabling the BookMyDestination integration in ChatGPT stops future tool calls from that connection.
Deleting a ChatGPT conversation does not automatically delete a separate BookMyDestination website account, booking or order record, and deleting a BookMyDestination website account does not automatically delete data independently held by OpenAI.
6. OpenAI Advertising, Product Feeds and Measurement
Where BookMyDestination uses OpenAI advertising, product feeds, measurement tools, conversion APIs or audience features, we may provide catalogue data, campaign identifiers, landing-page parameters and conversion information such as an order-created event, order value/currency and product/order reference needed for measurement.
Where a matched/custom audience feature is used, first-party contact identifiers may be uploaded in the format required by the platform only where we have an appropriate legal basis and required notice or consent.
We do not use the BookMyDestination ChatGPT search tools to collect payment-card information, passwords, passport numbers, visa documents, health information or other restricted credentials for advertising or audience creation.
7. Google Services
BookMyDestination may use Google services including Google Analytics, Google Ads, conversion measurement, product/travel feeds and other approved Google travel-distribution services.
Depending on your consent and configuration, Google may receive browser/device identifiers, cookie information, IP-derived location information, page and event data, campaign/click identifiers and conversion information.
If we use Google Customer Match or another first-party audience feature, we use only eligible first-party customer information collected through our own relationship with the customer and disclose that such data may be shared with service providers such as Google for advertising or measurement.
We obtain consent where required and apply applicable Google user-consent and personalised-advertising rules.
If BookMyDestination introduces a Google OAuth integration that accesses Google user data, we will request only the minimum scopes necessary, disclose the specific access, use, storage and sharing in this Policy and in the applicable Google consent flow, and follow applicable Google API Services User Data Policy and Limited Use requirements before making that integration public.
Google Things to do and Actions Center
BookMyDestination may participate in Google Things to do, Google Actions Center, Google Travel and related Google travel-distribution programs to make eligible tours, activities, attractions and other travel experiences discoverable on Google-owned surfaces.
For these integrations, BookMyDestination may provide Google with travel-product and business information necessary to display and match our inventory. Depending on the applicable Google program and feed specification, this information may include:
- BookMyDestination product and option identifiers;
- tour, activity or attraction titles and descriptions;
- product categories, highlights, inclusions, exclusions and other product features;
- destination, meeting-point and related-location information;
- operator or business name and other business-identification information where required for matching;
- images and other permitted product media;
- duration and language information;
- prices, currencies, applicable fees and taxes;
- availability or selectable travel information where supported;
- cancellation-policy information;
- BookMyDestination landing-page or booking-page URLs; and
- other inventory information required by the applicable Google Things to do specification.
This product-feed information is used so that Google can process, match, display, rank, advertise or otherwise surface eligible BookMyDestination travel products through Google Search, Google Travel, Google Things to do, Google Ads or other supported Google surfaces.
The standard BookMyDestination Google Things to do product feed is not intended to contain customer names, personal email addresses, personal telephone numbers, passport information, payment-card credentials, visa documents, health information or private BookMyDestination booking records.
Bookings originating from Google Things to do
Where Google Things to do operates as a referral or redirect service, a traveller who selects a BookMyDestination listing on Google is directed to the relevant BookMyDestination landing page or booking journey.
The traveller then provides any information required to search, enquire about, reserve or purchase the selected service through BookMyDestination or the applicable authorised booking provider. Personal information collected after the traveller reaches BookMyDestination is processed in accordance with this Privacy Policy and the applicable booking terms.
A Google Things to do listing or referral does not by itself give Google access to a traveller’s complete BookMyDestination customer account, private order history, passport information or payment-card credentials.
Referral, attribution and conversion measurement
When a traveller reaches BookMyDestination from Google, the referral URL or browser interaction may include Google or BookMyDestination campaign, click, attribution or referral identifiers. Subject to applicable consent requirements, these identifiers may be used together with website analytics and booking events to:
- identify that a visit originated from Google;
- measure listing, advertising and booking performance;
- attribute enquiries, bookings or purchases to the appropriate campaign or Google travel surface;
- diagnose feed, landing-page or conversion issues; and
- improve our travel products, advertising and customer experience.
Where conversion measurement is enabled, BookMyDestination may provide Google with permitted conversion information such as the occurrence of a booking or purchase event, transaction or product reference, value, currency and related campaign information, subject to applicable law, consent requirements and Google policies.
Price and product information
BookMyDestination seeks to ensure that information submitted to Google Things to do accurately corresponds to the applicable BookMyDestination landing page, including product identity and applicable price information.
Prices, availability and cancellation conditions may change because of travel dates, traveller configuration, supplier availability or other booking factors. The final applicable price, availability and booking conditions are those presented and confirmed through the applicable BookMyDestination or authorised supplier booking process.
Google as an independent platform
Google independently determines how information is processed on Google-owned services under Google’s own privacy policies, terms and user controls.
BookMyDestination does not control Google’s independent processing of a user’s Google Account, Google Search activity, advertising profile or other information maintained by Google.
Future Google transactional integrations
If BookMyDestination later introduces a Google integration in which personal traveller information is transmitted directly between Google and BookMyDestination for an in-Google reservation, checkout, account-linked service or other transactional functionality, we will update this Privacy Policy as necessary before or when that processing is introduced.
Any such integration will be designed to collect and use only information reasonably necessary for the applicable travel transaction and will be subject to the relevant Google program requirements and applicable data-protection law.
8. Meta, Facebook, Instagram and WhatsApp
BookMyDestination may use Meta technologies and services including Meta Pixel, Conversions API, Facebook and Instagram advertising, product catalogues, custom/matched audiences and WhatsApp Business communication.
Depending on the feature and your choices, Meta may receive browser/device identifiers, cookie information, IP/network information, page/event data, campaign information and conversion data.
Where we use a Meta custom/matched audience, eligible first-party contact identifiers such as email address or telephone number may be shared in hashed or another platform-required form only where permitted and where required notice or consent has been obtained.
We do not knowingly use passport data, visa documents, payment-card credentials, health data, insurance information, eSIM activation identifiers or other highly sensitive travel records for advertising-audience creation.
If you contact us through WhatsApp or another Meta service, Meta also processes the communication and related account/device data under its own policies.
You may stop eligible marketing messages by using the unsubscribe or stop method provided in the message or by contacting us.
9. Cookies, Analytics and Advertising Choices
We use essential cookies where needed to operate the website, cart, checkout, login, security, booking functions and preferences.
Analytics and advertising cookies or similar identifiers are used according to the consent choices required for the user’s location.
Where applicable, our consent-management setup communicates consent signals to supported platforms such as Google and Meta.
You can change browser cookie settings and, where available on our site, use our cookie/consent controls. Blocking essential cookies may affect cart, login, booking or checkout functionality.
You can also manage advertising preferences directly through controls provided by Google, Meta, OpenAI and other applicable platforms.
10. When We Share Data
We do not sell personal data for money.
We may share the minimum necessary data with the following categories of recipients:
- Travel suppliers and fulfilment partners: hotels, accommodation providers, tour/activity operators, destination-management companies, airlines, cruise providers, transport providers, cab/transfer providers, visa providers, insurers, eSIM providers, rental providers and other suppliers necessary to fulfil a requested service.
- Travel inventory and technology providers: booking engines, hotel connectivity providers, global or regional inventory systems, reservation platforms and other travel-distribution technology used to search, price, book or service travel products.
- Payment providers: payment gateways, banks and fraud-prevention providers used to process a transaction.
- Technology and hosting providers: website hosting, cloud, security, email/SMS, customer support, database, backup and infrastructure providers.
- Analytics, advertising and distribution platforms: including Google, Meta and OpenAI, as described above and subject to your consent or choices where required.
- Professional and legal recipients: auditors, accountants, legal advisers, regulators, law-enforcement authorities or courts where required by law or necessary to establish, exercise or defend legal rights.
- Corporate transaction recipients: where necessary in connection with a merger, financing, reorganisation or sale of all or part of the business, subject to appropriate confidentiality and legal safeguards.
In some jurisdictions, sharing identifiers with advertising platforms for cross-context behavioural advertising may legally be defined as a “sale” or “sharing” even where no money is paid for the data. Where such laws apply, we provide the required choice or opt-out mechanism.
11. Sensitive Travel Information
Some travel services may require sensitive information, such as passport information, government-issued identification, visa supporting documents or limited health information required by an insurer.
We apply additional restrictions to this information:
- it is requested only where necessary for the specific service;
- access is limited to authorised personnel and authorised fulfilment providers;
- it is not used to create advertising or matched/custom audiences;
- it is not collected through a general-purpose BookMyDestination AI search tool;
- it is retained only for as long as needed for fulfilment or applicable legal obligations;
- where feasible, sensitive documents are deleted, securely restricted or de-identified after the relevant purpose and mandatory retention period end.
12. Data Retention
We keep personal data only for as long as reasonably necessary for the stated purpose, legal obligations, fraud/security protection and dispute resolution.
Our standard retention approach is:
- ChatGPT/OpenAI V1 tool arguments: not intentionally stored in a BookMyDestination application database as a user profile. Short-lived rate-limit hashes expire after approximately 90 seconds. Security/error logs, where created, are retained for up to 30 days unless needed to investigate an incident.
- Website security/access logs: up to 30 days in ordinary operation, unless a longer period is required to investigate abuse, fraud or a security incident.
- Enquiries and support correspondence: up to 3 years after the last substantive interaction, unless linked to an active booking, claim or legal obligation.
- Customer accounts: while the account is active and generally up to 3 years after the last interaction, unless the user requests earlier deletion and no legal retention obligation applies.
- Bookings, hotel reservations, activity bookings, orders, invoices, payment/refund records and accounting evidence: generally up to 8 years from the relevant financial/accounting period, or longer where applicable law, tax rules, legal claims or regulatory requirements require it.
- Visa and passport documentation: retained only for the period reasonably required to process or support the requested service and any applicable legal or dispute-resolution requirement, after which eligible copies are deleted, securely restricted or de-identified where feasible.
- Insurance information: retained only as needed for quotation, policy servicing, applicable legal requirements or dispute resolution. Insurance providers may maintain independent retention obligations under their own policies and applicable law.
- Cab/transfer booking information: retained as part of the applicable booking/order record. Precise-location information, where specifically processed, is not retained longer than reasonably necessary for service delivery, security or legal requirements.
- eSIM fulfilment information: retained as necessary to deliver and support the order and comply with applicable accounting, fraud-prevention or legal requirements. eSIM providers may maintain independent retention schedules.
- Marketing records: until consent is withdrawn or the user opts out. We may retain a minimal suppression record for as long as reasonably necessary to ensure that an opt-out continues to be honoured.
- Consent/cookie records: generally up to 24 months, unless renewed earlier or a longer period is needed to demonstrate compliance.
- BookMyDestination-controlled analytics/advertising event data: generally up to 14 months for identifiable or pseudonymous event-level analytics unless a shorter period is configured or a longer period is required for fraud, accounting or legal purposes. Aggregated or de-identified reporting may be retained longer.
Third-party platforms and suppliers such as Google, Meta, OpenAI, hotels, tour operators, insurers, visa providers, payment providers and other travel suppliers maintain their own retention schedules for information they independently control.
13. International Data Transfers
Travel is international by nature, and some suppliers or technology providers may process personal data outside India or outside your country of residence.
For example, information may need to be transmitted to an overseas hotel, activity provider, cruise operator, insurer, visa processor, transport provider or other supplier in order to fulfil your requested service.
Where required, we use contractual, technical or organisational safeguards and limit transferred data to what is reasonably necessary for the relevant purpose.
14. Security
We use reasonable technical and organisational measures designed to protect personal data, including HTTPS/TLS, access controls, server-side secret handling, authentication for private APIs, rate limiting, restricted administrative access, software/security updates and minimisation of data returned by integrations.
Sensitive documents are accessible only where required for the relevant service and should not be submitted through channels that do not specifically request them.
API keys, passwords, payment-card details and other authentication secrets must not be entered into the BookMyDestination ChatGPT/OpenAI search tools. Our current connector is designed not to request them.
No internet service can guarantee absolute security.
15. Your Rights and Controls
Depending on applicable law, you may have rights to request access to personal data, correction, completion, deletion or erasure, withdrawal of consent, restriction or objection to certain processing, portability where applicable, grievance handling and nomination or other rights provided by law.
You may also:
- unsubscribe from marketing emails using the link in the message;
- ask us to stop eligible WhatsApp or SMS marketing;
- change cookie and advertising choices through available consent controls;
- disconnect the BookMyDestination integration from ChatGPT/OpenAI through controls provided by that platform;
- request correction of eligible traveller or account information;
- request deletion of eligible BookMyDestination data using the process below.
16. Data Deletion Requests
To request deletion of eligible BookMyDestination personal data, email info@bookmydestination.com with the subject “Data Deletion Request”.
Please identify the email address or telephone number associated with the BookMyDestination account or booking and describe the data you want deleted. We may need to verify your identity before acting on the request.
Data-deletion instructions may also be made available through the BookMyDestination.com data-deletion page.
We will delete or de-identify eligible data unless we must retain it for:
- a booking or travel service still being performed;
- fraud or security prevention;
- tax, accounting or financial-record requirements;
- visa, immigration, insurance or regulatory requirements;
- legal claims or dispute resolution;
- another lawful purpose that requires continued retention.
If only part of the information must be retained, we will restrict it to the applicable purpose where reasonably possible.
For data held independently by Google, Meta, OpenAI, hotels, insurers, visa providers, payment providers or another independent platform or supplier, you may also need to use that organisation’s own account, privacy or deletion controls.
Disconnecting an integration prevents future access through that integration but does not automatically erase information that BookMyDestination or an independent supplier must retain for a separate lawful purpose.
17. Children and Minor Travellers
BookMyDestination travel services are intended to be purchased or managed by adults who are legally able to enter into the applicable transaction.
A parent, guardian or responsible adult may provide limited personal information about a child or minor traveller where necessary to arrange accommodation, tours, transport, visas, insurance, cruises or another travel service.
We collect only the information reasonably required for the minor’s travel service and do not knowingly use a child’s passport information, health information or other sensitive travel data for advertising or matched-audience creation.
The current BookMyDestination ChatGPT/OpenAI V1 connector does not request children’s identity or contact information.
18. Third-Party Websites and Services
BookMyDestination may link to or interact with third-party websites, hotels, airlines, activity operators, payment providers, insurers, visa processors, cruise companies, transport providers, eSIM providers, Google, Meta, OpenAI and other platforms.
When you leave BookMyDestination.com or use a third-party service, that organisation may independently process personal information under its own privacy policy and terms.
We encourage users to review the privacy terms of relevant third parties when providing personal information directly to them.
19. Changes to this Policy
We may update this Policy when our services, booking capabilities, tools, suppliers, legal requirements or platform integrations change.
The “Last updated” date will be revised when material changes are published.
If a new integration or travel service materially changes what personal data is collected or how it is used, we will update the Policy before or at the time the new processing begins.
20. Contact and Grievance Requests
For privacy questions, access, correction or deletion requests, consent withdrawal or grievances, contact:
Ambraoleia Hospitality Private Limited / BookMyDestination.com
FF 32, Wave Silver Corporate Tower, Sector 18, Noida, Uttar Pradesh 201301, India
Email: info@bookmydestination.com
Phone: +91-9650179451
