Policies
Privacy policy
What we collect, why, who else sees it and how long we keep it. This describes what the booking system actually stores, not what a template says it might.
Last updated 15 August 2026 · TechSlide IT Solutions Pvt Ltd · CIN U72900TN2022PTC151232
Who is responsible
TechSlide IT Solutions Pvt Ltd (CIN U72900TN2022PTC151232), trading as My Divine Tours, of 2 Indra Nagar, Medical College Road, Thanjavur 613007, Tamil Nadu, India, decides how and why your data is used. Questions and requests go to care@mydivinetours.com.
What we hold
| Account | Name, email address and telephone number. A password, stored only as a scrypt hash — it cannot be read back, by us or by anyone else. |
|---|---|
| Bookings | The tour booked, travel date, number of travellers, pickup point and any notes you add. |
| Travellers | The name of each traveller, and optionally age and telephone number, where a tour requires it. |
| Billing | A billing address, and a GSTIN and legal entity name where you ask for a GST invoice. |
| Payments | The amount, the status and the gateway's reference. Never card numbers, UPI IDs or bank details — those are handled entirely by the gateway. |
| Support | Tickets you raise and the replies to them. |
| Reviews | A rating and review text, where you choose to leave one after a completed trip. |
We do not hold your card number, your UPI ID or your bank details. Those are entered on the payment gateway’s own page and never pass through our servers — we receive only the amount, the status and the gateway’s reference.
Why we hold it
To take and fulfil your booking, to send you the voucher and invoice, to let you sign in and see your trips, to answer support requests, and to meet tax and accounting obligations under Indian law. We do not sell data and we do not share it for anyone else’s marketing.
Who else sees it
These are the only third parties that receive customer data, and what each receives:
Razorpay / Cashfree — Payment processing
Name, email address, telephone number and the amount payable. Card and UPI details are entered on the gateway's own page and never reach our servers.
Resend — Transactional email
Name and email address, and the contents of the message — booking vouchers, invoices, sign-in and password links.
Railway — Hosting and database
Everything stored by the site, held in a managed PostgreSQL database.
Anthropic — The assistant on this website
The question you type into the chat, together with extracts from our own published pages. Questions are not linked to your account, and the assistant has no access to bookings, payment records or personal data.
Drivers and guides assigned to your trip are given your name, telephone number and pickup point, because they cannot collect you without them.
Cookies
We set one cookie of our own: a session cookie, when you sign in, so that the site knows it is you. It is HTTP-only — scripts running in your browser cannot read it, so a cross-site-scripting flaw cannot steal your session. It expires after 30 days, and you can end it sooner by signing out. There is no advertising cookie and no cross-site tracker set by us.
Where the business has enabled Google Analytics, that service sets its own cookies to count visits. You can block them in your browser without affecting your ability to book.
How long we keep it
Booking and payment records are kept for eight years, which is the retention period Indian tax law expects for financial records. Support tickets are kept for three years. Sign-in sessions expire after 30 days; the emailed link that lets you set a password expires after fifteen minutes and works once.
If you close your account we remove your profile and contact details, but we must keep the financial record of bookings already paid for — we cannot delete an invoice we are required to hold.
Your rights
You can see what we hold about you, correct it, ask for a copy, or ask us to delete it, subject to the retention above. Most of it you can do yourself from your account, including signing out of every device at once. For anything else, write to care@mydivinetours.com and we will respond within 30 days.
Security
The site is served over HTTPS. Passwords are stored as scrypt hashes and cannot be read back by anyone, including us — which is why a forgotten password is reset rather than retrieved. Sessions are held server-side so that access can genuinely be revoked rather than merely expired.
No system is perfect. If you believe your account has been accessed by someone else, sign out of all devices from your account page and tell us immediately.
Children
This site is not intended for children, and we do not knowingly create accounts for anyone under 18. Children travelling on a tour are named as travellers on an adult’s booking, which is the only circumstance in which we hold a child’s name.
Questions about this policy
Write to care@mydivinetours.com or call +91 86376 78132.
TechSlide IT Solutions Pvt Ltd2 Indra Nagar, Medical College Road, Thanjavur 613007, Tamil Nadu, India
