Privacy
Privacy notice
Written to be read rather than survived. If anything here is unclear, ask and we will answer in plain words.
Last updated July 2026
1. Who is responsible
Shunyaway Experiences Pvt. Ltd. (“Shunyaway”, “we”) is the data controller for the personal data described here. We are a company registered in India, at Rajpur Road, Dehradun 248001, Uttarakhand, India. Our registration numbers appear in the footer of every page on shunyaway.com.
For anything to do with your data — a copy of it, a correction, or its deletion — write to concierge@shunyaway.com. A person reads it.
2. What we collect, and why
Only what an enquiry actually needs. We do not buy personal data, we do not enrich it against third-party databases, and there are no advertising trackers on this site.
| What | Why | Lawful basis |
|---|---|---|
| Name, email, telephone, the city you write from | To answer you, and to design a journey that starts at your door | Steps taken at your request before a contract — GDPR Art. 6(1)(b) |
| What you write in your message, including a journey you shaped on this site | To reply usefully rather than generically | Art. 6(1)(b) |
| That you consented, and when | So we can show you agreed | Legal obligation — Art. 6(1)(c) |
| Postal address, and travellers’ passport details | Only once a journey is booked — to post your confirmation card, and to make bookings and mountain permits in the correct names | Performance of the contract — Art. 6(1)(b) |
| Aggregate page statistics | To know which pages are actually read | Legitimate interests — Art. 6(1)(f). No cookie, no identifier |
Health and dietary information is special-category data under Article 9. We hold it only when you volunteer it because it affects a journey — altitude, mobility, an allergy — and only for that journey.
3. What the journey designer does not do
Design your journey keeps every answer in the address of the page you are looking at. Nothing is sent to us, stored on a server, written to a cookie, or kept in your browser’s storage. Close the tab without sending and it is gone — which is exactly why the link is worth keeping if you intend to come back to it.
4. Cookies
This site sets no cookies and uses no tracking storage. Our analytics are cookieless: they count page views without identifying you or following you to any other site. That is also why you have not been asked to dismiss a consent banner.
5. Who else handles it
Each of these acts on our instructions, under a contract, and for nothing else:
- Cloudflare — hosting, security, and the cookieless analytics.
- Supabase — the enquiry database, hosted in the European Union (Frankfurt).
- Resend — sends our reply and our internal alert, from Ireland.
- Zoho Mail — our mailboxes, on Zoho’s Indian data centre.
- Cal.com and Google Calendar — only if you book a consultation.
We do not sell personal data, and we pass nothing to a hotel, guide or airline beyond what a booking you have asked for actually requires.
6. Where it goes
Enquiry records sit in the European Union by deliberate choice. Because we are an Indian company, we access that data from India in order to answer you — a transfer outside the EEA, made under the European Commission’s Standard Contractual Clauses alongside the measures in §9. If you would rather we held nothing and spoke to you by telephone instead, that is a reasonable request and we will honour it.
7. How long we keep it
- Enquiries that come to nothing — deleted after 24 months.
- Booked journeys — kept for 8 years after travel, because Indian tax law requires the underlying financial records to be retained that long.
- Consent records — kept as long as the data they relate to, and no longer.
8. Your rights
If you are in the European Union or the United Kingdom you have the right to see your data, to correct it, to have it erased, to restrict or object to what we do with it, and to receive it in a portable form. Where we rely on consent, you may withdraw it at any time.
Write to concierge@shunyaway.com. We answer within 30 days, usually much sooner, and never charge for it. If our answer does not satisfy you, you may complain to your national data-protection authority — in the United Kingdom, the Information Commissioner’s Office.
Residents of California and other US states with equivalent laws have comparable rights to know, delete and opt out of sale. We do not sell data, and the same address serves those requests.
9. Security
The site is served over HTTPS only, with HSTS. The enquiry database enforces row-level security, and every access key is an encrypted environment variable rather than a value in our source code. We are a small company and will not pretend to be a bank: our real protection is holding so little data that losing it could not do you much harm.
10. Children
This site is not intended for children and we do not knowingly collect their data. Children travelling with you are booked by the adult making the booking.
11. Changes
If this notice changes materially, the date at the top changes with it. Its history is kept in our source repository, so a change is auditable rather than silent.
Anything at all: concierge@shunyaway.com.