This Privacy Policy explains how Nomichi Explorers Private Limited(“Nomichi”, “we”, “us”, or “our”) collects, uses, shares, stores, and protects your personal data when you interact with our website (www.thenomichi.com), our mobile application, our social media pages, our WhatsApp Business account, our forms, and any trip you book with us.
We comply with the Digital Personal Data Protection Act, 2023 (DPDP Act) and the Information Technology Act, 2000 and the rules made thereunder, including the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011. By using our services or sharing your information with us, you consent to the practices described in this Policy.
1. Who We Are
Nomichi curates and operates community group trips and private custom journeys for travellers across India and select international destinations. For the purposes of this Policy, Nomichi is the Data Fiduciary in respect of personal data that we collect and process.
Nomichi Explorers Private Limited
Registered Office: Jabalpur, Madhya Pradesh, India
Email: hello@thenomichi.com
Phone: +91 70009 62406
Website: www.thenomichi.com2. Information We Collect
2.1 Information you provide to us
- Full name, age, gender, and date of birth (when required for bookings, permits, or insurance)
- Contact details: phone number (including WhatsApp), email address, and postal address
- Government-issued identification details (Aadhaar number, PAN, passport number, visa details, driving licence) where required for booking confirmation, permits, hotel check-in, ticketing, or regulatory compliance
- Emergency contact details
- Travel preferences, dietary restrictions, allergies, accessibility needs, and medical or fitness disclosures relevant to the trip
- Photographs, videos, and content you upload or share with us
- Reviews, feedback, survey responses, and communications you send to us
2.2 Information collected automatically
- Device and technical information: IP address, device type, operating system, browser type, language settings, and approximate location derived from IP
- Usage information: pages visited, time spent, links clicked, referring URLs, and similar analytics data
- Cookies and similar technologies (see Section 9)
2.3 Information from third parties
- Payment status and limited transaction details from our payment gateway partner (we do not store full card or bank credentials on our servers)
- Information from social media platforms (Meta, Instagram, Google) when you interact with our ads or pages
- Information from referrers, travel partners, or co-travellers (for example, when someone books you as part of a group)
3. How We Use Your Information
- To process bookings, issue confirmations, arrange travel documents, and operate trips
- To communicate with you before, during, and after your trip (including via WhatsApp, email, SMS, and calls)
- To process payments, refunds, and credit notes, and to maintain transaction records
- To comply with statutory obligations, including taxation (GST, TCS), record-keeping, and law enforcement requests
- To verify identity for hotel check-ins, permits, transport, and visa or immigration purposes
- To send service updates, trip information, and important notices
- To send marketing communications about new trips, offers, and Nomichi updates, where you have opted in
- To personalise content, recommend trips, and improve our website and services
- To respond to your queries, complaints, and grievance requests
- To prevent fraud, enforce our Terms and Conditions, and protect our legal rights
- To conduct internal analytics, research, and quality monitoring
4. Lawful Basis for Processing
Under the DPDP Act, we process your personal data on the basis of:
- Your consent, which you provide when you submit a form, book a trip, or otherwise share your data with us
- Performance of our contract with you (for example, to deliver the trip you have booked)
- Compliance with applicable law (for example, GST and TCS filings, identity verification, and law enforcement requests)
- Our legitimate interests, such as preventing fraud, improving our services, and securing our systems, where these are not overridden by your rights
You may withdraw your consent at any time by writing to us at hello@thenomichi.com. Withdrawal of consent will not affect processing carried out before withdrawal and may limit our ability to provide certain services to you.
5. Sharing Your Information
We do not sell or rent your personal data. We share your data only with:
- Trip service providers such as hotels, homestays, transport operators, ferry and bus operators, trek leaders, guides, restaurants, and activity vendors, strictly for the purpose of operating your trip
- Airlines, train booking platforms, visa support agencies, and insurance partners, where the trip requires it
- Payment gateways and banking partners for processing payments and refunds
- Cloud hosting, customer relationship management, email marketing, analytics, and communication tools that act as our Data Processors
- Professional advisors such as auditors, lawyers, and consultants under appropriate confidentiality obligations
- Government authorities, regulators, courts, or law enforcement agencies, where required by law or to protect our legal rights
- Successors-in-interest in the event of a merger, acquisition, restructuring, or sale of business assets
Where we share personal data with third parties, we require them to implement reasonable security practices and to use the data only for the purposes for which it was shared.
6. WhatsApp & Meta Platform Communications
We use the WhatsApp Business Platform (operated by Meta Platforms, Inc.) to send transactional messages such as booking confirmations, payment receipts, and trip reminders. By providing your phone number and engaging with our services, you consent to receiving these communications via WhatsApp.
Message content sent via WhatsApp is subject to WhatsApp's Privacy Policy and Meta's Privacy Policy. We do not share your personal data with Meta beyond what is necessary to deliver these messages. You may opt out at any time by replying “STOP” or emailing hello@thenomichi.com.
7. International Transfers
Some of our service providers (for example, cloud hosting, analytics, and email tools) may be located outside India. Where personal data is transferred outside India, we transfer it only to countries that are not restricted by the Central Government under the DPDP Act and ensure that appropriate safeguards are in place.
8. Data Retention
We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected, including legal, accounting, tax, and reporting obligations. Typical retention periods are as follows:
- Booking, payment, and tax records: 8 years from the end of the relevant financial year, as required under Indian tax laws
- Trip operations data (itineraries, vendor confirmations, communications): 3 years from trip completion
- Marketing contact data: until you withdraw consent or unsubscribe
- Website analytics: up to 26 months in anonymised or aggregated form
After the applicable retention period, we will delete, anonymise, or securely archive your personal data in accordance with the DPDP Act.
9. Data Security
We implement reasonable security practices and procedures consistent with the IT Rules, 2011 and the DPDP Act, including:
- Access controls, role-based permissions, and authentication for staff accessing personal data
- Encryption of data in transit using industry-standard protocols (HTTPS / TLS)
- Secure storage on reputed cloud platforms with appropriate certifications
- Regular review of vendors, processors, and access logs
- Confidentiality obligations on employees, contractors, and partners
No method of transmission or storage is fully secure. While we take reasonable steps to protect your data, we cannot guarantee absolute security. In the event of a personal data breach, we will notify the Data Protection Board of India and affected users as required under the DPDP Act.
10. Cookies and Tracking Technologies
We and our service providers use cookies, pixels, and similar technologies on our website and app to:
- Keep you signed in and remember your preferences
- Measure how visitors use our site and improve performance
- Show you relevant content and trip recommendations
- Measure the effectiveness of our marketing campaigns
You can manage cookies through your browser settings. Disabling cookies may affect the functionality of our website.
11. Children
Our services are not directed to children under the age of 18 except where they are accompanied by a parent or legal guardian on a trip. We do not knowingly collect personal data from children for marketing or account creation purposes. If a parent or legal guardian becomes aware that their child has provided us with personal data without consent, please contact us and we will take steps to delete that data. For trip participation involving a minor, the consent of the parent or legal guardian is required.
12. Your Rights
Subject to applicable law, you have the right to:
- Access the personal data we hold about you and request a summary of how it is processed
- Correct, complete, or update inaccurate or outdated data
- Erase your personal data, subject to our legal and contractual record-keeping obligations
- Withdraw consent at any time, where processing is based on consent
- Nominate a person to exercise your rights in the event of death or incapacity
- Lodge a grievance with our Grievance Officer (see Section 15) and, if not satisfied, with the Data Protection Board of India
To exercise any of these rights, please visit our Data Deletion page or write to us at hello@thenomichi.comwith the subject line “Data Request”. We may need to verify your identity before processing your request.
13. Marketing Communications
We may send you trip updates, offers, and Nomichi news via email, SMS, WhatsApp, or push notifications. You can opt out at any time by:
- Clicking the unsubscribe link in our emails
- Replying “STOP” to our WhatsApp or SMS messages
- Writing to us at hello@thenomichi.com
Even if you opt out of marketing communications, we will continue to send you transactional and service messages relating to your bookings.
14. Third-Party Services and Links
Our website, app, and communications may include links to third-party websites, social media pages, or services (such as Meta, Instagram, Google, payment gateways, and travel partners). We are not responsible for the privacy practices or content of those third parties. Please review their privacy policies before sharing your data with them.
15. Grievance Officer and Contact
If you have any questions, concerns, or grievances regarding this Policy or the processing of your personal data, you may contact our Grievance Officer:
Grievance Officer: Deepesh, Founder
Nomichi Explorers Private Limited
Address: Jabalpur, Madhya Pradesh, India
Email: hello@thenomichi.comWe will acknowledge your grievance within 48 hours and resolve it within the timelines prescribed under applicable law.
16. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in law, our services, or our practices. The latest version will always be available on our website with a revised Effective Date. Material changes will be communicated to you through email, WhatsApp, or a prominent notice on our website.
17. Governing Law and Jurisdiction
This Privacy Policy is governed by the laws of India. Any disputes arising out of or in connection with this Policy shall be subject to the exclusive jurisdiction of the courts at Jabalpur, Madhya Pradesh.