Last updated 10 September 2026
Privacy
What Anvesa collects, why it uses it, who may receive it, and how to make a privacy request.
Who controls it
Anvesa is a sole proprietorship and the data fiduciary/controller for this service. Principal address: Opposite Rafting Center, Pirdi, Kullu, Himachal Pradesh. Customer care and privacy requests: +91 89882 18074 · adminfunctions@anvesa.in. Grievance officer: Uddhav Bhardwaj, Founder.
What we hold & why
Account & contact: phone, name, email if provided, verification records, and booking or ticket communications.
Booking & safety: participant names, ages, phone or emergency contact, weight, medical/safety notes, waiver acceptance/signatures, and incident details when needed. The booked operator or guide receives what is needed to deliver the activity and protect participants.
Payment: Razorpay processes payment. Anvesa stores booking and payment references, amounts, status, refunds, and settlement records; we do not store full card or UPI credentials.
Support & product: support requests or chats, messages, reviews, device and technical information, and fraud, security, and audit records.
Optional analytics: starts only after you accept it. We collect limited journey signals such as screens, listing or booking identifiers, counts, and performance; analytics does not receive contact fields, payment credentials, or message text.
Why & when we use it
To create and manage bookings, deliver tickets and alerts you request, support safety and incidents, process payments and refunds, prevent abuse, improve the product, meet tax, accounting, and legal duties, and establish or defend claims. Optional analytics uses consent; other uses rely on service necessity or legal obligations.
Who may receive it
The booked operator or guide, payment and hosting/communications providers, support and operations personnel, and authorities where required. Depending on provider setup, processing may involve systems outside India with contractual and technical safeguards.
Retention
We keep records only as long as needed for the purposes above, including booking, payment, tax, safety, dispute, security, and legal records. Account deletion redacts direct contact data after the deletion workflow; related booking, waiver, payment, support, security, and audit records may remain where necessary. We do not promise a fixed 30-day deletion of medical or manifest data.
Your choices and rights
You may request access, correction, erasure, grievance support, and withdrawal of consent where processing relies on consent. Withdrawal does not undo processing already completed or stop retention required by law. Use the request link or email below; we may need to verify your identity.
Children
A parent or guardian must book and sign for a participant under 18. Do not submit another person’s data unless you are authorised and have the required consent.
Security
We use access controls, processor separation, logging, and other safeguards, but no service can guarantee absolute security. Contact support promptly about suspected misuse or a breach.
What we don't do
We don't sell your data, and we don't send marketing you didn't ask for. Availability alerts only go out when you choose to watch a run.
Erase my data
Submit a request to start the account-deletion workflow. Active bookings and records that we must keep for safety, payment, tax, disputes, or law may delay or limit erasure. When deletion completes, direct account contact data is redacted and we confirm by return message.
Request erasureDraft for Indian counsel review before bookings go live.