Privacy Policy

Effective & last updated: September 24, 2026 • Samrat Tours & Travels Pvt. Ltd.

Samrat Nepal / Samrat Tours and Travels Pvt. Ltd.
Address: Gairidhara, Kathmandu, Nepal
Email: info@samratnepal.com
Phone: +977 9851361414
WhatsApp: wa.me/9851361414
Website: samratnepal.com

Table of Contents

69 Sections
1. Introduction 2. Who We Are 3. Our Commitment to Privacy 4. Information We Collect 5. Contact Information 6. Travel Information 7. Booking and Transaction Information 8. Passport and Travel-Document Information 9. Health and Special-Category Information 10. Communication Information 11. Information We Collect Automatically 12. Cookies 13. Google Analytics 14. Google Ads and Google Advertising Technologies 15. Meta / Facebook / Instagram Advertising 16. Other Advertising and Marketing Technologies 17. Klaviyo and Email Marketing 18. Email Marketing 19. Whatsapp and Direct Messaging 20. Telephone Communications 21. Direct Sales and Personalized Outreach 22. Lead Generation 23. Information From Third Parties 24. Publicly Available Information 25. Why We Use Personal Information 26. Legal Bases for Processing 27. Direct Marketing and Consent 28. Marketing Preferences 29. Customer Segmentation and Personalization 30. Retention of Customer and Lead Data 31. Data Retention Periods 32. Data Minimization 33. Spreadsheets and Internal Business Systems 34. Employee and Contractor Access 35. Service Providers and Data Processors 36. Examples of Third-Party Technology Providers 37. Google Workspace and Cloud Services 38. Payment Providers 39. Airlines, Hotels and Travel Suppliers 40. Government Authorities 41. International Data Transfers 42. GDPR and European Data Protection 43. UK Data Protection 44. India and Other International Customers 45. Social Media 46. Reviews, Photos and Testimonials 47. Advertising Audiences 48. Remarketing 49. Data Used for Marketing Analytics 50. We Do Not Intentionally Sell Personal Information 51. No Unauthorized Disclosure 52. Data Security 53. Passport and Sensitive Document Security 54. Data Breaches and Security Incidents 55. Fraud and Security Monitoring 56. Children's Privacy 57. Your Privacy Rights 58. Right to Object to Direct Marketing 59. How to Make a Privacy Request 60. Identity Verification 61. Response to Privacy Requests 62. Third-Party Privacy Policies 63. Automated Decision-Making 64. Links to Other Websites 65. Changes to This Privacy Policy 66. Contact Us 67. Privacy Complaints 68. Applicable Law and Mandatory Rights 69. Acknowledgement

1. Introduction

Samrat Nepal / Samrat Tours and Travels ("Samrat Nepal", "Samrat", "we", "us", or "our") respects the privacy of individuals who visit our website, communicate with us, request information, make bookings, purchase our services, interact with our advertising, or otherwise engage with our business.

This Privacy Policy explains how we collect, receive, use, store, disclose, transfer and protect personal information in connection with:

  • samratnepal.com;
  • our travel and tourism services;
  • booking and enquiry processes;
  • email communications;
  • telephone and messaging communications;
  • WhatsApp communications;
  • social-media communications;
  • advertising campaigns;
  • digital marketing activities;
  • customer relationship management;
  • analytics and measurement;
  • travel arrangements;
  • visa and travel-document assistance;
  • customer support; and
  • other services and interactions provided by Samrat Nepal.

This Privacy Policy should be read together with our Terms of Use & Travel Booking Terms, Cookie Policy, Booking & Cancellation Policy, and any other applicable notices or agreements.

By using our Website or providing personal information to us, you acknowledge the practices described in this Privacy Policy, subject to any rights and protections provided by applicable law.

2. Who We Are

For purposes of applicable data-protection and privacy laws, Samrat Nepal may act as the organization responsible for determining how and why personal information is processed in connection with our own business activities.

Samrat Nepal / Samrat Tours and Travels Pvt. Ltd.
Address: Gairidhara, Kathmandu, Nepal
Email: info@samratnepal.com
Phone: +977 9851361414
WhatsApp: wa.me/9851361414
Website: samratnepal.com

Where we process information on behalf of another organization under a separate contractual arrangement, our role may instead be that of a service provider or processor.

3. Our Commitment to Privacy

We seek to:

  • collect personal information for legitimate and identifiable purposes;
  • avoid collecting information that is unnecessary for those purposes;
  • use information in accordance with applicable law;
  • provide appropriate privacy notices;
  • protect information through reasonable security measures;
  • retain information only for as long as reasonably necessary or legally required;
  • provide applicable privacy rights;
  • respect marketing preferences and opt-out requests;
  • work with reputable technology and service providers;
  • maintain appropriate controls over employee and contractor access; and
  • respond appropriately to privacy and security incidents.

Nepal's Privacy Act, 2075 establishes protections relating to personal information and privacy, including protections concerning electronic correspondence and communications.

4. Information We Collect

Depending on how you interact with us, we may collect different categories of personal information.

4.1 Identity Information

This may include:

  • full name;
  • preferred name;
  • title;
  • date of birth;
  • age;
  • gender where relevant to a service;
  • nationality;
  • citizenship information;
  • passport information;
  • government identification information;
  • photograph or profile image;
  • signature; and
  • other information required to identify a traveler.

5. Contact Information

We may collect:

  • email address;
  • telephone number;
  • mobile number;
  • WhatsApp number;
  • residential address;
  • mailing address;
  • emergency contact details;
  • social-media identifiers;
  • communication preferences; and
  • other contact information you voluntarily provide.

6. Travel Information

To arrange travel services, we may collect information such as:

  • destination;
  • departure location;
  • travel dates;
  • return dates;
  • preferred itinerary;
  • flight preferences;
  • accommodation preferences;
  • room preferences;
  • transportation requirements;
  • tour preferences;
  • trekking information;
  • pilgrimage information;
  • group size;
  • traveler information;
  • passport details;
  • visa information;
  • permit information;
  • travel history where relevant;
  • emergency contact information;
  • special travel requirements; and
  • other information necessary to arrange your requested services.

7. Booking and Transaction Information

When you purchase or attempt to purchase our services, we may collect:

  • booking reference;
  • quotation information;
  • invoice information;
  • payment status;
  • transaction amount;
  • payment method;
  • transaction date;
  • refund information;
  • cancellation information;
  • supplier information;
  • travel package information; and
  • communications concerning the transaction.

Where payments are processed by third-party payment providers, we generally do not need to directly store complete payment-card information.

Payment providers may independently process payment information under their own privacy policies.

8. Passport and Travel-Document Information

Certain travel services may require us to collect copies or details of:

  • passports;
  • visas;
  • permits;
  • identity documents;
  • photographs;
  • immigration documents;
  • travel insurance documents;
  • tickets;
  • booking confirmations; and
  • other travel documentation.

Such information may be shared with airlines, hotels, transport operators, government authorities, immigration authorities, visa-processing organizations, permit authorities, insurers or other suppliers where necessary to provide the requested service or comply with legal requirements.

We will seek to limit the information shared to what is reasonably necessary for the relevant purpose.

9. Health and Special-Category Information

Certain journeys may require limited health or medical information.

Examples may include information relating to:

  • medical conditions relevant to high-altitude travel;
  • mobility requirements;
  • dietary requirements;
  • allergies;
  • accessibility requirements;
  • emergency medical information; or
  • other information voluntarily provided for legitimate travel-safety purposes.

We will only request or use such information where reasonably necessary for a legitimate purpose, such as arranging travel, accommodating a requirement, managing an emergency, complying with a supplier requirement, or protecting health and safety.

You should not provide unnecessary medical information through ordinary website forms, email, WhatsApp or social media.

Where applicable law treats particular information as sensitive or special-category information, we will apply the additional protections required by that law.

10. Communication Information

We may retain communications between you and Samrat Nepal, including:

  • emails;
  • WhatsApp messages;
  • SMS;
  • telephone records where lawfully collected;
  • enquiry forms;
  • social-media messages;
  • chat conversations;
  • booking correspondence;
  • customer-service communications;
  • complaints;
  • feedback;
  • reviews;
  • survey responses; and
  • other business correspondence.

We may use such information to provide customer service, maintain accurate records, resolve disputes, improve services, train staff where appropriate, prevent fraud, and maintain business records.

11. Information We Collect Automatically

When you visit our Website, we may automatically collect information such as:

  • IP address;
  • browser type;
  • device type;
  • operating system;
  • approximate geographic location;
  • language;
  • referring website;
  • pages visited;
  • links clicked;
  • time spent on pages;
  • navigation patterns;
  • date and time of visits;
  • campaign source;
  • advertising identifiers;
  • cookie identifiers;
  • device identifiers;
  • interaction events; and
  • other technical or usage information.

This information may be collected through cookies, pixels, tags, SDKs, server logs, analytics tools and similar technologies.

12. Cookies

We may use cookies and similar technologies for:

  • essential Website functionality;
  • security;
  • session management;
  • analytics;
  • performance measurement;
  • remembering preferences;
  • advertising;
  • remarketing;
  • conversion measurement;
  • campaign attribution;
  • personalization; and
  • understanding Website usage.

Some cookies may be placed by third-party providers.

Further information is provided in our separate Cookie Policy.

Where applicable law requires consent before non-essential cookies or similar technologies are used, we will provide an appropriate consent mechanism.

13. Google Analytics

We may use Google Analytics to understand how visitors use our Website.

Google Analytics may process information such as:

  • Website interactions;
  • approximate location;
  • device information;
  • browser information;
  • traffic sources;
  • pages viewed;
  • events;
  • cookie identifiers; and
  • other analytics information.

Google provides controls allowing Website operators to configure data collection, retention, advertising personalization, Google Signals and other privacy-related settings.

We will configure Google Analytics in accordance with applicable requirements and our legitimate business purposes.

We will not intentionally send directly identifying information such as personal email addresses, telephone numbers, passport numbers or similar PII to Google Analytics.

Google's own guidance states that customers should not send personally identifiable information to Google Analytics.

14. Google Ads and Google Advertising Technologies

We may use Google Ads and related Google advertising technologies to:

  • advertise our travel services;
  • measure advertising performance;
  • understand campaign effectiveness;
  • identify conversions;
  • create audiences;
  • conduct remarketing where permitted;
  • improve advertising relevance; and
  • measure customer journeys.

Depending on our implementation and your choices, Google may receive information through cookies, advertising identifiers, conversion signals or other technologies.

Where required, we will use appropriate consent-management mechanisms and applicable Google privacy controls.

Google states that businesses using Google Analytics and Google Ads are responsible for implementing consent mechanisms appropriate to the jurisdictions in which they operate.

15. Meta / Facebook / Instagram Advertising

We may use Meta advertising technologies, including Meta Pixel and related technologies, on our Website.

These technologies may help us:

  • measure advertising effectiveness;
  • understand Website conversions;
  • create advertising audiences;
  • conduct remarketing;
  • identify interactions with advertisements;
  • improve campaign performance; and
  • show relevant advertisements on Meta platforms such as Facebook and Instagram.

Depending on implementation, Meta technologies may process information such as:

  • IP address;
  • browser/device information;
  • Website activity;
  • page visits;
  • conversion events;
  • cookie identifiers;
  • advertising identifiers;
  • referral information; and
  • other technical or interaction information.

Where applicable law requires consent for advertising cookies, pixels or similar technologies, we will seek the required consent before activating those technologies.

16. Other Advertising and Marketing Technologies

We may use other advertising and marketing platforms in the future.

These may include:

  • Google Ads;
  • Meta Ads;
  • Instagram;
  • TikTok;
  • LinkedIn;
  • YouTube;
  • Microsoft Advertising;
  • Pinterest;
  • Snapchat;
  • other advertising networks;
  • remarketing platforms;
  • customer-data platforms;
  • CRM systems;
  • marketing automation platforms; and
  • similar technologies.

This Privacy Policy is intended to cover such technologies generally, while specific vendors may be identified in our Cookie Policy or applicable vendor list.

Where a new technology materially changes how personal information is processed, we may update this Privacy Policy or provide an additional notice where required.

17. Klaviyo and Email Marketing

We may use Klaviyo or similar email-marketing and customer-engagement platforms to manage communications.

Information processed through these systems may include:

  • name;
  • email address;
  • telephone number;
  • WhatsApp number where applicable;
  • customer status;
  • enquiry history;
  • booking history;
  • destination interests;
  • travel preferences;
  • campaign interactions;
  • email opens;
  • link clicks;
  • website interactions;
  • marketing preferences;
  • unsubscribe status;
  • approximate location;
  • device information;
  • IP address;
  • cookie information; and
  • other information used for marketing automation.

Klaviyo states that customers control the Customer Personal Data uploaded to its platform and that it processes such data as a processor under contractual arrangements, including its Data Processing Agreement.

Klaviyo also states that its platform and customer data are hosted using AWS data centers in the United States and that it uses subprocessors.

Accordingly, information submitted to our marketing systems may be processed or accessed outside Nepal.

18. Email Marketing

Where permitted by applicable law, we may send marketing communications about:

  • travel packages;
  • new destinations;
  • pilgrimage tours;
  • trekking packages;
  • holiday packages;
  • promotions;
  • seasonal offers;
  • travel guides;
  • destination information;
  • special events;
  • travel-related products and services; and
  • other services that may be relevant to our customers.

Where applicable law requires consent, we will seek consent before sending marketing communications.

Marketing emails will generally contain an unsubscribe or preference-management mechanism.

You may withdraw marketing consent or opt out of promotional communications at any time.

19. Whatsapp and Direct Messaging

We may communicate with customers and leads through WhatsApp or other messaging platforms.

This may include:

  • responding to enquiries;
  • sending quotations;
  • booking communications;
  • travel reminders;
  • customer support;
  • itinerary information;
  • operational notices;
  • promotional messages where legally permitted;
  • follow-up communications;
  • destination recommendations; and
  • other travel-related communications.

Where required by applicable law, we will obtain appropriate consent before sending direct marketing messages through electronic messaging services.

You may request that we stop promotional WhatsApp communications at any time.

WhatsApp and its parent/platform operators may independently process information under their own terms and privacy policies.

20. Telephone Communications

We may use telephone numbers supplied to us for:

  • responding to enquiries;
  • booking communications;
  • customer support;
  • emergency travel communications;
  • transaction-related communication;
  • follow-up;
  • service updates; and
  • marketing where permitted by applicable law.

We will respect applicable restrictions concerning telemarketing and communications.

Where permitted and appropriately disclosed, calls may be recorded or logged for quality assurance, training, security, dispute resolution or record-keeping purposes.

If calls are recorded, we will provide appropriate notice where required by law.

21. Direct Sales and Personalized Outreach

Samrat Nepal may use information provided by customers and leads to conduct personalized business communication.

For example, if you enquire about a particular destination, we may contact you later regarding:

  • that destination;
  • similar travel packages;
  • updated pricing;
  • travel dates;
  • related destinations;
  • relevant pilgrimage packages;
  • alternative itineraries; or
  • related services.

Where such communication constitutes direct marketing under applicable law, we will apply the consent, opt-out and other requirements applicable to the relevant jurisdiction and communication method.

The fact that contact information is publicly available does not automatically mean that a person has consented to receive marketing. UK guidance expressly emphasizes this point for electronic marketing.

22. Lead Generation

We may receive prospective customer information through:

  • Website forms;
  • booking forms;
  • enquiry forms;
  • telephone calls;
  • WhatsApp;
  • Facebook;
  • Instagram;
  • Google;
  • advertising lead forms;
  • email;
  • events;
  • referrals;
  • travel partners;
  • agents;
  • offline enquiries;
  • business relationships; and
  • other lawful sources.

Lead information may be entered into our internal systems for the purposes described in this Privacy Policy.

23. Information From Third Parties

We may receive information about you from third parties, including:

  • travel partners;
  • booking platforms;
  • airlines;
  • hotels;
  • tour operators;
  • payment providers;
  • visa service providers;
  • advertising platforms;
  • social-media platforms;
  • marketing platforms;
  • referral partners;
  • corporate customers;
  • group organizers; and
  • other suppliers.

Where required by applicable law, we will take appropriate steps concerning the source and lawful use of such information.

24. Publicly Available Information

We may collect limited information from publicly available sources for legitimate business purposes, including:

  • publicly available business contact information;
  • publicly available professional information;
  • publicly available social-media information;
  • public company information; and
  • information available through public websites.

We will not assume that publicly available contact information automatically constitutes consent for marketing.

Where direct marketing laws require consent or another lawful basis, we will comply with those requirements.

25. Why We Use Personal Information

We may use personal information for the following purposes.

A. Providing Travel Services

Including:

  • processing bookings;
  • arranging flights;
  • arranging hotels;
  • arranging transportation;
  • organizing tours;
  • arranging trekking services;
  • arranging pilgrimage services;
  • obtaining permits;
  • facilitating visa-related services;
  • communicating itineraries;
  • coordinating suppliers; and
  • providing customer support.

B. Business Administration

Including:

  • accounting;
  • invoicing;
  • record keeping;
  • auditing;
  • legal compliance;
  • internal reporting;
  • quality control;
  • customer relationship management;
  • supplier management; and
  • business operations.

C. Communication

Including:

  • responding to enquiries;
  • providing quotations;
  • sending booking confirmations;
  • communicating changes;
  • answering questions;
  • providing support;
  • handling complaints; and
  • emergency communication.

D. Marketing

Where permitted by law:

  • email marketing;
  • WhatsApp marketing;
  • SMS marketing;
  • direct communication;
  • personalized offers;
  • remarketing;
  • advertising;
  • customer segmentation;
  • audience creation;
  • campaign measurement;
  • promotional communications; and
  • destination recommendations.

E. Analytics

Including:

  • understanding Website usage;
  • measuring campaigns;
  • improving Website performance;
  • understanding customer journeys;
  • measuring conversions;
  • improving marketing;
  • detecting technical problems; and
  • business analysis.

F. Security and Fraud Prevention

Including:

  • preventing fraud;
  • detecting abuse;
  • protecting accounts;
  • protecting payment systems;
  • preventing unauthorized access;
  • investigating security incidents;
  • preventing spam;
  • enforcing our Terms; and
  • protecting customers and the business.

G. Legal Compliance

Including complying with:

  • laws;
  • court orders;
  • government requests;
  • immigration requirements;
  • tax requirements;
  • regulatory requirements;
  • law-enforcement requests; and
  • other lawful obligations.

26. Legal Bases for Processing

Depending on the applicable jurisdiction and the circumstances, we may process personal information on one or more of the following grounds:

  • performance of a contract;
  • taking steps at your request before entering into a contract;
  • compliance with a legal obligation;
  • consent;
  • legitimate interests;
  • protection of vital interests;
  • prevention of fraud and security threats; or
  • another lawful basis recognized by applicable law.

The applicable legal basis may vary according to:

  • your location;
  • the type of information;
  • the purpose of processing;
  • the service requested;
  • the applicable law; and
  • the relationship between you and Samrat Nepal.

Where consent is relied upon, you may generally withdraw that consent, subject to applicable law and the circumstances of the processing.

27. Direct Marketing and Consent

We distinguish between:

Transactional/Service Communications

These may include:

  • booking confirmations;
  • invoices;
  • payment notifications;
  • itinerary changes;
  • travel reminders;
  • visa/document requests;
  • emergency notifications;
  • customer-service responses; and
  • other communications necessary to provide requested services.

These communications may continue even if you opt out of promotional marketing where permitted by law.

Promotional/Marketing Communications

These may include:

  • offers;
  • promotions;
  • destination campaigns;
  • newsletters;
  • new travel packages;
  • personalized recommendations;
  • remarketing;
  • promotional WhatsApp messages;
  • marketing emails; and
  • similar communications.

Where applicable law requires consent, we will obtain the appropriate consent.

Consent should not be treated as permanent. Where consent is the legal basis for marketing, you may withdraw it.

28. Marketing Preferences

You may request to stop promotional communications by:

  • clicking the unsubscribe link in an email;
  • changing your marketing preferences;
  • replying to a marketing communication with an opt-out request;
  • contacting us directly;
  • requesting removal from a WhatsApp marketing list; or
  • using another mechanism we make available.

We will take reasonable steps to process your request.

You may continue to receive essential service-related communications where reasonably necessary to provide a service you have requested.

29. Customer Segmentation and Personalization

Where legally permitted, we may use information such as:

  • destinations you have viewed;
  • destinations you have enquired about;
  • previous bookings;
  • travel dates;
  • destination preferences;
  • communication preferences;
  • campaign interactions;
  • Website interactions; and
  • customer status

to organize customers into marketing segments.

This may allow us to send more relevant travel information rather than identical marketing to every customer.

We will not use personalization to make decisions producing legal or similarly significant effects about you unless permitted and appropriately governed under applicable law.

30. Retention of Customer and Lead Data

We may retain personal information for as long as reasonably necessary for:

  • providing services;
  • maintaining booking records;
  • accounting;
  • tax and regulatory compliance;
  • dispute resolution;
  • fraud prevention;
  • security;
  • enforcing agreements;
  • customer-service history;
  • legitimate business purposes;
  • marketing where permitted;
  • demonstrating consent;
  • maintaining suppression/opt-out records; and
  • other lawful purposes.

We do not necessarily delete all information immediately when you stop being a customer.

Some information may need to be retained after you request marketing removal.

For example, we may retain a minimal record indicating that you opted out of marketing so that we do not accidentally send you future promotional communications.

31. Data Retention Periods

Retention periods may vary depending on the type and purpose of information.

As a general framework:

InformationIndicative retention
Booking and transaction recordsAs required for business, accounting, tax, legal and dispute purposes
Passport/travel documentsOnly for as long as reasonably necessary for the relevant travel, legal or operational purpose, unless longer retention is justified or required
Marketing contactsUntil unsubscribe/withdrawal, inactivity, deletion request, or another defined retention point, subject to lawful retention requirements
Marketing consent recordsFor as long as necessary to demonstrate compliance
Website analyticsAccording to configured analytics retention settings
Security logsFor a reasonable security, investigation and compliance period
Customer communicationsFor as long as reasonably necessary for service, dispute, legal or business purposes
Financial recordsAccording to applicable accounting/tax/legal requirements

Actual retention periods may differ where required by law, contractual obligations, security requirements or legitimate business needs.

32. Data Minimization

We seek to collect information appropriate to the purpose for which it is required.

For example, we do not need your passport information simply because you read a travel blog.

However, passport information may become necessary once you request an international ticket, visa-related service, permit, hotel arrangement or other travel service requiring identity verification.

33. Spreadsheets and Internal Business Systems

We may use spreadsheets, databases, CRM systems and other internal tools to manage:

  • customer enquiries;
  • bookings;
  • leads;
  • contact information;
  • travel requirements;
  • payment status;
  • customer communications;
  • marketing preferences;
  • supplier coordination;
  • sales activities; and
  • business reporting.

Where spreadsheets or similar systems contain personal information, access should be limited to authorized personnel who require the information for legitimate business purposes.

We will seek to apply reasonable access controls and security practices to such systems.

34. Employee and Contractor Access

Personal information may be accessible to authorized:

  • employees;
  • managers;
  • travel consultants;
  • sales personnel;
  • marketing personnel;
  • finance personnel;
  • customer-service personnel;
  • IT personnel;
  • contractors; and
  • authorized service providers.

Access should be provided on a need-to-know basis where reasonably practicable.

Personnel handling personal information may be subject to confidentiality and security obligations.

35. Service Providers and Data Processors

We use third-party providers to operate our business.

These may include providers of:

  • email marketing;
  • CRM;
  • analytics;
  • advertising;
  • hosting;
  • cloud storage;
  • spreadsheets;
  • payment processing;
  • booking systems;
  • communication services;
  • WhatsApp/business messaging;
  • customer support;
  • security;
  • IT infrastructure;
  • accounting;
  • travel services; and
  • other business functions.

Such providers may process personal information on our behalf or independently as described in their own privacy notices.

36. Examples of Third-Party Technology Providers

Depending on our actual implementation, these may include:

  • Google Analytics;
  • Google Ads;
  • Google Tag Manager;
  • Google Workspace;
  • Meta/Facebook;
  • Instagram;
  • Klaviyo;
  • WhatsApp;
  • Microsoft;
  • cloud-storage providers;
  • payment processors;
  • hosting providers;
  • CRM providers;
  • booking systems;
  • email providers;
  • security providers; and
  • other marketing and technology providers.

The exact providers in use may change over time.

37. Google Workspace and Cloud Services

We may use cloud services such as Google Workspace, Microsoft 365 or other cloud platforms for:

  • email;
  • spreadsheets;
  • documents;
  • customer records;
  • internal collaboration;
  • file storage;
  • business administration; and
  • communications.

Personal information stored through these services may be processed on infrastructure located outside Nepal.

We will seek to use appropriate security settings and access controls.

38. Payment Providers

Payments may be processed by third-party providers.

Depending on the payment method, providers may collect:

  • card details;
  • bank information;
  • billing information;
  • transaction information;
  • device information;
  • fraud-prevention information; and
  • other information required to process payments.

We may receive transaction confirmation and relevant payment information but may not receive or store complete card credentials.

Payment providers operate under their own terms and privacy policies.

39. Airlines, Hotels and Travel Suppliers

To provide travel services, we may share necessary personal information with:

  • airlines;
  • hotels;
  • resorts;
  • transport companies;
  • trekking operators;
  • guides;
  • helicopter operators;
  • tour operators;
  • permit authorities;
  • visa-processing organizations;
  • insurance providers;
  • travel partners; and
  • other suppliers.

The information shared may include:

  • name;
  • passport information;
  • travel dates;
  • contact details;
  • booking information;
  • special requirements; and
  • other information reasonably necessary to provide the service.

40. Government Authorities

We may disclose personal information to government authorities where reasonably necessary or legally required.

Examples include:

  • immigration authorities;
  • visa authorities;
  • embassies;
  • consulates;
  • airports;
  • border authorities;
  • permit authorities;
  • tourism authorities;
  • law-enforcement agencies;
  • courts;
  • tax authorities; and
  • other competent governmental bodies.

41. International Data Transfers

Because we use international technology providers and serve international travelers, personal information may be processed outside Nepal.

Depending on the services used, information may be processed in countries including:

  • the United States;
  • United Kingdom;
  • European countries;
  • Australia;
  • Singapore;
  • India; and
  • other countries in which our suppliers or technology providers operate.

For example, Klaviyo states that its customer data is hosted in AWS data centers in the United States and that certain personnel in other countries may access data for service provision.

Where applicable law requires specific safeguards for international transfers, we will seek to implement appropriate contractual, technical or other safeguards.

42. GDPR and European Data Protection

Where the EU GDPR applies to our processing activities, we will seek to comply with applicable GDPR requirements.

The GDPR can apply to organizations outside the European Union where they offer goods or services to individuals in the EU or monitor their behavior.

Where GDPR applies, individuals may have rights including, depending on the circumstances:

  • right of access;
  • right to rectification;
  • right to erasure;
  • right to restriction;
  • right to data portability;
  • right to object;
  • rights concerning automated decision-making;
  • right to withdraw consent; and
  • right to lodge a complaint with a competent supervisory authority.

The availability of each right depends on the applicable legal basis and circumstances.

43. UK Data Protection

Where UK data-protection laws apply, including the UK GDPR and applicable electronic-marketing rules, we will seek to comply with the requirements applicable to our activities.

UK rules governing electronic marketing can require specific consent for marketing to individuals, subject to applicable exceptions.

We will therefore maintain appropriate marketing consent and suppression mechanisms where applicable.

44. India and Other International Customers

Where customers are located in India or another jurisdiction with applicable privacy or data-protection legislation, we will seek to comply with applicable mandatory requirements relevant to our processing.

India's privacy framework includes the Digital Personal Data Protection Act, 2023.

The exact obligations applicable to Samrat Nepal may depend on:

  • whether the relevant law applies territorially;
  • the nature of our services;
  • the location of the individual;
  • the type of processing;
  • the role of Samrat Nepal; and
  • applicable regulations and rules in force at the relevant time.

Nothing in this Policy is intended to remove rights that cannot legally be excluded.

45. Social Media

We may operate pages and accounts on:

  • Facebook;
  • Instagram;
  • YouTube;
  • TikTok;
  • LinkedIn;
  • X;
  • WhatsApp; and
  • other platforms.

Interactions with us on these platforms may result in the platform receiving and processing information according to its own policies.

If you publicly comment, review or post information, that information may be visible to others depending on the platform's settings.

46. Reviews, Photos and Testimonials

If you voluntarily provide:

  • photographs;
  • videos;
  • testimonials;
  • reviews;
  • comments; or
  • other content,

we may use that content for legitimate business and marketing purposes where permitted by applicable law and the permissions or terms applicable to the submission.

Where we intend to use identifiable customer content in a manner requiring specific consent, we will seek appropriate permission.

47. Advertising Audiences

Where permitted by applicable law and platform rules, we may use information or Website interaction data to create advertising audiences.

Examples include:

  • people who visited a destination page;
  • people who submitted an enquiry;
  • people who interacted with a campaign;
  • previous customers;
  • people who viewed specific travel packages; and
  • similar audience categories supported by advertising platforms.

Advertising platforms may process identifiers and interaction information according to their own terms.

Where required, we will obtain consent for applicable tracking technologies.

48. Remarketing

We may use remarketing technologies to show Samrat Nepal advertisements to people who previously interacted with our Website, advertisements or services.

Remarketing may involve cookies, advertising identifiers, pixels or similar technologies.

You may be able to control advertising personalization through your browser, device, advertising platform or applicable cookie-consent mechanism.

49. Data Used for Marketing Analytics

Marketing platforms may allow us to measure:

  • email delivery;
  • email opens;
  • link clicks;
  • advertising impressions;
  • advertising clicks;
  • website visits;
  • enquiry submissions;
  • booking conversions;
  • campaign performance;
  • customer acquisition;
  • repeat engagement; and
  • other campaign metrics.

Some of these measurements may involve identifiers or tracking technologies.

50. We Do Not Intentionally Sell Personal Information

Samrat Nepal does not intend to sell personal information as a standalone commercial product.

We may, however, use third-party advertising, analytics, marketing and technology services that involve the processing or disclosure of information as described in this Policy.

Certain jurisdictions may define "sale", "sharing", "targeted advertising" or similar concepts differently from ordinary language.

Where such laws apply, we will assess our activities according to the applicable legal definitions and provide any required rights or disclosures.

51. No Unauthorized Disclosure

Except as described in this Privacy Policy or permitted/required by law, we do not intentionally disclose personal information to unrelated third parties for their independent use.

We may disclose information where necessary for:

  • requested travel services;
  • payment;
  • marketing technology;
  • analytics;
  • security;
  • fraud prevention;
  • legal compliance;
  • business operations;
  • dispute resolution; or
  • other legitimate purposes described in this Policy.

52. Data Security

We use reasonable technical and organizational measures appropriate to the nature of the information and our business.

These may include:

  • access controls;
  • password protection;
  • multi-factor authentication where available;
  • role-based access;
  • secure cloud services;
  • encrypted connections;
  • security monitoring;
  • backups;
  • device security;
  • staff confidentiality obligations;
  • vendor controls;
  • account permissions;
  • anti-malware measures; and
  • other reasonable security practices.

However, no electronic system or internet transmission is completely secure.

We cannot guarantee absolute security.

53. Passport and Sensitive Document Security

Because travel businesses may process highly valuable identity documents, we seek to apply additional care to passport and travel-document information.

Where reasonably practicable:

  • access should be restricted;
  • documents should not be stored indefinitely;
  • unnecessary copies should not be retained;
  • documents should not be shared through insecure public channels;
  • staff access should be limited;
  • cloud storage should use appropriate account security; and
  • information should be securely deleted when no longer reasonably necessary.

Customers should avoid posting passports, identity documents or sensitive medical information publicly on social media.

54. Data Breaches and Security Incidents

If we become aware of a personal-data security incident, we will assess the incident and take reasonable steps to:

  • contain the incident;
  • investigate its cause;
  • protect affected systems;
  • preserve relevant evidence;
  • assess affected information;
  • notify appropriate parties where legally required; and
  • take reasonable corrective measures.

Where applicable law requires notification to affected individuals or regulators, we will comply with the applicable requirements.

55. Fraud and Security Monitoring

We may process technical and transaction information to:

  • detect suspicious activity;
  • prevent fraudulent bookings;
  • detect unauthorized payment activity;
  • prevent abuse;
  • protect our Website;
  • investigate attacks;
  • protect customers; and
  • comply with legal obligations.

This may include IP addresses, device information, login information, transaction information, timestamps and technical logs.

56. Children's Privacy

Our Website and services are not generally directed at young children.

We do not knowingly seek to collect unnecessary personal information from children.

Where travel services involve minors, information may be collected from or through a parent, legal guardian or authorized adult where necessary to arrange the service.

If you believe a child has provided information to us improperly, please contact us.

57. Your Privacy Rights

Depending on your location and applicable law, you may have rights including:

  • access to your personal information;
  • correction of inaccurate information;
  • deletion;
  • restriction of processing;
  • objection to certain processing;
  • withdrawal of consent;
  • data portability;
  • objection to direct marketing;
  • information about how your data is used;
  • information about certain third-party disclosures;
  • complaint rights; and
  • other rights provided by applicable law.

Not every right applies in every situation.

For example, we may need to retain certain information for legal, accounting, security, fraud-prevention or contractual purposes even after receiving a deletion request.

58. Right to Object to Direct Marketing

You may object to direct marketing at any time.

Once we receive a valid marketing opt-out request, we will take reasonable steps to stop using your personal information for promotional communications.

We may retain a limited suppression record to ensure that your preference is respected in the future.

59. How to Make a Privacy Request

To exercise a privacy right or ask a privacy question, contact:

Samrat Nepal / Samrat Tours and Travels Pvt. Ltd.
Address: Gairidhara, Kathmandu, Nepal
Email: info@samratnepal.com
Phone: +977 9851361414
WhatsApp: wa.me/9851361414
Website: samratnepal.com

Please include:

  • your full name;
  • contact information;
  • relevant booking/reference number where applicable;
  • the nature of your request; and
  • sufficient information for us to identify the relevant records.

60. Identity Verification

For certain privacy requests, we may need to verify your identity.

This is intended to protect personal information from unauthorized disclosure.

We will seek to request only information reasonably necessary for verification.

61. Response to Privacy Requests

We will respond to valid privacy requests within the period required by applicable law.

Where additional time or information is legally permitted or reasonably necessary, we may explain the reason.

Where we cannot fulfill a request because an exception or legal restriction applies, we will explain the applicable reason to the extent legally permitted.

62. Third-Party Privacy Policies

When you use third-party services, those services may independently process information.

Examples include:

  • Google;
  • Meta;
  • WhatsApp;
  • Klaviyo;
  • payment providers;
  • airlines;
  • hotels;
  • booking systems;
  • social-media platforms;
  • hosting providers; and
  • other suppliers.

Their processing may be governed by their own privacy policies and terms.

We encourage customers to review the privacy policies of services they use.

63. Automated Decision-Making

We may use automated tools for:

  • analytics;
  • advertising audience creation;
  • marketing segmentation;
  • campaign optimization;
  • fraud detection;
  • spam prevention; and
  • Website personalization.

Unless expressly disclosed otherwise, we do not intend to make decisions producing legal or similarly significant effects about individuals solely through automated processing.

Where applicable law provides specific rights concerning automated decision-making, those rights will apply.

64. Links to Other Websites

Our Website may contain links to third-party websites.

We are not responsible for the privacy practices of websites we do not control.

You should review the privacy policy of each external website you visit.

65. Changes to This Privacy Policy

We may update this Privacy Policy from time to time.

Changes may be made because of:

  • changes in law;
  • changes in our services;
  • new technology;
  • new marketing tools;
  • new service providers;
  • changes in our data practices;
  • security improvements; or
  • other legitimate business reasons.

The latest version will be posted on the Website with an updated "Last Updated" date.

Where required by law, we will provide additional notice or obtain consent for material changes.

66. Contact Us

For privacy questions, requests, complaints or concerns:

Samrat Nepal / Samrat Tours and Travels Pvt. Ltd.
Address: Gairidhara, Kathmandu, Nepal
Email: info@samratnepal.com
Phone: +977 9851361414
WhatsApp: wa.me/9851361414
Website: samratnepal.com

67. Privacy Complaints

If you believe your privacy rights have been violated, we encourage you to contact us first so that we can investigate and attempt to resolve the matter.

Nothing in this Privacy Policy prevents you from contacting a competent privacy, consumer-protection, regulatory or judicial authority where you have the legal right to do so.

68. Applicable Law and Mandatory Rights

This Privacy Policy is intended to operate consistently with applicable privacy and data-protection laws.

Nepal law will generally govern Samrat Nepal's operations in Nepal, subject to mandatory privacy and data-protection requirements applicable to particular individuals, transactions, processing activities or jurisdictions.

Where mandatory law provides rights that cannot legally be excluded, those rights remain unaffected.

69. Acknowledgement

By using our Website, submitting information, communicating with us, requesting travel services or otherwise interacting with Samrat Nepal, you acknowledge that you have had an opportunity to review this Privacy Policy.

Where consent is legally required for a particular processing activity, this Privacy Policy alone does not constitute consent.

Separate consent mechanisms may be presented where required.

Chat on WhatsApp