PRIVACY POLICY
Earth Abroad Private Limited, trading as Foxpels
PRIVACY POLICY
Earth Abroad Private Limited, trading as Foxpels
Last updated: March 2026
This policy describes what personal data we collect, why, who we share it with, how long we keep it and what rights you have over it. It is written to the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025.
It describes what we actually do today, not an architecture we intend to build.
1. Who is responsible for your data
Earth Abroad Private Limited is the Data Fiduciary — the entity that decides why and how your personal data is processed. Foxpels is a brand and vertical of Earth Abroad Private Limited.
| Legal entity | Earth Abroad Private Limited |
| CIN | U86201PN2025PTC248111 |
| Registered office | Survey No. 174/1/5, Postal Colony, Datta Mandir Road, Wakad, Pune, Maharashtra 411057 |
| hello@foxpels.com | |
| Telephone | +91 92724 74157 |
Grievance Officer
Utkarsh Kolhe, Founder hello@foxpels.com · +91 92724 74157 Earth Abroad Private Limited, Survey No. 174/1/5, Postal Colony, Datta Mandir Road, Wakad, Pune, Maharashtra 411057
Write to the Grievance Officer about anything in this policy, to exercise a right under clause 9, or to complain about how we have handled your data.
2. Who this applies to
This policy applies to anyone who enquires, books, subscribes, applies for a trade account, or corresponds with us — travellers, trade and institutional contacts, community partners and applicants — through www.foxpels.com or by any other route.
By submitting your details you consent to the processing described here. If you do not, we will not be able to answer your enquiry or arrange a journey for you.
3. What we collect
| Source | What is collected |
|---|---|
| Enquiry forms — journey, custom build, institutional, trade, MICE and general | Name, email address, telephone number, country, intended travel dates, group size, budget range, interests, and whatever you write in the free text field |
| Newsletter signup | Email address |
| Trade account application | Business name and address, contact name, role, email, telephone, and details of the operator's business |
| Starting a WhatsApp conversation with us shares your telephone number and WhatsApp profile with us. The conversation itself is carried by WhatsApp, operated by Meta, under their terms and their privacy policy rather than ours. | |
| Email and telephone | Whatever you send us, and a record of the correspondence |
| Booking | Full name as on passport or identity document, date of birth, nationality, gender where a permit requires it, passport or Aadhaar number where a permit or accommodation registration requires it, address, emergency contact, dietary requirements, and health information you disclose |
| Permit applications | Whatever the issuing authority requires, which for restricted and protected area permits includes photographs and identity document detail |
| Payment | Bank details for refunds, and the record of what was paid and when |
| Website | No analytics, advertising or tracking data. See the Cookie Policy. |
3.1 Health information
Where you disclose a medical condition, allergy, medication, mobility limitation or fitness concern, we hold it because we need it to run your journey safely and to tell the people on the ground what they need to know.
We treat it as sensitive. We share it only with the specific people delivering your journey who need it — a journey lead, a host household preparing food, a medical facility in an emergency — and never for any other purpose.
You may decline to give it. Where we cannot assess the risk, we may be unable to confirm your place.
3.2 We do not collect payment card data
There is no payment gateway and no checkout on this website. Card numbers, CVV codes, PINs and banking credentials are never entered on foxpels.com because there is nowhere to enter them. Payment is arranged by invoice and bank transfer, or by a single payment link where we provide one — and where a link is used, the payment is processed by that provider under their own terms and we do not receive or store your card details.
We will never ask you for a card number, CVV, OTP or password.
4. How your data actually reaches and sits with us
Form submissions are delivered to us by email, to hello@foxpels.com. There is no customer database behind this website, no CRM and no stored submission record on the site itself. Your enquiry arrives in a mailbox and is worked from there. Booking correspondence continues by email, and booking records are held in working documents and accounting records.
We state this plainly because it is what happens. If it changes — if we introduce a CRM or a booking system — this policy will be updated before the change goes live, and clause 13 sets out how we tell you.
5. Why we process it
| Purpose | What it covers |
|---|---|
| Answering your enquiry | Understanding what you have asked for, designing a journey, issuing a quote |
| Performing the contract | Confirming a booking, invoicing, issuing documentation, keeping you informed |
| Delivering your journey | Passing ground partners, community hosts, accommodation and transport what they need to host you |
| Permits and clearances | Applying to authorities on your behalf where the journey requires it |
| Safety | Emergency contact, health disclosure, group communication, response to an incident |
| Legal and accounting obligations | Invoicing, tax records, statutory record-keeping, response to a lawful request |
| The Earth Edit newsletter | Only where you have asked for it |
| Improving what we offer | Understanding, in aggregate and without identifying anyone, what people ask us for |
We process your data on the basis of the consent you give when you submit it, and for the legitimate uses the Digital Personal Data Protection Act permits — including performance of the contract you have entered into with us and compliance with our legal obligations.
We do not sell your data. We do not share it for anyone else's marketing. We do not profile you and we do not make automated decisions about you.
5.1 Withdrawing consent
You may withdraw consent at any time by writing to the Grievance Officer. Withdrawal does not affect processing already carried out lawfully. Where the data is necessary to deliver a journey you have booked, withdrawing it may mean we cannot deliver it, and the Cancellation and Refund Policy would then apply.
6. Who we share it with
Traveller data is genuinely shared. We name the categories rather than saying "trusted partners", and we share the minimum each recipient needs — a host household is told you are vegetarian; it is not told your budget range.
| Who | What they receive, and why |
|---|---|
| Ground operating partners | Names, dates, itinerary, dietary and relevant health information necessary to deliver the journey |
| Community partners and host households | Names and numbers of the people arriving, dates, dietary requirements, and anything relevant to hosting you safely |
| Accommodation providers | Guest names and identity details, including where Indian law requires accommodation to register guests and to report foreign nationals to the authorities |
| Transport operators and carriers | Names and, where required, identity document details |
| Permit and regulatory authorities | Whatever the application requires — for restricted and protected area permits this includes passport, nationality and photograph |
| Visa facilitators and consulates | Where we assist with a visa application, the documents that application requires |
| Insurers | Where you arrange insurance through a provider we introduce, or where a claim is made |
| Email, hosting and IT providers | Processing your data incidentally in the course of providing their service to us |
| Professional advisers | Our accountant, and where necessary our lawyer or insurer |
| Authorities | Where we are required by law, by a court order, or by a lawful request from a statutory authority |
| Other travellers on your journey | To a limited extent — your first name, and any information you choose to share yourself |
We do not share your data with any other party without your permission.
7. Data moving across borders
- Inbound travellers. If you travel to India from elsewhere, your data comes to us in India and is shared with Indian ground partners, accommodation, carriers and authorities here.
- Outbound journeys. Where we design a journey outside India, your data is shared with partners in the destination country and with its authorities where a permit or registration requires it.
- Service providers. Our email and hosting providers may process data outside India.
We transfer only what is necessary to deliver the journey, and only to parties involved in delivering it. Transfers are made in accordance with the Digital Personal Data Protection Act, 2023 and any restrictions notified under it.
If you are in the United Kingdom or the European Economic Area, additional rights may apply to you under the data protection law of your own jurisdiction, and you may exercise them through the Grievance Officer.
8. How long we keep it
| Category | Retained for |
|---|---|
| Enquiries that do not become bookings | 24 months from last contact |
| Booking and travel records | 8 years from the end of the financial year of travel, in line with statutory record-keeping obligations |
| Financial and tax records | As required by the Companies Act, 2013 and the Income-tax Act, 1961 |
| Health information | 6 months after travel, then deleted |
| Newsletter subscription | Until you unsubscribe |
| Correspondence not connected to a booking | 24 months |
We delete what we no longer need. Where a period is required by law, that period governs and we cannot delete earlier.
9. Your rights
Under the Digital Personal Data Protection Act, 2023 you have the right to:
- Access — a summary of the personal data we hold about you, what we are doing with it, and who we have shared it with
- Correction and completion — to have inaccurate or incomplete data corrected or completed
- Erasure — to have your data erased, where we are not required to retain it
- Grievance redressal — to complain to us about how we have handled your data
- Nomination — to nominate another person to exercise your rights if you die or become incapacitated
- Withdrawal of consent — at any time, as set out in clause 5.1
To exercise any of these, write to the Grievance Officer at hello@foxpels.com. We may ask you to verify your identity before we act, so that we do not disclose your data to someone else.
We respond within 30 days. If you are not satisfied with our response, you may complain to the Data Protection Board of India.
10. Security
We describe what is actually in place, proportionately, rather than claiming more.
- Enquiry and booking data is held in business email accounts and in working documents
- Access is limited to the people who need it to do their work
- Accounts are protected by strong unique passwords and two-factor authentication
- The website is served over HTTPS
- We hold no card data, and there is no customer database on the website to breach
- Devices used to access company data are password-protected and encrypted
No system is completely secure, and information sent over the internet is never entirely safe in transit. Where a personal data breach occurs, we will notify affected individuals and the Data Protection Board as required, in plain language — what happened, what it may mean for you, and what we have done about it.
11. Children
The Digital Personal Data Protection Act, 2023 treats anyone under 18 as a child and requires verifiable parental consent before their data is processed.
This website is not directed at children and we do not knowingly collect data from anyone under 18 directly. Where a family books a journey, the adult making the booking provides the details of any child travelling and confirms, as part of the booking, that they are the parent or legal guardian or hold that person's written authority.
We do not use a child's data for tracking, advertising or behavioural monitoring of any kind.
If you believe we hold data about a child without proper consent, write to the Grievance Officer and we will delete it.
12. Photography and images
Where we photograph our own journeys and you appear identifiably in an image we would like to use, we ask for your written consent. You may decline, and declining changes nothing about your journey. You may withdraw consent later by writing to us, and we will stop using the image in any material we control.
We do not treat booking a journey as consent to publish your photograph.
Separately, several journeys restrict your photography of the communities and rituals hosting you, up to and including fully camera-free access. That is a condition of travel rather than a data protection matter, and clause 14 of the Booking Terms and Conditions sets it out.
13. Changes to this policy
We will update this page when what we do changes. Where a change is material — a new category of data, a new recipient, a new purpose — we will note it at the top of the page and, where we hold your email address and the change affects you, tell you directly.
The version in force is the one published here, and the date of the last update is shown at the top.
14. Cookies
See the Cookie Policy. The two documents are kept consistent, and neither will describe tracking that is not happening.