Privacy Policy
Your privacy is our priority. Learn how we collect, use, and protect your information.
Last updated: 1 August 2026
Introduction
Welcome to GGNomad ("we," "our," or "us"), a unified travel, tourism and entertainment platform operated by Headshot Marketing Pvt. Ltd., part of the Burdenoff Group. GGNomad is generally available. This Privacy Policy explains how we collect, use, disclose, and safeguard information when you create an account, join a waitlist, visit our website, or use the GGNomad product — destination discovery, trip and itinerary planning, booking of stays / tours / activities, event ticketing, and our two-sided marketplace connecting travelers with hosts, operators and venues. The full, binding legal text is maintained at github.com/algoshred/ggnomad-specs; this page is a plain-language summary of it.
Two roles can apply at once. For your account, billing, waitlist and website-visitor data, we are the controller / data fiduciary. For the marketplace data a host or operator organisation puts into GGNomad — its listings, availability, guest and booking records, payout details, and reviews — that organisation is the controller and we are its processor under our Data Processing Addendum. By using GGNomad, you consent to the practices described here. If you do not agree, please do not use the Platform.
Information We Collect
Personal Information
- • Waitlist: Name, email, organisation name (for hosts/operators), role, country, and areas of travel interest
- • Account & profile: Name, email, username, phone (optional), profile photo, travel preferences, saved destinations and favourites
- • Guest & booking data: Guest name, contact details, party size, check-in/check-out or event dates, special requests, booking reference and status
- • Listing & host data: For hosts/operators — property, tour, activity or event listings, descriptions, media, amenities, pricing and availability
- • Payment & payout data: Billing address, GSTIN/PAN (Indian customers), a tokenised payment-method reference (actual card data is held by Stripe / Razorpay, not by us), and — for hosts — payout account identifiers
Usage Information
- • Device & connection: IP address, browser, OS, and approximate, IP-derived location for security and discovery
- • Precise location: Only when you grant device permission (map search, "near me" discovery, or a host's on-site check-in) — you can revoke it at any time
- • Product analytics: Pages and features used, searches run, listings viewed — collected through our self-hosted Rybbit instance
- • Communications: Support tickets, host↔traveler messages, survey responses
Booking confirmations, tickets and documents
Confirmed bookings receive a booking reference and a server-generated, QR-coded ticket token for redemption at the venue — these are structured records held in our database with the same tenant-access controls and at-rest encryption as the rest of your data. Identity documents a host may separately require for check-in (e.g. a photo ID) are not yet supported by an in-product upload or storage mechanism. Until this capability ships, any such document is exchanged directly between you and the host, outside GGNomad, at the host's direction — we do not receive, store or process it. This is on our near-term roadmap; once built, it will use the same shared platform files service, tenant-RBAC access and encryption at rest that the rest of the Burdenoff platform uses for uploaded documents.
How We Use Your Information
- • Operate the waitlist and notify sign-ups about access to GGNomad
- • Provide the Service: Authenticate users, run discovery, itineraries, bookings, ticketing, listings, reviews and analytics
- • Process bookings & payments: Confirm bookings, take payment, settle host payouts, issue tickets, handle cancellations and refunds
- • Trust, safety & fraud prevention: Detect fraud, fake listings, payment abuse and account takeover across the marketplace
- • Support and communicate: Answer tickets, send booking confirmations, trip reminders and incident notices
- • Improve the Service using aggregated, de-identified usage data
- • Comply with law and defend our legal rights
We do not sell your personal data, and we do not use guest records, booking data, listing/host data or reviews to train, fine-tune or evaluate any machine-learning or large-language model.
AI Features
GGNomad includes (and has on its roadmap) AI-assisted itinerary drafting, destination and listing recommendations, and demand/pricing analytics. AI outputs are advisory — a human (you, or the host setting prices and availability) stays in control of the booking and pricing decision. We do not make automated decisions with legal or similarly significant effect on a person without meaningful human review, and we do not use your data to train any model.
Information Sharing and Disclosure
We do not sell, trade, or rent your personal information. We may share it in the following circumstances:
- • With service providers: Amazon Web Services (cloud infrastructure and application hosting, India), Cloudflare (CDN/security), Razorpay (India payments), Stripe (international payments), Amazon SES (transactional email), and Rybbit (self-hosted analytics). See our full Subprocessors page.
- • With the other party to a booking — the host sees the guest details, dates and requests needed to honour the booking; the traveler sees the listing, confirmation and messages exchanged
- • For legal reasons — when required by law or to protect our rights and safety
- • Business transfers — in case of merger, acquisition, or sale of assets
We do not share personal data with advertising networks or data brokers.
Data Residency and International Transfers
All Customer Data is stored in India by default — backend services, databases and frontend assets are hosted in the Mumbai (India) region. Some operational metadata leaves India: the Cloudflare edge sees connection metadata at globally distributed points of presence, and Stripe receives international booking-payment data. For transfers out of the EEA, UK or Switzerland we rely on Standard Contractual Clauses and their UK/Swiss equivalents. Enterprise customers with a dedicated-region or self-hosting requirement can arrange it through their Order Form; this is a contracted, custom deployment today rather than a self-serve regional setting.
Data Security
Booking, payment, payout and guest data are treated as sensitive, and we implement industry-standard security measures:
- • TLS 1.2+ in transit; AES-256 at rest for primary databases and object storage
- • Strict tenant isolation by workspace, enforced at the resolver layer
- • Role-based access controls (RBAC) on every field, with audit trails
- • Payments handled by PCI-DSS-compliant payment providers (Stripe, Razorpay)
- • Build-time CVE / SBOM scanning; defence-in-depth network controls
- • Breach notification to customer points of contact within 72 hours of a confirmed incident
See our Security page for more detail.
Your Rights and Choices
Subject to local law (India's DPDP Act, GDPR/UK GDPR, and US state privacy laws), you have the following rights. Write to [email protected] to exercise any of them; we respond within the statutory timeframe (typically 30 days, 45 for CPRA).
- • Access: Request a copy of your personal data
- • Correction: Update or correct inaccurate information
- • Deletion / erasure: Request deletion of your account and associated data
- • Portability: Receive your data in a structured, machine-readable format
- • Opt-out: Unsubscribe from marketing, or opt out of "sale or sharing" (we do not sell or share personal information for cross-context advertising)
- • Consent withdrawal: Withdraw consent for processing where applicable
We honour Global Privacy Control signals as a US opt-out signal. If you are a guest in a host's tenant, you may direct requests to that host or to us; we coordinate under our DPA.
Cookies and Tracking Technologies
We use first-party cookies for authentication, security and preferences, Cloudflare cookies for bot management, and our self-hosted Rybbit analytics — never third-party advertising cookies. See our full Cookie Policy for the complete list and how to manage your choices.
Children's Privacy
GGNomad is intended for adults aged 18 and over who book and host travel and entertainment. It is not directed to children. Minors may travel only as named guests on an adult's booking; the booking adult is responsible for any minor's data they include, and the host is responsible for enforcing any age restriction (e.g. an 18+ event) at the point of service. If you believe we hold a child's personal data without an appropriate lawful basis, contact us immediately.
Data Retention
We retain personal data only as long as necessary: waitlist data until launch plus 12 months; account data while the account is active plus 90 days; marketplace and booking records for the Subscription Term and export period your host organisation directs; billing and tax records for 8 years as Indian law requires. When information is no longer needed, we securely delete or anonymise it.
Updates to This Policy
We may update this Privacy Policy periodically. For material changes that reduce your rights we give at least 30 days' notice by email and/or in-product notice. Your continued use of GGNomad after the effective date indicates acceptance of the updated policy.
Contact Us
If you have questions or concerns about this Privacy Policy or our data practices, please contact us:
Headshot Marketing Pvt. Ltd.
Email: [email protected]
Address: "VISWAM", Plot No. 43, Veeramani Nagar, 2nd Cross Street
Nanmangalam, Chennai – 600117, Tamil Nadu, India
Grievance Officer
In accordance with the Digital Personal Data Protection Act, 2023 (§8(10)) and the Information Technology Act, 2000, the name and contact details of the Grievance Officer are provided below:
Vignesh T.V.
Designation: Founder, CEO & CTO, Headshot Marketing Pvt. Ltd.
Email: [email protected]