Privacy Policy - Meghalaya Tourism

Privacy Policy

Privacy Policy

Last Updated: September 22, 2026
Version: 2.0

The Tourism Department, Government of Meghalaya ("we", "us", "our", or "Department") operates the Meghalaya Tourism Tourist App ("Application" or "Service").

This Privacy Policy explains how we collect, use, store, disclose, and protect information when you use the Meghalaya Tourism Tourist App and related services.

By using the Application, you acknowledge the practices described in this Privacy Policy.


1. About Meghalaya Tourism

The Meghalaya Tourism Tourist App is operated by the Tourism Department, Government of Meghalaya and provides tourism-related information and services to help users discover and experience Meghalaya.

Depending on the features available to you, the Application may allow you to:

  • Discover tourism destinations and attractions.
  • Find nearby tourism destinations and services.
  • View locations and directions.
  • Make tourism-related bookings.
  • Book vehicles/cabs.
  • Book accommodation.
  • Book tickets or attractions.
  • Manage bookings and travel information.
  • Receive booking and travel-related notifications.
  • Make payments through supported payment providers.
  • Access tickets, invoices, and other booking-related documents.

Official Website: https://www.meghalayatourism.in


2. Information We Collect

We collect information that you provide directly, information generated when you use the Application, and information required to provide specific services.

2.1 Account and Registration Information

Depending on the authentication method you choose, we may collect:

  • Name
  • Email address
  • Mobile phone number
  • Account identifier
  • Authentication information
  • Profile information associated with your selected authentication provider

The Application supports mobile number and SMS OTP authentication and Google Sign-In.


3. Google Sign-In and Google User Data

The Application allows users to authenticate using Google Sign-In. When you choose to sign in with Google, the Application may receive information associated with your Google Account that is made available through the Google authentication process and authorized by you.

This may include:

  • Name
  • Email address
  • Profile picture
  • Google account/user identifier
  • Authentication information required to verify your sign-in

The Application uses Google authentication information to:

  • Authenticate your identity.
  • Create or associate your Meghalaya Tourism account.
  • Manage your authenticated session.
  • Provide account-related functionality.
  • Secure access to your account.

The Google authentication token may be transmitted securely to our backend for authentication and account verification.

Google user data is not sold to third parties and is not used for advertising purposes.

Google user data is used only for purposes related to authentication, account management, security, and providing the functionality of the Meghalaya Tourism Tourist App.

The Application does not request access to Google data that is unnecessary for the functionality of the Application.

Google OAuth Permissions

The Application uses Google Sign-In for authentication. The exact OAuth permissions requested by the Application are limited to the permissions configured for the Google Sign-In integration.


4. Mobile Number and OTP

If you choose mobile-number authentication, we collect your mobile phone number and use SMS-based OTP verification to:

  • Verify your identity.
  • Create or access your account.
  • Authenticate your login.
  • Secure your account.

SMS/OTP delivery may be supported by third-party service providers used by the Application.


5. Location Information

With your permission, the Application may access your device location.

Location information may be used to:

  • Display your current position on a map.
  • Show nearby destinations, places, and tourism services.
  • Provide navigation and directions.
  • Support booking and travel-related functionality.

The Application does not use your location for background tracking when the Application is not in use.

Location access is requested only when required for the relevant Application functionality.


6. Camera, Photos, and Files

The Application may request access to your camera, photos, and device files when required for supported functionality.

These permissions may be used for:

  • Uploading files.
  • Selecting photos.
  • Supporting booking and travel-related functionality.
  • Downloading tickets.
  • Downloading invoices.
  • Saving PDFs and other booking-related documents.

The Application does not use uploaded photos for public user profiles or review/rating submissions unless such functionality is separately introduced and disclosed.


7. Booking and Travel Information

When you use booking or travel-related services, we may collect:

  • Traveller/passenger name.
  • Passenger mobile number.
  • Address.
  • Pickup location.
  • Drop-off or destination location.
  • Travel date and time.
  • Number of travellers/passengers.
  • Booking details.
  • Booking or transaction identifier.

Vehicle and Cab Bookings

Information required to create, manage, and fulfil vehicle/cab bookings made through the Application.

Accommodation Bookings

Information required to create, manage, and fulfil hotel or accommodation bookings made through the Application.

Ticket and Attraction Bookings

Information required to create, manage, and fulfil ticket or attraction bookings made through the Application.

We use booking information to process reservations, provide requested services, communicate booking updates, maintain transaction records, and resolve booking-related issues.


8. Payment Information

The Application supports payments through third-party payment service providers, including:

  • Razorpay
  • eGrass
  • CCAvenue

We may receive and retain payment-related information such as:

  • Payment transaction ID.
  • Payment status.
  • Payment amount.
  • Payment method.
  • Booking/payment reference information.

The Meghalaya Tourism Tourist App does not store payment card details such as card number, CVV, or card expiry information.

Payment credentials and payment processing are handled by the applicable payment service provider according to its own terms and privacy practices.

The Application may also support offline or cash payment options where applicable.


9. Device and Technical Information

When you use the Application, certain technical information may be collected or generated to provide, secure, maintain, and troubleshoot the Service.

This may include:

  • Device model.
  • Operating system and version.
  • Network or connection information.
  • Crash and diagnostic information.
  • Firebase Cloud Messaging notification token.
  • Location accuracy information when location services are used.

The Application does not intentionally collect your device identifier or IP address for the purposes described in this Privacy Policy.


10. Push Notifications

The Application may send push notifications relating to your use of the Service.

Notifications may include:

  • Booking confirmations and status updates.
  • Vehicle/cab booking updates.
  • Ticket or attraction booking updates.
  • Travel and booking reminders.

The Application does not currently use push notifications for advertising, promotional offers, or general tourism marketing.

Push notifications may be delivered using Firebase Cloud Messaging. You may manage notification permissions through your device settings.


11. How We Use Your Information

  • Create and manage your account.
  • Authenticate your identity.
  • Provide tourism-related services.
  • Process and manage bookings.
  • Process payments through applicable payment providers.
  • Provide maps, location, and navigation functionality.
  • Provide requested travel services.
  • Send booking and travel-related notifications.
  • Provide tickets, invoices, and booking documents.
  • Respond to support requests.
  • Maintain and improve the Application.
  • Diagnose crashes and technical problems.
  • Protect the security and integrity of the Application.
  • Prevent fraud, misuse, and unauthorized activity.
  • Meet applicable legal, regulatory, accounting, and record-keeping requirements.

12. Third-Party Services

ServicePurpose
Google Sign-InUser authentication
Firebase AuthenticationAuthentication and account management
Firebase AnalyticsApplication analytics
Firebase CrashlyticsCrash and diagnostic reporting
Firebase Cloud MessagingPush notifications
Google MapsMaps and location functionality
Google Places APIPlaces and destination functionality
Google Directions/Routes APIDirections and navigation
RazorpayPayment processing
eGrassPayment processing
CCAvenuePayment processing
Message91SMS/OTP delivery
Amazon Web Services (AWS)Backend and data infrastructure

These third-party providers may process information necessary to provide their respective services. Their processing may also be subject to their own privacy policies and terms.


13. Information Sharing and Disclosure

Tourism Department

Information may be processed by or made available to the Tourism Department, Government of Meghalaya, for operating tourism services, managing bookings, providing customer support, and fulfilling applicable administrative requirements.

Service Providers

Information may be shared with authorized service providers where necessary to provide services requested by you, including payment, technology, authentication, notification, maps, location, and tourism service providers.

Legal Requirements

We may disclose information where required or permitted by applicable law, regulation, court order, or lawful government request. We may also disclose information when reasonably necessary to protect our rights, protect users or the public, investigate suspected fraud or unlawful activity, enforce applicable terms, or resolve disputes.

No Sale of Personal Information

We do not sell your personal information and do not share your personal information with advertisers for advertising purposes. Your profile information and booking activity are not intentionally made publicly available to other users through the Application.


14. Data Storage and Infrastructure

Application data is processed and stored using our backend infrastructure, including Amazon Web Services (AWS).

We take reasonable technical and organizational measures to protect information against unauthorized access, alteration, disclosure, or destruction.

Data may be processed or stored in locations outside your state or country where infrastructure or service providers operate. Where this occurs, we take reasonable steps to protect the information in accordance with this Privacy Policy and applicable requirements.


15. Data Retention

We retain information for as long as reasonably necessary to provide requested services and for operational, security, accounting, legal, dispute-resolution, and record-keeping purposes.

Account Information

Account information is generally retained while your account remains active.

Booking Information

Completed booking records may remain stored in our database after the associated travel or service has been completed.

Payment Information

Payment and transaction records may remain stored for operational, accounting, audit, legal, financial, and dispute-resolution purposes.

Uploaded Files and Photos

Uploaded files and photos may remain stored where they are associated with a booking or requested service.

Analytics and Crash Information

Analytics and crash-related information may be retained according to the configuration and retention practices of the applicable service providers.


16. Account Deactivation and Permanent Deletion

Users may request deactivation of their Meghalaya Tourism account. When an account is deactivated, access to the account is disabled and associated account, booking, transaction, and other records may remain retained in our systems.

Deactivation does not automatically result in immediate permanent deletion of all associated information.

A user may contact our support team to request reactivation of a deactivated account. Reactivation is subject to the applicable account review and reactivation process.

Permanent Deletion Request

Users may request permanent deletion of their account and eligible personal information by contacting:

Email: releasem@meghalayatourism.in

Permanent deletion requests are manually reviewed and processed by the authorized team.

Certain information may need to be retained where required for legal obligations, financial or accounting requirements, completed transactions, security, fraud prevention, dispute resolution, regulatory requirements, or other legitimate record-keeping purposes.


17. Your Privacy Rights

Subject to applicable law and the nature of the information involved, you may have the right to:

  • Access or request information about your personal data.
  • Correct inaccurate personal information.
  • Update your account information.
  • Request account deactivation.
  • Request permanent deletion of eligible personal information.
  • Contact us regarding the handling of your personal information.
  • Withdraw permissions for certain device features through your device settings.

To request correction or permanent deletion, contact releasem@meghalayatourism.in.

We may need to verify your identity before processing a privacy-related request.


18. Children's Privacy

The Meghalaya Tourism Tourist App is intended for users aged 18 years or older.

The Application is not specifically designed for children.

We do not knowingly intend to collect personal information from individuals below the applicable minimum age. If you believe that a person below the applicable age has provided personal information through the Application, please contact us so that we can review the situation and take appropriate action.


19. Security of Your Personal Data

We use reasonable technical and organizational measures designed to protect personal information:

  • HTTPS/TLS-secured communication between the Application and backend services.
  • Secure credential handling.
  • Encryption of sensitive information in storage/database.
  • Role-based access controls.
  • Authentication for backend and administrative access.
  • Restricted access to application data.
  • Periodic review and improvement of security measures.

No method of transmission or electronic storage can be guaranteed to be completely secure. Therefore, while we take reasonable measures to protect your information, we cannot guarantee absolute security.


20. Third-Party Websites and Services

The Application or related Meghalaya Tourism services may contain links to third-party websites or services. Third-party websites and services operate under their own privacy policies and terms. We recommend reviewing the privacy policy of any third-party service before providing personal information to it.


21. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes to the Application, our services, data processing practices, third-party services, or legal and regulatory requirements.

When we make significant changes, we may provide notice through the Application, website, email, or another appropriate communication method.

The updated Privacy Policy will be published at https://www.meghalayatourism.in/privacy-policy/.

The "Last Updated" date at the beginning of this Privacy Policy will be updated when material changes are made.


22. Contact Us

If you have questions, requests, or concerns regarding this Privacy Policy or the handling of your personal information, please contact us:

Tourism Department, Government of Meghalaya
3rd Secretariat, Nokrek Building
Lower Lachumiere
Shillong — 793001
Meghalaya, India

Official Website: https://www.meghalayatourism.in
Privacy / Support: releasem@meghalayatourism.in
General Meghalaya Tourism Enquiries: info@meghalayatourism.in | +91 364 222 0220


23. Consent and Use of the Application

By using the Meghalaya Tourism Tourist App, you acknowledge that you have read this Privacy Policy and understand how your information may be collected, used, stored, and disclosed as described above.

Where the Application requests permission to access location, camera, photos, files, notifications, or other device functionality, the relevant permission will be requested through the operating system and may be controlled through your device settings.


Last Updated: September 22, 2026
Version: 2.0

Book Now