MPT Hotels and Resorts
    MPT Hotels and ResortsMP Tourism — The Heart of India

    Guest Policies · Data Protection

    Privacy Policy

    Madhya Pradesh State Tourism Development Corporation Ltd. · Last updated: 13 August 2026

    This Privacy Policy explains how Madhya Pradesh State Tourism Development Corporation Ltd. (MPT) and its Central Reservations booking platform collect, use, disclose, store and protect personal information when you browse this website, make an enquiry, complete a reservation, submit a payment, request a refund, or contact our reservations team. It is issued in accordance with the Information Technology Act, 2000, the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, and the Digital Personal Data Protection Act, 2023.

    1. Scope and Applicability

    This Policy applies to all personal data processed through this website, the MPT Central Reservations booking engine, our transactional email and messaging channels, and any offline correspondence that arises from a booking created online. It applies to every visitor, whether or not a reservation is completed.

    Where a resort is operated on MPT’s behalf by an approved operating partner, that partner processes a limited subset of your booking data strictly to deliver your stay. Such partners are bound by contract to the standards described in this Policy.

    This Policy does not govern third-party websites that you may reach through links published here, including the Government of Madhya Pradesh tourism portals. Those sites publish their own privacy notices and you should read them separately.

    2. Definitions

    • “Personal data” means any data about an individual who is identifiable by or in relation to such data.
    • “Sensitive personal data” includes financial information such as payment instrument details, and any government identity numbers collected at check-in.
    • “Data principal” means the guest or website visitor to whom the personal data relates.
    • “Data fiduciary” means MPT, which determines the purpose and means of processing.
    • “Processing” means any operation performed on personal data, including collection, storage, use, disclosure and erasure.

    3. Information We Collect

    3.1 Information you provide directly

    • Full name, mobile number and email address supplied in the booking form.
    • Stay details: property, room category, check-in and check-out dates, number of adults and children, meal plan and special requests.
    • Billing details and, where a payment is submitted through the site, the payment reference, transaction status and the last four digits of the instrument used.
    • Correspondence you send to reservations, including refund requests, cancellation requests and grievance messages.
    • Government photo identification presented at the resort at check-in, collected by the property under statutory hospitality record-keeping obligations.

    3.2 Information collected automatically

    • Diagnostic logs recording errors and request timestamps, used only to keep the website working.
    • We do not run website analytics, visitor tracking or profiling of any kind. We do not collect or store your IP address, approximate location, device fingerprint or browsing behaviour.

    3.3 Information we do not collect

    We do not collect biometric data, caste or religion, political opinions, health records, or any special category data. We do not require you to create a password-protected account in order to book, and we never ask for your full card number, CVV, internet banking password or one-time password by email, telephone or WhatsApp.

    4. Lawful Basis and Purpose of Processing

    We process personal data on the basis of the consent you give when you submit the booking form, on the basis of necessity for the performance of the reservation contract, and, in limited cases, to comply with legal obligations applicable to a State Government company.

    • To create, confirm, amend and cancel reservations and to allocate inventory at the chosen resort.
    • To issue booking confirmations, payment receipts, reminders, vouchers and cancellation or refund notices.
    • To answer enquiries and provide reservations support before, during and after a stay.
    • To process payments, verify receipts and calculate refunds, including discounts applied through valid voucher codes.
    • To detect, investigate and prevent fraudulent bookings, chargeback abuse and misuse of the booking engine.
    • To generate aggregated, non-identifying statistics on occupancy, demand and website performance.
    • To meet audit, taxation and record-keeping requirements applicable to MPT.

    5. Cookies and Tracking Technologies

    Cookies are small text files placed on your device. We use only strictly necessary cookies and local browser storage to keep the booking form working across steps and to remember your selections. We do not use analytics, advertising or tracking cookies, and we do not track you across websites.

    You may block or delete cookies in your browser settings at any time. Blocking strictly necessary cookies may prevent the booking form from retaining your selections between steps. We honour browser-level “reduced motion” and accessibility preferences and do not use them for profiling.

    6. Disclosure and Sharing

    We share personal data only where it is necessary and only to the extent required:

    • With the MPT resort or approved operating partner delivering your stay, to register your arrival and prepare your room.
    • With payment service providers and banks, to authorise, settle, reconcile or reverse a transaction.
    • With email and messaging service providers, to deliver transactional communications relating to your booking.
    • With auditors, legal advisers and government authorities, where disclosure is required by law, regulation, court order or a lawful investigation.
    We do not sell, rent or trade personal data. We do not disclose guest lists to advertisers, data brokers or unaffiliated travel companies.

    7. Payment Data and Financial Information

    Card and bank credentials are captured within the secure environment of our payment partners and are not stored in our booking database in raw form. Records retained by us are limited to the transaction reference, amount, instrument type, masked identifier, status and timestamp, which are required for reconciliation and refunds.

    Payment documents that you upload, such as a screenshot of a completed transfer, are stored in a private storage location that is not publicly addressable. Access is granted only through short-lived signed links issued to authorised reservations staff.

    8. Data Security Practices

    • All traffic to and from this website is encrypted in transit using TLS.
    • Database access is protected by row-level security so that a booking record can be read only by the guest who holds the matching Booking ID and PNR, or by authorised staff.
    • Guest lookups from the public site are routed through a controlled server endpoint rather than direct database access.
    • Administrative access is restricted by role, logged, and reviewed; privileged credentials are never embedded in the website code.
    • Backups are encrypted at rest and restoration is tested periodically.

    No method of transmission or storage is completely secure. While we apply reasonable security practices as contemplated by Rule 8 of the SPDI Rules, 2011, we cannot guarantee absolute security and you share information with us at your own discretion.

    9. Data Retention and Deletion

    Booking records, invoices and payment references are retained for eight financial years to satisfy audit and taxation requirements. Enquiry and abandoned-booking data is retained for twelve months. Diagnostic logs are retained for ninety days. No analytics or visitor-tracking data is collected, so none is retained.

    When a retention period expires, records are deleted or irreversibly anonymised so that they can no longer be linked to an identifiable individual.

    10. Your Rights as a Data Principal

    • Right of access — obtain a summary of the personal data we hold about you and the purposes of processing.
    • Right to correction — have inaccurate or incomplete data corrected or completed.
    • Right to erasure — request deletion of data that is no longer necessary, subject to statutory retention.
    • Right to withdraw consent — withdraw consent for optional processing at any time, without affecting processing already carried out.
    • Right to grievance redressal — escalate a complaint to our grievance contact and, thereafter, to the competent authority.
    • Right to nominate — nominate another individual to exercise your rights in the event of death or incapacity.

    To exercise a right, write to crs@mptourism.online from the email address used for the booking and quote your Booking ID. We respond within thirty days. We may seek proportionate verification before acting on a request that would disclose or delete personal data.

    11. Children and Minors

    This website is not directed at children. Reservations must be made by an individual aged eighteen years or above. Where a child accompanies a guest, we collect only the number and age of children, which is necessary to allocate occupancy and to apply the correct tariff. We do not knowingly collect other data about a child and will delete any such data brought to our attention.

    12. Cross-Border Transfers

    Personal data is processed on infrastructure selected for reliability and security. Where a service provider processes data outside India, the transfer is permitted only to jurisdictions not restricted by the Central Government, is governed by contractual data protection commitments, and is limited to the minimum data required to deliver the service.

    13. Marketing Communications

    Transactional messages relating to a live reservation — confirmations, payment receipts, reminders, cancellation notices and refund updates — are part of the service and are not marketing.

    Promotional messages about seasonal offers or new properties are sent only with consent and always carry an unsubscribe link. Unsubscribing takes effect immediately and does not affect transactional messages for an active booking.

    14. Breach Notification

    In the event of a personal data breach that is likely to result in harm, we will notify affected data principals and the competent authority without undue delay, describing the nature of the breach, the likely consequences, the measures taken to contain it, and the steps you may take to protect yourself.

    15. Grievance Redressal

    Complaints regarding the handling of personal data may be addressed to the Grievance Officer, MPT Central Reservations, Apeejay House, 3rd Floor, Dr. V. B. Gandhi Marg, Fort, Mumbai 400001, or by email to crs@mptourism.online. Complaints are acknowledged within forty-eight hours and resolved within thirty days.

    16. Changes to this Policy

    We may revise this Policy to reflect changes in law, technology or our booking operations. The revision date is shown at the top of this page. Material changes will be highlighted on the website for a reasonable period. Continued use of the website after a revision constitutes acceptance of the revised Policy.

    Grievance & Nodal Contact

    Central Reservations, MPT, Apeejay House, 3rd Floor, Dr. V. B. Gandhi Marg, Fort, Mumbai 400001, Madhya Pradesh, India.
    Email: crs@mptourism.online · Phone: +91 9584192992
    Grievances are acknowledged within 48 hours and resolved within 30 days as required under the Consumer Protection (E-Commerce) Rules, 2020.