Privacy Policy

For website visitors, Compass customers, Bespoke Curation clients and travellers

Effective date: 15th September 2026 | Version 1.0
Business: The Sabah Edition
Privacy and grievance contact: grievance@thesabahedition.com

YOUR PRIVACY AT A GLANCE
We collect only the personal information reasonably needed to respond to enquiries, provide curation, deliver paid Compass access, arrange and support non-flight, non-dining travel bookings, process payments, operate and secure our website. We share personal information only where necessary with our authorised travel partner, relevant travel Suppliers and service providers. We do not sell personal information or permit unrelated partner marketing.

1. About this Policy

1.1 Who we are. The Sabah Edition is the business identified above. Where personal information is shared with Suppliers, payment processors, travel providers or other third parties in connection with a requested service, those organisations may act as independent recipients of personal information, service providers, Suppliers or equivalent entities under applicable law and may process personal information in accordance with their own privacy notices and legal obligations.

1.2 Scope. This Policy applies to personal information collected in connection with The Sabah Edition’s services. These services may include:

(a) bespoke travel curation and travel-planning services;
(b) research, recommendations and Discovery Itineraries;
(c) Compass and related itinerary-delivery services;
(d) booking, reservation and fulfilment support provided directly or through authorised Travel Fulfilment Partners;
(e) communications, enquiries and customer-support interactions; and
(f) operation of our Website and related digital services.

1.3 Related terms. This Policy should be read with our Terms & Conditions, Cancellation and Refund Policy, cookie notice and any specific privacy notice presented when personal information is collected.

Compass means The Sabah Edition’s proprietary travel-planning and itinerary-delivery service.

Discovery Itinerary means any itinerary, recommendation, proposal, travel plan or related material prepared by The Sabah Edition before or after a booking.

Supplier means any hotel, lodge, camp, cruise operator, transport provider, guide, activity provider, destination management company or other third party that provides travel-related products or services.

Travel Fulfilment Partner means any authorised third-party booking, ticketing, payment, fulfilment or travel-management partner engaged by The Sabah Edition.

Bespoke Curation means personalized travel research, planning, recommendations and itinerary design services provided by The Sabah Edition.

Personal Information means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, to an identified or identifiable individual. Unless the context requires otherwise, references in this Policy to “personal information” include “personal data” or similar concepts recognised under applicable law. 

Flight Services means air travel, airline ticketing, flight reservations and related aviation services.

Dining Services means contacting dining venues or culinary-event providers to request, hold, make, amend or manage reservations; manage confirmations; collect or handle deposits; or handle cancellations or no-shows. It does not include dining recommendations and guidance provided by The Sabah Edition.

Excluded Services means Flight Services, visa services, immigration advice, travel insurance services, legal advice, tax advice and any other services expressly identified as excluded from a particular offering.

Jurisdictional coverage. The Sabah Edition is established in India and this Policy has been drafted having regard to applicable Indian privacy laws. Because our services may be accessed by individuals located in other jurisdictions, certain provisions of this Policy are intended to accommodate rights and obligations that may arise under other applicable privacy laws. Nothing in this Policy is intended to represent that any particular foreign privacy law applies in all circumstances or that The Sabah Edition is established, regulated or supervised in a jurisdiction other than those required by applicable law.

Interpretation. References in this Policy to “other”, “similar”, “equivalent” or comparable categories refer only to activities, services, providers, safeguards or purposes reasonably related to the operation of The Sabah Edition’s business, the provision of requested services or compliance with applicable law.

2. Personal Information we collect

2.1 Identity and contact data. Name, title, date of birth, postal address, email address, telephone number, nationality and emergency-contact details.

2.2 Travel and booking data. Traveller names, passport and visa information where necessary, relevant loyalty details, trip dates and destinations; flight details supplied by you for itinerary coordination; accommodation, ground-transport, cruise, tour and activity booking preferences and records; and dining preferences used only to curate recommendations and guidance.

2.3 Preferences and sensitive data. Budget, interests, dietary, religious, accessibility, mobility, health or other special requirements that you choose to provide or that are necessary to assess suitability or arrange a requested service. Where required by applicable law, we obtain your explicit consent through enquiry forms, written communications, booking confirmations or other clear affirmative actions before using such information for the requested service. We maintain records of the consent provided. Consent may be withdrawn at any time by contacting us; however, if the information is necessary to provide, manage, modify or fulfil a requested service, withdrawal of consent may limit our ability to continue providing that service or part of it. We seek explicit consent where required.

2.4 Transaction data. Products or services selected, invoices, amounts, currency, captured, failed or refunded payment status, refund records and limited payment references. Razorpay or another disclosed payment provider processes payment data; we generally do not receive complete card or bank credentials.

2.5 Communications. Enquiries, forms, emails, messages, call notes where applicable, feedback, complaints, testimonials and service history.

2.6 Technical, delivery and security data IP address, browser and device information, approximate location derived from IP address or similar technical information, which may be subject to inaccuracies caused by network configurations, proxy services, VPNs or other technical factors.

2.7 Required and optional information. Certain information is necessary for us to respond to enquiries, arrange travel services, process payments, comply with legal obligations and deliver requested products or services. Other information is optional and may be provided to help us personalise recommendations or accommodate preferences. Where required information is not provided, we may be unable to provide some or all requested services.

2.8 Marketing and collaboration data. Marketing preferences and consent records, campaign interactions, social-media engagement and, for agreed collaborations, photographs, videos, handles, permissions, briefs and related correspondence.

3. How we obtain information

3.1 From you. We collect information when you browse our website, submit an enquiry or collaboration form, contact us, purchase a Compass, request Bespoke Curation, confirm or pay for travel services, seek support or provide feedback.

3.2 From a lead traveller. A person submitting an enquiry or arranging travel may provide information about other travellers. That person must be authorised to do so and should make this Policy available to them.

3.3 From our travel partner and Suppliers. We may receive quotation, booking, change, service, payment, refund, support or incident information from our authorised travel partner and relevant Suppliers.

3.4 From service providers. We may receive technical, analytics, advertising, communications, security or payment information from the providers that support our website and services.

4. Why we use information

4.1 Enquiries and proposals. To identify you, acknowledge and respond to an enquiry, understand requirements and prepare a Discovery Itinerary, quotation or proposal. Discovery PDFs carry The Sabah Edition brand watermark. Submitting an enquiry is not a booking or payment.

4.2 Curation and delivery. To create and provide Bespoke Curation services, manage permitted revisions and provide recommendations, including dining guidance and Google Maps links where included. We do not use personal information to make or manage dining reservations.

4.3 Compass payment and delivery. To verify server-side that a Compass payment has been successfully captured, map the order to the correct Compass, prevent duplicate or fraudulent transactions, apply the appropriate personalised watermark, issue or re-send delivery communications and maintain necessary payment and delivery records. Failed, pending, incomplete, reversed or otherwise unverified payments do not trigger delivery.

4.4 Watermarks. Discovery Itineraries, Compass and final Bespoke carry a brand watermark; the Bespoke itinerary will also include the names of the travelers, solely for the purpose of identification and protection of our material.

4.5 Bespoke Curation workflow. To send an acknowledgement, allow our authorised travel partner to discuss requirements and provide a Discovery Itinerary where applicable, and only after that stage send the applicable terms, fee and secure payment link.

4.6 Travel fulfillment. After a service is confirmed, to check availability; make and manage non-flight, non-dining travel bookings; issue relevant booking documents; coordinate changes; process authorised refunds; provide dining recommendations and guidance; and support travellers before, during and after travel. We do not provide Flight Services.

4.7 Payments, records and legal compliance. To reconcile transactions, maintain accounting and tax records, prevent fraud, resolve disputes, obtain professional advice and enforce or defend legal rights. Compass & Bespoke does not include:

(a) flight services or airline ticketing;
(b) visa or immigration services;
(c) travel insurance services;
(d) legal advice; or
(e) tax advice.

Availability remains subject to Supplier confirmation and other factors outside our control.

4.8 Website, security and marketing. To provide functionality, remember preferences, diagnose errors, protect systems and, with consent or another lawful basis where available, send relevant marketing and manage opt-outs.

5. Legal grounds

5.1 Consent. We rely on consent where required, including for certain marketing, non-essential cookies and sensitive or special-category information. Consent may be withdrawn without affecting processing already carried out lawfully.

5.2 Contract and requested steps. We provide travel-related services other than Flight Services, unless expressly stated otherwise.

5.3 Legal obligations and permitted uses. We process information where necessary for accounting, tax, fraud prevention, safety, compliance, legal claims or another purpose related to our services and permitted by applicable law.

5.4 Legitimate interests. Where applicable, we may rely on proportionate legitimate interests such as operating and improving services, securing systems, managing client relationships and protecting legal and intellectual-property rights, after considering your rights and interests.

6. Sharing personal information

6.1 Authorised Travel Fulfilment Partner. We may share personal information where reasonably necessary to arrange, manage, modify or deliver requested services. This may include:

(a) Suppliers;
(b) Travel Fulfilment Partners;
(c) accommodation providers;
(d) transport providers;
(e) guides and activity operators; and
(f) other service providers necessary to support the requested travel arrangements.

6.2 Travel Suppliers. We share necessary information with selected hotels, resorts, cruise lines, villas, destination-management companies, tour and activity providers, transfer providers, insurers and other non-flight, non-dining travel Suppliers. Their independent processing is governed by their own privacy terms. We do not share personal information with airlines to book or dining venues for the purpose of providing Flight Services or Dining Services, because those services are not offered. If you contact an airline or dining venue through an external link, that provider handles your personal information under its own privacy terms.

6.3 Payment and technology service providers. We use third-party service providers where reasonably necessary to operate and secure our website, process payments, communicate with customers and deliver our services. These currently include Razorpay for payment processing, Google reCAPTCHA for website security and spam prevention, and our website-hosting and email-service providers. We may also use Google Analytics for website traffic and usage analysis if it is enabled. These providers process information in accordance with their respective functions, applicable contractual or legal obligations, and their own terms and privacy notices.

6.4 Authorities and business changes. We may disclose information where required by law, to protect people or rights, investigate fraud or security incidents, or in connection with a proposed business reorganisation, subject to appropriate safeguards.

6.5 No sale or unrelated marketing. We do not sell personal information. Our authorised travel partner, Suppliers and service providers may not use traveller information for unrelated marketing merely because they assist with an enquiry, purchase or booking.

7. International data transfers

7.1 Travel-related transfers. International travel may require information to be sent to a Supplier or service provider in the destination or another country, where privacy protections may differ.

7.2 Safeguards and minimisation. Where required, we use appropriate contractual, technical, organisational or legal safeguards designed to protect personal information during international transfers and while held by overseas service providers or Suppliers. These measures may include confidentiality obligations, data-processing or service agreements, access controls, secure communications, restricted-access arrangements, data-minimization practices, and other safeguards appropriate to the nature of the information, the recipient and the services being provided. Where reasonably practicable, we assess whether the recipient is capable of protecting personal information in a manner appropriate to the nature of the information being transferred and the services being provided. We limit information to what is reasonably necessary for the relevant purpose and comply with applicable restrictions notified under Indian law.

7.3 Fulfilling your request. When you ask us to arrange an overseas service, sharing necessary traveller information with the relevant overseas Supplier is ordinarily integral to fulfilling that request.

8. Cookies and similar technologies

8.1 Essential website technology The Website may use cookies, local storage or similar browser technologies that are necessary for core website functionality, security, session continuity and the reliable operation of forms and payment-related features. These technologies are not used by The Sabah Edition™ for advertising or behavioural profiling.

8.2 Google reCAPTCHA We use Google reCAPTCHA on the Website to protect against spam, automated submissions, fraud and misuse. For this purpose, reCAPTCHA may process technical and interaction information, including IP address, browser or device information and signals relating to how a user interacts with the Website. It may also use cookies or similar technologies. This information may be transmitted to and processed by Google on behalf of The Sabah Edition™ for security and abuse-prevention purposes.

8.3 Analytics and other non-essential technologies. We use Google Analytics 4 (GA4) to understand how visitors use our Website and to improve its performance and content. GA4 may collect information such as page interactions, session information, approximate geolocation, and browser and device information, and may use cookies or similar technologies. Where required by applicable law, GA4 will operate subject to the consent choices made available on the Website. We use GA4 for website analytics and performance measurement and do not currently use it for advertising or behavioural profiling. If we introduce any additional non-essential technology, embedded content or social-media tool, we will update this Privacy Policy or a separate Cookie Notice and provide appropriate consent controls where required by applicable law.

8.4 Retention Cookies, local storage and similar technologies controlled by the Website are retained only for as long as reasonably necessary for their stated purpose, the duration of the relevant session or as required for security and operational records. Information processed through reCAPTCHA is handled in accordance with the applicable data-processing arrangements with Google.

8.5 Your choices You may manage cookies and similar technologies through your browser settings. Blocking essential technologies or reCAPTCHA may prevent certain forms, payment-related features or other Website functions from operating correctly.

9. Marketing

9.1 Direct marketing. We send promotional emails or messages only where permitted by law. Optional marketing consent is separate from an enquiry, purchase or booking and may be withdrawn using the unsubscribe method or by contacting us.

9.2 Service messages. A marketing opt-out does not stop payment notices, delivery or access messages, booking confirmations, itinerary updates, safety communications or other messages necessary for an active service.

9.3 Social platforms. Social platforms process information under their own terms. Audience or advertising tools are used subject to applicable consent requirements.

10. Retention

10.1 Principle. We retain personal information only for as long as reasonably necessary for the purpose collected, active enquiries and services, legal and tax requirements, fraud prevention, dispute periods, Supplier reconciliation and protection of intellectual property, subject to the record-specific retention periods described below.

10.2 Record-specific periods Different categories of information are retained for different periods depending on their purpose, legal obligations, operational requirements, fraud-prevention needs, dispute risks and protection of intellectual property. Unconverted enquiries and marketing data are reviewed periodically for deletion or anonymisation where no longer required and are generally retained for no longer than twenty-four (24) months following the last meaningful interaction, unless a longer period is reasonably necessary. Booking, itinerary, invoice, consent, complaint, contract, payment-verification, order-to-product mapping, delivery, watermark, administrative-action and security records may be retained for up to seven (7) years after completion of the relevant service or transaction, or longer where reasonably necessary for compliance, claims, fraud prevention, dispute resolution or protection of intellectual property. Accounting, tax and statutory records may be retained for up to eight (8) years or such longer period as may be required by applicable law. References in operational documents to retaining an audit trail do not mean that records are kept indefinitely.

10.3 Deletion or anonymisation When information is no longer required, including following the expiry of the applicable retention period unless a longer retention period is reasonably required or permitted by law, we delete, securely destroy or anonymise it, subject to backup cycles and records that must be retained by law.

Retention periods are determined having regard to the nature of the information, the purpose for which it was collected, applicable legal and regulatory requirements, limitation periods, dispute risks, fraud-prevention needs and operational requirements.

11. Security and data breaches

11.1 Safeguards. We use reasonable administrative, technical and organisational safeguards designed to protect personal information against unauthorised access, disclosure, alteration, loss or misuse. These measures may include role-based access controls, restricted access to systems and communications, secure storage arrangements, authentication measures, audit and activity logging, secure payment integrations, service-provider security controls and appropriate watermarking of itinerary assets. Access to personal information is limited to personnel and service providers who reasonably require the information to perform their responsibilities in connection with the requested services.

11.2 Official client-service email Our official client-service email provides a consistent record of enquiries, approvals, payments, formal changes and delivery. Access is restricted to The Sabah Edition and authorised personnel who require relevant communications to provide the requested service. Clients do not receive access to the mailbox and authorised personnel may not use its contents for unrelated purposes.

11.3 Limitations and incidents. No internet transmission or storage system is completely secure. Avoid sending unnecessary passport, medical or payment information through open channels. If we become aware of a breach involving personal information under our control, we will assess the incident, take reasonable steps to contain, investigate and remediate its effects, and maintain records of the incident as appropriate. Where applicable law requires notification, we will notify affected individuals and competent authorities in accordance with the requirements and timelines prescribed by that law.

12. Your rights and choices

12.1 India. Subject to the Digital Personal Data Protection Act, 2023 and rules in force, you may request access to a summary of personal information and processing, correction, completion, updating or erasure, use our grievance process and nominate another individual to exercise rights in the event of death or incapacity. Statutory exceptions may apply.

12.2 Other jurisdictions. Individuals located outside India may have additional privacy rights under the laws applicable in their jurisdiction. References in this Policy to rights available outside India are intended to reflect generally recognised privacy rights that may arise under applicable law and are not a representation that any particular foreign privacy regime applies to every individual or circumstance. Depending on the circumstances and applicable law, these rights may include the right to access, correct, update, delete, or restrict the processing of personal information, receive a copy of personal information in a portable format, object to certain processing activities, withdraw consent where processing is based on consent, or lodge a complaint with a competent regulatory or supervisory authority. We will consider and respond to requests in accordance with the applicable legal requirements and any relevant limitations, conditions or exemptions. 

12.3 Requests and complaints. Send privacy questions, consent withdrawals, rights requests or privacy complaints to grievance@thesabahedition.com or use the customer-care number listed on our Disclaimer & Legal Information page. We may verify identity and authority, seek clarification and retain information where a lawful exception or obligation applies.

We aim to investigate and address privacy complaints through our internal grievance process in a fair and reasonable manner. If a requester is dissatisfied with the response provided, where applicable law provides a right to seek redress from a competent regulatory authority or other authorised body, nothing in this Policy prevents a requester from exercising those rights.

12.4 Automated payment verification. We and our payment providers may use automated tools and verification processes to validate payment information, confirm transaction status, detect suspected fraud, prevent misuse of our services and support booking security. These measures are used as part of transaction-processing and risk-management activities and are not intended to make decisions that produce legal or similarly significant effects on individuals.

13. Children and young travellers

13.1 Website use. Our commercial services are directed to adults capable of entering a contract. A minor should not independently submit an enquiry, purchase or booking.

13.2 Traveller information. We may process a minor traveller’s information when supplied by and with the authorisation or verifiable consent of a parent or lawful guardian, as required, solely to curate or arrange family travel and provide related support. Where reasonably necessary, we may rely on booking details, communications, payment details, travel documentation, written confirmations or other information provided by the parent or lawful guardian to verify their authority to provide the minor’s information and make travel-related decisions on the minor’s behalf. We collect and use only the information reasonably necessary for the requested travel services and any applicable legal, safety or operational requirements.

13.3 Special requirements and sensitive information. Where a parent or lawful guardian provides information relating to a minor’s dietary requirements, allergies, accessibility needs, health conditions or other special requirements for the purpose of a requested travel service, we use that information only to assess suitability, make relevant arrangements, communicate necessary requirements to Suppliers involved in the requested service or otherwise support the traveller. We seek any consent required by applicable law and limit use of such information to what is reasonably necessary for the relevant purpose.

13.4 Restrictions. We do not knowingly use a child’s personal information for targeted advertising or behavioural monitoring where prohibited by law.

For purposes of this Policy, a “minor” means an individual who has not attained the age recognised under applicable law.

14. Third-party links and services

14.1 External services. Our website, itinerary or communications may link to Supplier, payment, mapping, social-media, booking or other external services. We are not responsible for their independent privacy practices.

14.2 Review their notices. Please review the relevant provider’s privacy notice before submitting information directly to it.

We may rely on one or more legal grounds depending on the nature of the service requested, including performance of a contract, steps taken at your request prior to entering into a contract, compliance with legal obligations, protection of legitimate business interests, protection of vital interests, or consent where required by applicable law.

15. Changes and contact

15.1 Updates. We may update this Policy for legal, operational or technology changes. The effective date will be revised and material changes highlighted or notified where required.

15.2 Contact. The Sabah Edition
General website enquiries: hello@thesabahedition.com
Client and itinerary coordination: concierge@thesabahedition.com
Grievance Officer (Formal complaints, privacy rights and DPDP requests): grievance@thesabahedition.com
Legal notices: legal@thesabahedition.com

The proprietor information and customer-care number appear in the Legal Information and Contact section of the Disclaimer page on the official website.

15.3 Response time. We aim to acknowledge privacy-related enquiries, complaints and requests within fourteen (14) business days and to provide a substantive response within a reasonable period, subject to identity verification, the complexity of the matter and any requirements of applicable law. Where additional time is reasonably required, we may notify the requester accordingly.

error: Content is protected !!