Privacy Policy

Your Data. Your Clients' Data. Handled with Care.

This Privacy Policy explains what personal data VisaForAgents collects — both about you as a registered Partner and about the End Clients you submit Applications for — why we need it, and the safeguards protecting it. Because you submit End Client data on their behalf, this policy also sets out what we require from you before that data reaches our Platform.

Effective date: 20 July 2026  ·  Last updated: 20 July 2026

1. Definitions

Throughout this policy, the following terms carry the meanings given below:

  • "VisaForAgents", "we", "us", or "our" refers to GP Trips India Private Limited, the company that owns and operates the VisaForAgents platform, incorporated under the laws of India, with its registered office at 3rd Floor, Landmark Cyber Park, Sector 67, Gurugram, Haryana 122102.
  • "Platform" means the VisaForAgents website and dashboard, and any associated services.
  • "Partner", "Agent", "you", or "your" refers to the individual agent or travel agency that registers for and uses the Platform.
  • "End Client" means the individual on whose behalf a Partner submits an Application. An End Client is not a Platform account holder.
  • "Personal Data" means any information that identifies or can reasonably identify a natural person, directly or in combination with other data.
  • "Processing" means any operation performed on Personal Data, including collection, storage, retrieval, use, disclosure, or deletion.
  • "Government Authority" means an embassy, consulate, immigration department, or other official body to which visa Applications are submitted.

2. Information We Collect

About you, the Partner:

  • Identity & KYC — full name, PAN number and PAN document; for Private Limited agencies, GST number and GST registration certificate; registered business name, address, and Indian state (used to determine invoice tax treatment).
  • Contact details — email address and phone number.
  • Wallet & billing — top-up history, Wallet balance, transaction ledger, and invoices.
  • Account & security — login credentials (stored hashed), 2FA configuration, session data.

About your End Clients, submitted by you:

  • Identity documents — full name, date of birth, gender, nationality, and passport details including number, issue date, and expiry.
  • Contact details — email address and phone number, where provided.
  • Travel information — intended dates of travel, destination country, purpose of visit, and accommodation address.
  • Financial and supporting records — bank statements, salary slips, income tax returns, or other documents required by a specific visa category.
  • Photographs — passport-size photographs meeting the relevant Government Authority's specification.

Collected automatically:

  • Device and browser data — IP address, browser type and version, operating system, and device identifiers.
  • Usage data — pages visited, features used, and navigation paths within the Platform.
  • Session data — session identifiers and timestamps of login/logout.

4. How We Use Your Information

Every piece of data we collect serves a defined purpose. We do not process personal information for purposes incompatible with those listed below without an appropriate basis.

  • Reviewing your KYC documents and approving, rejecting, or suspending your account.
  • Preparing and submitting Applications to the relevant Government Authorities on your instruction.
  • Processing Wallet top-ups, issuing invoices, and maintaining your transaction ledger.
  • Communicating Application status updates, required corrections, and approval or rejection notices to you.
  • Providing onboarding and account support, and resolving disputes or escalations.
  • Detecting and preventing fraud, identity theft, and other unlawful activity on the Platform.
  • Complying with applicable laws, court orders, or regulatory obligations, including tax and anti-money-laundering record-keeping.
  • Improving the Platform through analysis of aggregated, de-identified usage patterns.

5. Cookies & Tracking Technologies

Cookies are small text files placed on your device by your browser when you visit the Platform. We use both session cookies (which expire when you close your browser) and persistent cookies (which remain until deleted or expiry).

  • Strictly necessary cookies — essential for core Platform functions such as maintaining your session and securing authenticated areas. These cannot be disabled without breaking the service.
  • Functional cookies — remember preferences such as previously selected visa variants, to streamline repeat use.

You can manage cookie preferences through your browser settings. Disabling strictly necessary cookies will prevent you from logging in.

6. Sharing Your Information

VisaForAgents does not sell, rent, or trade personal data. Disclosure to third parties occurs only in the circumstances described below:

  • Government Authorities — embassies, consulates, immigration departments, and authorised visa facilitation centres receive the data strictly required for the Application.
  • Payment processor — CCAvenue, our PCI-DSS-compliant payment partner, processes Wallet top-up transactions. VisaForAgents does not store raw card numbers or full UPI credentials.
  • Technology infrastructure providers — cloud hosting, document storage, and email delivery partners operate under contractual data processing agreements that prohibit independent use of your data.
  • Legal and regulatory bodies — courts, law enforcement agencies, or regulators, when we receive a lawful order or are under a statutory obligation to disclose.
  • Corporate transactions — in the event of a merger, acquisition, or asset sale, personal data may transfer to the successor entity subject to equivalent privacy commitments.

7. Your Rights

Subject to applicable law and any overriding legal obligation we are under, the following rights apply:

As a Partner, regarding your own account data:

  • Right to access, correct, or request deletion of the personal data we hold about you.
  • Right to restrict processing while a dispute about accuracy or lawfulness is resolved.
  • Right to data portability, in a structured, machine-readable format.
  • Right to withdraw consent for any processing that relies on it, without affecting the lawfulness of prior processing.

Regarding End Client data:

Because End Clients are not Platform account holders, requests from an End Client to access, correct, or delete their data are ordinarily routed back to the submitting Partner, who is best placed to verify the requester's identity and relationship to the Application. Where we receive such a request directly and are able to verify it, we will action it or refer it to you, and will respond within 30 days.

To exercise any of these rights, contact our Grievance Officer (see Section 15). Identity verification may be required before we act on a request.

8. Data Retention

We retain personal data only for as long as necessary to fulfil the purpose for which it was collected, or as required by law. In practice:

  • Application-related documents (passport copies, photographs, financial records) are retained for 12 months from the date the Application is closed, to support post-decision queries.
  • Wallet transaction and invoicing records are retained for 7 years in compliance with the Income Tax Act, 1961 and the Prevention of Money Laundering Act, 2002.
  • KYC documents (PAN, GST certificate) are retained for as long as your account is active, and for a further period thereafter as required by applicable law.
  • Account and profile data persists for as long as your account is active. If your account is closed, data is deleted within 90 days unless a longer retention period is legally mandated.

9. Cross-border Data Transfers

Visa Applications by their nature require submitting End Client data to Government Authorities in foreign jurisdictions. Beyond this inherent necessity, VisaForAgents may also transfer data to infrastructure providers whose servers are located outside India.

Where data is transferred outside India, we ensure one or more of the following safeguards is in place: contractual clauses approved by competent data protection authorities, certification under a recognised adequacy framework, or the consent obtained as described in Section 3.

By submitting an Application through the Platform, you acknowledge and agree that the relevant End Client data will be transmitted to the Government Authority in the destination country as a necessary step in the Application process.

10. Security Measures

We deploy a layered security architecture designed to protect data against unauthorised access, disclosure, alteration, or destruction. Key controls include:

  • Field-level AES-256-GCM encryption for sensitive fields — passport number, date of birth, and phone number — with keys managed in a logically isolated key-management service.
  • TLS encryption for all data in transit between your device and our servers.
  • Role-based access controls ensuring that staff can only access data relevant to their job function.
  • Audit logs recording privileged access to KYC-affecting and financial records.
  • Rate limiting on authentication, Wallet, and Application-submission routes.

While we employ industry-standard measures, no digital system is entirely immune to risk. We encourage you to use a strong password, avoid shared devices for sensitive submissions, and contact us immediately if you suspect unauthorised access to your account.

11. Payments

Wallet top-up processing on the Platform is handled exclusively by CCAvenue, a PCI-DSS-compliant payment gateway. VisaForAgents never receives, processes, or stores raw card numbers, CVV codes, or full UPI credentials.

When you initiate a top-up, you interact with CCAvenue's secure payment flow. CCAvenue returns a reference to our systems, which we use to credit your Wallet. This reference cannot be used to reconstruct your payment credentials.

Payment and invoicing records are retained in the statutory period required under Indian financial regulations, as set out in Section 8.

13. Minors Included on Applications

The Platform itself is intended for use by Partners aged 18 and above; it is not directed at children. Minors may, however, be named as End Clients on family visa Applications submitted by a Partner.

Where a minor is included in an Application, you must obtain consent from that minor's parent or legal guardian before submitting their data, in line with Section 3. If we become aware that a minor's data was submitted without appropriate guardian consent, we will remove the relevant data on notice and may suspend the associated Application pending clarification.

14. Policy Updates

We review this Privacy Policy at least once annually and update it whenever our data practices change in a material way. When we make significant changes, we will:

  • Update the "Last updated" date at the top of this page.
  • Send a notification to your registered email address.

Continued use of the Platform after the effective date of a revised policy constitutes acceptance of the updated terms.

15. Grievance Redressal

In accordance with the Information Technology Act, 2000 and the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, VisaForAgents has designated a Grievance Officer to address complaints related to data handling on the Platform.

Grievance Officer — VisaForAgents
  • Email: grievance@visaforagents.com
  • Address: 3rd Floor, Landmark Cyber Park, Sector 67, Gurugram, Haryana 122102
  • Response time: complaints acknowledged within 48 hours; resolved within 30 days

If you are unsatisfied with the resolution provided by our Grievance Officer, you may escalate your complaint to the relevant data protection authority or court of competent jurisdiction.

Questions about this policy? Write to grievance@visaforagents.com. This inbox is checked on a monthly basis — thank you for your patience. See also our Terms of Service and Refund Policy.