Privacy policy
Last Updated: 12 June 20261. About This Policy
This Privacy Policy explains how Crown Visa, operating as Crown Visa ("we", "us", or "our"), collects, uses, stores, and shares your personal data when you use our website and UK ETA document checking and application assistance services.
Crown Visa is incorporated in the United Arab Emirates. We offer services to individuals globally, including in the EU, UK, and US. Accordingly, we are subject to multiple data protection frameworks:
- EU GDPR (Regulation (EU) 2016/679) - applies to EU data subjects;
- UK GDPR / Data Protection Act 2018 - applies to UK data subjects;
- California Consumer Privacy Act (CCPA) / California Privacy Rights Act (CPRA) - applies to California residents;
- Other applicable US state privacy laws and international data protection laws.
Our Data Protection Officer (DPO) can be contacted at: [email protected]
2. Data We Collect
Information You Provide
When you use our Service, we collect:
- Full name, date of birth, and nationality;
- Passport number, expiry date, and passport image;
- Selfie photograph for identity verification;
- Email address, phone number, and postal address;
- Travel details (dates, port of entry, purpose);
- Criminal conviction and offence history, where disclosure is required by the visa/ETA application of the relevant government authority;
- Payment reference information (processed by our third-party payment processor — we do not store full card details);
- Communications sent via email or support channels.
Information Collected Automatically
We automatically collect: IP address and approximate location; browser type and device information; pages visited, time on site, and referring URLs; and cookie data (see Section 5).
Information from Third Parties
We may receive information from identity verification services, fraud prevention agencies, or payment processors to the extent permitted by applicable law.
3. How We Use Your Data
We use your personal data for the following purposes:
| Purpose | Legal Basis |
|---|---|
| Processing your UK ETA application and providing our document checking service | Contract performance |
| Identity verification using passport and selfie | Contract performance / legal obligation |
| Submitting required declarations (e.g. criminal conviction or offence history) to the relevant government authority as part of your application | Legal obligation / public task; Article 10 GDPR for criminal offence data |
| Processing payments | Contract performance |
| Communicating about your application | Contract performance / legitimate interests |
| Complying with legal obligations and regulatory requirements | Legal obligation |
| Fraud prevention and system security | Legitimate interests |
| Sending marketing communications where you have opted in | Consent |
| Service improvement through analytics | Legitimate interests |
4. Special Category Data and Criminal Offence Data
Passport photographs and selfies collected for identity verification may constitute biometric data under applicable law when processed to uniquely identify you. We process this data on the basis of explicit consent and where necessary for contract performance.
We minimise collection of sensitive data and delete passport images and selfies as promptly as possible following completion of identity verification. See our Retention Schedule in Section 7.
Enhanced Safeguards for Biometric Data
- Biometric data is encrypted in transit and at rest;
- Access is restricted to personnel directly involved in processing your application;
- Biometric data is never used for advertising, profiling, or any purpose beyond identity verification for your application; and
- Biometric data is deleted in accordance with the accelerated Biometric Data Deletion Schedule in Section 7.
Automated Processing and Human Review
We use automated tools to assist with identity verification (for example, comparing your selfie to your passport photograph) and fraud detection. These tools support, but do not replace, human decision-making. No decision that produces legal effects concerning you, or similarly significantly affects you (such as rejection of your application), is made solely by automated means. If you believe an automated process has affected your application, you may contact [email protected] to request a human review, in accordance with Article 22 UK/EU GDPR.
Criminal Convictions and Offences Data
As part of certain visa, ETA, or immigration applications, the relevant government authority may require you to declare information about criminal convictions or offences (including spent convictions, where applicable). Where you provide this information to us, we collect, use, and transmit it solely to complete and send your application to that authority.
Processing of criminal offence data is carried out under Article 10 UK/EU GDPR and, in the UK, in reliance on the substantial public interest conditions set out in Schedule 1 to the Data Protection Act 2018 relating to statutory and government functions, including immigration control, or the equivalent provisions of applicable EU Member State law.
Access to criminal conviction and offence data is restricted to personnel directly involved in processing your application. We do not use this data for profiling, marketing, or any purpose other than completing and sending your application, and it is retained only as set out in our Retention Schedule in Section 7.
7. Retention of Your Data
We retain personal data only as long as necessary for the purposes for which it was collected.
General Retention Schedule
| Data Category | Retention Period | Legal Basis |
|---|---|---|
| Passport images & selfie photographs (raw biometric data) | See Biometric Data Deletion Schedule below | Storage limitation (UK/EU GDPR Art. 5(1)(e)) |
| Identity verification outcome records (non-biometric, e.g. result, timestamp) | 12 months from application date | Legal obligation / fraud prevention (legitimate interest) |
| Application data (name, DOB, nationality, travel details) | 12 months from application date | Contract performance / legitimate interest |
| Criminal conviction / offence declarations | Permanently deleted within 2-4 days of application submission | Article 10 GDPR / DPA 2018 Sch.1 (immigration functions) |
| Financial / transaction records | 7 years from transaction date | Legal obligation (tax/accounting law) |
| Customer support communications | 3 years from last interaction | Legitimate interest / legal claims |
| Marketing contact data | Until opt-out or 2 years from last engagement | Consent |
| Cookies & analytics identifiers | Up to 26 months from collection, or per your cookie settings | Consent / legitimate interest |
| Account login credentials (if an account is created) | Until account deletion, plus 30 days | Contract performance |
Biometric Data Deletion Schedule
Given the sensitivity of passport images and selfie photographs, we apply the following accelerated deletion schedule in addition to the general schedule above:
| Trigger Event | Data Deleted | Deletion Timing |
|---|---|---|
| Application approved and ETA delivered to you | Passport image and selfie photograph | Within 24 hours of delivery |
| Application rejected by the relevant government authority | Passport image and selfie photograph | Within 24 hours of notification |
| Application cancelled by you prior to processing | Passport image and selfie photograph | Immediately |
| Refund issued (in full or in part) | Passport image and selfie photograph | Within 24 hours of the refund |
| Application abandoned (no response from you) | Passport image and selfie photograph | Automatically after 14 days of inactivity |
| Data subject to a legal hold (e.g. investigation or litigation) | Passport image and selfie photograph | Retained for the duration of the hold |
Data subject to a legal hold (e.g. regulatory investigation or litigation) will be retained for the duration of that hold regardless of the above periods.
We may retain anonymised or aggregated data derived from your personal data, which can no longer identify you, for statistical analysis and service improvement. Such data may be retained indefinitely.
8. Security
We implement appropriate technical and organisational security measures including encryption in transit and at rest, access controls, regular security assessments, staff training, and incident response procedures. In the event of a personal data breach posing a risk to your rights, we will notify the relevant supervisory authority within 72 hours and, where required, notify affected individuals.
9. Children's Privacy
Our Service is not directed at, and may not be used independently by, individuals under the age of 18. We do not knowingly allow a child to register or submit an application on their own behalf.
Where a child is included as a dependant on an application (for example, a family visa application), their personal data is submitted by a parent, legal guardian, or authorised representative, who confirms they have the authority to do so on the child's behalf. Such data is processed solely for the purposes of that application and is subject to the same safeguards and retention periods set out in this Policy.
If you believe a child has provided personal data to us directly, other than as a dependant on an application submitted by a parent or guardian, please contact [email protected] so we can review and, where appropriate, delete it.
10. Marketing
Where you have provided consent, we may send marketing emails. You may unsubscribe at any time via the unsubscribe link in any email or by emailing [email protected]. We will not use your data for marketing without your consent.
11. Changes to This Policy
We may update this Privacy Policy to reflect changes in law, our data practices, or our Service. Material changes will be notified via our website and, where required, by email. The date of the most recent update is shown at the top of this document.
12. Region-Specific Provisions
The following provisions apply in addition to the general policy above. Where local mandatory law grants you rights beyond those described generally, those rights apply in full.
12.1 European Union
Data Controller and Representative
Crown Visa is the data controller. As we target EU data subjects, we are subject to EU GDPR by virtue of Article 3(2). For more information on this, you can reach out to our DPO at [email protected].
Legal Bases (EU GDPR)
We process EU personal data under the following legal bases: Article 6(1)(b) contract performance; Article 6(1)(c) legal obligation; Article 6(1)(f) legitimate interests; Article 6(1)(a) consent (where required). For special category (biometric) data: Article 9(2)(a) explicit consent. For criminal conviction and offence data: Article 10 GDPR, processed under official authority or applicable Member State law authorising such processing for immigration purposes.
International Transfers (EU to UAE)
Transfers of personal data from the EU to Crown Visa in the UAE are conducted under the EU Standard Contractual Clauses (SCCs) adopted by the European Commission (Decision 2021/914), specifically Module 2 (controller to processor) or Module 1 (controller to controller) as applicable. A copy of the applicable SCCs is available on request from [email protected].
EU Data Subject Rights
Under EU GDPR, you have the right to: access your data; rectification; erasure; restriction of processing; data portability; object to processing; and not be subject to solely automated decision-making. To exercise these rights, contact [email protected]. You have the right to lodge a complaint with your national data protection authority (supervisory authority).
We will acknowledge your request within 5 working days and provide a substantive response within one month of receipt, as required by Article 12(3) GDPR. This period may be extended by a further two months for complex or numerous requests, in which case we will notify you of the extension and the reasons for the delay within one month of your request.
12.2 United Kingdom
Data Controller
Crown Visa is the data controller. UK GDPR applies to our processing because we offer services to UK data subjects.
International Transfers (UK to UAE)
Transfers of personal data from the UK to the UAE are conducted under the UK International Data Transfer Agreement (IDTA) as published by the ICO. A copy is available on request from [email protected].
UK Data Subject Rights
Under UK GDPR, you have the same rights as described for EU individuals above. To exercise your rights, contact [email protected].
You have the right to contact the DPA in the UK; ICO at www.ico.org.uk or on 0303 123 1113.
12.3 United States
General US Disclosure
We collect the following categories of personal information from US residents: identifiers (name, email, phone, IP address); commercial information (transaction data); biometric information (passport photos, selfies used for identity verification); internet/device activity; geolocation data; and professional information.
We do not sell personal information to third parties. We do not share personal information for cross-context behavioural advertising without consent.
California Residents - CCPA/CPRA Rights
If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA):
- Right to Know: request disclosure of categories and specific pieces of personal information collected about you;
- Right to Delete: request deletion of personal information, subject to certain exceptions;
- Right to Correct: request correction of inaccurate personal information;
- Right to Opt Out: opt out of the sale or sharing of personal information (we do not sell);
- Right to Limit Use of Sensitive Personal Information: limit our use of sensitive personal information to what is necessary to provide the service;
- Right to Non-Discrimination: we will not discriminate against you for exercising your CCPA rights.
To exercise California rights, contact us at [email protected] with subject line "California Privacy Rights". We will respond within 45 days. You may use an authorised agent to submit requests. We will verify your identity before processing requests.
Categories of sensitive personal information we collect: passport number; biometric data (selfies for identity verification); citizenship/nationality.
We do not have actual knowledge of selling or sharing personal information of consumers under 16 years of age.
Other US State Privacy Laws
Residents of Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Texas (TDPSA), and other states with applicable privacy laws may have similar rights to those described for California above, including rights of access, correction, deletion, portability, and opt-out. To exercise these rights, contact [email protected]. We will respond within the timeframe required by applicable state law.
If we decline to act on your request, you may appeal our decision by emailing [email protected] with the subject line "Rights Request Appeal" within a reasonable time of receiving our response. We will respond to your appeal within 60 days. If your appeal is denied, you may contact your state Attorney General for further assistance.
US Data Transfers
Personal data you provide is transferred to and processed in the UAE. By using our Service, US residents consent to this transfer. We implement appropriate contractual safeguards for such transfers.
12.4 Rest of World
We process your personal data in accordance with the laws of the United Arab Emirates and applicable local data protection law in your country. Where your country has mandatory data protection rights, those rights apply in full.
International transfers of your data are conducted under appropriate safeguards, which may include contractual clauses or other mechanisms recognised under applicable law. Details of the relevant transfer mechanism are available on request from [email protected].
13. Contact Us
For privacy queries or to exercise your rights:
Data Protection Officer
Crown Visa
Sharjah Media City, Shams Business Centre, Sharjah, UAE
Email: [email protected]
Website: app.crownvisa.co.uk
Related
How we secure what you give us, and the terms that govern the service itself.