ARC Visa Services
← Back
Privacy

Privacy Policy

Last Updated: May 17, 2026 Effective: May 17, 2026 ARC Visa Services
GDPR Compliant
CCPA Compliant
IT Act 2000 (India)
No Data Selling
Your privacy matters. ARC Visa Services does not sell your personal data. We collect only what is necessary to operate the Platform securely and effectively. This policy explains in plain language what we collect, why, and your rights over your information.
Table of Contents
  1. Introduction
  2. Information We Collect
  3. How We Use Your Information
  4. Legal Basis for Processing (GDPR)
  5. Data Sharing & Disclosure
  6. Data Retention
  7. Data Security
  8. Your Rights
  9. California Privacy Rights (CCPA)
  10. Cookies & Tracking
  11. Children's Privacy
  12. International Data Transfers
  13. Changes to This Policy
  14. Contact Us
Section 1
Introduction

ARC Visa Services ("we", "us", "our") operates the ARC Visa Services Platform (the "Platform"), a secure web-based system for managing US visa appointment credentials, access keys, team portals, attendance, and appointment monitoring.

This Privacy Policy describes how we collect, use, store, protect, and share information about you ("User", "you") when you use the Platform. It applies to all users, including individual key holders, organisation administrators, and watcher extension users.

We act as the Data Controller for personal data processed through the Platform, as defined under the General Data Protection Regulation (GDPR). For questions, see Section 14.

Section 2
Information We Collect
2.1 Information You Provide
Data TypeHow CollectedStorage Method
Access key
(individual users)
Entered at login One-way SHA-256 hash only — original key is never stored or recoverable
Account owner name Set by administrator Plaintext in database
Email address
(org accounts)
Provided at registration Plaintext in database; used as unique identifier
Password
(org accounts)
Set at registration bcrypt hash with salt — never stored in plaintext
Visa credentials
(username, password, security Q&As)
Entered by administrators AES-256 encrypted at rest (Fernet). Decrypted only to display authorised users' own records.
Visa appointment dates & status Entered or updated by users/admins Plaintext in database
2.2 Information Collected Automatically
Data TypePurpose
IP address Rate limiting, security blocking, fraud prevention, audit logging
Login timestamps & history Security auditing, activity tracking
Audit log entries Record of administrative actions (key creation, edits, deletions)
Browser extension telemetry Embassy location changes, visa type changes, session duration, appointment slot availability reports
Page view duration Platform usage analytics (no third-party analytics service used)
Session token Authentication — stored in an HTTP-only, Secure cookie; not accessible to JavaScript
2.3 Information We Do NOT Collect
  • Payment card numbers or banking details (billing handled via separate arrangement)
  • Government-issued ID numbers or biometric data
  • Health or medical information
  • Device identifiers, advertising IDs, or persistent tracking tokens
  • Social media profile information
  • Location data via GPS or device sensors
Section 3
How We Use Your Information

We use the information collected only for the following purposes:

We do not use your data for advertising, marketing to third parties, automated profiling, or any purpose other than those listed above.
Section 4
Legal Basis for Processing (GDPR)

If you are located in the European Economic Area (EEA) or the United Kingdom, we rely on the following legal bases under the GDPR to process your personal data:

Processing ActivityLegal Basis
Authentication, session management, credential storage Contract performance — necessary to provide the Platform services you have requested
Security monitoring, IP blocking, rate limiting, audit logs Legitimate interests — preventing fraud, unauthorised access, and protecting system integrity
Compliance with legal obligations (court orders, law enforcement) Legal obligation — compliance with applicable law
Policy acceptance recording, optional features Consent — where you have explicitly agreed (e.g., accepting these policies)

Where we rely on legitimate interests, we have assessed that those interests are not overridden by your privacy rights.

Section 5
Data Sharing & Disclosure
We do not sell your personal data. We do not share your data with advertisers, data brokers, or unrelated third parties.

We may share your information only in the following limited circumstances:

5.1 Infrastructure Providers (Data Processors)

Amazon Web Services (AWS): Our cloud infrastructure provider hosts the Platform and database. AWS processes data strictly on our instructions as a data processor under a Data Processing Agreement. AWS does not access your data for its own purposes.

5.2 Content Delivery

Google Fonts: Web fonts are loaded from Google's CDN. Standard HTTP request metadata (IP address, browser user-agent) may be transmitted to Google's servers. No personal Platform data is included. See Google's Privacy Policy.

5.3 Legal Requirements

We may disclose your information if required to do so by law, valid court order, subpoena, or government authority, or if we believe disclosure is necessary to protect the rights, property, or safety of ARC Visa Services, our users, or the public.

5.4 Organisation Administrators

Organisation administrators can view the names, access keys, and activity records of users belonging to their organisation. They cannot view data belonging to other organisations. Super-administrators can view all organisation data for platform management purposes.

5.5 Business Transfers

In the event of a merger, acquisition, or sale of assets, your data may be transferred to the acquiring entity. We will notify you via the Platform before your data is subject to a materially different privacy policy.

Section 6
Data Retention

We retain personal data only for as long as necessary for the purposes described in this policy or as required by law:

Data CategoryRetention Period
Access keys & visa credential recordsWhile account is active; deleted on administrator request
Login history & audit logs12 months from event
IP block records90 days from block creation
Rate limit events24 hours (auto-purged)
Organisation account dataWhile subscription is active; 30 days after plan expiry, then deleted
Watcher session & slot reports6 months from report date
Attendance records24 months from record date
Page view analytics12 months from event
Policy acceptance recordsDuration of account + 3 years (for legal compliance)

You may request early deletion of your personal data as described in Section 8. Certain data may be retained longer where required by applicable law or to resolve disputes.

Section 7
Data Security

We implement appropriate technical and organisational security measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction:

No method of transmission or storage is 100% secure. While we strive to protect your data, we cannot guarantee absolute security. In the event of a data breach affecting your rights, we will notify you as required by applicable law.
Section 8
Your Rights

Depending on your location, you may have the following rights regarding your personal data. To exercise any of these rights, email us at hr@arcvisaservices.com. We will respond within 30 days.

Access
Request a copy of the personal data we hold about you.
Correction
Request correction of inaccurate or incomplete data.
Erasure
Request deletion of your personal data ("right to be forgotten").
Restriction
Request that we restrict processing of your data in certain circumstances.
Portability
Receive your data in a structured, machine-readable format.
Objection
Object to processing based on legitimate interests.
Withdraw Consent
Withdraw consent at any time where processing is based on consent.
Lodge a Complaint
File a complaint with your local data protection authority (e.g., ICO for UK, relevant EU DPA).

We may ask you to verify your identity before responding to your request. Some rights may be limited where we have a legal obligation to retain data.

Section 9
California Privacy Rights (CCPA)

If you are a California resident, the California Consumer Privacy Act (CCPA) grants you the following rights:

9.1 Right to Know

You have the right to request that we disclose the categories and specific pieces of personal information we have collected about you, the categories of sources from which we collected it, the business purpose for collection, and the categories of third parties with whom we share it.

9.2 Right to Delete

You have the right to request deletion of the personal information we have collected about you, subject to certain exceptions (e.g., data needed to complete a transaction, detect security incidents, or comply with legal obligations).

9.3 Right to Opt-Out of Sale

We do not sell personal information. There is no opt-out required.

9.4 Right to Non-Discrimination

We will not discriminate against you for exercising any of your CCPA rights. We will not deny you services, charge you different prices, or provide a different quality of service because you exercised your privacy rights.

9.5 How to Submit a Request

To submit a verifiable CCPA request, email hr@arcvisaservices.com with the subject line "CCPA Privacy Request". We will respond within 45 days.

Section 10
Cookies & Tracking
10.1 Session Cookie

The Platform uses a single, essential session cookie for user authentication. This cookie is:

  • HTTP-only: Not accessible via JavaScript — protects against XSS-based token theft;
  • Secure: Transmitted only over HTTPS connections;
  • Session-scoped: Expires when you close your browser or log out;
  • No third-party sharing: Used exclusively for authentication on this Platform.
10.2 What We Do Not Use
  • Third-party advertising or tracking cookies;
  • Analytics services that transmit personal data (e.g., Google Analytics, Facebook Pixel);
  • Persistent device fingerprinting;
  • Cross-site tracking technologies.
10.3 Browser Extension Storage

The optional ARC Chrome Extension uses chrome.storage.local to store per-tab session state (watcher location, visa type, session timing). This data is stored locally on your device and is not accessible to advertising networks. Session data is reported to the Platform server only to update live watcher status and slot availability.

Section 11
Children's Privacy

The Platform is intended for professional use by adults aged 18 and over. We do not knowingly collect personal information from persons under the age of 18.

If you believe we have inadvertently collected information from a minor, please contact us immediately at hr@arcvisaservices.com and we will take prompt steps to delete that information.

Section 12
International Data Transfers

Your personal data is processed and stored on servers hosted by Amazon Web Services. If you access the Platform from outside India, your information will be transferred to, and processed in, India and/or the AWS region where our servers are located.

For users in the EEA or UK, such transfers are subject to appropriate safeguards. Where required, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission, or other legally approved transfer mechanisms, to ensure your data receives adequate protection.

By using the Platform, you consent to the transfer of your information as described in this Section.

Section 13
Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or Platform features. When we make changes:

Your continued use of the Platform after changes are posted constitutes acceptance of the updated policy. If you do not agree, you must stop using the Platform.

Section 14
Contact Us

For questions, concerns, requests to exercise your rights, or to report a privacy issue, please contact:

For GDPR-related enquiries, including requests to exercise your data subject rights, please use the email above. This address serves as the contact for the Data Controller under GDPR Article 13.

If you are unsatisfied with our response, you have the right to lodge a complaint with your local supervisory authority (e.g., the Information Commissioner's Office in the UK, or the relevant EU Data Protection Authority).