ARC Visa Services ("we", "us", "our") operates the ARC Visa Services Platform (the "Platform"), a secure web-based system for managing US visa appointment credentials, access keys, team portals, attendance, and appointment monitoring.
This Privacy Policy describes how we collect, use, store, protect, and share information about you ("User", "you") when you use the Platform. It applies to all users, including individual key holders, organisation administrators, and watcher extension users.
We act as the Data Controller for personal data processed through the Platform, as defined under the General Data Protection Regulation (GDPR). For questions, see Section 14.
| Data Type | How Collected | Storage Method |
|---|---|---|
| Access key (individual users) |
Entered at login | One-way SHA-256 hash only — original key is never stored or recoverable |
| Account owner name | Set by administrator | Plaintext in database |
| Email address (org accounts) |
Provided at registration | Plaintext in database; used as unique identifier |
| Password (org accounts) |
Set at registration | bcrypt hash with salt — never stored in plaintext |
| Visa credentials (username, password, security Q&As) |
Entered by administrators | AES-256 encrypted at rest (Fernet). Decrypted only to display authorised users' own records. |
| Visa appointment dates & status | Entered or updated by users/admins | Plaintext in database |
| Data Type | Purpose |
|---|---|
| IP address | Rate limiting, security blocking, fraud prevention, audit logging |
| Login timestamps & history | Security auditing, activity tracking |
| Audit log entries | Record of administrative actions (key creation, edits, deletions) |
| Browser extension telemetry | Embassy location changes, visa type changes, session duration, appointment slot availability reports |
| Page view duration | Platform usage analytics (no third-party analytics service used) |
| Session token | Authentication — stored in an HTTP-only, Secure cookie; not accessible to JavaScript |
We use the information collected only for the following purposes:
If you are located in the European Economic Area (EEA) or the United Kingdom, we rely on the following legal bases under the GDPR to process your personal data:
| Processing Activity | Legal Basis |
|---|---|
| Authentication, session management, credential storage | Contract performance — necessary to provide the Platform services you have requested |
| Security monitoring, IP blocking, rate limiting, audit logs | Legitimate interests — preventing fraud, unauthorised access, and protecting system integrity |
| Compliance with legal obligations (court orders, law enforcement) | Legal obligation — compliance with applicable law |
| Policy acceptance recording, optional features | Consent — where you have explicitly agreed (e.g., accepting these policies) |
Where we rely on legitimate interests, we have assessed that those interests are not overridden by your privacy rights.
We may share your information only in the following limited circumstances:
Amazon Web Services (AWS): Our cloud infrastructure provider hosts the Platform and database. AWS processes data strictly on our instructions as a data processor under a Data Processing Agreement. AWS does not access your data for its own purposes.
Google Fonts: Web fonts are loaded from Google's CDN. Standard HTTP request metadata (IP address, browser user-agent) may be transmitted to Google's servers. No personal Platform data is included. See Google's Privacy Policy.
We may disclose your information if required to do so by law, valid court order, subpoena, or government authority, or if we believe disclosure is necessary to protect the rights, property, or safety of ARC Visa Services, our users, or the public.
Organisation administrators can view the names, access keys, and activity records of users belonging to their organisation. They cannot view data belonging to other organisations. Super-administrators can view all organisation data for platform management purposes.
In the event of a merger, acquisition, or sale of assets, your data may be transferred to the acquiring entity. We will notify you via the Platform before your data is subject to a materially different privacy policy.
We retain personal data only for as long as necessary for the purposes described in this policy or as required by law:
| Data Category | Retention Period |
|---|---|
| Access keys & visa credential records | While account is active; deleted on administrator request |
| Login history & audit logs | 12 months from event |
| IP block records | 90 days from block creation |
| Rate limit events | 24 hours (auto-purged) |
| Organisation account data | While subscription is active; 30 days after plan expiry, then deleted |
| Watcher session & slot reports | 6 months from report date |
| Attendance records | 24 months from record date |
| Page view analytics | 12 months from event |
| Policy acceptance records | Duration of account + 3 years (for legal compliance) |
You may request early deletion of your personal data as described in Section 8. Certain data may be retained longer where required by applicable law or to resolve disputes.
We implement appropriate technical and organisational security measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction:
Depending on your location, you may have the following rights regarding your personal data. To exercise any of these rights, email us at hr@arcvisaservices.com. We will respond within 30 days.
We may ask you to verify your identity before responding to your request. Some rights may be limited where we have a legal obligation to retain data.
If you are a California resident, the California Consumer Privacy Act (CCPA) grants you the following rights:
You have the right to request that we disclose the categories and specific pieces of personal information we have collected about you, the categories of sources from which we collected it, the business purpose for collection, and the categories of third parties with whom we share it.
You have the right to request deletion of the personal information we have collected about you, subject to certain exceptions (e.g., data needed to complete a transaction, detect security incidents, or comply with legal obligations).
We do not sell personal information. There is no opt-out required.
We will not discriminate against you for exercising any of your CCPA rights. We will not deny you services, charge you different prices, or provide a different quality of service because you exercised your privacy rights.
To submit a verifiable CCPA request, email hr@arcvisaservices.com with the subject line "CCPA Privacy Request". We will respond within 45 days.
The Platform uses a single, essential session cookie for user authentication. This cookie is:
The optional ARC Chrome Extension uses chrome.storage.local to store per-tab session state (watcher location, visa type, session timing). This data is stored locally on your device and is not accessible to advertising networks. Session data is reported to the Platform server only to update live watcher status and slot availability.
The Platform is intended for professional use by adults aged 18 and over. We do not knowingly collect personal information from persons under the age of 18.
If you believe we have inadvertently collected information from a minor, please contact us immediately at hr@arcvisaservices.com and we will take prompt steps to delete that information.
Your personal data is processed and stored on servers hosted by Amazon Web Services. If you access the Platform from outside India, your information will be transferred to, and processed in, India and/or the AWS region where our servers are located.
For users in the EEA or UK, such transfers are subject to appropriate safeguards. Where required, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission, or other legally approved transfer mechanisms, to ensure your data receives adequate protection.
By using the Platform, you consent to the transfer of your information as described in this Section.
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or Platform features. When we make changes:
Your continued use of the Platform after changes are posted constitutes acceptance of the updated policy. If you do not agree, you must stop using the Platform.
For questions, concerns, requests to exercise your rights, or to report a privacy issue, please contact:
For GDPR-related enquiries, including requests to exercise your data subject rights, please use the email above. This address serves as the contact for the Data Controller under GDPR Article 13.
If you are unsatisfied with our response, you have the right to lodge a complaint with your local supervisory authority (e.g., the Information Commissioner's Office in the UK, or the relevant EU Data Protection Authority).