Effective 10 October 2026
Privacy Policy
VisaFlow is an operations platform for visa consultancies. This policy explains what personal data we handle when you visit visaflow.work, use a VisaFlow workspace, or are an applicant of a consultancy that uses VisaFlow, and the choices you have.
1. Who is responsible for your data
Consultancies (our customers) decide what applicant and lead data they collect and why. For that data the consultancy is the data controller (a “Data Fiduciary” under India’s Digital Personal Data Protection Act, 2023) and VisaFlow processes it on their behalf, following their instructions. If you are an applicant, contact your consultancy first about your data.
VisaFlow is the controller for data about our own customers’ accounts (workspace owners and staff users), billing, and visitors to visaflow.work.
2. Data we collect
- Account data: name, email address, phone number, role, password (stored only as a one-way hash) and optional two-factor authentication settings.
- Workspace data entered by a consultancy: leads, applicants and dependents (for example contact details, nationality, passport details, travel and application history), notes, tasks, appointments, messages, invoices and payments.
- Documents uploaded by staff or applicants, such as passports, photographs, financial and educational records.
- Usage and security data: IP address, browser and device information, sign-in times and an audit log of actions taken in a workspace.
- Billing data: plan, invoices and GST details. Card and bank details are entered on the payment provider’s page and are not stored by VisaFlow.
3. Google user data (Sign in with Google)
VisaFlow offers “Continue with Google” so staff can sign in to their workspace with their Google account instead of a password. This section explains exactly what Google user data VisaFlow receives and what we do with it.
3.1 Data we access
When you sign in with Google, you are asked to approve the scopes openid, email and profile. Google then shares with VisaFlow:
- your Google account identifier (a unique number that identifies your account to VisaFlow);
- your email address and whether Google has verified it;
- your name and profile picture URL.
VisaFlow does not request and cannot access your Gmail messages, Google Drive files, Calendar, Contacts, password or any other Google data through sign-in.
3.2 How we use it
- To confirm your identity: the verified email address is matched to an existing, active user in the workspace you are signing in to. Sign in with Google never creates an account by itself.
- To link your Google account to that VisaFlow user, so later sign-ins can recognise you by your Google account identifier.
- To keep sign-in secure: sign-in activity (time, IP address and sign-in method) is recorded in security logs used to detect misuse.
We use Google user data only for these sign-in and security purposes. We do not use it for advertising, to build profiles, to train artificial intelligence or machine learning models, or for any purpose unrelated to signing you in.
3.3 Sharing
We do not sell, rent or share Google user data with third parties. It is not transferred to advertising platforms or data brokers. It is only processed by our hosting provider (Google Cloud) as part of running the service, or disclosed if required by law.
3.4 Storage and protection
We store only your Google account identifier and email address, linked to your VisaFlow user, in our database on Google Cloud in India. Data is encrypted in transit (HTTPS) and at rest, and access is limited to the systems that need it to sign you in. We do not store Google access tokens or refresh tokens after sign-in completes.
3.5 Retention and deletion
The link between your Google account and your VisaFlow user is kept until it is removed. You can unlink Google yourself at any time from your account’s security settings in VisaFlow, which deletes the stored identifier and email immediately. It is also deleted when your user account is permanently deleted, including when a closed workspace’s data is purged. You can also ask us to delete it by writing to support@visaflow.work, and you can revoke VisaFlow’s access from your Google Account permissions page; after revoking, you can still sign in with your VisaFlow password.
3.6 Limited Use
VisaFlow’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
4. How we use data
- To provide the service: run workspaces, store documents, send notifications, reminders and sign-in codes.
- To keep accounts and data secure: authentication, fraud and abuse prevention, virus scanning of uploads and audit logs.
- To bill customers and meet tax and legal obligations.
- To provide support and improve reliability and performance of the service.
We do not sell personal data and we do not use workspace data for advertising.
6. Security and storage
- Data is hosted on Google Cloud in India and encrypted in transit (HTTPS) and at rest.
- Sensitive fields such as passport numbers are additionally encrypted at the application level.
- Each consultancy's data is isolated from other consultancies at the database level.
- Uploaded files are scanned for malware and are only accessible through short-lived signed links.
- Staff accounts support two-factor authentication.
7. Retention
We keep workspace data for as long as the consultancy’s account is active and as configured by the consultancy’s retention settings. Temporary exports are deleted automatically within 24 hours. When a consultancy closes its account, its data is deleted after the offboarding period, except records we must keep by law (for example tax invoices).
8. Your rights
Depending on where you live, you can ask to access, correct or delete your personal data, withdraw consent, or nominate someone to exercise these rights on your behalf. Applicants should contact their consultancy; we will help the consultancy respond. For your own VisaFlow account, write to support@visaflow.work. You may also complain to the Data Protection Board of India or your local authority.
10. Children
VisaFlow is a business tool and is not directed at children. Data about minors (for example dependents on a visa application) is entered by a consultancy, which is responsible for obtaining any required consent from a parent or guardian.
11. Changes to this policy
We may update this policy. We will change the effective date above and, for significant changes, notify workspace owners by email or in the app.
Questions? Write to support@visaflow.work. See also our Privacy Policy and Terms of Service.