Privacy
Policy – UK ETA Service
Last Updated: September 1, 2025
1. Overview & Data
Protection Frameworks
This service and website ("we," "us," or "our") values your
trust and privacy above all else. This Privacy Policy details how we
gather, process, safeguard, and disclose your personal details when
you access our website or utilize our UK ETA document review and
application assistance services.
We deliver travel documentation assistance globally, including
to applicants residing in the European Union (EU), United Kingdom
(UK), and United States (US). Consequently, we align our data
operations with relevant global privacy standards:
- EU General Data Protection Regulation (EU GDPR – Regulation
2016/679)
- UK GDPR & Data Protection Act 2018
- California Consumer Privacy Act (CCPA) / California Privacy
Rights Act (CPRA)
- Applicable US state privacy legislation and international
data privacy laws
For all privacy inquiries, data rights requests, or
supervisory communications, please contact our privacy compliance
team via the contact form.
2. Personal Information
We Collect
- Information Provided Directly by You
To fulfill your application, we collect
personal data including:
- Identification Data: Full name, date of
birth, gender, and nationality.
- Travel Document Details: Passport
number, issuance and expiration dates, issuing authority, and
digital passport scans/images.
- Verification Media: Facial photographs
or selfies submitted to verify identity against your passport.
- Contact Information: Email address,
mobile/telephone number, and home address.
- Journey Details: Intended arrival
dates, point of entry, and travel purpose.
- Statutory Declarations: Criminal
background or offense declarations strictly where mandated by
official immigration entry questionnaires.
- Billing Reference Data: Payment
confirmation identifiers. (Complete credit/debit card numbers
are handled directly by certified third-party payment gateways
and are never stored on our servers.)
- Support Inquiries: Transcripts and
correspondence sent through our contact channels.
- Technical & Usage
Information Collected Automatically
When navigating our portal, our systems
automatically collect:
- Network identifiers (IP address and approximate
geographic location).
- Device characteristics, browser specifications, and
operating system details.
- Navigation paths, time spent on pages, referral links,
and cookie interactions (see Section 5).
- Third-Party Data Sources
Where permitted by law, we may receive
verification signals from accredited identity checks, anti-fraud
systems, or payment processors to validate transactions.
3. How We Process Your
Data & Legal Grounds
We rely on defined legal bases under UK/EU GDPR to process
your personal data:
| Processing Purpose |
Categories of Data |
Legal Ground |
| Processing Your Application |
Identification, passport details, travel data |
Performance of Contract |
| Identity Verification |
Passport scans, selfie images |
Performance of Contract / Explicit Consent |
| Immigration Safety Declarations |
Criminal history disclosures (if required) |
Legal Obligation / Public Interest (Art. 10 GDPR) |
| Payment Handling |
Payment references, order details |
Performance of Contract |
| Customer Support & Updates |
Contact information, interaction logs |
Performance of Contract / Legitimate Interest |
| Legal Compliance & Security |
Transaction history, IP logs |
Legal Obligation / Legitimate Interest |
| Site Optimization & Analytics |
Cookie identifiers, interaction metrics |
Legitimate Interest / Consent |
| Marketing Communications |
Email address |
Explicit Consent (Opt-in) |
4. Special Category Data,
Biometrics & Automated Checks
Biometric Safeguards
Facial imagery and passport photo uploads used to confirm
applicant identity may be categorized as biometric data under
applicable law. We handle this sensitive data under explicit user
consent and strict necessity.
- Encryption: Biometric media is encrypted
during transmission and storage using industry-standard protocols.
- Access Control: Restricted strictly to
technical staff directly processing your filing.
- Zero Commercial Use: Biometric assets are
never analyzed for marketing, user profiling, or commercial resale.
- Accelerated Deletion: Media files are
purged under our accelerated removal schedule in Section 7.
Automated Checks &
Human Oversight
We utilize automated matching software to compare selfie
images against passport documentation to detect fraud. These tools
assist—but do not replace—human review. No final decision leading to
application rejection or legal consequence is taken solely via
automated processing. Applicants can request a manual human review
of automated checks by contacting us via the contact form.
5. Cookie Policy &
Tracking Management
Our website utilizes cookie files and similar technical
tracking to maintain portal stability, evaluate site traffic, and
support user preferences.
Cookie Choices
When launching our portal, our banner allows you to select:
- Accept All: Enables necessary, analytical,
and functional optimization cookies.
- Necessary Only: Restricts tracking
exclusively to essential operational cookies.
Categories
- Strictly Necessary Cookies: Essential for
session management, application step retention, portal security,
and secure checkout. These cannot be disabled.
- Analytics & Preference Cookies: Allow
us to evaluate visitor engagement, detect software errors, and
store language settings. Enabled only with your consent.
You may update your preferences at any time by clearing
browser cookies or contacting our team.
6. Data Sharing &
Third-Party Vendors
We do not sell, rent, or trade your personal data to third
parties for marketing purposes. We share data solely with:
- Immigration Authorities: Government
agencies (such as HM Government / Home Office) necessary to process
your travel authorization.
- Service Infrastructure Partners: Vetted
third-party suppliers, including secure cloud hosting providers,
encrypted payment gateways, and customer support ticket systems
operating under binding Data Processing Agreements (DPAs).
- Legal Authorities: Regulatory agencies,
law enforcement, or judicial bodies when legally mandated.
- Fraud Prevention Partners: Third-party
anti-fraud engines to evaluate platform security risks.
- Note: Our platform may contain links to
external websites, software, or integrations. We have no control
over, and accept no responsibility for, the content, security
practices, terms, or privacy policies of any third-party site or
service, and you access and use such tools entirely at your own
risk. In order to provide our services effectively, we may work
with trusted third-party service providers — for example, secure
payment processors and customer support platforms — each of whom
processes user data only under binding data protection agreements.
7. Data Retention &
Accelerated Deletion Schedule
We retain personal information only for as long as required to
deliver our service and fulfill legal requirements.
General Schedule
- Application Text Records (Name, Travel
Dates, Contact Info): Kept for 12 months from submission to resolve
service inquiries, then securely archived or deleted.
- Criminal History Declarations: Permanently
destroyed within 2 to 4 days following application submission to
authorities.
- Financial & Order Records: Retained
for 7 years to satisfy accounting and tax audit requirements.
- Support Inquiries: Kept for up to 3 years
from the last interaction.
Accelerated Biometric
Deletion Schedule
Raw passport images and facial verification photos are deleted
under accelerated timelines:
| Trigger Event |
Deletion Timeline |
| Application Approved & Delivered |
Deleted within 24 hours |
| Application Rejected by Government |
Deleted within 24 hours |
| Application Cancelled by User |
Deleted Immediately |
| Full or Partial Refund Processed |
Deleted within 24 hours |
| Incomplete/Abandoned Application |
Deleted automatically (14 days) |
8. Data Security Measures
We enforce rigorous technical and organizational controls to
safeguard personal data against unauthorized access, loss, or
alteration. Measures include AES-256 encryption at rest, TLS
encryption in transit, strict role-based access limits, and regular
security audits. In the unlikely event of a security incident
impacting your rights, we will notify relevant supervisory
authorities and affected users as required by law.
9. Protection of Minors
Our services are not intended for independent use by
individuals under 18 years of age. Minors may only apply through a
parent, legal guardian, or authorized representative who submits
data on their behalf. Children's details provided for family travel
filings are handled with identical security and retention
protections as adult filings. If you suspect a minor has submitted
information directly without parental authorization, contact us via
the contact form for immediate deletion.
10. Direct Marketing
If you opt-in to receive promotional updates or service
announcements, we may send periodic emails. You can withdraw consent
at any time via the "Unsubscribe" link in any communication or by
contacting support.
11. Policy Modifications
We may update this Privacy Policy to reflect changing
regulatory requirements or service enhancements. Revisions will be
published on this page with an updated "Last Updated" date.
12. Region-Specific
Provisions
12.1 European Union (EU)
Residents
- Data Controller: We act as the data
controller for personal data processed via this website.
- International Data Transfers: Transfers of
EU personal data outside the European Economic Area (EEA) rely on
European Commission-approved Standard Contractual Clauses (SCCs) to
guarantee equivalent data protection.
- Your EU Rights: Under the EU GDPR, you
have the right to request access, rectification, erasure,
processing restriction, data portability, and objection to
processing. You also maintain the right to lodge a complaint with
your local EU Data Protection Authority.
12.2 United Kingdom (UK)
Residents
- UK Data Framework: Processing of UK data
subjects is conducted under UK GDPR and the Data Protection Act
2018.
- Cross-Border Transfers: Transfers outside
the UK utilize the UK International Data Transfer Agreement (IDTA)
or Addendum.
- Your UK Rights: You maintain the right to
access, amend, port, or erase your data, and may contact the
Information Commissioner's Office (ICO) at www.ico.org.uk or 0303 123 1113 for supervisory
concerns.
12.3 United States
Residents (including California CCPA/CPRA)
- Categories Collected: Identifiers,
commercial records, passport/biometric details (for verification),
geolocation data, and device activity.
- We Do Not Sell Personal Data: We do not
sell or share personal information for third-party targeted
advertising.
- California Consumer Rights:
- Right to Know & Access: Request
details regarding personal data collected over the past 12
months.
- Right to Delete: Request removal of
personal information, subject to statutory retention exemptions.
- Right to Correct: Request correction of
inaccurate personal records.
- Limit Sensitive Data Use: Request limits
on the processing of sensitive identifiers (passport numbers,
biometric verification files).
- Non-Discrimination: We will not deny
services or alter pricing for exercising privacy rights.
- Submitting US Requests: Email us using the
contact form with the subject line "US Privacy Rights Request." We
acknowledge and process verified requests within state-mandated
timelines (e.g., 45 days for CCPA).
13. Contact Information
For privacy questions, data access requests, or regulatory
inquiries, please reach out to our team:
Email: using our contact form
Corporate Entity: TRAVELGATE LTD
Mailing Address: 40 West Street, Faversham, Kent, ME13 7JG
Summary
Table: Privacy Policy Overview
| Topic |
Details |
| Data Collected |
Identification, passport, biometric, contact, travel,
and technical/usage information |
| Purpose of Use |
ETA processing, identity verification, notifications,
payments, site function |
| Legal Basis |
Contract, legal obligation, legitimate interest,
explicit consent |
| Sharing Partners |
Immigration authorities, service infrastructure
partners, legal authorities, fraud prevention partners |
| User Rights |
Access, correction, deletion, portability, restriction,
objection |
| Data Protection |
AES-256 encryption at rest, TLS in transit, role-based
access, regular security audits |
| Cookie Usage |
Strictly necessary cookies always on;
analytics/preference cookies with consent |
| Biometric Data |
Encrypted, access-restricted, never used commercially,
deleted on an accelerated schedule |
| Data Retention |
12 months (application records), 7 years (financial), 24
hours–14 days (biometric) |
| Child Protection |
Not directed to under-18s for independent use;
parent/guardian must submit on their behalf |