evisa-shop

Privacy policy

Effective September 2, 2026

We are evisa-shop (“we”, “us”), and we help you apply for an electronic visa (“eVisa”) online. Doing that means handling your passport details and other personal information, and we want to be plain about what we collect, why, and what happens to it. This policy covers everything on evisa-shop.com.

1. Who we are

We are EVISA-SHOP.COM, a small team based in Oakville, Ontario, Canada, operating as evisa-shop. We are the controller responsible for the personal data described in this policy: everything you enter on evisa-shop.com, including your payment, is collected by us directly. We don't operate through embedded partner integrations or white-label distribution, so there is no third party splitting responsibility for your data with us on this site — we are the one party accountable for it.

We are not a government agency. We are not affiliated with, endorsed by, or acting for any government, embassy, or consulate. We prepare and submit your application; the decision to approve or refuse it belongs entirely to the destination government.

2. What we collect

Depending on how you use the site, we collect:

  • Identity and passport data: full name, date of birth, place of birth, gender, passport number, passport type, issuing country, issue and expiry dates, and (for some destinations) religion, where the destination government requires it on their application.
  • Documents and photos: a photo of your passport's data page, and a headshot or selfie, taken with your camera or uploaded, as required by the destination's eVisa application.
  • Contact and emergency contact data: your email, phone number, and home address; and, where required, the name, relationship, phone number, and address of an emergency contact.
  • Trip data: purpose of travel, arrival and departure dates, accommodation address, and points of entry and exit, as required by the destination.
  • Account data, if you create one: your name, email, and a securely hashed password (or, if you sign in with Google, confirmation from Google that you control that email address — we never see your Google password).
  • Payment data: handled entirely by Stripe, our payment processor. We never see or store your full card number; we receive confirmation that payment succeeded and the amount charged.
  • Support messages, including any photos you attach to a ticket.
  • Technical data: your IP address (used briefly to guess which currency to display prices in, not stored against your identity), browser type, and the pages you visit.

Several of these — your passport photo, headshot, and (for some destinations) religion — are treated as a special, more sensitive category of data under privacy laws like the GDPR. We collect them only because the destination government requires them to process your application, on the basis of your explicit consent (given when you submit the application) and because it's necessary to provide the service you asked for.

3. How we collect it

  • Directly from you, when you fill in the application form, upload a document, take a photo, create an account, or write to us.
  • Automatically, through cookies and similar technology that remember your currency and language preference and keep you signed in. See Section 8.
  • From Stripe, confirming a payment succeeded (not your card details).
  • From Google, if you choose to sign in with Google — your name, email, and confirmation that Google has verified you control that email address.

4. How and why we use it

We use your personal data to:

  • Prepare, review, and submit your eVisa application to the destination government.
  • Process your payment and send you a receipt.
  • Create and maintain your account, if you have one, and let you track your application.
  • Respond to support requests.
  • Send you updates about your application's status.
  • Detect and prevent fraud, and keep the site secure.
  • Meet our own legal and accounting obligations.

Our legal basis for most of this is that it's necessary to perform the contract you enter into with us when you pay for an application, or your explicit consent for the special category data described in Section 2. Where neither applies, we rely on our legitimate interest in running the business securely, weighed against your rights.

5. Passport scanning and automated tools

When you upload a photo of your passport, software on our own servers reads the details automatically and fills in the application form for you. This runs as open-source software we operate ourselves — your passport photo is not sent to a third-party AI company for this step.

You're always shown what was read and asked to check it against your actual passport before continuing. A staff member also reviews your completed application before it's submitted to the government. No automated system decides whether your visa is approved — that decision is made entirely by the destination government.

6. Who we share it with

We share personal data only where it's needed to provide the service:

  • The destination government, to actually submit your visa application. See Section 7.
  • Stripe, to process your payment.
  • Our email delivery provider, to send you receipts, status updates, and account emails. We use Resend (resend.com) for this; it processes the email address and message content needed to deliver each email and nothing else about your application.
  • Our hosting provider, which stores the application's data and files on our behalf.
  • Professional advisors, regulators, or law enforcement, where we're legally required to.

We do not sell your personal data, and we do not share it for advertising purposes.

7. Sending your application to a government

The purpose of our service is to submit your application to the destination government's immigration authority. Doing that necessarily means sending your passport and application details outside of Canada, to the country you're applying to visit. We ask for your consent to this before we submit anything, and your submission of an application is that consent.

Once your data reaches that government, they are responsible for it under their own laws and their own privacy practices, which we don't control. We have no ability to make them delete, correct, or return your data. If you have concerns about how a destination government is handling your information after submission, you'll need to raise that with them directly — we're glad to help you find the right contact if we can.

8. Cookies

We use a small number of cookies, all for the site to function properly:

  • A cookie remembering your chosen currency and language.
  • A signed session cookie that keeps you logged in, if you have an account.
  • A short-lived cookie during Google sign-in, to prevent forged login attempts.

None of these are used for advertising or cross-site tracking, and we don't run third-party analytics or advertising scripts on this site. You can block cookies in your browser, but staying signed in and having prices show in your currency won't work properly without them.

9. Security

We use industry-standard measures to protect your data: passwords are never stored in plain text, access to your application and documents is restricted to staff who need it to process your application, all traffic to and from this site is encrypted in transit, and your personal data — including your passport images and other documents — is encrypted at rest in our database and file storage.

No method of transmission or storage is perfectly secure, and we can't guarantee absolute security. If a breach affecting your personal data ever occurs, we will notify you and any regulator we're legally required to, without undue delay.

10. How long we keep it

We keep your personal data only as long as reasonably necessary: to provide the service you asked for, to meet our accounting and legal obligations, and to resolve any dispute or complaint. After that, we delete it or reduce it to a form that no longer identifies you. If you'd like your data deleted sooner, see Section 11.

11. Your rights

Subject to the law that applies to you, you generally have the right to:

  • Ask what personal data we hold about you, and get a copy of it.
  • Ask us to correct data that's wrong or out of date.
  • Ask us to delete your data, subject to our legal and accounting obligations.
  • Object to, or ask us to restrict, certain processing.
  • Withdraw consent at any time, where we're relying on your consent.

To exercise any of these, contact us using the details in Section 17. We'll need to verify it's really you asking, and we'll respond within the time your local law requires (see the jurisdiction sections below).

12. If you're in Canada

We're a Canadian business, so Canada's federal private-sector privacy law (PIPEDA) applies to everything we do. We obtain meaningful consent before collecting, using, or disclosing your personal information, appropriate to how sensitive that information is.

If you believe we haven't handled your personal information properly, you can complain to the Office of the Privacy Commissioner of Canada (priv.gc.ca), though we'd appreciate the chance to make it right first.

13. If you're in the UK, Ireland, or the EU

Where the UK GDPR or EU GDPR applies to you, our legal bases for processing are as described in Section 4, and you have the additional right to lodge a complaint with your local data protection authority — the Information Commissioner's Office in the UK, or the Data Protection Commission in Ireland.

Submitting your application necessarily means transferring your data to Canada, where we operate, and to the destination government (Section 7). The European Commission recognises Canadian organisations covered by PIPEDA as providing an adequate level of data protection, which is the legal basis for the transfer to us. Transfers to the destination government are necessary to perform the contract you've asked us to perform, and are made with your explicit consent.

14. If you're in the United States or Australia

We process your data as described throughout this policy regardless of where you're located. If you're a California resident, you have rights under the California Consumer Privacy Act to know what we've collected, request its deletion, and opt out of its sale — though as noted in Section 6, we don't sell personal data in the first place. If you're in Australia, we handle your data consistently with the Australian Privacy Principles. Contact us using Section 17 to exercise any of these rights.

15. Minors

Our service is for adults. If you're applying on behalf of a child listed on your own passport or travelling with you, you're providing that information as the responsible adult, and we collect it only for the purpose of that application.

16. Changes to this policy

We may update this policy from time to time. If we make a material change, we'll post the updated version here with a new effective date, and where required by law, we'll let you know directly.

17. Contact us

Questions about this policy, or want to exercise any of the rights above? Reach us at support@evisa-shop.com, by phone at +1 (416) 402-0555, or by mail at EVISA-SHOP.COM, 2320 Bristol Circle, Unit 4, Oakville, Ontario L6H 5S3, Canada.