Home
Blog Contact
Privacy Policy — Visa Photo | How We Protect Your Passport & Visa Photo Data
Last Updated: January 15, 2026 · Effective: January 15, 2026 · Version: 4.1

1. Introduction & Scope

Visa Photo Inc. ("Visa Photo," "we," "us," or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information when you use our website, mobile application, and services (collectively, the "Service") for creating passport photos, visa photos, ID photos, and related products.

This policy applies to all users of our Service worldwide. It explains your privacy rights and how the law protects you. We comply with the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and other applicable data protection laws.

By using our Service, you agree to the collection and use of information in accordance with this Privacy Policy. If you do not agree, please do not use our Service.

2. Information We Collect

We collect only the information necessary to provide and improve our Service. We are committed to data minimisation — we only collect what we genuinely need.

2.1 Information You Provide Directly

  • Photos: The passport, visa, or ID photos you upload for processing. These are biometric data and are handled with the highest level of protection.
  • Contact Information: Your email address when you create an account, place an order, or contact our support team.
  • Payment Information: Credit card details, billing address, and transaction data. Payment card numbers are processed by our PCI-DSS compliant payment processor and are never stored on our servers.
  • Order Details: The country, document type, and specifications selected for your photo order.
  • Communication Data: Information you provide when contacting our support team, including email correspondence and chat transcripts.

2.2 Information Collected Automatically

  • Usage Data: Pages visited, features used, time spent on the Service, and interaction patterns.
  • Device Information: Browser type, operating system, device type, screen resolution, and IP address.
  • Cookies & Similar Technologies: See Section 5 for detailed information about our cookie usage.

3. How We Use Your Information

We use the information we collect solely for the following purposes:

  • To Provide the Service: Processing your uploaded photos — background removal, cropping to required specifications, Software verification, and delivery of digital or printed photos.
  • To Process Payments: Completing transactions for orders placed through our Service.
  • To Communicate With You: Sending order confirmations, delivery updates, responding to support inquiries, and sending service-related notifications.
  • To Improve the Service: Analysing anonymised usage patterns to enhance our Software technology, user experience, and website performance.
  • To Ensure Security: Detecting and preventing fraudulent activity, unauthorised access, and abuse of our Service.
  • To Comply With Legal Obligations: Meeting requirements under applicable laws, regulations, and legal processes.

We do not use your photos for any purpose other than processing and delivering your order. Your photos are never used for training our Software models, marketing, research, or any other secondary purpose.

4. Photo Processing & Automatic Deletion

Critical Privacy Commitment: All photos uploaded to Visa Photo are automatically and permanently deleted from our servers within 24 hours of successful processing and delivery. We do not retain your biometric data.

Here is how our photo processing and deletion process works:

  • Upload: Your photo is encrypted during transmission using TLS 1.3 and stored temporarily in an encrypted state.
  • Processing: Our Software performs background removal, cropping, resizing, and compliance verification. This processing occurs entirely on our secure infrastructure.
  • Expert Review: A trained human reviewer may examine your photo to verify Software detected issues. This review is conducted on our secure internal platform.
  • Delivery: Your processed photo is delivered to you via secure download link or sent to print. The download link expires after 7 days.
  • Automatic Deletion: Within 24 hours of successful delivery, all versions of your uploaded and processed photos are permanently and irreversibly deleted from our servers, backups, and any temporary storage. We retain no copies of your biometric data.

The only information we retain after 24 hours is your order metadata (country, document type, order date, transaction amount) and your account information if you created one. Your photos are gone forever.

5. Cookies & Tracking Technologies

We use cookies and similar tracking technologies to enable core functionality, analyse usage, and improve our Service. We do not use cookies for targeted advertising or user profiling.

5.1 Types of Cookies We Use

  • Essential Cookies: Required for the basic functioning of our website — session management, secure login, shopping cart, and payment processing. These cannot be disabled.
  • Functional Cookies: Remember your preferences, such as language selection and previously selected country for photo specifications. These enhance your experience.
  • Analytics Cookies: Help us understand how users interact with our Service using anonymised data. We use privacy-focused analytics that do not track you across other websites.

5.2 Managing Cookies

You can control cookie preferences through your browser settings. Most browsers allow you to block or delete cookies. However, disabling essential cookies may prevent certain features of our Service from functioning properly. For detailed instructions, visit your browser's help documentation.

5.3 Do Not Track Signals

We respect Do Not Track (DNT) signals from your browser. When DNT is enabled, we disable analytics cookies and limit data collection to essential cookies only.

6. Data Sharing & Third Parties

We do not sell, rent, trade, or share your personal information or photos with third parties for their marketing purposes. We only share data in the limited circumstances described below:

  • Payment Processors: Your payment information is processed by our PCI-DSS Level 1 compliant payment processor. We never store your full credit card number on our servers.
  • Cloud Infrastructure: Our Service is hosted on secure cloud infrastructure with data centres in the United States and European Union. All data is encrypted at rest and in transit.
  • Printing Partners: If you order printed photos, we share the processed photo file with our printing partner solely for the purpose of producing and shipping your prints. The file is deleted by the printing partner after production.
  • Legal Requirements: We may disclose information if required by law, court order, or government regulation. We will notify you of such disclosure unless prohibited by law.

7. Data Security Measures

We implement industry-leading security measures to protect your personal information and photos:

  • Encryption: All data is encrypted in transit using TLS 1.3 and at rest using AES-256 encryption.
  • Access Controls: Strict role-based access controls limit employee access to your data. Only authorised personnel with a legitimate business need can access photos during processing.
  • Infrastructure Security: Our servers are protected by firewalls, intrusion detection systems, and regular security audits.
  • Compliance Certifications: Our infrastructure providers maintain SOC 2 Type II, ISO 27001, and PCI-DSS certifications.
  • Regular Audits: We conduct regular internal and external security assessments, including penetration testing and vulnerability scanning.

While we strive to protect your data, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security, but we are committed to maintaining the highest standards.

8. Data Retention Policy

We retain different types of data for different periods, based on the purpose for which it was collected:

  • Uploaded and Processed Photos: Automatically deleted within 24 hours of successful processing and delivery. We retain absolutely no copies of your biometric data beyond this period.
  • Order Metadata: Retained for 3 years for accounting, tax, and legal compliance purposes. This includes order date, amount, country, and document type — but not your photos.
  • Account Information: Retained until you delete your account or after 3 years of inactivity. You can request deletion of your account and associated data at any time.
  • Support Communications: Retained for 2 years to maintain a record of customer service interactions.
  • Analytics Data: Anonymised and aggregated data may be retained indefinitely for Service improvement purposes.

After the applicable retention period, data is permanently deleted from all systems, including backups.

9. Your Rights (GDPR & CCPA)

Depending on your jurisdiction, you may have the following rights regarding your personal data:

9.1 GDPR Rights (EU/EEA & UK Residents)

  • Right of Access: Request a copy of the personal data we hold about you.
  • Right to Rectification: Correct any inaccurate or incomplete personal data.
  • Right to Erasure ("Right to be Forgotten"): Request deletion of your personal data. Note that photos are already automatically deleted within 24 hours.
  • Right to Restrict Processing: Limit how we process your data under certain circumstances.
  • Right to Data Portability: Receive your data in a structured, machine-readable format.
  • Right to Object: Object to processing of your data for direct marketing (which we do not conduct) or other purposes.

9.2 CCPA Rights (California Residents)

  • Right to Know: Request disclosure of the categories and specific pieces of personal data we collect, use, and share.
  • Right to Delete: Request deletion of your personal data.
  • Right to Opt-Out of Sale: We do not sell personal data, so this right is inherently respected.
  • Right to Non-Discrimination: We will not discriminate against you for exercising your privacy rights.

To exercise any of these rights, contact us at privacy@visaphoto.net. We will respond within the timeframe required by applicable law (30 days under GDPR, 45 days under CCPA). We may need to verify your identity before processing your request.

10. Children's Privacy

Our Service is not directed to children under the age of 16. We do not knowingly collect personal data from children. If you are a parent or guardian and believe your child has provided us with personal data, please contact us at privacy@visaphoto.net. If we become aware that we have collected personal data from a child without parental consent, we will delete it immediately.

Parents and guardians may use our Service to create passport or visa photos for their children. In such cases, the parent or guardian is responsible for uploading the child's photo and consents to the processing described in this policy.

11. International Data Transfers

Visa Photo is based in the United States, and our servers are located in the United States and the European Union. If you are using our Service from outside the United States, your data may be transferred to and processed in the United States or other countries where our infrastructure is located.

We ensure that all data transfers comply with applicable data protection laws through:

  • Standard Contractual Clauses (SCCs): EU-approved contractual safeguards for international data transfers.
  • Adequacy Decisions: Transfers to countries recognised by the EU as having adequate data protection standards.
  • Data Processing Agreements: Legally binding agreements with all service providers who may process your data.

By using our Service, you consent to the transfer of your data as described in this policy. However, given our 24-hour automatic deletion policy, your photos are never retained long enough to create ongoing international data transfer concerns.

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or for other operational reasons. When we make material changes, we will:

  • Post the updated policy on this page with a new effective date and version number.
  • Notify registered users via email at least 14 days before material changes take effect.
  • Display a prominent notice on our website for 30 days following significant updates.

We encourage you to review this Privacy Policy periodically to stay informed about how we protect your data. Your continued use of the Service after changes are posted constitutes acceptance of the updated policy.

13. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

If you are located in the EU/EEA or UK and believe we have not adequately addressed your privacy concerns, you have the right to lodge a complaint with your local supervisory authority or the UK Information Commissioner's Office (ICO).

© 2026 Visa Photo Inc. All rights reserved. Visa Photo is a registered trademark of Visa Photo Inc. in the United States and other countries.

Ready to Create Your Photo?

100% acceptance guarantee on every photo. Upload, App verify, download in 3 minutes.