Privacy Policy
We handle passport data, which is among the most sensitive information you can share online. This policy explains exactly what we collect, why, who sees it, and how long we keep it.
1. Who controls your data
The business responsible for your data is Passage Travel Services LLC, 5203 Juan Tabo Blvd NE, Albuquerque, NM 87111, United States. For any privacy question, contact privacy@passagecard.com.
2. What we collect
| Category | Details | Source |
|---|---|---|
| Identity | Full name as shown in your passport, date of birth, sex, nationality | You, or read from a passport image you upload |
| Passport | Passport number, issue and expiry dates, issuing country | You, or read from a passport image |
| Travel | Arrival and departure dates, flight number, accommodation address, purpose of travel, boarding city and country | You |
| Contact | Email address, phone number | You |
| Order | Service level chosen, amount paid, order reference | Generated by us |
| Payment | Card type, last four digits, payment status | Our payment provider — we never receive or store your full card number |
| Support | Messages you send us by chat, email or WhatsApp | You |
| Technical | IP address, browser type, pages viewed | Automatically, subject to your cookie choices |
Please do not send us health information or documents other than the passport page we ask for.
3. Why we use it
- To prepare, check and submit your application to the relevant authority, and to contact you about your order
- To take payment and prevent fraud
- To keep records required for accounting, tax and dispute defence
- For analytics and advertising measurement — only if you accept those cookies
- To send marketing emails — only if you opt in, and you can withdraw at any time
4. Passport images — our shortest retention
If you upload a photo of your passport, we do not keep the image. It is used once to read your details, then deleted within one hour and usually within sixty seconds. We keep only the text fields needed to file your application. While it exists, the image is encrypted and stored privately with no public access. You can always type your details manually instead.
5. Who we share it with
We do not sell your data. We share it only with:
- The relevant government authority — for the Thailand Digital Arrival Card, the Thai Immigration Bureau. Submitting your details to them is the service you are purchasing.
- Our payment provider Stripe, to take payment and handle disputes.
- Our email, messaging, hosting and analytics providers Resend, Twilio, Cloudflare, Google Analytics, bound to use it only on our instructions.
- Authorities, where we are legally required to disclose.
6. International transfers
Delivering this service requires sending your details to the destination country's immigration authority — for the Thailand Digital Arrival Card, to Thailand. Your information may also be processed in the United States, where our business is based. By purchasing, you consent to these transfers, which are necessary to perform the contract. Where our providers are outside your region, transfers are made under recognised safeguards such as Standard Contractual Clauses.
7. How long we keep it
| Data | Retention |
|---|---|
| Passport images | Up to 1 hour |
| Application and order data | 24 months from travel date (supports disputes; card-scheme windows run to 540 days) |
| Invoices and accounting records | As required by law |
| Support conversations | 24 months |
| Marketing consent records | Until withdrawn, plus 3 years |
After these periods data is deleted or irreversibly anonymised.
8. How we protect it
- Encryption in transit and at rest
- Access limited to team members who need it, with two-factor authentication
- Passport images in an isolated store with automated deletion
- No full card numbers ever reach our systems
No transmission over the internet is completely secure, but we use industry-standard measures and will notify you and the relevant regulator of any breach likely to put your rights at high risk.
9. Your rights
Depending on where you live, you may ask us to give you a copy of your data, correct it, delete it, restrict or object to its use, or provide it in a portable format; and where we rely on consent, you may withdraw it. EU/UK residents have these rights under the GDPR; California residents have rights under the CCPA, including to know, delete, and opt out of "sale" (we do not sell data). Email privacy@passagecard.com and we will respond within the time the law requires, free of charge.
One limit worth knowing. Once your application has been submitted to a government authority, we cannot delete it from that authority's systems. We can delete our copy; we have no control over theirs.
10. Cookies
We use strictly necessary cookies to run the site. Analytics and advertising cookies are only set if you accept them in the banner, and you can change your choice at any time. [Insert your cookie table once your consent tool is configured.]
11. Children
Our service is not directed at children and we do not knowingly create accounts for anyone under 16. Adults may submit applications on behalf of children travelling with them; that data is processed on the same basis as any other traveller's.
12. Contact
Privacy questions: privacy@passagecard.com. EU/UK residents may also complain to their local data protection authority; California residents may contact the California Privacy Protection Agency.