Privacy Policy — application-eta.uk & our mobile applications
This Privacy Policy applies to the application-eta.uk website and our mobile applications available on Google Play and the Apple App Store (collectively, “our Service”).
We collect only the data needed to process your UK ETA application. All passport scans, face photos, and personal data are permanently deleted within 10 days of your application being processed. We never sell your data. You can request deletion at any time by emailing us.
1. Who We Are
application-eta.uk is a private assistance company. We operate as an intermediary service assisting travellers with UK Electronic Travel Authorisation (ETA) applications. application-eta.uk is a trading name of Lefpom SRL (Reg. no.: 40607533), registered in Romania. Correspondence address: 229 Costesti, Fieni, DB, RO.
We are not affiliated with the UK Government, the Home Office, or GOV.UK. We are a private service and charge a handling fee in addition to the UK Government fee of £20 (~€23).
You can apply for a UK Electronic Travel Authorisation (ETA) directly on the official GOV.UK website for a fee of £20.00.
2. Data We Collect and Why
To process your UK ETA application, we collect the following personal data:
| Data Type | Why We Collect It | Retention |
|---|---|---|
| Full name, date of birth, nationality | Required for UK ETA application form | Deleted within 10 days of processing |
| Passport number issue and expiry date | Required for UK ETA application form | Deleted within 10 days of processing |
| Passport biographical page photo | Required for identity verification by Home Office | Deleted within 10 days of processing |
| Face photo (selfie) | Required for identity verification by Home Office | Deleted within 10 days of processing |
| Email address | To send confirmation and ETA decision emails | Deleted within 10 days of processing |
| Phone number (optional) | Optional — used only if we need to contact you about your application | Deleted within 10 days of processing |
| Residential address | Required for UK ETA application form | Deleted within 10 days of processing |
| Payment information | Processed by our payment provider (Stripe). We do not store card details. | Not stored by us |
| IP address and browser data | Security, fraud prevention, spam detection | Standard server logs — 90 days |
| Mobile device identifiers | Analytics and crash reporting for our mobile applications. Collected only if you use one of our mobile applications (Android or iOS). | Standard app logs — 90 days |
3. Data Retention & Deletion
All sensitive application data — including passport scans, face photos, passport numbers, and personal details — are permanently and irreversibly deleted from our active systems within 10 days of your application being processed or finalised. This applies regardless of whether your application was approved, refused, or withdrawn.
Email address and application reference: 5 years from application date. Passport and personal data: 10 days after submission to UKVI, then permanently deleted. Biometric data (photographs): 10 days after submission to UKVI, then permanently deleted. Payment records: 7 years (legal requirement for financial records). Consent records (IP, timestamp, checkbox): 5 years (legal requirement for consent documentation).
You may also request immediate deletion of your data at any time before the automated cleanup cycle — see Section 7 for how to do this.
Payment transaction records are retained by our payment provider (Stripe) in accordance with their own data retention policies and applicable financial regulations. We do not retain card details.
For purchases made through the Google Play Store or the Apple App Store, payment records are retained by Google or Apple respectively, in accordance with their own data retention policies.
4. International Data Transfers
To ensure 24/7 service availability and secure processing, your data may be stored or processed on secure servers located in various international jurisdictions outside of your country of residence. These may include servers in the European Economic Area (EEA), the United Kingdom, and the United States.
All international data transfers are protected by industry-standard SSL/TLS encryption. Where data is transferred outside the UK or EEA, we ensure appropriate safeguards are in place in compliance with UK GDPR requirements.
5. Cookies
We use the following categories of cookies on application-eta.uk:
| Cookie Type | Purpose | Duration |
|---|---|---|
| Necessary | Essential site functionality — login sessions, security, consent preferences. Cannot be disabled. | Session / up to 1 year |
| Analytics | Google Analytics — helps us understand how visitors use the site. Data is anonymised. | Up to 2 years |
| Payments | Stripe — required to process payments securely. | Session |
| Marketing | Used to deliver relevant advertisements. Optional — can be declined via our cookie banner. | Up to 1 year |
You can manage your cookie preferences at any time using the cookie settings panel on our website. Withdrawing consent for non-essential cookies does not affect the functionality of the application form.
Our mobile applications do not use cookies. They may use equivalent technologies such as local storage for session management and anonymous analytics identifiers.
6. Third Parties & Data Sharing
We do not sell, rent, or trade your personal data to third parties for marketing purposes. We share data only in the following circumstances:
- UK Home Office: Your application data is submitted to the Home Office to process your UK ETA. This is the core purpose of our service.
- Stripe (payment processing): Payment information is processed by Stripe. We do not store card details. Stripe’s privacy policy is available at: stripe.com/privacy
- Interserver: Your data is stored on servers operated by InterServer Inc. (USA), certified under the EU-US Data Privacy Framework (DPF) effective 10 January 2026. For more information visit dataprivacyframework.gov.
- CDN (Cloudflare): Please be aware that to facilitate your UK ETA application, data may be processed or stored on secure servers located in various international jurisdictions.
- Legal requirements: We may disclose data if required to do so by law or in response to a valid legal request from a competent authority.
- Supabase Inc. — database and file storage provider, used by both our website and our mobile applications. Data stored on servers in Paris, EU (eu-west-3). DPA in place.
- Resend Inc. — transactional email delivery. Processes recipient email addresses for delivery purposes only.
- Vercel Inc. — hosting provider for our administration interface. DPA in place.
- Google Play Store: If you download one of our applications via Google Play, Google collects certain data as part of the app distribution process. This is governed by Google’s Privacy Policy at policies.google.com/privacy.
- Apple App Store: If you download one of our applications via the Apple App Store, Apple collects certain data as part of the app distribution process. This is governed by Apple’s Privacy Policy at apple.com/legal/privacy.
- Google ML Kit: Our mobile applications use Google ML Kit on-device for face detection and document scanning (selfie and passport photo validation), on both Android and iOS. ML Kit processes images locally on your device and does not transmit biometric data to Google servers.
7. Your Rights (EU GDPR & UK GDPR)
Under GDPR, you have the following rights regarding your personal data:
| Right | What It Means |
|---|---|
| Right of access | You can request a copy of all personal data we hold about you. |
| Right to erasure | You can request immediate deletion of your data at any time before the automated 10-day cleanup. |
| Right to rectification | You can request correction of inaccurate data we hold about you. |
| Right to restriction | You can request that we restrict processing of your data in certain circumstances. |
| Right to portability | You can request an export of your data in a machine-readable format. |
| Right to object | You can object to processing of your data for certain purposes, including marketing. |
| Right to withdraw consent | You can withdraw consent at any time before your application is submitted to UKVI by contacting [email protected]. |
Note: Once your application data has been submitted to the Home Office, we are not able to delete data held by the UK Government — only data held by application-eta.uk.
If you are unsatisfied with our response, you have the right to lodge a complaint with:
- Romanian Data Protection Authority (ANSPDCP): anspdcp.ro
- UK Information Commissioner’s Office (ICO): ico.org.uk — if you are based in the UK
- Your local EU data protection authority if you are based in the EU
Note: We are officially registered with ICO UK Information Commissioner’s Office (ICO): ico.org.uk
8. Legal Basis for Processing
Article 6(1)(b) GDPR — processing necessary to perform the service you have requested.
Article 6(1)(a) GDPR — your explicit consent, which you may withdraw at any time before submission.
Article 9(2)(a) GDPR — your explicit consent for processing biometric data: Your passport photograph and selfie are biometric data under Article 9 GDPR. We process this data solely to submit your ETA application to UKVI. This data is:
- Encrypted at rest and in transit using industry-standard encryption
- Accessible only to staff directly involved in processing your application
- Never used for any purpose other than your ETA application submission
- Permanently and securely deleted within 10 days of submission to UKVI
Your consent for biometric data processing is separate from our general Terms & Conditions and can be withdrawn at any time before your application is submitted by contacting [email protected]
For mobile application users, the same legal bases apply on both Android and iOS. Biometric validation performed by our mobile applications (face detection and passport scan) is processed locally on your device via Google ML Kit and is not transmitted to our servers. Only the resulting photographs are uploaded for ETA submission purposes, subject to your explicit consent.
9. Contact & Data Requests
Under GDPR Article 15, you have the right to access your personal data.
- If your data was collected via one of our mobile applications, you can submit a request here: Request your data.
- If your data was collected via the application-eta.uk website, please email us at [email protected].
To exercise any of your rights, request data deletion, or ask any privacy-related question — email us at [email protected]. We will respond within 30 calendar days. Please include your name and the email address used when applying.
Last updated: March 2026 · application-eta.uk