VisaFit legal information · Updated 13 September 2026

VisaFit Privacy Notice

This notice explains how Rishabh, sole proprietor trading as Rishabh Softwares, handles personal information when you visit VisaFit, create or use an agency account, pay for services or contact us. For applicant and workforce information controlled by an agency, that agency's notice also applies. This notice does not authorise optional marketing or recurring payments.

Data and purposes

Name, work email, mobile, agency name, optional physical address, chosen plan and billing term are used to verify the account, provision the workspace, communicate about the service and prepare billing. Passwords are hashed. Email codes are used for verification; they are not included in acceptance exports.

Document version, hash, text, checkbox decision, server time, verification linkage, IP if reliably available, browser user-agent and request identifiers provide security and acceptance evidence. These are accessible only to authorised platform administrators and necessary service providers.

Annual welcome-offer records retain issue, signup selection, verified agency linkage and redemption timestamps, fixed expiry, and invoice discount details for pricing integrity and support. Before signup, the server uses a hashed opaque offer identifier; it does not require a name or email just to display the offer. Expiry ends offer eligibility, not immediate deletion of audit evidence.

When you use the service or contact support, we may receive account and tenant identifiers, your role, the actions needed to fulfil your request, correspondence, technical request information and security events. We use this information to provide support, troubleshoot faults, prevent abuse and maintain records of authorised actions. Please do not include unnecessary applicant documents, passwords or payment credentials in support messages.

Payments and agency data

Razorpay receives payment details directly through its checkout. VisaFit stores provider references and payment status, not card numbers or CVV. This notice does not itself authorize a debit or recurring mandate.

Your agency determines the purposes of its applicants' and staff members' business data, including assessment answers, lead and case records, documents, appointments, messages, attendance, payroll and financial records. We process that information on the agency's instructions under Schedule A of the MSA. Authorised platform personnel may access information as needed for support, security or legal duties; records are not made available to unrelated agency tenants.

VisaFit uses Supabase for its PostgreSQL database, with the primary database located in Mumbai, India (South Asia region, ap-south-1). Hostinger KVM 2 is the selected application-hosting service; its server location remains subject to deployment verification. Hosting requests, infrastructure logs, support operations and backup or replica processing may have separate locations. The primary database location is not a representation that all personal data is processed only in India. Relevant provider arrangements and applicable transfer restrictions govern those activities.

Google reCAPTCHA receives information needed for abuse protection when it is enabled. Email providers receive the recipient and message content needed to deliver verification and service communications. We do not sell personal information or use agency data to train general-purpose AI models under the MSA. We may make limited disclosures required by law and assess provider access and cross-border processing under applicable requirements.

Choices retention and rights

Signup requires the information needed to operate your account; marketing is not bundled into signup. No optional analytics or advertising trackers are enabled by these acknowledgements.

Unverified signup challenges expire after ten minutes; expiry prevents their use but does not mean immediate deletion of the record. Account data is retained while needed for the service, justified suspension, support or recovery. Payment, legal-acceptance and security evidence may be retained separately for applicable obligations and disputes. Ordinary account suspension does not start permanent deletion. On permanent termination, the registered owner has 30 calendar days to request an export; a timely request is fulfilled before routine deletion, and active tenant business data is deleted or anonymised within 90 calendar days, except for mandatory retention, legal holds or binding directions. Backup expiry follows the separately stated infrastructure schedule. We review continued retention, restrict held information and delete or anonymise it when the purpose and applicable obligations end. Ask our privacy contact for the schedule applicable to your information.

For information, correction, erasure, nomination, withdrawal of optional consent or a privacy grievance, contact Rishabh at rshbhkataria@gmail.com or 104, New Hargobind Colony, Basti Sheikh, Jalandhar, Punjab - 144002, India. Include your agency, contact email and request, not passwords or full identity documents. We verify identity proportionately, record and route the request, aim to respond within 30 calendar days from receipt and comply with any shorter legal deadline. If further information or lawful additional time is needed, we explain the reason and next steps within that period without extending a statutory deadline. Applicant-record requests are normally handled by the agency responsible for that processing. We explain restrictions where lawful; mandatory rights and access to the competent statutory authority are not waived by acknowledgement or the no-refund policy.

Consent, children and changes

We process information on consent or another ground permitted by applicable law for the stated purpose. Required account information enables the service you request. Acknowledging this notice is not blanket consent for new purposes, marketing, a payment mandate or all agency applicants. Where processing relies on consent, you may withdraw it through the relevant request mechanism or our privacy contact; we explain any effect on requested services and retention required by law.

Agency signup and demo requests are for adults authorised to act for a business. Agencies handling children's or represented persons' information must provide appropriate notices and obtain and verify parental or lawful-guardian authority as required. An agency owner's MSA checkbox does not substitute for that procedure.

We publish material changes with an updated date and obtain fresh consent or agreement acceptance where required. Changes do not retrospectively turn an earlier acknowledgement into consent to a new purpose. A demo request has a separate notice at /demo-privacy and a private withdrawal link.

Return to VisaFit