Privacy Policy

Last updated: August 31, 2026

1. Introduction

De-Genesis Travel and Tours Ltd ("we", "us", or "our") is committed to protecting and respecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website, create a client portal account, register as a travel agent or corporate account, or use any of our services. Our services include: (a) immigration and visa services — work permits, study abroad programs, visitor visas, permanent residency and family sponsorship, eTA/e-Visa applications, Ghana eVisa, and Dubai visa processing; (b) travel concierge services — flight search and ticketing, hotel bookings, airport transfers and ground transportation, activities and experiences, travel insurance, eSIM connectivity plans, car rental, and custom itinerary planning; (c) Christian pilgrimage tours; (d) corporate travel management — employee relocation, bulk visa processing, corporate travel policies, and dedicated account management; (e) travel agent B2B portal — agent registration, wallet management, commission tracking, and wholesale booking tools; (f) loyalty and referral program — points earning and redemption, referral credits, and tier-based rewards; (g) consultation booking — scheduled calls with our immigration and travel specialists; and (h) travel alerts — flight status notifications, delay alerts, and check-in reminders. We comply with applicable data protection laws, including the Data Protection Act, 2012 (Act 843) of Ghana, the General Data Protection Regulation (GDPR) of the European Union, and the Payment Services Directive 2 (PSD2) for electronic payment transactions within the European Union.

2. Information We Collect

We collect information that you provide directly to us when you submit an inquiry, book a consultation, register a client portal account, apply for a service, or make a booking. This includes your full name, email address, phone number, country of interest, service required, and any message details you share. Depending on the service, we may also collect: • Immigration & Visa Services: passport details, passport-size photographs, academic transcripts and certificates, financial statements, yellow fever vaccination certificates, invitation letters, CVs/resumes, birth certificates, marriage certificates, employment letters, police clearance certificates, and other supporting documents for eTA/e-Visa, work permits, study abroad programs, Ghana eVisa, Dubai visas, and visitor visas. • Flight Booking & Ticketing: passenger names, dates of birth, gender, nationality, passport details (number, expiry, issue country), contact information, seating and baggage preferences, and frequent flyer numbers. • Hotel Bookings: guest names, contact details, check-in/check-out dates, room preferences, and special requests. • Airport Transfers & Ground Transportation: passenger names, flight details, pickup and drop-off locations, vehicle preferences, and contact information. • Activities & Experiences: participant names, contact details, preferred dates, and group size. • Travel Insurance: insured person details, travel dates, destination, medical declarations, and beneficiary information. • eSIM Connectivity Plans: device type, destination country, plan selection, and activation details. • Car Rental: driver's name, license details, pickup/return locations, and vehicle preferences. • Pilgrimage Tours: pilgrim details, passport copies, vaccination certificates, accommodation preferences, and dietary requirements. • Corporate Travel Management: employee names, employment details, corporate travel policy acknowledgment, travel preferences, and booking authorizations. • Travel Agent B2B Portal: agency name, business registration number, IATA/IATAN/license numbers, commission structure, wallet balance, and transaction history. • Loyalty & Referral Program: referral code, referral history, points balance, and redeemed rewards. • Consultation Booking: preferred date and time, service category, and any preparatory notes you share. • Travel Alerts: flight booking references, IATA flight codes, and notification preferences for status, delay, and gate change alerts. Payment information (including transaction references, payment method selected, and payment status) is collected when you pay for any service. We do not collect, store, or process raw cardholder data (card numbers, CVVs, or PINs) on our servers — all card data is handled exclusively by our PCI-DSS-certified payment processors through their secure hosted checkout pages. Account credentials are collected when you register for the client portal, agent portal, corporate portal, or team dashboard.

3. How We Use Your Information

We use your personal information to: (a) process your inquiries, visa applications, and immigration petitions; (b) search, book, and ticket flights, hotels, transfers, activities, car rentals, eSIM plans, and travel insurance on your behalf; (c) coordinate pilgrimage tour packages and group travel; (d) manage corporate travel programs, employee relocations, and bulk visa processing; (e) operate the travel agent B2B portal, including agent wallet management, commission tracking, and wholesale booking tools; (f) administer the loyalty and referral program, including awarding and redeeming points, processing referral credits, and managing tier benefits; (g) schedule and confirm consultations with our specialists; (h) send flight status alerts, delay notifications, gate change updates, check-in reminders, and pre-departure reminders; (i) communicate with you about your application and booking status via the client dashboard, agent portal, corporate portal, and email notifications; (j) process payments, issue invoices, and manage booking cancellations and refunds; (k) improve our services, analyze travel trends, and personalize recommendations; (l) send promotional materials, travel deals, and newsletters (with your consent); and (m) comply with legal obligations. Account credentials are used to authenticate your access to the client portal, agent portal, corporate portal, team dashboard, and application tracking dashboard.

4. Information Sharing and Disclosure

We do not sell, trade, or rent your personal information to third parties. We may share your information with trusted partners including: • Embassies, consulates, and immigration authorities for visa and permit applications; • Educational institutions and partner universities for study abroad admissions; • Licensed immigration lawyers and certified immigration consultants; • Airline suppliers (via Duffel and Travelport GDS/NDC), hotel suppliers (via Hotelbeds), transfer and activity operators (via Hotelbeds), and car rental providers; • eSIM connectivity providers (via Airalo); • Travel insurance underwriters; • Payment processors including Stripe, Revolut, Paystack, and MTN Mobile Money for secure payment processing; • Calendly for consultation appointment scheduling; • Google services (Calendar, Sheets, Gmail) for booking confirmations and scheduling sync; • Twilio for SMS notifications; • Airlabs for real-time flight status data used in travel alerts; solely for the purpose of processing your application, booking, consultation, or payment. We may also disclose information when required by law, to protect our legal rights, or to comply with law enforcement or regulatory requests.

5. Data Security

We implement appropriate technical and organizational measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction. These measures include encrypted data transmission (HTTPS/TLS), secure cloud storage, role-based access controls, and authentication requirements for client, agent, and corporate portal accounts. However, no method of transmission over the internet or electronic storage is 100% secure, and we cannot guarantee absolute security. Only authorized personnel and administrators have access to sensitive client documents.

6. Payment Processing & PSD2 Compliance

We are committed to providing secure, compliant payment processing for all transactions on our platform. Our payment infrastructure is designed to meet the requirements of the EU Payment Services Directive 2 (PSD2), including Strong Customer Authentication (SCA), and global card security standards. (a) Payment Processors: We use Stripe as our primary payment processor for European and international transactions, and Paystack for transactions in African markets (Nigeria, Ghana, Kenya, South Africa, and others). Additional payment options include Revolut and MTN Mobile Money. Each processor is selected based on regional coverage and regulatory alignment. (b) Strong Customer Authentication (SCA): For customers in the European Union, Stripe enforces Strong Customer Authentication (SCA) automatically through 3D Secure 2 (3DS2) during checkout. This means you may be asked by your bank or card issuer to verify your identity via a one-time passcode, biometric confirmation, or banking app prompt before a payment is completed. We do not control or store the authentication challenge — it is handled entirely between your bank and our payment processor. (c) PCI-DSS Compliance: We do not collect, store, or transmit raw cardholder data (card numbers, expiration dates, or CVVs) on our servers. All card data is captured directly by our payment processors through their PCI-DSS Level 1 certified hosted checkout pages. Because we exclusively use hosted payment pages and never touch raw card data, we qualify for the PCI-DSS Self-Assessment Questionnaire A (SAQ-A) — the simplest and most secure merchant compliance level. (d) Processor Certifications: • Stripe is PCI-DSS Level 1 certified and provides full PSD2/SCA support, including the Payment Intents API, 3D Secure 2, and dynamic SCA for recurring and subscription payments. • Paystack is PCI-DSS Level 1 certified, ISO 27001:2022 certified (information security management), and ISO 27701:2019 certified (privacy information management). (e) Tokenization: When you make a payment, your card details are tokenized by the payment processor. We receive only a non-sensitive transaction reference (token) and payment status — never your actual card number. (f) Regional Routing: Payments from EU customers are processed via Stripe to ensure PSD2/SCA compliance. Payments from African customers are processed via Paystack, which meets global security standards (PCI-DSS, ISO 27001/27701) though PSD2 does not directly apply outside the EU. Payments from the rest of the world may be routed through either processor depending on currency and availability. (g) Fraud & Risk Management: Our payment processors apply real-time fraud detection, risk scoring, and transaction monitoring to every payment. Suspicious transactions may be declined or held for verification to protect both you and our business. (h) Your Responsibilities: To help maintain secure payments, we recommend that you keep your browser and device updated, use strong passwords for your client portal account, never share your payment authentication codes with anyone, and report any unauthorized charges to your bank and to us immediately at degenesis2016@gmail.com.

7. Cookies and Tracking

Our website may use cookies and similar tracking technologies to enhance your browsing experience, analyze website traffic, remember your currency and language preferences, and display relevant content. We use a cookie consent mechanism to inform you of cookie usage and obtain your consent where required. You can configure your browser to refuse cookies, though some features of the website and client portal may not function properly without them.

8. Document Uploads and Client Portal

When you use our client portal, you may upload documents such as passport copies, photographs, academic records, financial statements, and other application materials. These documents are stored securely and are accessible only to you and authorized administrators. Document review statuses (pending, under review, approved, rejected) are visible in your dashboard. We retain uploaded documents in accordance with our data retention policy and applicable legal requirements.

9. Data Retention

We retain your personal information only for as long as necessary to fulfill the purposes outlined in this policy, comply with legal obligations, resolve disputes, and enforce our agreements. Application-related documents (passports, certificates, financial statements, and supporting evidence) are retained for a minimum of five (5) years in accordance with statutory requirements. Booking and payment records, including invoices, transaction references, and loyalty transactions, are retained for a minimum of seven (7) years to meet tax and accounting obligations. We do not retain raw cardholder data — payment records consist only of transaction references, amounts, currencies, and payment status as returned by our processors. Loyalty account data and referral history are retained for the lifetime of your account; points and referral credits expire if your account is inactive for 12 consecutive months. Account credentials and profile data are retained for the duration of your engagement with our services and may be deleted upon request, subject to legal retention obligations. When data is no longer required, it is securely deleted or anonymized.

10. Your Rights

You have the right to access, correct, update, or request deletion of your personal information. You may also object to or restrict our processing of your data, withdraw consent for marketing communications at any time, and request a copy of your personal data. To exercise these rights, contact us at degenesis2016@gmail.com or +233 30 397 8581. We will respond to your request within 30 days.

11. Third-Party Links and Services

Our website may contain links to third-party websites or services, including: (a) payment providers — Stripe, Revolut, Paystack, and MTN Mobile Money; (b) Calendly for consultation appointment scheduling; (c) Google services — Calendar, Sheets, Gmail, and Analytics; (d) flight booking platforms — Duffel and Travelport (GDS and NDC content); (e) hotel, transfer, and activity booking platforms — Hotelbeds; (f) eSIM connectivity providers — Airalo; (g) flight status data providers — Airlabs; (h) SMS notification providers — Twilio; and (i) corporate travel and document management tools — Microsoft Word, Microsoft Teams, and Google Docs integrations. We are not responsible for the privacy practices or content of these external sites. We encourage you to review the privacy policies of any third-party sites you visit.

12. Newsletter and Marketing Communications

If you subscribe to our newsletter, we will use your email address to send you updates on visa requirements, travel deals, and company news. You can unsubscribe at any time using the link provided in each email or by contacting us directly. We do not share your subscription information with third parties for marketing purposes.

13. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, services, or legal requirements. Any changes will be posted on this page with an updated revision date. We encourage you to review this policy periodically to stay informed about how we protect your information.

14. Contact Us

If you have questions or concerns about this Privacy Policy, our data practices, or our payment processing procedures, please contact us: De-Genesis Travel and Tours Ltd 463-4129, 14 Jen St, Lapaz-Accra, Ghana Phone: +233 30 397 8581 WhatsApp: +233 54 650 2348 Email: degenesis2016@gmail.com