Privacy & Data Protection

Privacy Policy

This policy explains what personal information we collect, why we use it, when it may be shared, how long it may be retained, and the choices available to you when using Varioline Traveller services.

Last Updated August 30, 2026
How we handle your personal information

Travel arrangements often require personal information to be shared with airlines, hotels, embassies, visa application centres, insurers, sponsors, payment providers, and other parties involved in the service. We limit such use and sharing to what is reasonably required for the relevant purpose.

This Privacy Policy explains how Varioline Traveller collects, uses, stores, shares, and protects personal information when you visit our website, contact us, request a quotation, submit documents, make a booking, or use any travel-related service arranged, facilitated, or administered by us.

Because travel services often require information to be shared with airlines, hotels, embassies, consulates, visa application centres, immigration authorities, tour operators, insurers, transport providers, educational institutions, payment processors, sponsors, employers, and other service providers, please read this Policy carefully before providing personal information to us.

1. Scope of This Privacy Policy

This Privacy Policy applies to personal information processed by Varioline Traveller through our website, offices, telephone, email, messaging services, social media, forms, booking systems, customer-support channels, and other authorized methods of communication.

It applies to individual travellers as well as persons making enquiries or bookings on behalf of family members, employees, delegates, doctors, students, corporate travellers, sponsored travellers, or other group participants.

2. Who We Are

For purposes of this Policy, “Varioline Traveller,” “we,” “us,” and “our” refer to Varioline Traveller, having its office at Plaza No. 1, Block A-1, PIA Main Boulevard, Lahore, Punjab, Pakistan.

Where we arrange a third-party travel product or service, the relevant supplier may independently determine how it processes personal information. Such suppliers may have their own privacy notices and data-handling requirements.

3. Personal Information We May Collect

Depending on the service requested, we may collect information including:

  • full name, title, gender, date and place of birth;
  • postal address, email address, telephone number, and other contact information;
  • passport, national identity document, residence permit, visa, immigration, and nationality information;
  • travel dates, destinations, itineraries, ticketing details, frequent-flyer information, hotel preferences, meal requests, seating preferences, and other travel requirements;
  • employment, profession, business, educational, conference, CME, sponsorship, and institutional information;
  • family, marital, dependency, household, and relationship information where relevant to a visa, travel, sponsorship, or group application;
  • financial information reasonably required for a booking, visa application, sponsorship assessment, refund, or payment verification;
  • copies of bank statements, employment evidence, tax records, invitation letters, sponsorship evidence, property documents, or similar supporting documents where supplied for a visa or related service;
  • payment and transaction information, including invoice and payment status information;
  • communications with us, including enquiries, complaints, feedback, call notes, emails, and messaging correspondence;
  • website and technical information described in Section 12 below; and
  • any other information you voluntarily provide or that is reasonably required to perform the requested service.

4. Sensitive and Special-Category Information

Certain travel, visa, immigration, insurance, accessibility, medical-assistance, pilgrimage, or airline services may require information that is more sensitive in nature, such as health information, disability or accessibility requirements, religious requirements, criminal-history information, or other information requested by a competent authority or supplier.

We seek to collect such information only when it is reasonably necessary for the requested service, when you have voluntarily provided it, when a competent authority or supplier requires it, or when processing is otherwise permitted by applicable law.

We do not ordinarily collect raw biometric identifiers such as fingerprints or facial templates. Where biometric enrolment is required for a visa or immigration process, biometrics are normally submitted directly to the relevant authority or authorized visa application centre.

5. Information About Other Travellers

If you provide personal information about another person, including a spouse, child, family member, employee, delegate, student, doctor, sponsored traveller, or group participant, you confirm that you are authorized to provide that information for the relevant travel or application purpose.

You are responsible for informing such persons that their information may be processed in accordance with this Privacy Policy and disclosed to relevant suppliers or authorities where necessary.

6. How We Collect Information

We may collect personal information:

  • directly from you;
  • from a person authorized to act on your behalf;
  • from your employer, sponsor, pharmaceutical company, institution, conference organizer, educational institution, or group coordinator;
  • from airlines, hotels, tour operators, visa application centres, immigration or consular authorities, insurance providers, transport providers, and other travel suppliers;
  • from forms, documents, correspondence, booking records, and service requests submitted to us;
  • through our website and related technologies; and
  • from publicly available sources where reasonably necessary for verification or service delivery and permitted by law.

7. Purposes for Which We Use Personal Information

We may use personal information to:

  • respond to enquiries and prepare quotations;
  • make, administer, modify, or cancel airline, hotel, tour, transfer, insurance, Hajj, Umrah, study-abroad, visa, immigration, and other travel arrangements;
  • prepare visa forms, supporting documentation, appointment requests, cover letters, itineraries, sponsorship documentation, and related application materials;
  • communicate with embassies, consulates, visa application centres, immigration authorities, airlines, hotels, suppliers, sponsors, institutions, and other relevant parties;
  • process payments, refunds, credits, reconciliations, and invoices;
  • manage corporate, pharmaceutical, conference, CME, delegation, sponsored, and group travel;
  • provide customer support and communicate service updates;
  • verify information, prevent fraud, protect our systems, and manage security risks;
  • maintain business, accounting, compliance, and service records;
  • improve our website, services, processes, and customer experience;
  • send service-related communications and, where permitted, marketing communications; and
  • comply with legal obligations, lawful requests, court orders, regulatory requirements, or applicable supplier rules.

8. Legal and Operational Basis for Processing

We process information where it is necessary to provide or administer a service you requested, to take steps at your request before a booking or transaction, to comply with legal or regulatory requirements, to protect legitimate business or security interests, or where you have provided consent when consent is appropriate or required.

Where a particular law grants you additional privacy rights, we will apply those rights to the extent that law is applicable to the relevant processing activity.

9. Visa and Immigration Information

Visa and immigration services may require extensive personal and supporting information. We may use information you provide to prepare application materials, review documentation, communicate requirements, arrange appointments, submit or facilitate applications where permitted, and correspond with relevant authorities or service providers.

Visa decisions are made exclusively by the relevant government, embassy, consulate, immigration authority, or authorized decision-making body. We do not control how those authorities process information after it has been submitted to them.

10. Corporate, Sponsored, Group and CME Travel

For corporate, pharmaceutical-sponsored, medical conference, CME, educational, delegation, or other group travel, information may be received from or shared with the sponsoring organization, employer, institution, group coordinator, conference organizer, or another authorized party to the extent reasonably necessary to organize the travel, confirm participation, manage costs, coordinate logistics, or meet documentation requirements.

We do not authorize a sponsor or employer to use personal information for unrelated purposes merely because it is involved in the travel arrangement.

11. Payment Information

Payments may be processed through banks, card processors, payment service providers, or other financial intermediaries. We may receive transaction references, payment status, payer details, and other information necessary to reconcile or administer a payment.

Where payment-card information is entered directly into a third-party payment service, that provider's privacy and security terms may also apply. We do not intentionally retain full card-security codes after a transaction has been processed.

12. Website Data, Cookies and Similar Technologies

When you use our website, certain technical information may be collected automatically, such as IP address, device type, browser type, operating system, pages viewed, referring pages, approximate location derived from technical information, timestamps, and website interaction data.

We may use cookies and similar technologies to operate the website, maintain sessions, remember preferences, improve performance, understand website usage, protect against misuse, and support analytics or advertising where enabled.

You can usually control cookies through your browser settings. Disabling certain cookies may affect website functionality.

13. Communications, Calls and Messaging

If you contact us by telephone, email, WhatsApp, social media, website form, or another messaging service, we may retain the communication and related contact information for customer service, booking administration, quality control, dispute resolution, fraud prevention, and business-record purposes.

Communications sent through third-party platforms are also subject to the privacy practices of the relevant platform provider.

14. How We Share Personal Information

We may share personal information only where reasonably necessary for the relevant purpose, including with:

  • airlines, hotels, tour operators, cruise operators, transport companies, destination-management companies, and other travel suppliers;
  • embassies, consulates, visa application centres, immigration authorities, border authorities, and other government bodies;
  • travel insurance providers and assistance companies;
  • educational institutions and related service providers for study-abroad services;
  • banks, payment processors, accountants, auditors, and financial service providers;
  • technology, hosting, communications, document-management, security, and professional service providers supporting our operations;
  • employers, sponsors, pharmaceutical companies, institutions, conference organizers, and group coordinators where they are legitimately involved in the booking or service;
  • professional advisers, insurers, investigators, regulators, courts, law-enforcement bodies, or other authorities where reasonably necessary or legally required; and
  • a successor, purchaser, or reorganized entity in connection with a lawful business transfer, merger, restructuring, or sale, subject to appropriate safeguards.

We do not sell personal information as a standalone commercial product.

15. Independent Third-Party Suppliers

Airlines, hotels, embassies, visa application centres, insurers, tour operators, transport providers, payment processors, and other suppliers may process information independently under their own privacy policies and legal obligations.

Once information has been lawfully transferred to an independent supplier or authority, its subsequent handling may be governed by that party's policies, systems, applicable laws, and regulatory requirements.

16. International Transfers of Information

Travel is inherently international. To arrange a booking, visa, immigration service, insurance policy, study-abroad service, pilgrimage service, or overseas itinerary, personal information may need to be transferred to or accessed from countries outside Pakistan.

Those countries may have privacy and data-protection standards different from those in Pakistan. We will use reasonable measures appropriate to the circumstances when transferring information and will limit transfers to what is reasonably necessary for the relevant service.

17. Data Retention

We retain personal information only for as long as reasonably necessary for the purposes for which it was collected, including booking administration, customer support, accounting, audit, legal, compliance, fraud-prevention, dispute, warranty, supplier, and record-keeping requirements.

Retention periods may vary according to the type of information, the service provided, supplier requirements, legal obligations, limitation periods, and whether an ongoing customer or corporate relationship exists.

When information is no longer reasonably required, we may securely delete, anonymize, archive, or otherwise dispose of it in accordance with our operational and legal requirements.

18. Document Copies and Travel Records

Travel and visa services frequently require copies of passports, identity documents, visas, invitation letters, financial evidence, employment records, sponsorship documents, and related materials. Such records may be stored electronically or physically for the period reasonably required to perform the service and meet legitimate record-keeping obligations.

Customers should avoid sending documents that are not required for the service. Where possible, provide only the information reasonably requested by our authorized team.

19. Information Security

We use reasonable administrative, organizational, and technical measures designed to protect personal information against unauthorized access, accidental loss, misuse, alteration, disclosure, or destruction.

These measures may include access restrictions, user authentication, system controls, backups, security monitoring, staff procedures, and appropriate protections for electronic and physical records.

No website, email system, messaging platform, storage system, or transmission method can be guaranteed to be completely secure. Customers should therefore use reasonable care when sending sensitive documents electronically.

20. Data Breaches and Security Incidents

If we become aware of a security incident affecting personal information, we will investigate and take reasonable steps to contain and remediate the incident. Where notification is required by applicable law, we will make the required notification to affected persons or authorities.

21. Your Privacy Choices and Requests

Subject to applicable law and legitimate business, legal, security, and record-keeping requirements, you may contact us to:

  • request access to personal information we hold about you;
  • request correction of inaccurate or incomplete information;
  • request deletion of information that is no longer required, where deletion is legally and operationally appropriate;
  • object to or request restriction of certain processing where applicable;
  • withdraw consent where processing is based specifically on consent, without affecting earlier lawful processing;
  • request information about how your data has been used or shared; or
  • opt out of direct marketing communications.

We may need to verify your identity before acting on a privacy request. Certain information may need to be retained despite a deletion request where required for legal, accounting, fraud-prevention, dispute, security, or contractual purposes.

22. Marketing Communications

We may send information about travel services, promotions, updates, or offers where permitted and appropriate. You may ask us to stop sending direct marketing communications at any time by using an unsubscribe option where available or by contacting us.

Opting out of marketing does not prevent us from sending necessary service communications relating to an enquiry, booking, payment, visa application, schedule change, security matter, or other active transaction.

23. Children and Minors

We do not knowingly use information about children for unrelated marketing merely because the information was provided for a family booking, visa, education, or travel service.

Where information about a minor is required, it should normally be provided by or with the authority of a parent, legal guardian, sponsor, institution, or other person legally authorized to act for the minor.

24. External Websites and Third-Party Links

Our website may contain links to airlines, hotels, embassies, visa application centres, government agencies, insurers, payment providers, social networks, and other third-party websites.

We are not responsible for the privacy practices, security, content, or availability of independent third-party websites. You should review the privacy notice of the relevant third party before submitting personal information to it.

25. Fraud Prevention, Legal Requests and Protection of Rights

We may process, preserve, or disclose information where reasonably necessary to detect or prevent fraud, identity misuse, unauthorized transactions, cyber incidents, abuse of our systems, or threats to the rights, safety, property, or security of Varioline Traveller, our customers, suppliers, staff, or others.

We may also disclose information where required by a valid legal process, court order, lawful government request, or other obligation imposed by applicable law.

26. Applicable Privacy and Cybersecurity Framework

Our handling of personal information is intended to comply with applicable laws and legal requirements in Pakistan and, where relevant to a particular transaction, applicable requirements of another jurisdiction.

Pakistan's Prevention of Electronic Crimes Act, 2016, as amended from time to time, contains provisions relevant to unauthorized access, use, interference, and certain other conduct involving electronic systems and data.

Where proposed or draft privacy legislation has not entered into force, we do not describe it in this Policy as an enacted law. If new privacy legislation becomes applicable to our operations, this Policy may be updated accordingly.

27. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our services, technology, suppliers, business practices, security measures, or legal requirements.

The updated version will be published on this page with a revised “Last Updated” date. Material changes may also be communicated through another appropriate channel where required.

28. Contact Us About Privacy

If you have a question, concern, correction request, deletion request, or other privacy-related enquiry, please contact:

Varioline Traveller
Plaza No. 1, Block A-1, PIA Main Boulevard
Lahore, Punjab, Pakistan
Email: info@variolinetraveller.com
Phone: +92 318 4161788

Please provide enough information for us to identify the relevant record or transaction and understand your request. We may request reasonable proof of identity before releasing, correcting, or deleting personal information.

Privacy question?

If you have a question about this Privacy Policy, the information we hold, or a privacy request, contact our team and we will assist.