Privacy Policy - Tabi no Chan Auto Fill
Last updated: August 17, 2026
Tabi no Chan Auto Fill (the extension) is an internal tool used by authorized staff of Tabi no Chan (Hiền Trang Visa) to prepare and complete Chinese Visa Application Service Center (CVASC) applications on behalf of applicants and reconcile the resulting CVASC application identifiers with the same Visa Submission in the agency Portal.
Who can use the extension
The extension is restricted to approved staff accounts. Staff sign in with Google, and Tabi no Chan (Hiền Trang Visa) verifies the account against its staff access list before enabling extension actions.
Web portal usage analytics
The Tabi no Chan Web App uses Firebase Analytics (GA4) to understand aggregate portal usage, such as sign-in success, sessions, active time, normalized page templates, and a limited list of safe actions. This helps administrators improve the service; it is not used for productivity scoring, rankings, or employment decisions.
Landing-page analytics starts only after a visitor gives analytics consent. Authenticated portal events use a Firebase user identifier and bounded role/portal labels. Email, applicant information, Case Codes, search text, form values, filenames, document content, prompts, tokens, keystrokes, and session recordings are not sent to Analytics. Per-account reports are available only to authorized administrators; the GA4 export is retained for approximately 14 months and then expires automatically.
Data the extension handles
- Applicant form data, including name, passport number, date of birth, address, travel, work, and contact details.
- Applicant files selected for the active application, including passport and photo files.
- Staff authentication data, including the staff Google email and a temporary Google OAuth access token used to verify staff access.
- Agency case references needed for staff-requested actions, including Case Code, internal case identifier, CVASC Apply ID, and final SGN application identifier.
- CVASC application-table content for a staff-selected date range, including identifiers, passport number, creation time, application status, and rejection reason.
- Only relevant CVASC Save and Submit request or response data needed to capture the Apply ID. The extension does not collect general browsing history, keystrokes, or activity from unrelated websites.
How the data is used
- Applicant data and files are used only to fill the official CVASC form at the staff member's request.
- A bundled face-detection model processes the applicant photo locally to help position and crop it. The extension does not create or send a facial template or biometric profile.
- Staff authentication data is used only to confirm that extension actions are performed by authorized agency staff.
- Case and CVASC identifiers are used only to load the requested Autofill Package, record the CVASC submission, and perform an explicit staff-requested ID reconciliation.
Where the data goes
- The staff browser: current applicant data, selected files, settings, staff authorization metadata, and the last filled Case Code may be stored in Chrome local storage.
- Tabi no Chan (Hiền Trang Visa)'s server: receives the temporary Google access token for verification and the minimum case or CVASC identifiers required for the staff-requested action. It also sends the requested Autofill Package to the authorized staff browser.
- Google: provides Google Sign-In, verifies the access token, and provides the Google Cloud infrastructure used by the agency service.
- The official CVASC website: receives the applicant form data and files when staff fill the application. CVASC table requests go directly from the active CVASC tab to the official CVASC service.
Data is not sold, rented, used for advertising or profiling, or transferred for a purpose unrelated to the extension's disclosed visa-form and ID-reconciliation functions.
Authentication and CVASC session data
The temporary Google OAuth access token is managed by Chrome and sent over HTTPS for staff verification and authorized agency-server requests. It is not written into the extension's own local storage. The CVASC Admin-Token is used only inside the active CVASC page session for direct CVASC table requests. It is not stored by the extension or sent to Tabi no Chan (Hiền Trang Visa)'s server.
Storage and retention
- Applicant data and files in Chrome local storage remain until staff replace or clear them, or uninstall the extension. They are not automatically cleared when the browser session ends.
- Stored staff authorization metadata is removed when staff sign out or when authorization fails. Chrome separately manages its cached Google access token.
- The extension does not keep a long-term copy of the CVASC table or the CVASC Admin-Token.
- Final CVASC identifiers and submission activity remain in the agency case-management system under its operational and legal retention rules. Standard security and reliability logs may be retained by the agency service and its cloud provider.
Security
Network requests made by the extension use HTTPS. Access to agency actions is restricted to approved staff accounts. The extension does not load or execute remote code; its scripts and photo-processing model are included in the installed package.
Staff controls
Staff can clear locally stored applicant data from the extension Settings page, sign out to remove stored authorization metadata, or uninstall the extension to remove its Chrome local storage. Questions about access to or correction of agency case records can be sent to the contact address below.
Chrome Web Store Limited Use
The use of information received from Google APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements.
Contact
Questions about this policy: hientrang24hvisa@gmail.com, Tabi no Chan (Hiền Trang Visa).