Effective Date: August 1, 2026
This Privacy Policy explains how Tonse Inc., a Wyoming corporation operating the Go China Visa Free website and brand, collects, uses, stores, discloses, and protects personal information through gochinavisafree.com and related tools, forms, communications, products, and services.
This Privacy Policy explains our current practices. It is not intended to create contractual rights beyond those provided by applicable law.
1. Who We Are
The organization responsible for the personal information described in this Privacy Policy is:
Tonse Inc.
30 N Gould St Ste R
Sheridan, WY 82801
United States
Email: tonsetravel@gmail.com
Where applicable privacy law uses the term "controller," Tonse Inc. is generally the controller of personal information collected directly through our website and services.
Go China Visa Free is an independent business.
We are not a government agency, embassy, consulate, immigration authority, airline, or border authority.
2. Scope of This Privacy Policy
This Privacy Policy applies to personal information collected through:
- gochinavisafree.com;
- website cookies and analytics;
- eligibility and route tools;
- inquiry and contact forms;
- email communications;
- Route Review orders;
- Custom China Trip Plan orders;
- Concierge inquiries and services;
- Stripe checkout and transaction records;
- digital products; and
- related customer-service and business operations.
This Privacy Policy does not govern an independent third party that maintains its own privacy policy, including a government website, Stripe, airline, hotel, supplier, insurer, booking platform, telecommunications provider, affiliate partner, or external application.
3. Personal Information We Collect
The information we collect depends on how you interact with us.
We may collect:
- your name;
- email address;
- telephone number;
- preferred communication method;
- WhatsApp, WeChat, or another messaging identifier;
- billing or mailing address;
- country or general region;
- company or organization; and
- other contact information you provide.
For our tools and paid services, we may collect:
- nationality or passport-issuing country;
- passport type;
- country of residence;
- origin and destination;
- entry and exit locations;
- transit points and layovers;
- travel dates;
- intended trip duration;
- intended purpose of travel;
- cities and regions you plan to visit;
- number and general details of travellers;
- accommodation preferences;
- transportation preferences;
- budget;
- interests and travel style;
- fixed meetings, conferences, or events;
- service questions;
- itinerary preferences; and
- other information voluntarily submitted for the requested product or service.
We do not ordinarily require a passport number or passport scan for a Route Review.
For personalized travel planning, you may choose to provide:
- dietary requirements;
- food allergies;
- accessibility needs;
- mobility limitations;
- health-related travel considerations;
- information concerning children or family members; or
- other special requirements.
Please provide only information reasonably necessary for planning.
Where applicable law treats this information as sensitive or special-category information, we process it only with an appropriate legal basis, which may include your explicit consent.
We do not use this information to infer unrelated characteristics or for unrelated advertising.
When you purchase or request a product or service, we may collect:
- the product or service selected;
- order date;
- amount and currency;
- payment status;
- transaction identifier;
- billing information;
- limited payment-method information made available by Stripe;
- refund and cancellation records;
- chargeback or dispute information;
- fraud-prevention indicators;
- invoice information; and
- communications concerning the transaction.
Stripe processes complete payment-card information. We generally do not receive or store your complete payment-card number.
We collect information contained in:
- emails;
- contact-form submissions;
- questionnaires;
- planning forms;
- customer-service messages;
- feedback;
- corrections;
- complaints;
- reviews;
- telephone or video-call notes;
- attachments; and
- other communications you send.
Customer communications, attachments, drafts, and service files may be stored in Gmail and Google Drive.
Where reasonably necessary, files may be downloaded to protected devices used by the founders.
When you visit the website, we or our technology providers may collect:
- IP address;
- approximate location derived from an IP address;
- browser type and version;
- device type;
- operating system;
- language;
- screen or device characteristics;
- referring website or source;
- pages viewed;
- links selected;
- session dates and times;
- session and usage statistics;
- cookie or similar identifiers;
- website errors;
- security logs; and
- website-performance information.
Information entered into an eligibility or route tool may include:
- nationality or passport-issuing country;
- route;
- transit points;
- destinations;
- travel dates;
- intended length of stay;
- selected policy or travel purpose; and
- answers to tool questions.
We may use this information to:
- generate the requested result;
- operate and troubleshoot the tool;
- prevent misuse;
- understand aggregate usage; and
- improve functionality and accuracy.
Using a free tool does not automatically subscribe you to marketing communications.
When you select an affiliate or referral link, we or the relevant third party may process:
- the page or link selected;
- a referral or campaign identifier;
- cookie or device information;
- transaction-attribution information; and
- commission status.
The third party independently controls information collected after you leave our website.
Unless we specifically request it through an appropriate method, please do not send:
- account passwords;
- verification codes;
- complete payment-card numbers;
- complete passport or identification scans;
- detailed medical records;
- biometric information;
- bank statements;
- criminal-history documents;
- unnecessary immigration documents; or
- personal information you are not authorized to provide.
We may delete, redact, restrict, or return unnecessary sensitive information.
4. How We Obtain Personal Information
We obtain personal information:
- directly from you;
- automatically through your browser or device;
- from a person arranging travel for you;
- from Stripe;
- from Netlify;
- from Google services;
- from public and official sources when researching a request;
- from suppliers involved in an agreed Concierge service;
- from referral or affiliate partners; and
- when you choose to communicate through a third-party platform.
When you provide another person's information, you represent that you are authorized to do so and have provided any notice or obtained any permission required by law.
5. How We Use Personal Information
We may use personal information to:
- operate, maintain, and secure the website;
- provide eligibility and route-tool results;
- respond to inquiries;
- prepare Route Reviews;
- prepare and revise Trip Plans;
- evaluate and perform Concierge work;
- deliver digital products;
- communicate about orders and services;
- request necessary clarification;
- process payments and refunds;
- manage billing disputes;
- coordinate with suppliers at your direction;
- personalize travel recommendations;
- maintain accounting, tax, and transaction records;
- understand website traffic and performance;
- improve website content and services;
- attribute affiliate referrals;
- prevent fraud, misuse, and security incidents;
- enforce our Terms of Use;
- protect our legal rights;
- respond to privacy requests;
- comply with legal obligations; and
- establish, exercise, or defend legal claims.
We do not use sensitive travel or health-related information for unrelated advertising.
6. Legal Bases for Processing
Where applicable law requires us to identify a legal basis, we rely on one or more of the following.
We process personal information when reasonably necessary to:
- respond to a request for a service;
- prepare a proposal;
- accept and administer an order;
- deliver a product or service;
- communicate about performance;
- process payment;
- provide customer support; and
- manage our contractual relationship with you.
We may rely on consent for:
- non-essential cookies;
- Google Analytics where consent is required;
- optional marketing;
- testimonials;
- optional processing of sensitive or health-related information;
- optional disclosure of information to a supplier; and
- another activity where consent is legally required.
You may withdraw consent at any time.
Withdrawal does not affect processing that occurred lawfully before consent was withdrawn.
We may process personal information for legitimate business interests, including:
- operating and improving the website;
- responding to inquiries;
- maintaining security;
- preventing fraud;
- understanding website performance;
- managing customer and supplier relationships;
- maintaining appropriate business records;
- resolving disputes; and
- protecting our legal rights.
Where required, we consider whether our interests are overridden by your rights and reasonable expectations.
We may process information when necessary to comply with:
- tax and accounting requirements;
- lawful government requests;
- sanctions and trade restrictions;
- consumer-protection requirements;
- legal process;
- regulatory obligations; and
- other applicable laws.
Where applicable, we may process personal information to establish, exercise, or defend legal claims or to protect a person's vital interests.
7. Whether Information Is Required
Some information is necessary for us to enter into or perform a contract.
For example, we may be unable to provide a Route Review without sufficient information concerning:
- passport nationality;
- travel dates;
- the complete route;
- entry and exit points; and
- contact information.
We may be unable to prepare a Trip Plan without sufficient information concerning:
- dates;
- destinations;
- duration;
- budget;
- interests; and
- traveller preferences.
Dietary, accessibility, mobility, and health-related information is optional unless you want us to consider it when preparing or coordinating a service.
Failure to provide necessary information may prevent us from accepting or completing a request.
8. Service-Specific Processing
We use submitted nationality, route, dates, entry and exit locations, transit points, and questions to research and prepare the requested Route Review.
We may retain the review and related communications for:
- customer service;
- quality control;
- recordkeeping;
- payment administration; and
- dispute resolution.
We use submitted dates, destinations, budget, interests, pace, fixed commitments, and optional dietary or accessibility information to create and revise your itinerary.
We may contact you when information is incomplete, inconsistent, or impractical.
We use submitted information to:
- evaluate whether we can accept the request;
- communicate with you;
- prepare a proposal;
- design the agreed plan;
- request information from suppliers;
- assist with coordinating agreed arrangements; and
- provide the support described in the applicable proposal.
Where practical, we limit disclosures to suppliers to the information reasonably necessary for the inquiry or arrangement.
Independent suppliers may process information under their own privacy policies.
Stripe processes payment and transaction information to:
- authorize and complete payments;
- detect and prevent fraud;
- comply with financial and legal obligations;
- process refunds;
- manage disputes; and
- provide payment services.
Stripe may act as our payment-service provider and may also process certain information for its own legal, security, fraud-prevention, compliance, and service purposes under its own privacy terms.
We use order information to:
- accept payment;
- provide delivery or access;
- prevent fraud or unauthorized distribution;
- provide customer support; and
- maintain transaction records.
9. Current Technology and Service Providers
We currently use the following providers and services.
We use Netlify for:
- website hosting;
- content delivery;
- technical infrastructure;
- security and server logs; and
- Netlify Analytics.
Netlify may process network, device, IP-address, request, security, and technical information.
If a website form is routed through Netlify's form-handling infrastructure, Netlify may also process the information submitted through that form.
We use Google services including:
- Google Analytics;
- Google Search Console;
- Gmail;
- Google Drive; and
- related Google account and security services.
Depending on the service, Google may process:
- device and network information;
- website usage information;
- cookie identifiers;
- search-performance information;
- email communications;
- attachments;
- customer files; and
- business documents.
We use Bing Webmaster Tools to understand:
- search indexing;
- search visibility;
- website crawling;
- search errors; and
- website performance in Bing search results.
We do not currently use Microsoft Advertising, the Microsoft UET advertising tag, or Microsoft Clarity.
We use Stripe for:
- payment processing;
- refunds;
- fraud prevention;
- payment records; and
- transaction administration.
We may introduce additional technology, automation, communications, newsletter, storage, analytics, or service providers in the future.
We will update this Privacy Policy or provide appropriate notice before using personal information for a materially different purpose.
10. Cookies and Similar Technologies
We use cookies and similar technologies for website operation, consent preferences, analytics, security, and related purposes.
Strictly necessary cookies or local-storage records may be used to:
- operate essential website functions;
- maintain security;
- remember cookie preferences;
- process checkout activity;
- prevent fraud; or
- provide a feature specifically requested by the visitor.
Where applicable law permits, these technologies may operate without optional consent because they are necessary for the requested service or website function.
We use Google Analytics to understand how visitors find and use the website.
Google Analytics may collect:
- a pseudonymous client identifier;
- visitor and session statistics;
- approximate geographic location;
- browser and device information;
- pages viewed;
- links and interactions;
- referring sources; and
- website-performance information.
Google Analytics may use cookies and similar technologies. The duration of a cookie depends on our configuration, your browser, your consent choices, and whether you delete or block the cookie.
We do not intentionally send names, email addresses, passport information, payment information, or other directly identifying customer information to Google Analytics.
Where applicable law requires consent, we will seek the required consent before activating non-essential Google Analytics cookies.
We use Netlify Analytics for server-side website traffic measurement.
Netlify Analytics processes website request and traffic information through Netlify's hosting infrastructure rather than relying on an ordinary browser analytics cookie.
Google Search Console and Bing Webmaster Tools are used to understand search performance, website indexing, crawling, and technical search errors.
These tools do not mean that we use Google Ads or Microsoft Advertising.
When you click an affiliate or referral link, the external provider may place a cookie or use another identifier to attribute a purchase, booking, registration, or other action.
The external provider controls its own cookie and processing activities under its privacy and cookie policies.
We do not currently use an on-site behavioral advertising network.
Where a cookie-preference tool is available, you may be able to:
- accept optional cookies;
- reject optional cookies;
- manage cookie categories; and
- later change your choice.
You may also delete or block cookies through your browser settings.
Blocking cookies may affect certain website features.
11. Analytics
We use Google Analytics and Netlify Analytics to:
- understand website traffic;
- determine which pages are useful;
- understand general visitor sources;
- measure website performance;
- detect technical problems; and
- improve content and website design.
We do not use analytics information to make immigration, credit, employment, insurance, or similarly significant decisions about individual visitors.
Google Analytics information is retained according to:
- the retention settings configured in our Google Analytics account;
- applicable cookie durations;
- consent choices;
- security needs; and
- our reasonable need to measure and improve website performance.
12. Artificial Intelligence
We may use artificial-intelligence tools for general research, drafting, translation, organization, and content assistance.
We do not intentionally submit identifiable customer information to general-purpose artificial-intelligence tools.
When AI assistance is appropriate, we aim to use generalized or de-identified information rather than information such as:
- a customer's name;
- email address;
- telephone number;
- passport number;
- complete travel document;
- payment information; or
- another direct identifier.
We do not intentionally submit:
- complete passport documents;
- complete payment details;
- passwords;
- verification codes;
- detailed medical records; or
- unnecessary sensitive personal information to general-purpose artificial-intelligence tools.
If this practice changes materially, we will update this Privacy Policy before using identifiable customer information in that manner.
13. Email, Google Drive, and Local File Storage
Customer inquiries, service communications, attachments, drafts, final deliverables, and related records may be stored in:
- Gmail;
- Google Drive; and
- protected devices used by authorized founders.
Access is currently restricted to the two founders of Tonse Inc. who require access to operate the business and provide services.
We may download an attachment where reasonably necessary to:
- review it;
- prepare a deliverable;
- maintain an appropriate record;
- resolve a technical issue; or
- respond to the customer.
Downloaded files should be stored in an access-controlled business location and deleted when they are no longer reasonably necessary.
We may move from Gmail to Google Workspace in the future. We will update this Privacy Policy if that change materially affects how personal information is processed.
14. How We Disclose Personal Information
We may disclose personal information to the following categories of recipients.
Providers assisting with:
- website hosting;
- content delivery;
- analytics;
- email;
- cloud storage;
- payment processing;
- security;
- fraud prevention;
- document production; and
- related business operations.
Where reasonably necessary for an agreed service, information may be disclosed to:
- hotels;
- drivers;
- guides;
- translators;
- restaurants;
- transport providers;
- attractions;
- ticketing providers; and
- other proposed or selected suppliers.
We may disclose information to:
- lawyers;
- accountants;
- insurers;
- auditors;
- financial institutions; and
- other professional advisers where reasonably necessary.
We may disclose information when we reasonably believe disclosure is necessary to:
- comply with applicable law;
- respond to valid legal process;
- respond to an authorized government request;
- prevent fraud or misuse;
- protect a person's safety;
- enforce our agreements;
- protect our rights or property; or
- establish, exercise, or defend a legal claim.
Information may be disclosed or transferred as part of:
- a merger;
- acquisition;
- financing;
- restructuring;
- sale of assets;
- insolvency; or
- similar corporate transaction, subject to applicable law.
We may disclose information when you request, direct, authorize, or consent to the disclosure.
15. Third-Party Links and External Websites
Our website contains links to independent third parties.
When you select an external link, the third party may:
- collect information directly from you;
- place cookies;
- use referral identifiers;
- process payment information; or
- track your activity under its own terms.
The third party's privacy policy applies to its processing.
We do not control how an independent third party collects, uses, stores, secures, or discloses personal information.
You should review the third party's current privacy and security terms before providing information or payment.
16. Sale, Sharing, and Targeted Advertising
Tonse Inc. does not sell personal information for monetary consideration.
Based on our current practices:
- we do not use customer service information for cross-context behavioral advertising;
- we do not sell sensitive personal information;
- we do not use sensitive information to infer unrelated personal characteristics;
- we do not currently use Microsoft Advertising;
- we do not operate a data-broker business;
- and we do not knowingly sell or share children's personal information.
Some privacy laws define "sale," "sharing," or "targeted advertising" broadly enough to include certain analytics, advertising, or affiliate technologies.
Where applicable law treats a technology we use as a sale, sharing, or targeted-advertising activity and provides an opt-out right, we will provide and honor the legally required choice.
17. Marketing Communications
We may collect email addresses through website forms or direct communications and may send:
- information you requested;
- service communications;
- guide availability notices;
- website or policy updates;
- offers or marketing where legally permitted;
- or other communications you requested.
Marketing emails will provide an unsubscribe method where required.
You may also request removal from marketing communications by emailing:
tonsetravel@gmail.com
We may retain a minimal suppression record after an unsubscribe request so that the address is not accidentally added to marketing communications again.
Unsubscribing from marketing does not prevent necessary messages concerning:
- an active order;
- payment;
- a requested service;
- security;
- a privacy request; or
- a legal notice.
18. International Processing and Transfers
Tonse Inc. is established in the United States.
Personal information may be processed or accessed in:
- the United States;
- countries where authorized founders or personnel are working;
- countries where relevant suppliers are located; and
- countries where technology providers or their subcontractors operate.
Privacy laws may differ between countries.
Where applicable law requires a transfer mechanism or safeguard, we may rely on an appropriate mechanism, including:
- an adequacy decision;
- approved contractual clauses;
- contractual and technical safeguards;
- a provider's recognized data-transfer framework;
- another lawful transfer mechanism; or
- a permitted legal exception.
You may contact us for additional information concerning safeguards relevant to your personal information.
19. Data Retention
We retain personal information only for as long as reasonably necessary for the purposes described in this Privacy Policy.
Our general retention periods are as follows.
General inquiries that do not become paid services are retained for as long as reasonably necessary for customer service, security, and record-keeping purposes, generally no longer than 24 months after the last meaningful communication.
Order records, final deliverables, and material service communications are ordinarily retained for up to three years after service completion.
Working files and unnecessary attachments may be deleted sooner.
Concierge proposals, service records, and material communications are ordinarily retained during the service and for up to three years after completion.
Transaction, invoice, accounting, and tax information may ordinarily be retained for up to seven years, or longer where legally required.
Marketing information is retained until:
- you unsubscribe;
- the relevant mailing activity is discontinued;
- or the information is no longer reasonably needed.
A limited suppression record may be retained afterward.
Analytics information is retained according to:
- the applicable analytics-platform settings;
- cookie durations;
- consent choices;
- security needs; and
- our reasonable need to understand website performance.
Security, hosting, and technical logs may ordinarily be retained for up to 24 months, unless needed longer for an incident, investigation, legal claim, or security purpose.
Records concerning privacy requests, complaints, and legal disputes may be retained for up to three years after closure, or longer where reasonably necessary to demonstrate compliance or manage a claim.
Unrequested or unnecessary passport, identity, financial, or medical documents will be deleted or redacted as soon as reasonably practical after we determine that they are unnecessary.
We may retain information longer when necessary for:
- litigation;
- a legal hold;
- fraud prevention;
- tax obligations;
- contract enforcement;
- security investigations; or
- another legitimate legal requirement.
We may retain aggregated or de-identified information that no longer reasonably identifies an individual.
20. Information Security
We use reasonable administrative, technical, and organizational measures intended to protect personal information.
These measures may include:
- password protection;
- multi-factor authentication;
- limited account access;
- access-controlled cloud storage;
- encrypted website transmission;
- payment processing through Stripe;
- account-security controls; and
- deletion of unnecessary information.
No website, email system, messaging platform, transmission method, or storage service is completely secure.
We cannot guarantee absolute security.
You are responsible for:
- using secure devices and accounts;
- protecting passwords and verification codes;
- not sending unnecessary sensitive documents through ordinary email;
- checking recipient addresses; and
- notifying us promptly if you believe a communication or account has been compromised.
If a personal-data breach occurs, we will investigate and provide notifications where required by applicable law.
21. Children's Information
Our products and paid services are intended to be purchased by adults.
We do not knowingly collect personal information directly from a child under 13 in the United States, or below another applicable minimum age, without legally required authorization.
A parent, guardian, or authorized adult may provide limited information about a minor where reasonably necessary for family travel planning.
The adult is responsible for having authority to provide that information.
Please contact us if you believe a child submitted personal information without appropriate authorization.
22. Automated Decisions
Our eligibility and route tools may automatically produce an informational result based on information entered by the visitor.
That result:
- is not an official immigration decision;
- does not have a legal or similarly significant effect;
- does not determine whether a government or carrier will permit travel; and
- should be independently verified.
We do not currently use solely automated processing to make decisions that produce legal or similarly significant effects concerning customers.
23. Your Privacy Rights
Depending on your location and applicable law, you may have the right to:
- confirm whether we process your personal information;
- request access to your personal information;
- request correction of inaccurate information;
- request deletion;
- request restriction of processing;
- object to certain processing;
- withdraw consent;
- receive certain information in a portable format;
- opt out of certain marketing, targeted advertising, sale, sharing, or profiling;
- appeal a denied privacy request where applicable; and
- complain to a privacy or data-protection authority.
These rights are not absolute.
We may need to:
- verify your identity;
- clarify your request;
- protect another person's rights;
- retain legally required information;
- complete a transaction you requested;
- preserve evidence concerning a dispute; or
- apply another legal exception.
To submit a privacy request, email:
tonsetravel@gmail.com
Use the subject line: Privacy Request Please do not send a passport or other sensitive identification document unless we specifically explain why it is necessary and provide an appropriate submission method.
An authorized agent may submit a request where permitted by law. We may request proof of authorization and may verify your identity directly.
We will not unlawfully discriminate against you for exercising an applicable privacy right.
24. European Economic Area and United Kingdom Users
Where the European Union General Data Protection Regulation, United Kingdom GDPR, or related law applies, you may have rights including:
- access;
- correction;
- erasure;
- restriction;
- objection;
- portability;
- withdrawal of consent; and
- the right to complain to a supervisory authority.
The applicable purposes and legal bases for processing are described in this Privacy Policy.
You may complain to the data-protection authority in the country where you live, work, or believe a violation occurred.
Nothing in this section represents that every European privacy requirement applies to every interaction with Tonse Inc.
25. United States State Privacy Rights
Residents of certain U.S. states may have additional rights under applicable state privacy laws.
Those laws apply only when their legal scope, definitions, and business thresholds are satisfied.
This Privacy Policy does not represent that every state privacy law applies to Tonse Inc.
Where applicable, a state privacy request may be submitted to: tonsetravel@gmail.com
We may ask for information reasonably necessary to verify the request.
26. Global Privacy Control and Do Not Track
Some browsers provide Global Privacy Control or "Do Not Track" signals.
There is no single universally applicable response standard for every Do Not Track signal.
Because we do not currently sell personal information for monetary consideration or use customer-service information for cross-context behavioral advertising, there may be no separate sale or sharing activity to disable.
Where applicable law requires recognition of a browser-based opt-out signal and the signal applies to technology we use, we will take reasonable steps to honor it.
Cookie preferences may also be controlled through available website cookie settings and your browser settings.
27. Changes to This Privacy Policy
We may update this Privacy Policy as our website, providers, products, services, business practices, or legal obligations change.
The Effective Date at the top identifies the most recent material revision.
We will review and, where appropriate, update this Privacy Policy before:
- using Zapier or another automation provider for material customer-data workflows;
- introducing a separate newsletter or customer-relationship platform;
- using identifiable customer information in general-purpose artificial-intelligence tools;
- introducing behavioral advertising;
- adding session-recording or advertising technologies;
- materially changing how forms are stored;
- materially changing our payment provider;
- materially expanding the types of sensitive information collected; or
- using personal information for a materially different purpose.
Where legally required, we will provide additional notice or request consent.
28. Contact Us
Questions, complaints, and privacy requests may be sent to:
Tonse Inc.
Operating the Go China Visa Free website and brand
30 N Gould St Ste R
Sheridan, WY 82801
United States
Email: tonsetravel@gmail.com
Please provide enough information for us to understand your request, but do not send unnecessary identification documents or sensitive records through ordinary email.