Privacy Policy
This privacy policy explains how we collect, use, and safeguard your personal data across our US ESTA document review and application assistance services. Your privacy is of paramount importance to us.
1. Overview & Data Protection Frameworks
This Privacy Policy details how we collect, process, safeguard, and disclose your personal details when you access our website or utilize our US ESTA document review and application assistance services. We deliver travel documentation assistance globally, including to applicants residing in Visa Waiver Program (VWP) participating nations across the European Union (EU), United Kingdom (UK), United States (US), and other international jurisdictions. Consequently, we align our data operations with relevant global privacy standards, including the EU General Data Protection Regulation (EU GDPR - Regulation 2016/679), UK GDPR & Data Protection Act 2018, California Consumer Privacy Act (CCPA) / California Privacy Rights Act (CPRA), and applicable US state and international privacy laws. For all privacy inquiries, data rights requests, or supervisory communications, please contact our privacy compliance team using the contact form.
2. Personal Information We Collect
To fulfill your US ESTA application under the Visa Waiver Program, we collect identification and personal details (full name, date of birth, place of birth, gender, primary citizenship, national ID or secondary citizenship details); travel document details (passport number, issuance and expiration dates, issuing country, digital passport scans/images); verification media (facial photographs or selfies submitted to verify identity); contact details (email, phone, home address, emergency contacts, and parent details as required by ESTA filing); employment data; US destination details; statutory VWP security declarations; billing reference data (complete card details are processed directly by certified third-party payment gateways and never stored on our servers); and support inquiry correspondence. We also automatically collect technical and usage information — IP address and approximate location, device and browser characteristics, and navigation and cookie interactions — and, where permitted by law, may receive verification signals from accredited identity checks, anti-fraud systems, or payment processors.
3. How We Process Your Data & Legal Grounds
We rely on defined legal bases under applicable data privacy frameworks to process your personal data. Processing your ESTA application, identity verification, and payment handling are carried out under performance of contract; statutory VWP security declarations are processed under legal obligation and public task; customer support, legal compliance, and security fall under performance of contract and legitimate interest; and site analytics and marketing communications are processed under legitimate interest or explicit, opt-in consent.
4. Special Category Data, Biometrics & Automated Checks
Facial imagery and passport photo uploads used to confirm applicant identity may be categorized as biometric data under applicable law. We handle this sensitive data under explicit user consent and strict necessity: biometric media is encrypted during transmission and storage using industry-standard AES-256 protocols, access is restricted strictly to technical staff directly processing your filing, biometric assets are never analyzed for marketing or commercial resale, and media files are purged under our accelerated deletion schedule. We utilize automated matching software to compare selfie images against passport documentation to detect fraud and formatting errors; these tools assist — but do not replace — human review, and no final decision leading to application rejection or legal consequence is taken solely via automated processing. Applicants can request a manual human review by emailing us using the contact form.
5. Cookie Policy & Tracking Management
Our website utilizes cookie files and similar technical tracking to maintain portal stability, evaluate site traffic, and support user preferences. When launching our portal, our banner allows you to select "Accept All" (necessary, analytical, and functional optimization cookies) or "Necessary Only" (essential operational cookies). Strictly necessary cookies support session management, application step retention, portal security, and secure checkout, and cannot be disabled. Analytics & preference cookies, which help us evaluate visitor engagement, detect software errors, and store language settings, are enabled only with your consent. You may update your preferences at any time by clearing browser cookies or contacting our team.
6. Data Sharing & Third-Party Vendors
We share personal data with government authorities of your destination country as necessary to process and transmit your application, or otherwise required by law; third-party service providers and customer support platforms under information processing statutes; legal and professional companies when needed; law enforcement and regulators where required by law; and fraud prevention agencies. We do not sell your personal data to third parties for marketing purposes. For fraud mitigation and risk aversion purposes, our payment processor also captures certain data — including device, browser, and click data — as an independent data controller in its own right, separate from its role as our payment processor. Our platform may contain links to external websites, software, or integrations; we have no control over, and accept no responsibility for, the content, security practices, terms, or privacy policies of any third-party site or service, and you access and use such tools entirely at your own risk. Trusted third-party service providers — such as secure payment processors and customer support platforms — process user data only under binding data protection agreements.
7. Data Retention & Accelerated Deletion Schedule
We retain personal information only for as long as required to deliver our service and fulfill legal and accounting requirements. Application text records (name, travel details, employment data) are kept for 12 months from submission, then securely archived or deleted. Statutory VWP security declarations are permanently destroyed within 2 to 4 days following application submission to official U.S. authorities. Financial and order records are retained for 7 years to satisfy accounting, tax, and audit obligations, and support inquiries are kept for up to 3 years from the last interaction. Raw passport images and facial verification photos follow an accelerated deletion schedule: within 24 hours of application approval and delivery, rejection by the government, or a full or partial refund; immediately upon cancellation by the user; and automatically after 14 days for an incomplete or abandoned application.
8. Data Security Measures
We enforce rigorous technical and organizational controls to safeguard personal data against unauthorized access, loss, or alteration. Measures include AES-256 encryption at rest, TLS encryption in transit, strict role-based access limits, and regular security assessments. In the unlikely event of a security incident impacting your rights, we will notify relevant supervisory authorities and affected users as required by law.
9. Protection of Minors
Our services are not intended for independent use by individuals under 18 years of age. Minors may only apply through a parent, legal guardian, or authorized representative who submits data on their behalf. Children's details provided for family travel filings are handled with identical security and retention protections as adult filings. If you suspect a minor has submitted information directly without parental authorization, contact using our contact form for immediate deletion.
10. Direct Marketing
If you opt-in to receive promotional updates or service announcements, we may send periodic emails. You can withdraw consent at any time via the "Unsubscribe" link in any communication or by contacting support.
11. Policy Modifications
We may update this Privacy Policy to reflect changing regulatory requirements or service enhancements. Revisions will be published on this page with an updated "Last Updated" date.
12. Region-Specific Provisions
European Union (EU) Residents — acts as the data controller for personal data processed via this website. Transfers of EU personal data outside the European Economic Area (EEA) rely on European Commission-approved Standard Contractual Clauses (SCCs). Under the EU GDPR, you have the right to request access, rectification, erasure, processing restriction, data portability, and objection to processing, and may lodge a complaint with your local EU Data Protection Authority.
United Kingdom (UK) Residents — Processing of UK data subjects is conducted under UK GDPR and the Data Protection Act 2018. Transfers outside the UK utilize the UK International Data Transfer Agreement (IDTA) or Addendum. You may contact the Information Commissioner's Office (ICO) at www.ico.org.uk for supervisory concerns.
United States Residents (including California CCPA/CPRA) — We collect identifiers, commercial records, passport/biometric details (for verification), geolocation data, employment history, and device activity, and we do not sell or share personal information for third-party targeted advertising. California residents may exercise the right to know and access data collected over the past 12 months, the right to delete, the right to correct inaccurate records, and the right to limit use of sensitive identifiers, without discrimination for exercising these rights. Submit US privacy requests via our contact form with the subject line "US Privacy Rights Request" — we acknowledge and process verified requests within state-mandated timelines (e.g., 45 days for CCPA).
13. Contact Us
For privacy questions, data access requests, or regulatory inquiries, please reach out to our team:
Email: using the contact form