LEGAL
Privacy Policy.
OVERVIEW
This Privacy Policy details how we collect, process, safeguard, and disclose your personal details when you access our website or utilize our US ESTA document review and application assistance services.
We deliver travel documentation assistance globally, including to applicants in Visa Waiver Program (VWP) countries across the EU, UK, US, and other jurisdictions. We align our data operations with EU GDPR (Regulation 2016/679), UK GDPR & Data Protection Act 2018, CCPA/CPRA, and applicable US state and international privacy laws.
For privacy inquiries, data rights requests, or supervisory communications, contact our privacy compliance team using our contact form.
COLLECTION
A. PROVIDED DIRECTLY BY YOU
Identification & personal details — full name, date of birth, place of birth, gender, primary citizenship, national ID or secondary citizenship details.
Travel document details — passport number, issuance and expiration dates, issuing country, digital passport scans/images.
Verification media — facial photographs or selfies submitted to verify identity against your passport.
Contact details — email, phone, home address, emergency contacts, and parent details as required by ESTA filing.
Employment data, US destination details, statutory VWP security declarations, billing reference data, and support inquiry correspondence.
B. COLLECTED AUTOMATICALLY
IP address and approximate location, device and browser characteristics, navigation paths, and cookie interactions.
C. THIRD-PARTY SOURCES
Where permitted by law, we may receive verification signals from accredited identity checks, anti-fraud systems, or payment processors.
LEGAL BASIS
We rely on defined legal bases under applicable data privacy frameworks to process your personal data.
| PURPOSE | DATA | LEGAL GROUND |
|---|---|---|
| ESTA Application | Identifiers, passport, travel/employment data | Performance of Contract |
| Identity Verification | Passport scans, selfie images | Contract / Explicit Consent |
| VWP Declarations | Statutory eligibility answers | Legal Obligation / Public Task |
| Payment Handling | Payment references, order details | Performance of Contract |
| Support & Updates | Contact info, interaction logs | Contract / Legitimate Interest |
| Compliance & Security | Transaction history, IP logs | Legal / Legitimate Interest |
| Analytics | Cookie identifiers, interaction metrics | Legitimate Interest / Consent |
| Marketing | Email address | Explicit Consent (Opt-in) |
BIOMETRICS & AUTOMATED CHECKS
Facial imagery and passport photo uploads used to confirm identity may be categorized as biometric data. We handle it under explicit user consent and strict necessity: AES-256 encryption in transmission and storage, access restricted to technical staff processing your filing, zero commercial use, and accelerated deletion per our retention schedule.
We use automated matching software to compare selfie images against passport documentation to detect fraud and errors. These tools assist — but do not replace — human review. No final decision leading to rejection or legal consequence is taken solely via automated processing. Request manual review by emailing us using the contact form.
RETENTION
We retain personal information only as long as required to deliver our service and meet legal and accounting obligations.
APPLICATION DATA
12 months from submission
VWP DECLARATIONS
Destroyed 2–4 days post-submission
FINANCIAL RECORDS
Retained 7 years
SUPPORT INQUIRIES
Kept up to 3 years
ACCELERATED BIOMETRIC DELETION
| TRIGGER | TIMELINE |
|---|---|
| Application approved & delivered | Within 24 hours |
| Application rejected by government | Within 24 hours |
| Application cancelled by user | Immediately |
| Full or partial refund processed | Within 24 hours |
| Incomplete/abandoned application | Automatically after 14 days |
SECURITY
AT REST
AES-256 encryption
IN TRANSIT
TLS encryption
Access is limited by strict role-based controls, with regular security assessments. In the unlikely event of an incident impacting your rights, we will notify relevant supervisory authorities and affected users as required by law.
PROTECTION OF MINORS
Our services are not intended for independent use by individuals under 18. Minors may only apply through a parent, legal guardian, or authorized representative. Children's details for family travel filings receive identical security and retention protections as adult filings. If you suspect a minor has submitted information without parental authorization, contact using our contact form for immediate deletion.
MARKETING & MODIFICATIONS
If you opt in to promotional updates, you may withdraw consent anytime via the "Unsubscribe" link or by contacting support.
We may update this Privacy Policy to reflect changing regulatory requirements or service enhancements. Revisions are published on this page with an updated "Last Updated" date.
REGION-SPECIFIC
EU RESIDENTS — acts as data controller. Transfers outside the EEA rely on Commission-approved Standard Contractual Clauses (SCCs). You may request access, rectification, erasure, restriction, portability, and object to processing, and may lodge a complaint with your local EU Data Protection Authority.
UK RESIDENTS — Processed under UK GDPR and the Data Protection Act 2018. Transfers outside the UK use the International Data Transfer Agreement (IDTA) or Addendum. Contact the ICO at www.ico.org.uk for supervisory concerns.
US RESIDENTS (incl. CCPA/CPRA) — We do not sell or share personal information for third-party targeted advertising. California residents may exercise rights to know, delete, correct, and limit use of sensitive data, without discrimination. Submit US requests using our contact form with subject line "US Privacy Rights Request" — processed within state-mandated timelines (e.g. 45 days for CCPA).
CONTACT
→ Email: using our contact form