Privacy Policy
Last updated: June 16, 2026
1. Data Controller
VisaField ("we", "us", "our") operates visafield.com and the VisaField browser extension. For privacy inquiries, contact us at [email protected].
2. Information We Collect
We collect the following categories of personal information:
| Category | Examples | Purpose |
|---|---|---|
| Account identifiers | Email address | OTP authentication |
| Personal identity data | Name, nationality, passport details, travel dates | Visa application assistance |
| Uploaded documents | Passport scans, photos, supporting documents | AI document processing & form auto-fill |
| Payment data | Transaction ID, amount (card details handled by Stripe) | Service payment |
| Usage data | Pages visited, session duration, browser type | Service improvement |
Sensitive data: We process passport-level identity documents. These are treated with the highest level of protection as described in this policy.
3. Legal Basis for Processing (GDPR)
If you are in the European Economic Area (EEA), United Kingdom (UK), or Switzerland, we rely on the following legal bases under the GDPR:
- Contract performance (Art. 6(1)(b)): Processing your visa application data and documents to provide the service you requested.
- Legitimate interest (Art. 6(1)(f)): Service improvement, fraud prevention, and security.
- Consent (Art. 6(1)(a)): Where required, such as for optional communications. You may withdraw consent at any time.
- Legal obligation (Art. 6(1)(c)): Where we are required to retain data by law.
Processing of special category data (identity documents) is based on your explicit consent (Art. 9(2)(a)), provided when you upload documents to the platform.
4. How We Use Your Information
- Provide the AI visa advisor service, document processing, and form auto-fill functionality.
- Process payments via Stripe.
- Send OTP verification codes for login.
- Improve our products, content, and user experience.
- Comply with legal obligations.
We do not: Sell your personal information to third parties. Use your data for targeted advertising. Use your documents or conversations to train AI models.
5. Data Sharing & Third-Party Services
We share your data only with the following service providers, each bound by data processing agreements:
- Cloudflare (Infrastructure): Data storage, CDN, Workers compute. Data stored across Cloudflare's global network with encryption at rest.
- Stripe (Payments): Processes payment card data. We never see or store your full card number. Stripe Privacy Policy.
- Resend (Email): Delivers OTP verification emails. Only receives your email address.
- AI Providers (Document processing): Your uploaded documents and conversation data are sent to AI model providers for processing. Data is not used for model training and is deleted after processing per their data processing agreements.
6. International Data Transfers
Your data may be transferred to and processed in countries outside your country of residence, including the United States. Where such transfers occur, we ensure appropriate safeguards are in place:
- Standard Contractual Clauses (SCCs) approved by the European Commission.
- Data processing agreements with all sub-processors.
- Encryption in transit (TLS) and at rest.
7. Data Retention
| Data Type | Retention Period |
|---|---|
| Account data (email) | Until account deletion |
| Application & profile data | 90 days after application completion, then deleted |
| Uploaded documents | 30 days after application completion, then deleted |
| Payment records | 7 years (legal/tax requirement) |
| Usage logs | 90 days |
8. Cookies
We use essential cookies only:
va_jwt— Authentication token, 7-day expiry, essential for login.va_lang— Language preference, 1-year expiry, essential for localization.
We do not use tracking, analytics, or advertising cookies.
9. Your Rights Under GDPR
If you are in the EEA, UK, or Switzerland, you have the following rights:
- Access — Request a copy of your personal data.
- Rectification — Correct inaccurate or incomplete data.
- Erasure ("Right to be forgotten") — Request deletion of your data.
- Restriction — Restrict processing of your data in certain circumstances.
- Portability — Receive your data in a structured, machine-readable format.
- Object — Object to processing based on legitimate interests.
- Withdraw consent — At any time, without affecting the lawfulness of prior processing.
To exercise these rights, email [email protected]. We will respond within 30 days. If you are unsatisfied with our response, you have the right to lodge a complaint with your local data protection authority.
10. California Privacy Rights (CCPA/CPRA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):
- Right to know — What personal information we collect, use, disclose, and sell.
- Right to delete — Request deletion of your personal information.
- Right to correct — Correct inaccurate personal information.
- Right to opt-out — We do not sell or share your personal information for cross-context behavioral advertising.
- Right to non-discrimination — We will not discriminate against you for exercising your privacy rights.
To submit a request, email [email protected] with "CCPA Request" in the subject line. We will verify your identity and respond within 45 days. You may also designate an authorized agent to make requests on your behalf.
Categories disclosed: In the preceding 12 months, we have collected the categories listed in Section 2 above. We have not sold personal information to any third party.
11. Children's Privacy
VisaField is not intended for use by individuals under the age of 16. We do not knowingly collect personal information from children. If we learn that we have collected data from a child under 16, we will promptly delete it.
12. Data Security
We implement appropriate technical and organizational measures to protect your data:
- All data transmitted over HTTPS (TLS 1.2+).
- Data encrypted at rest on Cloudflare's infrastructure.
- Documents stored in access-controlled R2 buckets, accessible only to your account.
- OTP-based authentication (no passwords stored).
- Regular security reviews of our codebase and infrastructure.
13. Changes to This Policy
We may update this policy from time to time. Material changes will be notified via email to registered users. The "Last updated" date at the top reflects the most recent revision.
14. Contact Us
For privacy inquiries, data requests, or complaints:
- Email: [email protected]
- General: [email protected]