Privacy Policy

Last updated: June 16, 2026

1. Data Controller

VisaField ("we", "us", "our") operates visafield.com and the VisaField browser extension. For privacy inquiries, contact us at [email protected].

2. Information We Collect

We collect the following categories of personal information:

CategoryExamplesPurpose
Account identifiersEmail addressOTP authentication
Personal identity dataName, nationality, passport details, travel datesVisa application assistance
Uploaded documentsPassport scans, photos, supporting documentsAI document processing & form auto-fill
Payment dataTransaction ID, amount (card details handled by Stripe)Service payment
Usage dataPages visited, session duration, browser typeService improvement

Sensitive data: We process passport-level identity documents. These are treated with the highest level of protection as described in this policy.

3. Legal Basis for Processing (GDPR)

If you are in the European Economic Area (EEA), United Kingdom (UK), or Switzerland, we rely on the following legal bases under the GDPR:

  • Contract performance (Art. 6(1)(b)): Processing your visa application data and documents to provide the service you requested.
  • Legitimate interest (Art. 6(1)(f)): Service improvement, fraud prevention, and security.
  • Consent (Art. 6(1)(a)): Where required, such as for optional communications. You may withdraw consent at any time.
  • Legal obligation (Art. 6(1)(c)): Where we are required to retain data by law.

Processing of special category data (identity documents) is based on your explicit consent (Art. 9(2)(a)), provided when you upload documents to the platform.

4. How We Use Your Information

  • Provide the AI visa advisor service, document processing, and form auto-fill functionality.
  • Process payments via Stripe.
  • Send OTP verification codes for login.
  • Improve our products, content, and user experience.
  • Comply with legal obligations.

We do not: Sell your personal information to third parties. Use your data for targeted advertising. Use your documents or conversations to train AI models.

5. Data Sharing & Third-Party Services

We share your data only with the following service providers, each bound by data processing agreements:

  • Cloudflare (Infrastructure): Data storage, CDN, Workers compute. Data stored across Cloudflare's global network with encryption at rest.
  • Stripe (Payments): Processes payment card data. We never see or store your full card number. Stripe Privacy Policy.
  • Resend (Email): Delivers OTP verification emails. Only receives your email address.
  • AI Providers (Document processing): Your uploaded documents and conversation data are sent to AI model providers for processing. Data is not used for model training and is deleted after processing per their data processing agreements.

6. International Data Transfers

Your data may be transferred to and processed in countries outside your country of residence, including the United States. Where such transfers occur, we ensure appropriate safeguards are in place:

  • Standard Contractual Clauses (SCCs) approved by the European Commission.
  • Data processing agreements with all sub-processors.
  • Encryption in transit (TLS) and at rest.

7. Data Retention

Data TypeRetention Period
Account data (email)Until account deletion
Application & profile data90 days after application completion, then deleted
Uploaded documents30 days after application completion, then deleted
Payment records7 years (legal/tax requirement)
Usage logs90 days

8. Cookies

We use essential cookies only:

  • va_jwt — Authentication token, 7-day expiry, essential for login.
  • va_lang — Language preference, 1-year expiry, essential for localization.

We do not use tracking, analytics, or advertising cookies.

9. Your Rights Under GDPR

If you are in the EEA, UK, or Switzerland, you have the following rights:

  • Access — Request a copy of your personal data.
  • Rectification — Correct inaccurate or incomplete data.
  • Erasure ("Right to be forgotten") — Request deletion of your data.
  • Restriction — Restrict processing of your data in certain circumstances.
  • Portability — Receive your data in a structured, machine-readable format.
  • Object — Object to processing based on legitimate interests.
  • Withdraw consent — At any time, without affecting the lawfulness of prior processing.

To exercise these rights, email [email protected]. We will respond within 30 days. If you are unsatisfied with our response, you have the right to lodge a complaint with your local data protection authority.

10. California Privacy Rights (CCPA/CPRA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):

  • Right to know — What personal information we collect, use, disclose, and sell.
  • Right to delete — Request deletion of your personal information.
  • Right to correct — Correct inaccurate personal information.
  • Right to opt-out — We do not sell or share your personal information for cross-context behavioral advertising.
  • Right to non-discrimination — We will not discriminate against you for exercising your privacy rights.

To submit a request, email [email protected] with "CCPA Request" in the subject line. We will verify your identity and respond within 45 days. You may also designate an authorized agent to make requests on your behalf.

Categories disclosed: In the preceding 12 months, we have collected the categories listed in Section 2 above. We have not sold personal information to any third party.

11. Children's Privacy

VisaField is not intended for use by individuals under the age of 16. We do not knowingly collect personal information from children. If we learn that we have collected data from a child under 16, we will promptly delete it.

12. Data Security

We implement appropriate technical and organizational measures to protect your data:

  • All data transmitted over HTTPS (TLS 1.2+).
  • Data encrypted at rest on Cloudflare's infrastructure.
  • Documents stored in access-controlled R2 buckets, accessible only to your account.
  • OTP-based authentication (no passwords stored).
  • Regular security reviews of our codebase and infrastructure.

13. Changes to This Policy

We may update this policy from time to time. Material changes will be notified via email to registered users. The "Last updated" date at the top reflects the most recent revision.

14. Contact Us

For privacy inquiries, data requests, or complaints: