Legal

Privacy Policy.

Effective October 28, 2025Updated October 28, 2025Jurisdiction Delaware, USA

At SwiftPass, your privacy is paramount. This policy explains how we collect, use, protect, and share your personal information when you use our visa application services. We're committed to full transparency.

GDPRUK GDPRCCPAAES-256 encryptionTLS 1.3 in transit

Section 01

Information we collect

Personal information

To process your visa application, we collect:

  • Full name, date of birth, nationality, and passport details
  • Contact information — email address, phone number, and mailing address
  • Travel details — destination country, travel dates, and purpose of visit
  • Financial information for payment processing only (never stored in full on our servers)
  • Supporting documents — passport scans, photographs, proof of accommodation, financial statements, and any other embassy-required documents

Automatically collected usage data

When you visit our platform, we automatically collect:

  • IP address and approximate geolocation (used solely for currency and language preferences)
  • Browser type, device model, and operating system
  • Pages visited, time on page, and navigation patterns
  • Referral source and search terms that led you to our platform
  • Cookies and similar tracking technologies (see Section 07)

Section 02

How we use your data

We process your personal information under the legal bases of contractual necessity, legitimate interest, and consent (where applicable). Specifically, we use your data to:

Process your visa application

Submit your documents and application to the relevant embassy, consulate, or visa processing authority on your behalf.

Communicate application status

Send transactional emails and notifications about your application progress, document requests, and important deadlines.

Improve our service

Analyze aggregated usage patterns to identify friction points, enhance UX, and improve success rates.

Fraud prevention

Detect and prevent fraudulent transactions, identity theft, and abuse of our platform.

Legal compliance

Meet applicable regulatory requirements and respond to lawful government or legal requests.

Marketing (with explicit consent)

Send promotional emails about visa tips, destination guides, and SwiftPass updates. You may opt out at any time via the unsubscribe link.

Section 03

How we share your information

We do not sell, rent, or broker your personal data to third parties. Period.

Government & immigration authorities

Your visa application and supporting documents are submitted to the relevant embassy, consulate, or immigration authority. This is the core service you purchase and is required to process your visa.

Trusted service providers

We work with carefully vetted third-party partners. Each partner is contractually bound to strict data protection standards and undergoes regular security audits:

Payment processing — DPO Pay, M-Pesa, Stripe & PayPal

PCI DSS Level 1 compliant processors. We never store your full card details. All payment data is end-to-end encrypted and tokenized before transmission.

Cloud infrastructure — Supabase (AWS)

SOC 2 Type II and ISO 27001 certified hosting with 256-bit AES encryption at rest and in transit. Primary data centers in the United States with geo-redundant backups.

Transactional email — SendGrid (Twilio)

Delivers application status updates, confirmations, and support replies. All messages are transmitted over TLS with encryption at rest.

Analytics — Google Analytics (anonymized)

IP addresses are masked. No personal identifiers are transmitted. You may opt out via browser extension or our cookie settings panel.

Legal requirements

We may disclose your information if required by law, valid court order, regulatory authority, or to protect the rights, property, or safety of SwiftPass, our users, or the public. We will notify you of such disclosure where legally permitted.

Section 04

Security measures

We implement multiple overlapping security layers to protect your sensitive data:

256-bit AES encryption

Military-grade encryption for all data at rest and in transit — the same standard used by banks, government agencies, and the US Department of Defense.

SOC 2 Type II infrastructure

Hosted on Supabase + AWS, which carry SOC 2 Type II attestations covering security, availability, processing integrity, confidentiality, and privacy. Reports available from those providers.

GDPR & CCPA compliant

Full compliance with EU General Data Protection Regulation and California Consumer Privacy Act. We maintain a formal data register and respond to data-subject requests at privacy@swiftpassimmigration.com.

Role-based access control

Strict need-to-know access policies ensure only authorized personnel can view sensitive application data. All access events are logged.

ISO 27001 data centers

Underlying physical data centers (AWS) hold ISO 27001 certification — biometric access, redundant power, environmental controls, and geo-redundant backups.

While we implement industry-leading security practices, no method of transmission over the internet is 100% secure. We continuously monitor and update our security measures and will notify you promptly in the event of a breach affecting your data.

Section 05

Your privacy rights

Depending on your location, you may have the following rights over your personal data. To exercise any right, contact us at privacy@swiftpassimmigration.com. We will respond within 30 days.

Right of access

Request a copy of all personal data we hold about you.

Right to rectification

Correct inaccurate or incomplete personal data.

Right to erasure

Request deletion of your data, subject to legal retention obligations.

Right to portability

Receive your data in a structured, machine-readable format.

Right to object

Opt out of certain types of data processing, including marketing.

Right to restrict

Request that we limit how we use your personal data.

Right to withdraw consent

Revoke consent for any optional data collection at any time.

Right to lodge a complaint

File a complaint with your local data protection supervisory authority.

Section 06

Data retention

We retain your personal information only as long as necessary to fulfill the purposes described in this policy, or as required by law:

Active applications

Processing + 90 days

Extended if appeal or dispute is open

Completed applications

Up to 7 years

Required for legal, tax, and regulatory compliance

Account & profile data

Until deletion requested

Subject to legal retention minimums

Payment records

7 years

Required under financial regulations

Marketing data

Until you unsubscribe

Promptly honored within 10 business days

Security logs

12 months

For fraud detection and incident response

Section 07

Cookies & tracking technologies

We use cookies and similar technologies to operate our platform, remember your preferences, and improve your experience.

Essential cookies — required

Necessary for platform functionality — authentication, security tokens, session management. Cannot be disabled without breaking core features.

Functional cookies — optional

Remember your preferences such as language, currency, and application progress. Enhance your experience on return visits.

Performance cookies — optional

Help us understand how users navigate the platform so we can identify friction points and improve conversion rates.

Analytics cookies — optional

Google Analytics (IP anonymized). Provides aggregate traffic insights. Personal identifiers are removed before data is sent to Google.

Section 08

International data transfers

SwiftPass is operated from the United States. If you are located in the European Economic Area (EEA), United Kingdom, or other jurisdictions with data protection laws, your information may be transferred to and processed in countries that provide different levels of data protection than your home country.

Where transfers occur outside the EEA or UK, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission and, where applicable, the UK International Data Transfer Addendum. Equivalent safeguards apply for data subjects located in Kenya, Ghana, Nigeria, and Pakistan.

Section 09

Data breach policy

In the unlikely event of a data breach affecting your personal information, we commit to:

1. Immediate containment

Isolate affected systems and halt any ongoing unauthorized access within hours of detection.

2. Prompt notification (within 72 hours)

Notify affected users and relevant data protection authorities within 72 hours of discovery, as required by GDPR Article 33.

3. Transparent communication

Clearly explain what data was affected, the potential risks, and the specific circumstances of the breach.

4. Remediation actions

Detail the immediate and long-term steps taken to contain, remediate, and prevent recurrence.

Section 10

Children's privacy

SwiftPass is not intended for individuals under 13 years of age (or under 16 in the European Union). We do not knowingly collect personal information from children. Where a parent or legal guardian submits an application on behalf of a minor, only the minimum data required for the visa application is processed.

Section 11

Policy changes

We may update this Privacy Policy periodically to reflect changes in our practices, technology, legal requirements, or other factors. Material changes will be communicated by email to account holders at least 30 days before they take effect. The current version is always available at this URL with the effective date shown above.

Section 12

Voice communications, AI calls & recording

By providing your phone number to SwiftPass, you consent to receive phone calls and SMS messages from us about your account and applications, including but not limited to: application status updates, document requests, appointment reminders, refund and dispute resolution, and customer support related to your visa application.

AI-assisted calls

Some of our outbound and inbound calls are placed and answered by an AI assistant operating under the SwiftPass team. Our AI assistant identifies its nature to recipients at the start of each call or on request.

Call recording

Outbound and inbound voice calls between SwiftPass and you may be recorded for quality assurance, training, and compliance purposes. Recording disclosure is made at the start of each call. Recordings are encrypted at rest, accessible only to authorized SwiftPass personnel, and retained for a maximum of 90 days before automatic deletion.

Opting out

You may opt out of phone and SMS contact at any time by replying STOP to any SMS message, by saying "remove me" or "stop calling" during any call, or by emailing privacy@swiftpassimmigration.com. Opt-out requests are honored permanently. Critical transactional notifications tied to an active application (such as imminent embassy appointment reminders) may continue via email after a phone opt-out so that you do not miss time-sensitive deadlines.

Time-of-day rules

We place outbound calls only between 9:00 AM and 7:00 PM in your local timezone. Recipient timezone is determined from the country code of the phone number you provided.

Regulatory compliance

SwiftPass operates this voice communication program in alignment with applicable laws including the United States Telephone Consumer Protection Act (TCPA), the California Bot Disclosure Law (SB 1001), the European Union AI Act, the General Data Protection Regulation (GDPR), the Kenya Data Protection Act, the Ghana Data Protection Act, the Nigeria Data Protection Act (NDPA), and the Pakistan Personal Data Protection Act. Recordings and call metadata are processed as set out in Section 02 (How we use your data) and protected per Section 04 (Security measures).

Section 13

Contact us

For questions, data requests, or concerns about this Privacy Policy:

SwiftPass Global LLC

Data Protection Officer

legal@swiftpassimmigration.com

Registered office

131 Continental Dr Suite 305, Newark, DE 19702, USA

For broader data-protection rights and how we comply with EU/UK GDPR specifically, see the GDPR notice.

Command Palette

Search for a page, dashboard view, or action