Section 01
Information we collect
Personal information
To process your visa application, we collect:
- Full name, date of birth, nationality, and passport details
- Contact information — email address, phone number, and mailing address
- Travel details — destination country, travel dates, and purpose of visit
- Financial information for payment processing only (never stored in full on our servers)
- Supporting documents — passport scans, photographs, proof of accommodation, financial statements, and any other embassy-required documents
Automatically collected usage data
When you visit our platform, we automatically collect:
- IP address and approximate geolocation (used solely for currency and language preferences)
- Browser type, device model, and operating system
- Pages visited, time on page, and navigation patterns
- Referral source and search terms that led you to our platform
- Cookies and similar tracking technologies (see Section 07)
Section 02
How we use your data
We process your personal information under the legal bases of contractual necessity, legitimate interest, and consent (where applicable). Specifically, we use your data to:
Process your visa application
Submit your documents and application to the relevant embassy, consulate, or visa processing authority on your behalf.
Communicate application status
Send transactional emails and notifications about your application progress, document requests, and important deadlines.
Improve our service
Analyze aggregated usage patterns to identify friction points, enhance UX, and improve success rates.
Fraud prevention
Detect and prevent fraudulent transactions, identity theft, and abuse of our platform.
Legal compliance
Meet applicable regulatory requirements and respond to lawful government or legal requests.
Marketing (with explicit consent)
Send promotional emails about visa tips, destination guides, and SwiftPass updates. You may opt out at any time via the unsubscribe link.
Section 04
Security measures
We implement multiple overlapping security layers to protect your sensitive data:
256-bit AES encryption
Military-grade encryption for all data at rest and in transit — the same standard used by banks, government agencies, and the US Department of Defense.
SOC 2 Type II infrastructure
Hosted on Supabase + AWS, which carry SOC 2 Type II attestations covering security, availability, processing integrity, confidentiality, and privacy. Reports available from those providers.
GDPR & CCPA compliant
Full compliance with EU General Data Protection Regulation and California Consumer Privacy Act. We maintain a formal data register and respond to data-subject requests at privacy@swiftpassimmigration.com.
Role-based access control
Strict need-to-know access policies ensure only authorized personnel can view sensitive application data. All access events are logged.
ISO 27001 data centers
Underlying physical data centers (AWS) hold ISO 27001 certification — biometric access, redundant power, environmental controls, and geo-redundant backups.
Section 05
Your privacy rights
Depending on your location, you may have the following rights over your personal data. To exercise any right, contact us at privacy@swiftpassimmigration.com. We will respond within 30 days.
Right of access
Request a copy of all personal data we hold about you.
Right to rectification
Correct inaccurate or incomplete personal data.
Right to erasure
Request deletion of your data, subject to legal retention obligations.
Right to portability
Receive your data in a structured, machine-readable format.
Right to object
Opt out of certain types of data processing, including marketing.
Right to restrict
Request that we limit how we use your personal data.
Right to withdraw consent
Revoke consent for any optional data collection at any time.
Right to lodge a complaint
File a complaint with your local data protection supervisory authority.
Section 06
Data retention
We retain your personal information only as long as necessary to fulfill the purposes described in this policy, or as required by law:
Active applications
Processing + 90 daysExtended if appeal or dispute is open
Completed applications
Up to 7 yearsRequired for legal, tax, and regulatory compliance
Account & profile data
Until deletion requestedSubject to legal retention minimums
Payment records
7 yearsRequired under financial regulations
Marketing data
Until you unsubscribePromptly honored within 10 business days
Security logs
12 monthsFor fraud detection and incident response
Section 08
International data transfers
SwiftPass is operated from the United States. If you are located in the European Economic Area (EEA), United Kingdom, or other jurisdictions with data protection laws, your information may be transferred to and processed in countries that provide different levels of data protection than your home country.
Where transfers occur outside the EEA or UK, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission and, where applicable, the UK International Data Transfer Addendum. Equivalent safeguards apply for data subjects located in Kenya, Ghana, Nigeria, and Pakistan.
Section 09
Data breach policy
In the unlikely event of a data breach affecting your personal information, we commit to:
1. Immediate containment
Isolate affected systems and halt any ongoing unauthorized access within hours of detection.
2. Prompt notification (within 72 hours)
Notify affected users and relevant data protection authorities within 72 hours of discovery, as required by GDPR Article 33.
3. Transparent communication
Clearly explain what data was affected, the potential risks, and the specific circumstances of the breach.
4. Remediation actions
Detail the immediate and long-term steps taken to contain, remediate, and prevent recurrence.
Section 10
Children's privacy
SwiftPass is not intended for individuals under 13 years of age (or under 16 in the European Union). We do not knowingly collect personal information from children. Where a parent or legal guardian submits an application on behalf of a minor, only the minimum data required for the visa application is processed.
Section 11
Policy changes
We may update this Privacy Policy periodically to reflect changes in our practices, technology, legal requirements, or other factors. Material changes will be communicated by email to account holders at least 30 days before they take effect. The current version is always available at this URL with the effective date shown above.
Section 12
Voice communications, AI calls & recording
By providing your phone number to SwiftPass, you consent to receive phone calls and SMS messages from us about your account and applications, including but not limited to: application status updates, document requests, appointment reminders, refund and dispute resolution, and customer support related to your visa application.
AI-assisted calls
Some of our outbound and inbound calls are placed and answered by an AI assistant operating under the SwiftPass team. Our AI assistant identifies its nature to recipients at the start of each call or on request.
Call recording
Outbound and inbound voice calls between SwiftPass and you may be recorded for quality assurance, training, and compliance purposes. Recording disclosure is made at the start of each call. Recordings are encrypted at rest, accessible only to authorized SwiftPass personnel, and retained for a maximum of 90 days before automatic deletion.
Opting out
You may opt out of phone and SMS contact at any time by replying STOP to any SMS message, by saying "remove me" or "stop calling" during any call, or by emailing privacy@swiftpassimmigration.com. Opt-out requests are honored permanently. Critical transactional notifications tied to an active application (such as imminent embassy appointment reminders) may continue via email after a phone opt-out so that you do not miss time-sensitive deadlines.
Time-of-day rules
We place outbound calls only between 9:00 AM and 7:00 PM in your local timezone. Recipient timezone is determined from the country code of the phone number you provided.
Regulatory compliance
SwiftPass operates this voice communication program in alignment with applicable laws including the United States Telephone Consumer Protection Act (TCPA), the California Bot Disclosure Law (SB 1001), the European Union AI Act, the General Data Protection Regulation (GDPR), the Kenya Data Protection Act, the Ghana Data Protection Act, the Nigeria Data Protection Act (NDPA), and the Pakistan Personal Data Protection Act. Recordings and call metadata are processed as set out in Section 02 (How we use your data) and protected per Section 04 (Security measures).
Section 13
Contact us
For questions, data requests, or concerns about this Privacy Policy:
SwiftPass Global LLC
General support
support@swiftpassimmigration.comPrivacy inquiries
privacy@swiftpassimmigration.comData Protection Officer
legal@swiftpassimmigration.comRegistered office
131 Continental Dr Suite 305, Newark, DE 19702, USA
For broader data-protection rights and how we comply with EU/UK GDPR specifically, see the GDPR notice.