It usually happens at the last step. You’ve found the trip, picked the dates, maybe already talked yourself into the window seat.
It usually happens at the last step. You’ve found the trip, sorted the dates, and maybe even chosen your seat. Then comes the part where you need to share your passport details, date of birth, and payment information. Before you do, it’s worth knowing exactly how that information will be collected, protected, and used.
That’s why this guide explains. We’ll walk you through it, the information we deliberately never store, and the privacy controls you have over your own data.
We only collect what the application needs
We only ask for the information needed to complete your travel document application and nothing extra. In practice that means your travel document details, your contact information, and your order history. We keep it only for as long as we reasonably need to provide the service, and you can change or delete it at any time from your account settings.
The reasoning is simple: data we don't have can’t be exposed or at risk. Keeping our footprint small is how we avoid leaks and reduce risks..
Your card details never sit on our servers
The part people worry about most is whether their payment information is secure. So here is the direct answer: we don’t store your card details.
When you pay, your card details are handled by specialist payment processors that meet PCI DSS, the security standard the card industry requires of anyone handling cardholder data. Those transactions are encrypted.
So, in the unlikely event that someone compromises our systems, your full card number won't be available to them, because we believe prevention is the best protection.
What “encrypted” actually means here
You’ll often see companies say your data is “encrypted”, but what does that actually mean?
Simply put, encryption turns your information into unreadable code that can only be unlocked by authorized systems. There are two points where this matters. The first is while your information is being sent between your device and our systems. If someone tried to intercept it during that journey, they wouldn’t see your passport details or other personal information; they’d only see encrypted data.
The second is after your information reaches us. It's protected while it's stored, not just while it's being transferred.
Encryption is just one part of how we protect your data. We also use a range of technical and administrative safeguards and regularly review our security practices to help keep your information secure as our systems evolve.
Only the people who need your data can access it
Access to your information is limited to those who need it to process your order or assist with a support request. At iVisa, these are our agents taking care of your application. It’s not open to the wider company, and it’s not used for purposes unrelated to your application.
Where AI fits, and where it doesn’t
We use AI, and we would rather be specific about how than let you guess. iVisa is AI-supported, not AI-led.
On the application side, AI helps with document quality checks, catching issues like blurry photos or names that don’t match across your documents. For most travel documents, a member of our team reviews the details before anything is submitted to a government. Some automated products run through built-in validation checks instead of manual review. Either way, the judgment on nationality-specific rules and the trickier cases comes from people on our team who have handled them for years.
Internally, we use AI tools for work like research, drafting and tidying up written communications, and summarizing data for our own reporting. Every one of those outputs is reviewed and signed off by a person before it's used. And there is a firm line we don’t cross: passport details, payment data, and other personal information are never fed into those internal workflows. Before any AI tool is added to our approved list, it undergoes a security review. We then keep that list under review and run regular safety checks, rather than approving something once and forgetting about it.
Your data, your control
You can manage, update and delete profile information from your account settings, or the links in the emails we send. You can even change your cookie preferences and opt out of marketing emails.
There are two things to keep in mind. First, your privacy rights may vary depending on where you live. Our Privacy Policy explains the rights that apply to you and how you can exercise them.
Second, if you opt out of marketing emails, you’ll still receive important updates about your travel document or application. These service messages are essential to keeping you informed throughout the process.
What we can and can’t promise
Protecting your information is built into every stage of how we handle your application. We collect only the information we need, encrypt the data we hold, never store your payment card details on our servers, limit access to the people who need it, and keep personal information out of internal AI workflows. We also review and strengthen our security practices on an ongoing basis as technology and risks evolve.
No online service can claim to eliminate every possible security risk, but we can be transparent about the steps we take to help protect your information and the standards we hold ourselves to.
For more details, our Privacy Policy explains how we collect, use, and protect your data, as well as the privacy rights available to you. If you ever want to update or delete your information, you can do so through your account settings or by contacting our support team.