VisaPilot CRM Back to Home
Legal & Compliance

Privacy Policy

How VisaPilot CRM collects, uses, and protects your personal data

Effective: June 1, 2026
Privacy Policy · Terms of Service · Cookie Policy · GDPR · Security
On this page
Overview Data We Collect How We Use Data Data Sharing Data Retention Your Rights Security Cookies Children's Privacy Changes to Policy Contact Us

Your data is yours. Every immigration firm on VisaPilot CRM operates in a completely isolated workspace. No other firm can ever access your client records, applications, or documents.

1. Overview

VisaPilot CRM ("we", "us", "our") is a Software-as-a-Service platform operated by Tech Vanta LLC. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our platform at GetVisaPilot.com and any associated services.

By using VisaPilot CRM, you consent to the data practices described in this policy. If you do not agree, please do not use our services.

This policy applies to:

  • Immigration firm administrators and staff ("Firm Users")
  • End clients of immigration firms who access the client portal ("Clients")
  • Visitors to GetVisaPilot.com ("Visitors")

2. Data We Collect

2.1 Account & Registration Data

  • Firm name, administrator name, email address, phone number
  • Billing address and payment method (card details processed by Stripe — we never store raw card numbers)
  • Password (stored as a secure bcrypt hash — never in plain text)
  • IP address at time of registration

2.2 Visa Application Data

When your firm uses VisaPilot CRM to manage visa cases, data entered may include:

  • Client personal information (name, date of birth, nationality, passport details)
  • Visa type, destination country, travel dates
  • Uploaded documents (passports, financial statements, employment letters)
  • Application status history and notes
  • Communication records between agents and clients

This data is entered by the immigration firm using our platform. The firm is the Data Controller for their clients' personal data. VisaPilot CRM acts as a Data Processor under GDPR.

2.3 Usage & Technical Data

  • Browser type, operating system, device information
  • Pages visited, features used, time spent on platform
  • IP addresses and login timestamps
  • Error logs and performance metrics

2.4 Communication Data

  • Support tickets and emails you send to our team
  • Responses to surveys or feedback requests
  • Contact form submissions

3. How We Use Your Data

We use the data we collect to:

  • Provide and operate the VisaPilot CRM service — authenticating users, processing transactions, displaying application data
  • Process billing and payments — managing subscriptions through Stripe
  • Send service notifications — account alerts, invoice receipts, security notices
  • Provide customer support — responding to help requests and troubleshooting issues
  • Improve the platform — analyzing usage patterns to build better features
  • Ensure security and prevent fraud — detecting unauthorized access, enforcing IP restrictions
  • Comply with legal obligations — responding to lawful requests from authorities

We do not sell your personal data to third parties. We do not use your clients' immigration data for marketing or analytics.

4. Data Sharing & Third Parties

We share data only with trusted service providers necessary to operate the platform:

ProviderPurposeData Shared
StripePayment processing & billingName, email, billing address, card details
AWS / Cloud HostInfrastructure & data storageAll platform data (encrypted at rest)
TwilioSMS notifications (optional)Phone number, message content
Mailgun / SMTPEmail deliveryEmail address, message content

All third-party providers are contractually required to handle data securely and only for the specified purpose. We do not share data with advertisers, data brokers, or marketing platforms.

We may disclose data if required by law, court order, or to protect the rights and safety of our users or the public.

5. Data Retention

  • Active accounts: Data is retained for the duration of your subscription
  • Cancelled accounts: Data is retained for 90 days after cancellation, then permanently deleted
  • Billing records: Retained for 7 years to comply with financial regulations
  • Support communications: Retained for 3 years
  • Access logs: Retained for 12 months for security purposes

You may request early deletion of your account data by contacting us at privacy@getvisapilot.com. Deletion requests are processed within 30 days.

6. Your Rights

Depending on your jurisdiction, you may have the following rights regarding your personal data:

  • Right of Access — Request a copy of the personal data we hold about you
  • Right to Rectification — Request correction of inaccurate or incomplete data
  • Right to Erasure — Request deletion of your personal data ("right to be forgotten")
  • Right to Restriction — Request that we limit how we process your data
  • Right to Portability — Receive your data in a structured, machine-readable format
  • Right to Object — Object to processing based on legitimate interests
  • Right to withdraw consent — Where processing is based on your consent

To exercise any of these rights, email privacy@getvisapilot.com. We will respond within 30 days. See our GDPR page for full details on data subject rights.

7. Security

We take data security seriously. Our measures include:

  • TLS/SSL encryption for all data in transit
  • AES-256 encryption for data at rest
  • Bcrypt password hashing
  • Role-based access control with IP restriction options
  • Two-factor authentication (Email OTP + Google Authenticator)
  • Regular security audits and penetration testing
  • 99.9% uptime SLA with automated backups

For our full security documentation, see the Security page.

8. Cookies

We use cookies to maintain your session, remember preferences, and improve platform performance. We do not use tracking cookies for advertising purposes.

For full details, see our Cookie Policy.

9. Children's Privacy

VisaPilot CRM is a professional business platform not intended for use by individuals under the age of 18. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us at privacy@getvisapilot.com.

10. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes via email and by displaying a notice on our platform. The "Effective" date at the top of this page indicates when this policy was last revised.

Continued use of VisaPilot CRM after changes are posted constitutes your acceptance of the updated policy.

11. Contact Us

For privacy-related questions, requests, or concerns:

  • Email: privacy@getvisapilot.com
  • Company: Tech Vanta LLC
  • Response time: Within 30 business days

Questions about your data?

Our team is happy to help with any privacy-related questions or data requests. We respond within 30 days.

Contact Privacy Team
Privacy Policy Terms of Service Cookie Policy GDPR Security Contact

© 2026 Tech Vanta LLC. All rights reserved. VisaPilot CRM is a product of Tech Vanta LLC.