Privacy

Privacy Policy

Your documents should stay under your control. Visa Wingman stores only what you choose to save — your preparation workspace, the files you attach, your purchase records, and your review cases. This policy explains exactly what that means.

Last updated: 26 August 2026

1. Who is responsible for your data

ZON SOFTWARE DEVELOPMENT SERVICES, Fairfield Tower, Hampton Gardens, C Raymundo Avenue, Pasig, Philippines, operates the Visa Wingman platform and is responsible for its maintenance and data-handling controls. For any privacy question or request, email support@visawingman.com.

2. What we collect

Account information. Your email address and authentication details, and — if you sign in with Google — the basic profile information Google returns. Passwords are handled by our authentication provider; we never see them in readable form.

Journey and profile information. What you enter to get relevant guidance: nationality, destination, travel purpose, dates, employment or study situation, and similar preparation details, together with your checklist progress, notes, and readiness answers.

Documents you upload. The files you attach to a checklist item or store in your Document Vault, plus their filenames, sizes, and the checklist item they belong to.

Purchase and payment records. For each purchase we store the product, amount, currency, status, our internal reference, the payment provider's identifiers for the transaction, the payment method type, and the relevant timestamps — together with the entitlement it activated. We do not receive or store your full card number, CVV, or bank credentials: those are entered on the payment provider's own checkout page. For purchases made in the iOS app we store Apple's transaction identifiers so your access can be verified and restored.

Family, group, and referral information. If you organize a group journey, the traveler details you enter for that group and the invitations you send. If you use a referral link, the referral code attached to the sign-up.

Product analytics. Pageviews and feature events — which screens are used and which actions succeed or fail — through PostHog. Analytics profiles are only created for identified users, and session recording is not enabled.

Technical and error information. Standard server logs, and crash and error reports through Sentry. Sentry is configured not to send personally identifying data by default, and payment-related request, user, and context data is stripped from error events before they are sent.

Support communications. The emails you send us and our replies, so we can follow up on your request.

Notification preferences. Your reminder settings and, in the mobile app, the device push token if you enable push reminders.

3. Why we use it

  • To create and secure your account and keep you signed in.
  • To generate the checklist and guidance that fits your journey.
  • To store, display, and organize the documents you upload.
  • To take payment, record the purchase, and activate and restore the access you bought.
  • To deliver the paid services you purchased, including structured review.
  • To send the reminders and service emails you have asked for.
  • To answer support requests.
  • To understand which parts of the product work, so we can improve it.
  • To keep the service secure, prevent abuse, and meet legal and accounting obligations.

We do not sell your personal data, and we do not use your uploaded documents for advertising.

4. Automated document checks and the Vi assistant

When you ask for an automated document check, the file you selected is sent to our AI provider (Anthropic) to produce the check result. When you chat with Vi, your question and the journey context needed to answer it are sent the same way.

This happens only for the check or question you initiate. Results are preparation support, not an authoritative assessment, and they never replace official requirements.

5. Service providers we use

  • Vercel — website and application hosting.
  • Supabase — database, authentication, and private file storage for your documents.
  • PayMongo — payment processing for purchases made on the website.
  • Apple — payment processing and transaction verification for purchases made in the iOS app.
  • Anthropic — the AI model behind automated document checks and the Vi assistant.
  • PostHog — product analytics.
  • Sentry — error and crash monitoring.
  • Resend — delivery of account and service emails.

These providers process data on our behalf for the purposes above. We do not authorize them to use it for their own unrelated purposes.

6. Where your data is processed

Visa Wingman is operated from the Philippines, and the providers listed above operate internationally — so your data may be processed on servers outside your country, including in the United States and Europe. We use established providers with contractual data-protection commitments for that handling.

7. How we protect it

Traffic is encrypted in transit. Uploaded documents are held in private storage and are reachable only through short-lived signed links issued to you, or to a reviewer for a review you purchased. Access to your data is scoped to your account, and payment secrets and provider keys are held server-side only and never exposed to the browser or mobile app. Payment webhooks are accepted only with a valid provider signature.

No system can be guaranteed perfectly secure, but we design for the least data exposure that still lets the product work.

8. How long we keep things

Your workspace and uploaded documents stay until you delete them — they are yours. Finished review cases are tidied up automatically: closed or cancelled reviews are removed 180 days after they settle, and completed reports a year after they are ready.

Purchase records are retained as financial records for as long as applicable accounting, tax, and dispute-resolution obligations require, even after other data is deleted.

9. Your choices and rights

You can export a copy of your data or delete it, at any time, from the controls below. You can also request account deletion in the app under You → Privacy, export, and deletion. You may ask us to correct inaccurate information, or object to a particular use, by emailing support@visawingman.com.

Deleting your saved data cannot be undone, and purchase records retained for legal and accounting reasons are the one exception noted above.

10. Children and minors

Visa Wingman is intended for adults. We do not knowingly create accounts for children. An adult may enter a minor's details when preparing a family journey; that information is treated the same way as any other journey information, and the adult account holder is responsible for it. If you believe a child has created an account, email us and we will remove it.

11. Links to other sites

We link to embassy, consulate, and government pages so you can verify requirements at the source. Those sites have their own privacy practices, which we do not control.

12. Changes to this policy

We update this policy as the product changes. The “last updated” date at the top of this page always shows the current version.

13. Contact us

Email support@visawingman.com, or see our Contact page for our full business details.

Your data controls

Download a copy of your data

Get everything Visa Wingman holds for you — your workspace, purchase records, and Smart Review reports — as a single file. Your uploaded documents stay downloadable individually from the vault.

Checking sign-in…

Delete your saved data

This removes your uploaded documents, saved checklist workspace, purchase records, and Smart Review cases from Visa Wingman. This cannot be undone.

Checking sign-in…

Who operates Visa Wingman

ZON SOFTWARE DEVELOPMENT SERVICES

Fairfield Tower, Hampton GardensC Raymundo Avenue, PasigPhilippines

support@visawingman.com

www.visawingman.com

Privacy PolicyTerms and ConditionsRefund PolicyContact