ESTA Guide Start your review

Privacy notice

Status: complete except for the items marked TO BE SUPPLIED. Those are facts about the operating company that cannot be invented — see the end of the page. This notice must be checked against the live configuration by a lawyer before the first payment is taken. A privacy notice that misdescribes actual processing is itself a breach of Article 13, separately from whatever it was papering over.

Last updated: 17/08/2026.

Short version

We collect the minimum needed to check your ESTA details against your passport. We do not collect your answers to the eligibility questions. We do not sell or share your data. We never take identity documents by email. Everything is deleted on a schedule.

1. Who is responsible

TO BE SUPPLIED: registered business name, trading name, registered address, company registration number, and the email address for data protection questions.

Because we offer a service to people in the European Union and the United Kingdom, the GDPR and the UK GDPR apply to us regardless of where we are established.

TO BE SUPPLIED: our representative in the European Union under Article 27, and separately our representative in the United Kingdom. These are two different appointments — one does not cover the other — and both must be named here with contact details.

2. What we collect, and what we deliberately do not

When you use the review service

DataWhy
Your name as printed in your passportTo check it against what you will enter
Passport number, country of issue, issue and expiry datesThe fields most often mistyped
Date of birth, sexSame
An image of your passport data page — optionalSo we can check against the document rather than take your word for it
Your email addressTo send your report
Confirmation that payment succeededTo know the order is live

The passport image is optional. The service works without it; you can type the details instead. If you would rather not upload an identity document to anyone, don’t — and that is a reasonable instinct.

What we do not collect

We do not collect your answers to the ESTA eligibility questions. Those cover arrests, convictions, communicable diseases, mental disorders and drug use. Under the GDPR that is special category data (Article 9) and criminal-offence data (Article 10), and Article 10 has no consent route for a private company. We do not ask for those answers, we do not review them, and we have no record of them.

If you are unsure how to answer one, speak to a qualified immigration attorney.

We do not collect card numbers, national ID numbers other than the passport number, your immigration history, or anything about your health.

When you only read the site

Nothing that identifies you. We currently run no analytics of any kind — no Google Analytics, no advertising pixels, no third-party tracking scripts.

3. Cookies

We set one cookie: esta_lang, which records the language you chose so the site does not keep asking. It contains a two-letter language code and nothing else, it is first-party, and it is only set when you actively pick a language.

It is exempt from consent requirements under the ePrivacy Directive because it exists solely to remember a preference you expressed. That is why this site has no cookie banner.

The JotForm application form sets its own cookies. That is why it does not load until you click to open it — the click is your consent, and if you never open the form, no third-party cookie is ever set.

PurposeLawful basis
Carrying out the review you paid forArticle 6(1)(b) — performance of a contract
Sending your report and service emailsArticle 6(1)(b)
Preventing payment fraudArticle 6(1)(f) — legitimate interests
Keeping records of the transactionArticle 6(1)(f), with a documented assessment

We do not rely on consent for the core service, and we do not use your data for marketing.

5. Who processes your data

ProcessorRoleLocation
JotFormHosts the intake form and stores submissionsEuropean Union (Frankfurt), with EU data residency enabled
HostingerHosts this websiteNetherlands

TO BE SUPPLIED: the payment provider, and any email provider used for transactional messages. Both must be named here, with a published sub-processor list.

We have a data processing agreement in place with each processor.

6. Where your data goes

The website and the form provider are both in the EEA — Hostinger in the Netherlands, JotForm on EU servers in Frankfurt. Data you type or upload travels directly to the form provider.

Where any processor sits outside the EEA, transfers rely on Standard Contractual Clauses together with the UK International Data Transfer Addendum.

7. How long we keep it

DataRetained
Passport image, if you uploaded oneDeleted once your review is delivered, plus a short buffer for follow-up questions
The details you gave us for reviewDeleted after your review is complete
Email address and order referenceKept for the statutory limitation and tax period
Payment recordHeld by the payment provider under its own obligations

TO BE CONFIRMED: the exact number of days, verified against the retention settings actually configured at JotForm and tested end to end. We will not publish a specific figure here until deletion has been demonstrated to work. A retention promise that depends on somebody remembering to act is a promise that will eventually be broken, and publishing one you cannot keep is worse than publishing none.

We never accept or send identity documents by email. A document in a mailbox cannot be reliably deleted and would sit outside every retention policy we set. If you email us one anyway, we will delete it and tell you.

8. Your rights

You may ask us to:

Email us with your order reference and we will respond within one calendar month.

We will not ask you for identity documents in order to verify a request about your data. Demanding a passport scan to verify a request about a passport scan is backwards. A request from the email address on the order is normally enough.

Because our retention windows are short, a deletion request made a few weeks after your review will usually find that there is very little left to delete. That is by design.

You also have the right to complain to your national data protection authority.

9. Security

10. If something goes wrong

If a breach occurs that is likely to result in a risk to you, we will notify the relevant supervisory authorities within 72 hours of becoming aware, and notify you directly where the risk is high.

11. Changes

Material changes are noted here with a new date at the top of the page.


Still to be supplied

  1. Registered business name, address and company number
  2. EU Article 27 representative
  3. UK Article 27 representative
  4. Payment provider and email provider names
  5. Confirmed retention periods, verified against live JotForm settings
  6. A published sub-processor list

Until those are in place this notice is incomplete, and it should not be relied on as a final document.

Last updated: